Private Israeli spyware used to hack cellphones of journalists, activists
washingtonpost.com
washingtonpost.com
Every time we allow special laws or special tools to fight "terrorism" or "child abuse" or other evils that get people worked up, they end up being used against the people in general. Every time. Why are we even surprised.
You are right. Terrorism and cp are commonly used excuses to enable even more surveillance.
When you talk about “allowing laws” it makes it sound as if we somehow got conned into letting them have these laws. In reality powerfull people want these tools. Powerfull people get these tools. Where does the allowing happen exactly?
And don’t tell me that all would be well if only we would vote for the other guy.
Voting against any politicians who contribute to its passing, even if they're from your preferred political party.
We already see this in American primary elections where the incumbent runs against a half dozen or more “nobodies” and seems to win on name recognition and vote splitting alone.
For instance, many Americans heavily favored Bernie Sanders and Elizabeth Warren who were both policy candidates in 2020. With ranked choice, they would have been the P/VP pairing. Instead, it went to Joe Biden because the candidates all dropped out and gave him their endorsements months prior to the end of the primaries to prevent Sanders' nomination and to secure a little political capital.
The current system is designed (to be able to) rob any candidate who builds popular support over the establishment. For instance, superdelegates are bullshit, but they're the tool the DNC decided on to prevent another Carter from happening, which is how they viewed Sanders.
Biden didn't even campaign and ended up POTUS, and he hasn't done anything towards enacting any of the promises he gave lip service to during the debates. I just wonder if that's not backfiring, what is?
Arguably 4 is too low a number to represent the varied interests of any state, and the first round will likely leave people unsatisfied until candidates can start researching the actual values preferences of their electorate and offer e.g. the top 4 ways to order the most important issues and alignments. I think there will be a strong force to abandon divisive hot-button issues that sound good on TV but are actually lower on most people's preference ordering.
As I often point out, surveillance is bad but so is child abuse and complaining about surveillance without acknowledging that is a good way to get ignored.
This is a very Machiavellian and realpolitik take, so please keep that in mind. People in a democracy “allow” laws whenever they just continue to live normally. Sure, you can protest with signs and vote differently in the next election, but we know that’s not particularly effective at shaking the status quo.
What does “not allowing” a law look like? Civil disobedience, defiance, harassing politicians, and trying to force change. In essence, it’s average people and activists using every tool at their disposal to force the politicians to act differently. We saw plenty of this in 2020.
> ""public health" is now likely to be a part of the surveillance justification tool kit too"
I don't have any specific examples, but this article gives a good gist of what might be at stake. [1]
I think this is a key quote
> "The Snowden disclosures came twelve years after the initial implementation of the Patriot Act, and it was only last year that the U.S. Court of Appeals for the 9th Circuit ruled that the subsequent dragnet surveillance employed by the NSA may well have been unconstitutional."
[1] https://slate.com/technology/2021/07/government-data-collect...
https://www.businessinsider.com/nyc-contact-tracers-not-aski...
All state governments had initially ensured the public that the data was not available to LE, but none of them had actually passed legislation to make it unlawful until journalists discovered that the Police were using the data.
https://www.afr.com/policy/health-and-education/call-for-nat...
https://www.abc.net.au/news/2021-06-15/safewa-app-sparks-urg...
https://www.innovationaus.com/qld-police-accessed-qr-code-ch...
Of course that didn't stop police from still going into some places and demanding the data. But doing so was a clear breach of law.
Every piece of personal data you collect creates a pull factor for various actors to abuse said data, which is why you shouldn't collect more than you need, you should delete (or anon/pseudonymize) it once it is not needed anymore or you should collect it in such a way ot wouldn't be useful for state actors.
I am amazed how the German Corona-Warn-App was designed with these principles in mind. They managed to allow people to register into locations while only storing the data locally on your phone. Your phone then downloads the data from the servers in an non-revealing way and queries it for warnings/positive cases that have been issued in these locations at that time. If yes, you get a warning and you can decide how to proceed with this without having any other actor knowing of this.
This software is a piece of art from a privacy standpoint.
https://www.reuters.com/article/us-health-coronavirus-singap...
