Spyware Maker NSO Group Promises Reform but Keeps Snooping
nytimes.com
nytimes.com
If their government is intent on protecting them from prosecution, then extralegal retributive action taken by an competing spy agency could be suitable payback. Unfortunately that assumes the existence of a competing spy agency that isn't equally morally bankrupt.
Not sure why this is being downvoted. NSO and its employees willfully facilitate criminal violations of CFAA, among other laws. (They have received payment in U.S. dollars, making the question of jurisdiction trivial.)
Given the heinousness of some of the crimes they've aided and abetted, many against American citizens, most Americans would be on board with arresting their employees on arrival to the America or our allies.
They are criminal accessories to gross human rights violations and murder, and should be prosecuted as such.
What about companies that produce bombs, will you arrest them as well?
Save your outrage for those who actually spied, not on those who make the tools.
Whereas Pegasus was designed to exploit a specific WhatsApp vulnerability, and to interact specifically with WhatsApp's servers. And NSO had paid support relationships with the organizations doing the attacking.
Another difference is that NSO employees themselves had to reverse engineer and exploit the vulnerability during development (possibly illegal under the CFAA). This action also violated WhatsApp's terms of service. There's no parallel to this with guns and bombs.
Another difference is that according to the complaint, NSO-operated servers talked to the exploited devices. So this wasn't just a tool that NSO handed over to governments to be used (like guns and bombs) and then was uninvolved in, it was a service that NSO operated, and governments issued commands to the service telling it who to attack.
Are exploit brokers like Zerodium exempt from this criticism because they off load the targeting and execution part to third parties and governments?
There's a limited pool of talent that can generate something like this. If you make is sufficently toxic and/or difficult to work for a company that involved with flagrantly violating human rights (like NSO), you'll substantially starve them of talent.
Worst case, you'll significantly reduce the quality of their exploits. Best case, it'll be effectively unavailable.
The people with power to be hostile to exploit devs who sell their talent to the highest bidder are the same people who are bidding for that talent. So long as NSO group and others dont harm the interests of countries protecting them they will always be in demand.
If even the entire west punished developing exploits for money a high crime, at best you give business to chinese,russian and indian companies. At worse, western devs move to other coubtries or simply sell exploits illegally without getting caught...to non-western entities.
The only way to beat this sort of a problem is to compete with demand. But that means competing against resources of nation states. Perhaps international treaties to control this arms race would help?
And yes, I know at best there are only a few hundred people with enough talent, but I bet you there are even less nuclear bomb scientists and you know how that supply/demand is turning out...
Presumably to another company where they live, or are comfortable relocating to.
You seem to continuously be assuming a perfect market, that doesn't exist.
I agree that just blocking this sort of thing from countries that actually care about human rights won't solve the issue, but stopping a lot of it is still valuable. Additionally, I don't know if this sort of thing could exist in some of the countries you name. For China, at least, it sure seems like if you're good enough at this sort of thing, you get strongarmed into their existing military infrastructure used for spying on everyone else. I can only assume Russia is similar. I don't think either of those countries have free enough markets that a NSO-like company could exist.
India, I don't know enough to comment.
> At worse, western devs move to other coubtries or simply sell exploits illegally without getting caught...to non-western entities.
Do people just up and move to other countries at the drop of the hat? That requirement alone is going to substantially reduce the number of people doing this sort of work.
Again, the goal isn't to completely prevent exploit sales (which I agree is basically impossible), but to reduce the harm. Stomping out these companies (or having MUCH more aggressive oversight) won't substantially impact the hosting state's economy, and it will substantially reduce the available products on the market. I can't see a argument against that.
You think reducing volume means what little supply is available will be used against high value targets only. In reality, the smaller supply will focus more on high value exploits which will still be leveraged at the same scale. Even if that was not true, you still have no control over exploit sales and use.
Allowing places like NSO and Zerodium to thrive with some control and restrictions is the best outcome. But really, do we even have law makers that understand any of this or perhaps the NSA/CIA can control them. Normal security companies have intel community ties,I think that can be acheived here as well.
What further surprises me is that this article speaks only about India. Hasn’t Pegasus been used by other governments too?
Or is the toolmaker a much easier target? This criticism really seems misplaced to me.
I have to wonder if you’re being serious when you describe the kind of software NSO produces. It’s software to let other people take control of hardware you possess. The better analogy would be to the iOS jailbreaking folks; people aren’t generally mad at them either.
Let's try this NYTimes: "Israeli company NSO Group Promises Reform but Keeps Snooping". That conveys the essential facts at a glance.
"NSO creates technology that helps government agencies prevent and investigate terrorism and crime to save thousands of lives around the globe."