NYT journalist hacked with Pegasus after reporting on previous hacking attempts
citizenlab.ca
citizenlab.ca
It's a weekly news show that focuses on tech (mainly Apple). They do a good job with technical details and talking through tech product decisions (why did Apple/Google/FB do X? What are its merits?). People have sort of polarized opinions about each of the 3 hosts, but IMO they each have their moments.
To me, one of the powerful things of ATP is that it’s one of those cases where the sum is more than the parts. The hosts complement each other very well.
I also like that, although it’s an Apple-centered podcast, they are willing to take a critical stance towards Apple. I once listened to one of the other major Apple-related podcasts (not Gruber) and the level of fanboyism was cringeworthy.
If you assume the photo was made with one of the consumer applications, there are only so many popular bluring algorithms. You can brute force it quite easily by testing each character and each type of blur until you get exact match (and in many cases even inexact will suffice).
Safest is probably just to cut/crop the sensitive bits out.
I did blur over black box because the blur was less visually obtrusive
Yeah, the right way to use blurring is to mockup a lookalike for content you want to hide, then blur the mockup.
https://eclecticlight.co/2020/12/11/how-effective-and-safe-i...
Whoops.
Tech savvy people, but also journalists
https://arstechnica.com/tech-policy/2021/10/missouri-gov-cal...
My critical security step was rendering out the PDF as individual flat image files, then re-assembling it like a traditionally photo-copied document.
That way the loss-full operation is enforced, at the cost of forcing end users to OCR unsearchable image-scan (like) PDFs.
I think you mean "illegally hack the black bars".
There may be graphic design reasons you don't want to do that. A big black redaction bar isn't much of an illustration.
Pedo who used to swirl his face not knowing people can unswirl.
Are they?
They have an enormous level of control over their deployed software. It seems like they could push out the required changes and nearly all clients would support it in no time.
For the remaining clients it seems consistent with the feature to simply block incoming messages in the wrong format.
Now, whether they'd want to implement a feature that essentially advertises that they have a security problem is another thing. (the answer is quite obviously no, regardless of what's best for their users)
Hell, GPG isn't fit for any human users. Yet Debian is still able to hand-crank a extant web-of-trust off of it.
The solution is to have a processor that is so simple that it cant do more then what you expect, and building the tools to make the unexpected stand out.
However, there is a bigger market for a processor with 3 extra layers of root access to ensure your boss can spy on you and Disney&Co really want this to be the norm.
Yes, all of it is 'fundamentally flawed', and it would take a herculean effort to start over with a clean slate, yes, to figuratively burn it all down and make simple provably correct and safe hardware and a small and minimal OS that has browsing and communications built in.
Anyone?
But if you use devices with hardware kill switches and the most secure OS possible (storing nothing on device, perhaps it's a gateway to another security hardened machine).
Secure computing is possible, but it takes a lot of time, effort and dedication.
If you're just using off the shelf hardware and software you're going to have a bad time.
One thing that seems to link these Pegasus stories is that none of these targeted individuals are practising seemingly decent security ops, being hacked over WhatsApp or iMessage seems fairly trivial and hopefully now they would reconsider their threat model.
There are likely many out there secure computing, and we don't hear the news about them because they don't get hacked.
But with the convenience of using smartphones and sending anything quickly over them using (insert your favorite messenger service) statistically many people will be using them, even for absurdly important/critical communication, and a small number of them will be hacked.
Services like WhatsApp/iMessage will just keep adding more features to stay feasible, and more people will be using the feasible services, with more features creating new attack surfaces inevitably.
IMO nation states had a very negative influence on the internet, bringing secrecy, warfare, balkanized markets, mandatory identification and other closed concepts to a place that worked on open principles.
If states would invest more in security advancement and open research than in warfare, we might have been in a better position.
That became much more inconvenient as technology just progressed to a point where 99.9% of the society couldn't resist using the smartphone, rightly for many purposes, including many of us here too.
But as OSs (and even SoCs) became more complex as more features are added (well, I can't think of Apple or Samsung execs on stage saying "hey we didn't add any features this year" so it has to go this way naturally) flaws are inevitable.
I think the original landlines, which were/are a few switches connected to a write on one side and some microphones on the other, were close to inherently insecure. Phones haven't ever been "your device" whereas a laptop might, maybe be rendered trustworthy.
One of my banks has been closing branches left and right, and if I want to use my accounts for anything other than debit purchases, I need to use the app. Some banks even charge you when you go to a branch location in person and use a teller to access your accounts.
Some jobs require you to install and use apps on your phone. Last time I was a big box retailer, the floor staff had the company's app installed on their phones so they could do instant price look ups and confirm discounts on their store's inventory.