Otherwise we end up with the "who watches the watchmen" narrative over and over.
It's still arguably better than dictatorships, where your citizens don't matter either, as long as you have a good police system.
We act surprised when we notice such things but we shouldn't be, it is a mistake to apply the same standards that we, as the lucky citizens of "free countries" enjoy, to any other system of power.
From a less cynical point of view, as an Israeli, I am not happy at all to see this kind of export products from my country. It is in great part because of the conflict. Te SIGINT units are huge and among the people who graduate from the army with this kind of knowledge you will certainly find many who will turn a blind eye to ethics for a huge paycheck. Not to mention that the research itself that the defense apparatus needs attracts capitals from other countries that will buy some of it and use it for unorthodox means. I wish we exported less of these things, especially to autocratic countries. I agree it's horrible.
Not long ago, what determined whether you "mattered" or not was your religion and belief. We now replaced it with a state issued piece of paper and convinced ourselves that this is progress.
Also, "belief" has a propensity to produce circular logic (I believe in X because X is true), non-escapable rational traps (you don't believe in anything, so you believe in non believing, so you believe...), tribalism (we should convert the nonbelievers), righteousness (how can't they see it? It is the truth), wishful thinking (I believe that X is good and Y is bad so of course I will ascribe every good event to X and every bad one to Y), insincere debates, existential crisis caused by the lack of it, and so on... So as much as it's possible I in favor of leaving beliefs and religions out of the analysis.
But two wrongs don't make a rights. It's despicable to export weapons, especially to dictatorships, no matter if you are Israel, China, Russia, Italy or Sweden (the last two being major weapon exporters but keeping themselves conveniently under the radar)
But I am sure that governments of all countries might be interested because it is just a weapons race from their perspective. A race to the bottom again.
The people who work at NSO and companies like this are a stain on the whole tech industry and are outcasted by their own IOF peers for being greedy and morally-lacking.
Absolutely disgusting to think your hands are clean while you make tools that directly empower dictators and keep whole regions of people subjugated.
Can't get a job at Google under security? Guess I need to hack for Russia.
I think we should shun marketers too, they literally use exploits on our brain.
So far my quest to encourage only positive jobs hasn't changed anything.
Cause I think I'm in the wrong game
Their sells are export controlled in a similar manner that arms sales are.
Same with suits.
it would be like trying to sue a ransomware group in russia, or a phone company in america.
The state absolutely has the power to turn this into an instrument of foreign policy; it has chosen not to do so, in order to use it as an instrument of military-industrial policy.
(To be clear - the Israeli state is absolutely the actor to put pressure on if you want this kind of thing to stop, and indeed bears moral responsibility. But the actions of these companies are not so closely tied to Israeli state interests as to make them immune to lawsuits abroad, or even in Israel if they violate Israeli law.)
The article says that the governmental agencies are breaking into the phone. These hacking companies just license their software to these governmental agencies.
It is illegal to provide assistance in the commitance of a crime even if you're not the one that pulls the trigger.
Isn't that basically the same as selling weapons?
(I would appreciate if no worker of the rank would accept to collaborate with manufacturing any form of weapons, but we are well past the point where lay people make their own mind about these things)
How many states do you know where that's explicitly legal? The only one I know is Russia.
(If, say, Saudi Arabia tracks down a journalist because of NSO, then, what might follow thereafter)
Like Russia, Israel doesn't seem to give a damn when criminal enterprises operating in their borders victimize people in other countries. This shit has been going on for years: https://en.wikipedia.org/wiki/Download_Valley
2. You say 'adware', while Wikipedia says: "These software items are commonly browser toolbars, adware, browser hijackers, spyware, and malware."
3. I provided two examples of countries that operate like this, not a comprehensive list. I gave the second example to make clear that I was not claiming only one country operates like this. I already clarified this for you.
I don't think you are commenting in good faith. I will not respond to you again, even this response was doubtlessly a waste of my time.
But they are breaking the law. Same as many security agencies. It just doesn't matter.
Facebook is suing NSO Group and winning, at least on procedural grounds [1].
