Leak uncovers global abuse of cyber-surveillance weapon
theguardian.com
theguardian.com
It sounds like the new info putting them back in the new cycle is related to this sentence:
"The Guardian and its media partners will be revealing the identities of people whose number appeared on the list in the coming days. They include hundreds of business executives, religious figures, academics, NGO employees, union officials and government officials, including cabinet ministers, presidents and prime ministers."
Should be a very interesting release.
Most people simply don't care that much about digital privacy. Lots of people believe Facebook is spying on them constantly including recording everything said in the presence of their phone and many of those people go right on continuing to use those apps.
if this were true, cardiovascular disease and cancer would be the top stories everyday, as they combine for tens of millions of deaths per year. the media focuses on novel fear because it's attention-getting, not rationally dire.
And you can't just blame this on the generic "media". They sell what the people want to buy. They report on novel fears because that is what attracts more attention from readers/viewers. The story about a murder is always going to get more attention than a dozen people dying of heart disease.
It isn't that the media doesn't care about these privacy issues. It is that people generally don't care about these privacy issues.
the point is that the pandemic isn't a bigger threat to our daily lives than common diseases for most people, yet we've blathered on about it like it's an imminent threat to everyone for over a year and a half. we don't do that for (other) respiratory infections or tuberculosis, for instance, which affect the same order of magnitude of people worldwide every year. this misfocus is acutely irrational (an availability/recency bias). the novelty only exacerbates the misfocus, it doesn't justify it in any way.
the pandemic isn't even a long-term threat in the way that concentration of power, as manifested by this privacy/surveillance issue, is for every person on earth (and the way climate change is for humankind on a multigenerational scale). it's just that the change is so relatively slow and incremental that we don't understand the severity of the threat until it's overwhelming. it's how we boil frogs so easily.
The forensic investigation showed that bezos’ device was clean. From what I saw.
HN called them out on failing to decrypt and properly analyze the file when that came up:
https://www.vice.com/en/article/v74v34/saudi-arabia-hacked-j...
Reviews of the report suggest that it contains circumstantial evidence, but lacks conclusive evidence:
https://en.wikipedia.org/wiki/Jeff_Bezos_phone_hacking#Analy...
Don't you?
I use mine in the bath.
One is an crime.
Personal disclosure: I've never sent nude photos of myself, until I had a super-hot girlfriend repeatedly ask for them. She got the photos. Was it a long-term smart move on my part? Probably not. Anything could happen in the future. Did I care at the time? Not at all. Sometimes a zero-tolerance, "just say no" policy isn't going to work.
https://www.vice.com/en/article/v74v34/saudi-arabia-hacked-j...
Bezos asked his security consultant Gavin De Becker, to conduct the investigation he did and published his oped in a month.
The brother bla bla bla is just a distraction deployed by those who want you to believe NSO wasn’t used on to hack the phone of an American citizen.
https://www.thedailybeast.com/jeff-bezos-investigation-finds...
We discussed it here as well https://news.ycombinator.com/item?id=19532185
I will admit I am tantalized.
Did all of the media outlets organize together for months in advance to be able to release everything today? The content and production quality makes it seem like this release was planned months in advance.
Also, assuming they did, what’s the process all of these news organizations go through in order to plan such a release on the same exact day? The planning of the release in such a coordinated way is almost questionable itself, though it would be good to get insight into this.
It was that movie/documentary where I first heard of Pegasus and how it had been used by the Saudi government.
The last I can remember was the Panama papers, which followed a very similar process. I seem to remember they all synchronized through the ICIJ [1], and more or less each journalist would cover their own territory / domain. Then they agreed on a reasonable date to release the news.
They shared more than just information, but also technical infrastructure to do the investigation.
> Forbidden Stories, a Paris-based nonprofit media organisation, and Amnesty International initially had access to the leaked list and shared access with media partners as part of the Pegasus project, a reporting consortium.