Even just applying for a job requires an internet browser, and many people's only access to the internet is through their phone.
I don't think the smartphone is inescapable at all, and I don't think any of the conveniences it offers is worth surrendering one's privacy. But there is a tendency in businesses to ignore the fact that some potential customers do not have smartphones. I wonder if legislation against this might be possible.
There is one smartphone with those: https://puri.sm/products/librem-5. The alternative one, Pinephone, has quite inconvenient kill switches.
Is this really true where you are? No menus?
You're not wrong that this fundamentally excludes those who don't have (powered-up) smartphones. But it's not like restaurants and bars had the luxury of thinking through and choosing to have these effective new smartphone requirements: they adapted to Covid for their survival, and the odd case who got unlucky with a dead phone is just collateral damage.
I'm in Canada, and we use QR codes, signed by the government, to show and validate status.
Mine is printed out, and in my pocket. No phone is required.
Thus, no one needs to avoid anything, phone or not.
Also, in your case, is this a federal system or a state by state one? If the latter, this sounds way worse than what NY is doing; with my CA vaccination I couldn't get in anywhere.
The QR code is provincial, but it only requires minor changes to have one provincial app, look at other validation sources.
I agree that sadly, restaurants may find some metrics too high/annoying to deal with, and opt for a lost sale.
I was also at a play where a QR code was the only way to get the program.
Using your device to read the menu puts your device in the loop where formerly it was not.
It's not comparing websites accessed via QR against every other already tracked thing in society, it's comparing it with laminated pieces of paper.
I didn't mean they generate QR codes dynamically. It wouldn't be hard at all to encode the table number, for example, and then of course they have the time and know your reservation, and thus can identify their customer's phone.
Really not much you can do with zero-clicks.
Don't be rich or famous I guess? Or don't use smartphones.
E.g. https://news.ycombinator.com/item?id=28469193 and https://news.ycombinator.com/item?id=27564236
If your threat model includes targeted attack by a major intelligence agency, just accept that you are likely screwed.
I was driving home today and the satnav warned us about driving over speed limit (74 mph on UK motorway). Ok. But the solution to that is technology - and organisation. There are speed cameras on this road. But most of the time they don't take images or don't trigger an action. If every road camera triggered a warning / fine on every violation then speeding would stop in a few months.
Is that something socially beneficial ? Probably. Would it be disruptive and cause great anger and political resentment? Yes.
That is one tiny example but I think that pretty much every criminal act can be detected with technology - it's going to become which one we care enough about to prosecute and which we give up and decriminialise?
Or governments will continue to have those laws on the books and prosecute them with discretion (which is what happens today). It is very convenient for those in power when every person is already guilty of something.
If society is not free or fair, that's the problem to fix first.
Location can be determine with sufficient accuracy for this purpose from cell-tower connections. More so as 5G, with its greater tower density and shorter range, is rolled out.
(An actual 5G threat you can get behind.)
If you add a VPN to the stack, the VOIP service doesn't know your IP (though I wonder if a VOIP service would work well through a VPN, due to added latency).
If you're making VOIP calls over a device that is itself connected to mobile networks ... you've still got the connectivity of the device itself to track. Presumably that's a long-lived relationship. At this point the information is limited to location data, but that, at the postal-code level is again sufficient to identify 90% of individuals within the US, based largely on residential and workplace locations.
The notion of having short-lived individually-attributable 5G connection history, perhaps through a dongle- or tether-swapping system, in which many individuals utilise devices for a short period of time, might work. With a sufficient budget, disposable devices might also be an option. (As the cost of SBCs / SOCs falls through $0.10/device, the disposable option might be tractable, leaving SIM card provisioning as the bottleneck.)
The tether is connected over WiFi (the MAC address space is already repetitive, and MAC addresses can be arbitrarily changed at the OS kernel level), giving a two-stage connection to the actual mobile network itself. Frequently-relocating (via a swap) or short-lived / previously unknon tethers, as identified through IMEI is required for mobile connections to work, would still be possible, but at a much greater workload. (I'm very sketch on how 5G identifies specific devices, take what I'm saying here with a few kilos of salt.)
I'd still have concerns with a VOIP device that itself has access to information and computing capabilities, but at least the degree of tracking that's possible over a PSTN direct-dialed mobile handset on a 4G/5G network would be sharply reduced. Other threat vectors remain.
Burner phones on a one-use / short-use cycle would probably be preferable.
If by "two problems" you mean that VOIP adds an additional problem, I don't quite grok it. It isn't a panacea, as you point out, but seems like a clear improvement.
Another advantage of VOIP is that you can easily obtain throwaway phone numbers.