[1] https://www.reuters.com/article/us-facebook-nso-cyber-idUSKB...
Snowden needs to repeat and remind people, over and over, that people should just not trust their electronics if they are doing sensitive work that somebody powerful elsewhere (government or a rich company) might not like.
I'm also curious how whatsapp/facebook will respond to those vulns. Hard to really trust them at all, it's really easy to imagine a conspiracy theory when intelligence agency negotiate inserting backdoors into popular software.
I'm really discouraged from working in computer security, it really looks like a shady industry.
Old-school techniques such as physically smuggling microdots[1] seem much safer than relying on any computer technology, which can always be hacked.
These firms are helping authoritarian regimes kill and imprison journalists. The journalists who survive by being paranoid will be made less effective by having to use less effective methods of communication, which likely aren't understood by the people journalists talk to (whistleblowers, witnesses, etc.)
Also reports Mexican journalist was hacked, then executed right after at an obscure location. Heavily implies GPS tracking was used for the hit.
And that's before considering that a journalist would never have a realistic chance to meet potential sources under repressive regimes on the other side of the world, certainly not a useful number.
Computers and encryption made this kind of covert communication far more accessible to the laymen. Anything that sets that back just deters people from even trying and this is exactly the chilling effect those oppressive regimes are looking for.
The difference is you need way more resources and funds to physically watch and search a lot of people than to spy on their computer communications or hack in to their phones/laptops.
Mass computer surveillance is practical, easy, and affordable.. mass physical surveillance is much harder, much more expensive, and impractical to do effectively on large populations.
You're right but old-school methods make everything impractical, hard, expensive, and far riskier for both the dissident who already has enough reasons to just stay quiet, and also for the journalist. They set a very high bar for succeeding. You're asking a regular person to take the end-to-end role of a Cold War spy and their source. And this when having access to sensitive info, suspicious purchases like photographic equipment and chemicals, trips abroad, or any attempt to contact a journalist would individually be enough to put someone on a watch list. There are only so many ways to get in contact with a journalist and set up meetings that don't involve any electronic communication.
The state can take a lot more than the individual. So the question is how many people who have sensitive information to share could or would go that route in face of this dramatically mounting pressure? Anything that raises that bar for doing it is a win for the oppressive regime because it makes surveillance that much easier.
People sometimes seem to imagine some world inhibited by security-conscious professions that is more akin to a slick movie than real life. Witness the common believe that, say, blocking websites at DNS levels has zero impact on crime because it's easy to circumvent.
Real-life criminals, journalists, or activists prefer Telegram over code tattooed on a messenger's scalp for the same reason we all do: hair grows too slow and nobody is getting on international flights right now. I know it's fun to imagine all these activities involving "threat actors" and steganographic key exchanges via Pornhub (Alex and Bob getting on?). But that road leads to busywork that doesn't get any corrupt politician's name on that white page.
An exploit is to encryption as a sword is to a shield.
We don't regulate shields.
Stop trying to find gotchas. Weapons (read: items whose primary goals are to inflict damage, maim, kill, injure, destroy) are and should be regulated.
That's your mistake right there
I wonder what the rationale behind this federal law is. Does wearing/purchasing armor indicate that you, convicted felon, are simply up to no good once again? Is it one of those "you don't need ~~privacy~~ armor if you don't have anything to hide" things?
[1] https://www.shotstop.net/resources-1/2020/9/8/is-it-legal-to...
Or a company for that matter, if we want to keep up the pretense that the NSO group is acting independently.
If you can secure a movie from being copied by the owner of the device showing the movie, you can hide spyware on that device. That's OK for a usb gizmo you plug into your TV, but why would supposedly security minded enterprises accept that in their computers?
This happens in finance, tech, food, pharma and pretty much all the industries that have a "legal" risk due regulation.
If breaking the law means a fine that sometimes is less than the profit then you can imagine that the incentive is to break the law.
They likely do not sell to anyone or for any reason that does not contribute to Israel’s foreign policy in some way or another.
These days that is a very real possibility if you run Windows.
You've already lost, then. Printers' output can be uniquely identified.
Nothing should ever be in dead-tree format. If you need to carry something that does not need electricity to display text, use eInk. Or build your own printer.
