How does NSO and/or it's customers steer clear of CFAA violations? Are they given some kind of perpetual amnesty?
Edit: Oh, they ran up against this just a few weeks ago according to their Wikipedia article. How about that.
Edit: Oh, they ran up against this just a few weeks ago according to their Wikipedia article. How about that.
Google could potentially sue them under civil CFAA if there was some unauthorized access to Google infrastructure needed to develop the exploits, but that's unlikely to be the case.
Using NSO tools against unwilling targets would violate US law, but that's not what NSO does.
Standby while I look for a source.