Edward Snowden calls for spyware trade ban amid Pegasus revelations
theguardian.com
theguardian.com
https://www.bbc.com/news/technology-50166147
Lone wolf creepers or quasi legal harassment companies have access to similar tools.
https://www.nefariousjobsmain.com/the-works
https://www.vice.com/en/article/ppmpe8/a-revenge-for-hire-bu...
Although of course the state sponsored aspect of this is very real too, and the greatest threat.
I would take that for granted, as I do with any government, including mine. But thinking that you're more likely to be kept under surveillance by the same government -no matter the color- you fund with your taxes, than some private or foreign entity, makes this even more revolting. Makes one think if nationalism was invented as a tool to throw smoke in the eyes and minds of people so that they can't see their rulers for what they really are.
What criminal acts?
Edit: "Severe psychological warning, this package is only available for use on clients over 30 years of age."
...because a 26 year old can't handle getting a dildo in the mail?
Extensive (40G) information on this was leaked via reddit in August 2014[4], and the leaker noted[5]:
> I assumed the hacking would be the hard part and once I got the data it would just kinda go viral on it's own or something. But it turn's out without any media access or idea how that shit works, getting people to notice or care is actually kind of hard.
------
1:
"FinSpy Mobile. Version 4.4, released in of Q4 2012, has the ability to collect data through Skype across iOS, Blackberry, Android, and Windows Mobile platforms . An updated Version 4.5, released in Q1 2013, included the ability to target emails, calendars and keylogging of Windows Phones, and an updated ability to collect data through the camera of a Blackberry or iOS phone."
- https://privacyinternational.org/blog/1522/six-things-we-kno... (2014)
2: https://en.wikipedia.org/wiki/Gamma_Group
3: https://www.independent.co.uk/news/uk/politics/uk-spyware-wi...
4: https://privacyinternational.org/blog/1522/six-things-we-kno...
5: https://www.reddit.com/r/Anarchism/comments/2cjlop/gamma_int...
I like what some other user proposed here: military grade classification. Tada. Now sanctions apply to both sellers and users of this crap.
The big deal with the NSO story is the 50K target names, I think, and it is a big deal, but you'd expect in a supposedly oppositional paper like the Grauniad, that there'd be some mention of the current UK government's spotty record in this very department, and a sense of the history of the abuse of this technology. I'd have a hard time believing that any of this is news to the journalists reporting the story.
If Israel for example provides software to Morocco that is used to spy on Algeria, Israel gets free intelligence on Algeria. It is even more valuable than directly spying on Algeria because it is absolutely deniable and may target foreign spies or terrorists that might not have been on Israel's radar to start with.
While spying on journalists and NGOs is horrific from a human rights perspective, it is sadly of little significance to how the intelligence game is played.
Yeah, it was that way even before that. Microsoft and Apple got into a "donation war" tryin'a get their corporate garbage into schools back when I was a kid. Looks like Microsoft largely won that war. Hard to fight multiple generations deep corporate brainwashing.
In these cases I think administrative oversight of broad and long term benefits to society is important, rather than the more narrow decision of "this choice will benefit next year's budget". Early offers by Microsoft were in a way a trap that kept schools and students paying for decades.
Schools in California are government-run, zoned, and compulsory. A complete opposite of the free market.
Which belief? The belief that corporate spyware devices and software are infinitely superior to anything in the F/L/OSS world? I literally can't escape 'em. Especially in "gamer" circles, I get endlessly hassled by Windows users tryin'a convince me with decades old Steve Ballmer FUD that Linux is inferior junk and a cancer on the software industry, and that I should just switch to Windows.
> That feels like one of those stereotypes that people are sure exists but actually doesn’t.
Sadly, you name a stereotype, and I promise you there's people out there that'll do their best to prove that stereotype true. Cryin' shame, because they're just doin' harm to an entire group of folks who never asked for it, and harming an entire other group that believes false stereotypes are true by reinforcing their wrongness with "proof".