[broken link #33] https://forbiddenstories.org/they-support-us/
"Prominent supporters are:[33]
Can Dündar, former Editor-in-chief of Turkish newspaper Cumhuriyet
Khadija Ismayilova, Azerbaijani investigative journalist
Marina Walker Guevara, deputy director of the U.S.-based International Consortium of Investigative Journalists[34]
Bastian Obermayer, Pulitzer Prize-winning German investigative journalist with the newspaper Süddeutsche Zeitung
Fabrice Arfi, Co-head of investigations at French online newspaper Mediapart[35]
Will Potter, U.S.-American investigative journalist
https://en.wikipedia.org/wiki/International_Consortium_of_In...
Usually, joint investigations between multiple media outlets are released in a planned fashion. It's rare to see 17 news outlets collaborate on one story, but when "more than 180 journalists" have been targeted with Pegasus, it may be that the targeted journalists worked together on this investigation, using their exploited devices as evidence.
Snowden basically dragged news orgs into reporting it. After that initial rush tho, reporting was largely muted. Most DoJ and other abuses were minimally covered if at all.
That improved somewhat during the next administration but authoritarian deference still seemed in play to me.
I heavily disagree?
With this report, the Amnesty International has also released Mobile Verification Toolkit (MVT) - a forensic tool to look for signs of infection in smartphone devices: https://github.com/mvt-project/mvt
Also rather stupid was Apple's statement about their phones being secure, when its obvious there are zero days being sold to NSO instead of telling Apple. Everything is insecure these days, at some level.
If NSO paid people $1M for a zero day (I bet they don't say), and Apple/Google/etc paid $10K, who do you think gets the info.
Beyond those buyers, the lines start to blur (defense contractors, companies in countries allied with the US e.g. FVEY). I would not recommend it either. Unethical buyers have completely different interests. I know Zerodium for one is a terrible place to sell to (you may be a target), and anything that is sold to Crowdfense is likely to be used against American interests.
My take away advice is, you can choose between painting a target on your front or one on your back.
ZDI, on the other hand can say: "We want $10M for this iOS zero day, or we don't report it to you." And the process of negotiation goes back and forth, but the end result is, Apple will pay considerably more to ZDI than through the direct program.
Or rather that when i cross the wrong broader in to the wrong country that i might disappear?
Summary: Wired report is a $1M and Ars reports three, one at $2.5M - all paid by Zerodium. Wow.
Google, on the other hand, regularly pays white-hats something like $100k for "arbitrary access to contents of any Gmail content".
Apple has never made such a statement.
From the article:
> Apple said: “Security researchers agree iPhone is the safest, most secure consumer mobile device on the market.”
Saying they claimed their phones to be secure is just a lie.
It is a claim of relative security but it is a lie to say that Apple claimed their device is secure.
>The average reader would not interpret that statement as you did
I think most people can read the statement for what it is - a comparison to other devices on the market.
You are imagining that computer security is absolute. A system cannot be 100% secure or 100% insecure. To claim either is obviously false.
Systems can be relatively more or less secure than other system.
It's as if they are vetting for the most authoritarian, human-rights-abusing, anti-free-press countries in the list. A peculiar vetting process indeed
Question: How would you solve the Trolley problem?
Answer: By using more trolleys.
NSO are clearly concerned about any such claims sticking.
Shared and joint liability for such consequences of software and tools strikes me as one of the more viable ways of limiting their over development.
Finding a firm, its officers, its engineers, its salespeople, its investors, and its creditors culpable for assassinations and murders would tend to dampen enthusiasm significantly. That's not enough to utterly quash development, but it makes it far more expensive and unattractive.
I don't have high hopes for this. But one may dream.
Unprecedented action needs to be taken against NSO Group.
At least it's an interesting question why so many shady companies seem to operate out of Israel.
My proposition is to put known employees of these companies on a blacklist for conferences like CanSecWest or similar.
For example:
> Despite rules saying the UK should not export security goods to countries that might use them for internal repression, ministers have signed off more than £75m in such exports over the past five years to states rated “not free” by the NGO Freedom House.
> The 17 countries include China, Saudi Arabia and Bahrain, as well as the United Arab Emirates, which was the biggest recipient of licences totalling £11.5m alone since 2015.
> Human rights groups said the UK was developing a reputation for not conducting proper checks on who it sold arms to, while Labour called on the government to show it is working to prove that it is complying with its own rules against arming dictators.