Nobody mildly self-conscious with a shred of ethics works there.
It's not fair to an entire industry to be painted in this light because of one bad actor.
We’re at the point of, at the very least, barring NSO Group, its employees and its investors from travelling to the U.S., using our financial system or keeping assets here. (Which would indirectly bar our police departments and agencies from contracting with them.)
Financing terrorism is a crime. Aiding and abetting journalistic suppression should be in a similar, albeit lower severity, category.
I haven't followed the US response to the behaviour of NSO Group but if things like you mention have already been done I very much doubt it isn't a smokescreen. The US is arguably the biggest user and customer to these kinds of services.
>Financing terrorism is a crime
Yes but if you have the power to define what is and what isn't terrorism (or journalistic suppression) then a law is useless. Fixing this is beyond the reach of a representative democracy and the likes. It needs a full-on direct democracy and enough citizens that are against it or a Dictatorship with a dictator that is against it. Otherwise any law pretending to be against stuff like this are at best a smokescreen or at worst a plot to keep it for those in power but out of reach of anyone else.
So perhaps that's a way in? If not law in civil court? pardon my lack of legal jargon/knowledge
"Also listed in the leaked records is a UK phone number belonging to the American investigative journalist Bradley Hope, who lives in London. At the time of his selection he was an employee at the Wall Street Journal."
https://www.theguardian.com/world/2021/jul/18/ft-editor-roul...
With great power comes great responsibility, and if you knowingly use your great power to write this kind of software you are a terrible person, in my opinion.
I can't say I know where the line is. For example, would it be unethical to work for Facebook? I don't know and I don't think so. Working for an online casino? In my opinion yes, but others would disagree. Writing software that is used by authorities to hack activists cell phones? Absolutely! It's so far beyond the pale that I can't fathom how anyone could defend it.
One of the things you'll learn in an ethics class is that ethical values are heavily influenced by culture and circumstance, and there are vast differences in what different groups of people believe is ethical and not.
Of course they have been exposed to ethical questions for writing the software. If you know Israel well, and the famed Unit 8200 [0], the initial creation of this type of software is definitely built with morals in mind - saving lives is the entire impetus.
Lots of security software out of Israel (see CheckPoint, a now public company) is first born out of the IDF with the goal of fighting terrorism and criminals. I don't see an ethics class being the answer here, as this type of cyber & security software has certainly saved lives. The issue is what happens after this software is developed, with seemingly justified reason to exist, and now in the hands of a business growing around it.
[0] https://en.wikipedia.org/wiki/Unit_8200
[1] https://www.theguardian.com/world/2021/jul/18/revealed-leak-...
I'm a software developer so my life is all about identifying and fixing bugs. And it is a "bug" and a big problem that developers are willing to write software to hack journalists' and activists' cell phones. We should fix this bug. More ethics education? Shunning developers writing phone hacking software? I don't know what the solution is.
There will always be people who will build weapons, and those weapons can always be used on innocent people. The only hope we have is that the people holding the weapons will have the right environment and presence of mind, and we can only do that through culture and education.
Plenty of people work on products that may be immoral in some application or frame of reference.
Developing technologies that facilitate the predatory practices for social media networks, ad targeting, gaming/gambling and plenty of other shit.
And this goes beyond tech I don’t think that the 40 something machinist that works at Glock in Austria or the 23 year old EE engineer that works on imagines sensors for BAE in the UK some loses sleep at night because a handgun or some guided bomb somewhere killed someone.
https://citizenlab.ca/2018/09/hide-and-seek-tracking-nso-gro...
https://www.amnesty.org/en/latest/research/2021/07/forensic-...
> NSO Group licenses its products only to government intelligence and law enforcement agencies for the sole purpose of preventing and investigating terror and serious crime. Our vetting process goes beyond legal and regulatory requirements to ensure the lawful use of our technology as designed.
Also, the company's owner, Novalpina, is not Israeli, though the founders and engineers of this particular surveillance product are in Israel.
Hard to think anyone is surprised that top-tier pay-to-play malware is being promulgated by Israeli firms...