As to the bein' called "paranoid" from my earlier comment, it happens to me frequently when I try to talk to people about backups, network security practices, or passwords, and I'm not alone there. I've had more'n a few discussions with other IT folks who've met frequent resistance to security ideas until after there's been an issue, and then the "people in charge" still generally wanna seek the absolute minimum solution they can get that they think would cover their asses, even if it's nowhere close to enough of a solution for the problem at hand.
The point is that it takes more than just a few people to validate a stereotype; otherwise, I could make up any stereotype I want, and by your admission, it would be valid. But that isn't how sterotypes work.
The point wasn't to have a discussion of the semantic definitions of what makes something a stereotype, GP was merely asserting that such people might not actually exist and asking for an example. An example was provided.
If I cared to dig up actual examples I could link, I've numerous trolls that follow the word "Linux" around gaming forums spouting Ballmer-era anti-Linux FUD at every opportunity, just to begin the endless thread of examples, but the entire mentality sickens me and I'm actually trying to extricate myself from the Troll-pit that keeps wanting to drag me into pointless discussions of why A is better than B, when the true fact is that operating systems are tools to launch and run software. Use the one that lets you get your job or activity done in the way that works best for you and leave other people to their choice of tool if it's workin' to get their activities done for them.
That wasn't my point either, so we're all in agreement. We're talking about whether or not the stereotype is valid here, so it would be a good idea to use the term correctly instead of using a made up definition. "There's people out there" doesn't cut it.
Maybe the Baader Meinhof syndrome will kick in and you'll start noticing Proton mail/vpn users or anybody that took drank some Youtuber's VPN koolaid trying to bargain for impossibly damning evidence about their particular service instead of recognizing the flaw in the entire concept
Edit: Curious what part of the above statement is unhelpful or inaccurate…
> Telemetry is strictly optional and disabled by default. No data is shared unless you choose to opt-in and enable telemetry.
https://github.com/audacity/audacity/pull/835
Ars Technica published an article describing the controversy as "massively overblown" and I agree with their analysis:
https://arstechnica.com/gadgets/2021/07/no-open-source-audac...
I could totally see that I guess… My point was more that the way folks reacted to that would probably be a pretty accurate indicator of how well "open source spyware" would be likely received. ;)
>Curious what part of the above statement is unhelpful or inaccurate…
I have no idea how you think the incident played out. Your post is basically "something like that happened, there were results."
Pretty much exactly my thinking on the topic. It also resulted in them changing and/or clarifying some of the things they thought were the cause of the complaints. Still led to a fork anyhow.
Can you provide evidence to back up this statement? I'm not disputing your claim outright, I'd just like to see your evidence.
Yes, I know it's a decade old, but it's a great example of „open source is better/safer/whatever”.
The use of such military weapons by civilians (or civilian police) against civilians become more obviously ban-able.
That said we have near zero ability to enforce this at the moment.
How long will it take for pentesting tools and end-to-end encryption to be labelled 'military weapons' under such a scheme?
Here's what we will find next: military and political leaders' phones have also already been compromised by NSO Group tools. I feel confident it has happened at a higher rate than among journalists. Imagine both your favorite and your most hated political firebrands: how will their rhetoric sound when they realize they've been pwned by the opposition for the past year using COTS tools?
Not sure it would stop the police part. https://en.wikipedia.org/wiki/Militarization_of_police
Pretty hard sell that it's a "military" weapon when you can carry it around on a thumb drive.
SCOTUS says that the 2nd applies to weapons which are “bearable”, i.e:
> "“[w]eapo[n] of offence” or “thing that a man wears for his defence, or takes into his hands,” that is “carr[ied] . . . for the purpose of offensive or defensive action.”