- UK selling spyware and wiretaps to 17 repressive regimes including Saudi Arabia and China[1]
Or just search[2] for "gamma" and "privacy international"
1: https://www.independent.co.uk/news/uk/politics/uk-spyware-wi...
2: https://www.google.com/search?q=%22gamma%22+%22privacy+inter...
Compromising the personal devices of private citizens for nefarious means should be globally illegal and, if perpetrated by a government, should be considered an act of war.
Why does it seem like we're all just kind of okay with citizens being attacked like this?
Is there a reason we also also forbid Google and FB from gathering this information? Or are their business models too important, and we can't decrease shareholder value?
Or since "the users" click-agreed the business model is absolved and it's okay! What could go wrong, ever?
Or, a modest proposal: we could agree that even corporations who sell HW/SW for personal devices shouldn't be allowed to collect this data, period. No one needs to mine our GPS history, messages, search, etc. Even if it means those who do it today makes less money.
Ads are fine, but maybe we agree it's fine if ads aren't quite as targeted, either.
I'm wondering if we might be better off with "punch the monkey" than hyper tracking and targeting.
Both India and Hungary are currently governed by anti-democratic right wing administrations (Modi and Orban). Not that surprising to see the State try to abuse power.
The list for India is weird though. It has a lot of names which are in the pro current establishment camp and some of their own leaders as well.
Could it be some other state snooping on them or has it found usage by non state actors as well?
Ah, that's incorrect. The first article released yesterday released names of 40 Indian journalists. I see a few pro Modi names there. https://thewire.in/media/pegasus-project-spyware-indian-jour...
As far what's to come: "The numbers of those in the database include over 40 journalists, three major opposition figures, one constitutional authority, two serving ministers in the Narendra Modi government, current and former heads and officials of security organisations and scores of businesspersons."[1]
These will be released in further articles of the series "Project Pegasus"
[1] https://thewire.in/government/project-pegasus-journalists-mi...
It’s not that weird when you look at it. Most news agencies are privately owned. These journalists aren’t born stooges of the Government. Many of them were forced to become pro-Government when the Government threatened to pull advertising by Public corporations on their networks. That’s one lever. Having dirt on the journalists? Another lever.
In fact, I would argue, that they have a mandate from its people ( hence they are democratic ) and their program is very open about the changes they propose ( which may unpopular in EU salons, but not for an ordinary citizen ).
This market has been developing for the past 2 decades there are a lot more players than NSO and most of them aren’t in Israel.
Hungary is being run as a cleptocracy, it will align with whoever gives the chance for higher embezzlement.
On a completely unrelated note, if I were a security researcher, I'd start being extremely mindful about to whom I'm selling zero-days.
Unless you're dependent on the money, responsible disclosure is probably the most ethical way.
If this bothers you the best thing individuals can do is invent better computers.
https://www.theguardian.com/news/2021/jul/18/what-is-pegasus...
I am not defending NSO here, but I just want to provide a sample of a simple defense of this. In practical sense, there is very little regulation in this space. And if you add to it some of the territories involved in that race, you will quickly notice that it may be hard to force them to do anything. They are sovereign after all.
Maybe it isn't practical when you have trade secrets and engineering actively working on development. But maybe if IT was given this constraint, they'd figure out a solution.
> The research, conducted by Amnesty’s Security Lab, a technical partner on the Pegasus project, found traces of Pegasus activity on 37 out of the 67 phones examined.
> The analysis also uncovered some sequential correlations between the time and date a number was entered into the list and the onset of Pegasus activity on the device, which in some cases occurred just a few seconds later.
> Amnesty shared its forensic work on four iPhones with Citizen Lab, a research group at the University of Toronto that specialises in studying Pegasus, which confirmed they showed signs of Pegasus infection. Citizen Lab also conducted a peer-review of Amnesty’s forensic methods, and found them to be sound.
---
> NSO has always maintained it does “does not operate the systems that it sells to vetted government customers, and does not have access to the data of its customers’ targets”.
Private spy software sold by NSO group found on cellphones worldwide - Washington Post
https://www.washingtonpost.com/investigations/interactive/20...