> If you're making VOIP calls over a device that is itself connected to mobile networks ... you've still got the connectivity of the device itself to track. Presumably that's a long-lived relationship. At this point the information is limited to location data, but that, at the postal-code level is again sufficient to identify 90% of individuals within the US, based largely on residential and workplace locations.
Good point. They still don't know who I talk to and when, but they certainly can figure out who I am. I wonder how expensive the latter is, which I'd guess it depends on whether that analysis and the sharing of it is done automatically or takes a special request.
> The tether is connected over WiFi
I'm not sure that helps privacy: Wifi networks are likely shorter range than 5G cells, and the networks are well mapped. I suppose it does require involvement of someone with the map, but that might be easy to obtain.
> the MAC address space is already repetitive, and MAC addresses can be arbitrarily changed at the OS kernel level
I think iOS and Android randomize MAC addresses these days ?
> Burner phones on a one-use / short-use cycle would probably be preferable.
Yes, but a single burner phone, between the hardware and a one month plan, can cost $75-100. Using lots of them is out of reach for many people.
On connecting to the tether over WiFi, the advantages over cellular data or Bluetooth is that a WiFi identity (MAC address, SSID) can be arbitrarily changed, and in fact are in consumer-grade hardware (yes, iOS uses a distinct MAC per connected network AFAIU, not positive of Android). This could be modified on every network connection, or even within a single session (requiring periodic reconnects). Other means of specific host identification via TCP/IP and 802.11 protocols are fairly limited.
On increasing workload, much surveillance is done via mass-produced hardware and software, and targets frequently-encountered devices (e.g., stock mobile phones, iOS, and Android systems). Adopting measures and methods other than these ... leaves a signature, but also means that specific new surveillance methods need to be devised for a specific target.
Also: in case anyone mistakes me for an expert on this area, I'm not. I've general familiarity with methods, techniques, protocols, devices, and operating systems.
I was recently asked how to make an anonymous post to a local news organization where all they wanted to do was hide their IP. I said if their only worry is the news organization then a VPN would be enough... Now that I'm reading your comment I'm having second thoughts whether it was right.
Varies by country I’m sure, but I was surprised how difficult it was to buy a SIM in Indonesia and Malaysia without an ID. Even little shops wanted an ID or passport number to type in to activate it.
This is near impossible now. I tried a few years ago to get an anonymous phone to activate an anonymous twitter account and you have to provide too much information to activate the sim card across the major providers and other companies that use their infrastructure.
There's no escape really, your only option is to embrace the paranoia and learn to love the cat-and-mouse game, or (what most people choose) give up. Remember, this is the future you voted for when you signed up for Google Drive and bought your iPhone. This is the future you willingly supported with each ad that YouTube showed you on movie night, and the one you opted-into when you noticed you were low on popcorn and got 2-day delivery on kernels from Amazon.
To illustrate this point, Apple gives up users' data for about 150,000 users/accounts in the US[1] a year in response to government data requests.
Yes, Apple is no different than any other tech company in that regard. The difference is that Apple's PR tells you otherwise. The whole San Bernardino shooting case had many people on HN saying that it meant that Apple would refuse to work with law enforcement when law enforcement would ask for users' data, even to the point of challenging subpeonas and warrants in court. That is clearly not the case.
One of the issues I have is that those warrants are rubber-stamped out. We should change how the judiciary approaches that, raise the bar law enforcement has to meet to be able to request that data, while also encouraging the use of encryption at every level.
Until we make those changes (which I'm of the opinion the wider society does not have an appetite for the legal and usability trade-offs that come with the even if I personally do), I guess I'm confused by what we're demanding when we point out that a company based in the US cooperates with valid legal requests from the US government.
The sentiment towards Apple is just disappointment today. Their 'ecosystem' approach has had detrimental effects on the consumer electronics market, and has given them a frightening amount of power over the flow of information. Apple's treatment has been generally irresponsible, though: they do nothing to assuage the general public of what's running in their OSes, rather choosing to occasionally throw out unverifiable whitepapers of how these systems might work, but we've got no way to verify that. For a company that claims 'privacy is a human right', I was really hoping to dig into something more profound.
The biggest issue is that we're taking Apple at face-value. They're documented liars, and their insistence on being right contrasts with their tacit rejection of transparency. They operate without accountability, and the only people keeping them in check have a mutual interest in creating a monopoly. Their factories are staffed by political prisoners, and they're the only FAANG company who's comfortable operating in China's homeland. It's crazy how people forget this with nothing more than a little marketing and some diversity in their iPhone commercial.
I expect better from a company with more money in the world than anyone else. But maybe this is yet another reminder that shareholders don't care about your security, privacy or peace-of-mind.