The closest parallel is probably an EMP strike. They're designed to inflict 0 casualties, but they cripple the enemy. That mirrors the usage of offensive software; they don't inflict any casualties directly, but they can ruin supply chains, remove communication capabilities from the enemy, etc.
They probably deserve to be classified as weapons, and banned by a subsequent law. I think the government has a compelling case that would almost certainly pass strict scrutiny. It seems a logical place to put them, because they are dangerous, and the strict scrutiny puts an onus on the government to use the least restrictive means possible to legislate them. I fear the alternative is that they aren't classed as weapons, and we get some overly broad CFAA type legislature that threatens to penalize security researchers.
Instead, we should rather harden the security of our computer. I consider all smartphones are insecure. Anybody who own or relies on smartphones are just trading security for the convenience.
I will never want to own or relies on smartphone... or phone at all.
Think about the Tokyo metro attacks and, not to minimize the tragedy, but how many more lives would have been lost if they had detonated similar quantities of explosives instead of spreading sarin gas - and that is inside a closed tube, with no protection whatsoever and with most victims receiving no medical care until many hours later, as hospitals were entirely unprepared for a gas attack.
Like some crazy airborne virus but only the good guys™ have the antidote/vaccine.
>how many more lives would have been lost if they had detonated similar quantities of explosives
Wasn't it just a few guys with suitcases, and I think one of them didn't even puncture the container? With conventional weapons there might be more deaths but maybe not.
> Wasn't it just a few guys with suitcases, and I think one of them didn't even puncture the container? With conventional weapons there might be more deaths but maybe not.
They had several liters of sarin gas, most of which was splashed on the ground entirely. If they had had some way to spread it as an aerosol the death toll would have been much greater, but still sarin is apparently the most volatile nerve agent, so even in liquid form it evaporates relatively quickly.
Even so, if they had started a fire with a few liters of fuel, even without an explosion, they would have probably killed more than 14 people. If they had pulled out guns, or detonated bombs, the death toll would certainly have been worse.
What is especially stupid is that the US does this as well, while they're the ones who are the most vulnerable. Just look at the debacle with WannaCry. These attacks come from countries who have a lot less to lose than the US, yet the US insists on throwing stones from their glass house.
Every single government uses such tools. The ones that don't likely have bigger problems such as sustenance, lack of electricity, etc.
What people should be looking at is the crazy amount of Israeli presence in the so called cyber security sector. I can think of a few such companies that literally spy and track hundreds of thousands of people all over the world. The government is using their services and therefore lets them whatever they want.
I know a few guys working for such companies. No longer friends with them. Works foriteral evil. No better than military types
Limiting the ability of nations to export this kind of capability as a product for other entities to use is precisely what "trade ban" would do.
You're right that a trade ban won't affect the ability of nations to develop and deploy their own spyware, but most of the targets in the Pegasus dump seem to be of people peripheral to smaller governments that don't have this kind of capability themselves (which is exactly why they buy it!).
It's like banning arms sales to countries like Saudi Arabia. All it does is push them towards China or Russia.
Banning this stuff just leads to consolidated power blocs of nasty regimes.
Again, that's experimentally false. Saudi and Mexico didn't develop their own home-grown spyware. They bought an Israeli product instead. This stuff is harder than you think.
if you're in a precarious political position, a homegrown entity that produces these tools can quickly become a threat; the citizens you train/employ will have their own political ambitions, nationalistic tendencies, empathy for their fellow citizens, etc.
there are most certainly situations where it's safer to just outsource your natsec/tradecraft to an entity that only cares about their bottom line.
Saudi and Mexico don't produce many homegrown weapons systems either. Again, non-proliferation is well-travelled territory. In fact most of these things are not something small governments will have access to if big governments don't give it to them. And treaties restricting trade in these things are known to work.
DPRK manages this shit, it's in the reach of any nation-state.
Who would issue and enforce such a ban? The US?
I can't tell what your point is, exactly. You're just making a cynical point that this won't work so we shouldn't even try?