7 ms·
I've interviewed with these types of companies (not the ones in the article). I've even caught them using their exploits on me after they made me an offer and t
by bink 1y ago
I've interviewed with these types of companies (not the ones in the article). I've even caught them using their exploits on me after they made me an offer and that seems to be the most likely explanation for what happened here. I don't know how anyone can develop exploits for resale in good conscience.
If these companies have no qualms using their exploits against their own employees they'll have absolutely no problem using them against members of Congress, the Courts, investment banks, tech leaders, and anyone with any sort of power. This gives them the ability to blackmail some of the most powerful people in the world.
edit: And that's not even mentioning their reported "intended use" against dissidents and journalists.
- Ms-J 1y agoThat's outrageous that they tried to attack you like that. How exactly did it happen? Did they send a link via SMS to your phone, or some other way?
- bink 1y agoI don't wanna give away too much in case they're reading, but they didn't use their stealthiest exploit. It was pretty obvious, especially if you monitor your network traffic.
- cj 1y agoHow obvious would it be to someone being hired as an office manager or janitor or similar?
- cobertos 1y agoMonitoring your network traffic on your local PC (ala Little Snitch or Open Snitch) or monitoring it at the gateway/router level?
- bink 1y agoAt the router level. I turned off cellular data to be sure, but I don't even think that was necessary since it was on wifi.
- matheusmoreira 1y agoI gotta admit I'm not in the habit of monitoring my network traffic... Gotta wonder if it's even possible to protect ourselves against this surveillance without going full OPSEC mode.
- throwaway48476 1y agoIf you're developing tools you're likely testing against vendor network monitoring apps and in the habit of using them.
- Ms-J 1y agoOk guessing against a computer of yours and not a phone (which of course is still possible) thanks. Hope it can help all of us stay safe.
- commandersaki 1y agoI really don't want to belittle what you say, but this just looks like misplaced paranoia.
- tptacek 1y agoYou don't know how any of these could be developed in good conscience? How about: anti-proliferation intelligence work is going to happen whether it requires human intelligence or CNE, and CNE is less costly and harmful? I get where you're probably coming from: this same technology is used all over the world to target journalists and dissidents in countries with and without the rule of law. A very real concern. I wouldn't do this kind of work either (also, it's been over a decade since I had the chops even to apprentice at it). But there are very coherent reasons people are comfortable doing this work for NATO countries. Our reflexive distrust of law enforcement and intelligence work is a fringe belief: a lot of families are very proud to include people working in these fields. The most important thing I guess I'd have to say here is: our opinion of this stuff doesn't matter. At current market rates every country in the world can afford CNE technology, and it's a market well served by vendors outside of NATO.
- Ms-J 1y ago"our opinion of this stuff doesn't matter." It very much does matter. If more people refuse to do this type of work, it eventually won't be done to the required standard. People would cut family ties and this would stop fast.
- tptacek 1y agoThat's an incredibly blinkered view of the ecosystem that assumes that the only talent capable of delivering this work is people you talk to or share cultural ties with. There are ultra-skilled people in developing countries who could not give less of a fuck about how uncomfortable this stuff makes people in the west.
- GauntletWizard 1y agoThere are tons of people in the West who have no qualms about doing this for pure crime purposes; many of them are the ones who espouse most ardently that doing this work for the government is immoral.
- 1y ago
- duxup 1y agoI think by default these companies kinda filter out people with values that would impede unrestricted use of their tools. And at worse possibly attract people who think "I'd sure like to spy on other people". That's scary.
- gessha 1y agoThat or they mask their activity with layers of management and vague and abstract products.
- saagarjha 1y agoMaybe that was just a phase of your interview.
- neilv 1y agoI figured security researchers were always targets of multiple APT actors and random individuals. However... > I've even caught them using their exploits on me after they made me an offer Not only for exploit companies that eat their own dog food, nor only cybersecurity jobs, but I've heard of this happening to people interviewing for other tech area considered strategic. The noticed ones weren't that subtle, and were presumably noticed because the attacker wasn't using the best methods, but maybe more routine SOP for lower-value targets. I have no idea what the actors and motivations actually were. Speculation: * the hiring company or its country, vetting the candidate by spying on them, including for corporate/national counterintelligence reasons (it's really not much different than a lot of the sneaky surveillance capitalism vetting that many companies quietly do, just unambiguously illegal in this case); * the hiring company, spying to monitor the competitive offer situation (e.g., what counteroffers or concerns does the candidate have); * other state, individual, and possibly corporate actors, for whom the imminent offer flagged the target as worth keeping an eye on (for, e.g., advance access to research they do individually, knowledge of attacks they do individually, possible technical entry point to the job-offering organization or others, or kompromat for getting access/actions); or * random associated individuals acting on their own, recreationally enjoying the power over others that their cracking toys give them (which at least used to be not too uncommon, before cybersecurity was professionalized, when there were proportionally much more teens and alienated people, and they hadn't yet been told about color-coded hats for prefabricated codes of behavior from which they could choose; now, most people with skillz have the carrot of a lucrative job or respected status as researcher that they can pursue, instead of seeking power/status other ways and without guidelines). Personally, I try not to work on strategic target areas, since I like to save my very limited guts for fighting product concepts and reliable systems into shape, not for being helplessly violated by lawless authoritarian institutions. Good luck.
- jokoon 1y agoThis is why I don't want to work in cybersecurity This is too dangerous, it's the wild west
- hopelite 1y agoForget blackmail, people wildly overestimate the value of blackmail. Far more predictable and lucrative is just to use exploits for insider information, including as favors and bribes, and selling them to governments willing to pay immense amounts of money. Blackmail is far too messy. Grease works way better.
- throwaway48476 1y agoPlata o plomo. Usually a combination of threats and bribery is most effective. The truly dangerous groups usually have the ability and willingness to pay well.
- hopelite 1y agoSorry, that’s just not how it is practices and at least has not for a long time. You’ve heard the saying, you catch more flies with honey than vinegar, right. If you have unlimited funds and you are the giver and bringer and provider, there is no need for blackmail. It’s just the nuclear option, so to say. At the political level things don’t operate like some cartel, sort of certain places and certain rather narrow regions of the world where it may take some additional motivating to do the right thing for themselves.
- throwaway48476 1y ago"It's the implication"
- octoberfranklin 1y agoForget blackmail Tell that to Epstein.
- hopelite 1y agoIronically that actually applies to him too. Sure, he likely had all kinds of stuff on people, but frankly bribery still always works far more effectively unless you encounter some resistance. It’s a rather established practice. The “blackmail” material is really just an insurance, not actual leverage.
- IT4MD 1y ago[dead]