Facebook wanted NSO spyware to monitor users, NSO CEO claims
vice.com
vice.com
The honeypot phones would behave exactly like normal phones but save all incoming data at the lowest protocol layer (whether by wifi, cellular, Lightning connector, and maybe even in-circuit attempts to reflash firmware) to hidden internal terabyte microSD storage, which it would later exfiltrate back to Apple at some point —- perhaps by even having a second hidden cellular connection. I’m assuming that Apple has all the talent it needs to reverse engineer and plug the NSO malware once it has an actual copy of the malware.
I wouldn’t be surprised if everything that NSO does depends on just one or two extremely good exploits. Once Apple rolls out an update to patch the one or two critical bugs, it’ll stop NSO for a nice long time until they spend hundreds of man years or millions of dollars to find another exploit that’s just as good.
I'm sure you know this, but deliberately committing an act of espionage to directly or indirectly subvert the activities of government agencies would be a silly thing for Apple to try to do.
Their dollars are better spent on lobbying (make shit like this illegal), and engineering (make shit like this literally not work because iPhone is as secure as it can be).
What I mean is: making software like this for sale to the highest bidder should not be something a company is able to do legally.
It should be as bizarre as the idea of incorporating a business in the US specifically, and publicly, to rob banks or commit securities fraud.
I disagree. There ahould be nothing inherently illegal about owning, making or selling such software to an entity that can legally use it. (I would assume any country employing such software would indemnify there agents using it against foreign adversaries).
Not that I like it, and as a private citizen, I dont like thw prospect of being spied on, even though I have nothing to hide.
To stop it, I think you'd need to take a step back into the 90s and early 2000s and classify such programs as munitions and restrict export (not that all offerings are from US countries).
Have just read your answer and I totally see your point! I don't agree but it's definitely a judgement call.
Perhaps this would be a better way of expressing my position (with a few simplifications of the current situation):
1/ It seems morally wrong for it to be possible for an American company to buy spyware which exploits security vulnerabilities in another American company's software. The act of exploiting those vulnerabilities is illegal in the United States and against the terms of service of the software developer. The outcome of the exploitation (mass clandestine collection of user data without any permissioning) is also illegal.
2/ The US government could solve this by making it illegal for US companies to use the software, outright. They and other nations could also solve or diminish the issue for foreign nations by precluding private companies within their jurisdiction from building commercial propositions around these vulnerabilities. So both a ban on domestic "import" of the product, and a ban on "export" too.
3/ Clearly government agencies need and will continue to produce and procure software like this in the same way as they need to produce and procure military-grade assault weapons, surface-to-air missiles, and stealth bombers. The production, trafficking, and purchase of these items is highly regulated and tightly controlled: I cannot simply start manufacturing firearms because I have the equipment! This regulation is in part a means of preventing widespread availability of dangerous items getting into the hands of consumers and bad actors.
4/ At the very least, the same ought to apply here: an infosec company wishing to auction exploits or sell spyware SaaS should have to be very tightly regulated by the state, and should be unable to sell any of its products or services to any domestic or foreign entity without state approval — a QUANGO of sorts.
1. How big will the project be? I.E. what staff you need to develop AND deploy honeypot phones.
2. Who would decide targets?
3. What do you do with the data collected? Who enforces those rules?
4. How do you keep the project secret?
5. How do you prevent various 3 letter agencies from ordering you to deploy this technology for national security?
6. How do you protect Apple's reputation once it leaks out that there are secret phones that eavesdrop on you?
A better long term strategy is to offer large bug/exploit bounties. This foils malware and builds trust in Apple platform.
APTs are not exactly a new thing. On windows you get endpoint security software that logs excessive telemetry to a place threat hunters of security companies can search to find exploitation or infection attempts.
https://www.vice.com/en_us/article/pke9k9/facebook-wanted-ns...
"The Facebook representatives stated that Facebook was concerned that its method for gathering user data through Onavo Protect was less effective on Apple devices than on Android devices," the court filing reads. "The Facebook representatives also stated that Facebook wanted to use purported capabilities of Pegasus to monitor users on Apple devices and were willing to pay for the ability to monitor Onavo Protect users."
"NSO is trying to distract from the facts Facebook and WhatsApp filed in court over six months ago. Their attempt to avoid responsibility includes inaccurate representations about both their spyware and a discussion with people who work at Facebook. Our lawsuit describes how NSO is responsible for attacking over 100 human rights activists and journalists around the world. NSO CEO Shalev Hulio has admitted his company can attack devices without a user knowing and he can see who has been targeted with Pegasus. We look forward to proving our case against NSO in court and seeking accountability for their actions," the statement from a Facebook spokesperson read.
None of this makes the original claim true or false. I'll be curious to see what comes to light around that. I just like to notice these subtle things.
"purported capabilities to monitor users" can mean anything from full on CIA spy-mode with pema-enabling audio and video and 24/7 recording to logging their IP address when they visit a website.
Even the best case outcome is negative here.
This seems to be a case of the pot calling the kettle black.
"Please submit the original source. If a post reports on something found on another site, submit the latter."
^ This is what Mark Zuckerberg tells government and journalists.
And you know what? If you are a Facebook user, he's right! Only non-users and people dragged onto the platform only to communicate with friends/family/partners who insist in Facebook-only communication, have a right to complain.
Perhaps stock price/awareness?
The same way that lots of companies put their ticker symbol in their advertising, or the way local television news programs will put its parent company's ticker symbol in the closing graphics.
Facebook is actively malicious.
Then we only need to hate one company.
I did, and found out who my real "friends" really are.
You will probably have to install it for them.
Make a group chat.
Use it regularly.
But as it’s basically the same functionality, you won’t have to train them to use it. It’s worth it.
Also in mine, but it's not a global thing.