Very unlikely give that the US does this as much as anyone. We are all potential victims in this new form of warfare.
Like we do with anything else:
These are crimes, but we are stuck in the mindset of the nascent Internet, when it was a growing experiment, a subculture in our society, harmless, and we wanted to nurture it and give it maximum freedom.
Those days are long gone. The Internet is completely integral to our society, like a major city (an extraordinarily large one) - in fact, anything not integrated into the Internet is on the fringe, like a business without a website. The idea of a harmless Internet has been antiquated for a long time; it is a serious place of serious money, serious criminals, and serious political actors.
Yet we still don't have serious law or law enforcement, not as an oppressive force but in the tradition of free, open societies. It would be like New York or Tokyo without law or law enforcement. We should create in the federal government (not state governments, given the Internet's borderless nature) a major domestic law enforcement agency, on the scale of the FBI, to protect people and enforce laws; I suspect we need a major addition to or revision of our legal code to go with it. That is how we deal with crime in other parts of society; the Internet is no different. We need divisions dealing with theft, fraud, destruction or property, invasions (hacking), etc. It's long past time to stop applying the antiquated notions to the current reality. Why do you accept this Wild West chaos; it no long fuels creativity and growth, it greatly hampers it.
Bringing justice to international actors opposing democratic ethics is regrettably less of a priority today than enforcing highly publicized and politicized criminal cases.
But to answer your question more fully, you can't solve this problem without supranational cooperation. A "police force" working to safeguard the Internet would have to work under authority of the UN, not any single nation.
It's an association of governments, where they get together and organize things. All the power is in the individual governments. There are some grey areas and exceptions, but overwhelmingly the above is the case.
The UN could coordinate cybercrime law and national agencies.
Based on an estimate of the design of organizations: Sometimes you expand an existing function within an organization, sometimes you add a sub-organzation (e.g., a division), sometimes you create a new organization. Which, when, and why? Standard CEO fare. A couple basic considerations off the top of my head:
Organizations have priorities. As one example, the story (I can't promise perfect details here) is that the US Air Force has always had the priority of pilots - it's run by pilots, they are glorified - strategic bombers and air superiority (air-to-air) fighter planes. Tasked also with providing close air support for ground soldiers, drones for surveillance, and orbital operations, they don't quite get around to those needs: They want bombers and air superiority fighters, flown by pilots, so that's what gets attention, that's what they invest in researching, developing, and buying - F-35's, B-21's, etc. (name a high-price uber-tech platform they've built for close air support, surveillance, or space). For close air support, they insist the F-35 will do it well enough as a secondary function, and want to cut other options - 'well enough' is not the language of priority. It's a constant battle to get them to deliver on these other needs. Partly for that reason, the Marines provide their own air support and the Army has helicopters - they have different priorities than the Air Force - and the US created a separate Space Force.
Organizations also have competencies, which affects the expertise of leaders, the acquired deep organizational knowledge, the asset investments, the organizational structure, and the culture - systems engineers have a different culture than movie actors. If the people in the executive meeting know storage but not networking, you can imagine the results for the networking function. Consider recruiting, training, mentoring, and promotion for networking personnel. Just consider office locations, which will be near the storage talent and facilities, but not near the Internet exchange and networking talent hotbed.
The FBI's priority has been terrorism. Catching domestic terrorists seems much different than investigating cybercrime. The FBI leaders have little expertise in the latter; the entire organization is built around the former. The agent training and skills needed for cybercrime and terrorism seem completely different, the assets needed seem completely different (field offices versus high-performance, highly secure computing centers). I would guess the culture would be very different, with cybercrime placing a very high priority on intellectual ability seated in a room, not interpersonal skill (interviews, etc.), tactical decisions, and physical action around the world. My impression is that a different agency, or at least a major FBI division that reports directly to the top, is needed.
Sure, not everything is always their fault, but usually it is and comes with yoloing from the first line of code, shipping alph… proof of concept software, or outsourcing their network’s security to MS Word. If a breach could ruin a company beyond reputation, people may stop storing cleartext credentials or testing merely their app’s UI at best; if a hacker could stop your show, companies may take bug bounty programs serious, and be grateful for disclosures instead of filing reports, when someone edit-and-resend’ed on a web API and accidentally got a copy of their database.
Today, a breach has zero consequences. Why would you spend a shitton of money on security, when marketing’s budget isn’t downright ridiculous yet?
And of course it would be super helpful, if governments would stop encouraging insecurity by buying e.g. NSO’s products for what they do. Always awkward persecuting someone you depend on… The NSO’s business should be straight illegal, including export/import. Since hacking someone without their consent usually comes with the ability to tamper with evidence, it’s really questionable for law enforcement and straight unethical for anyone else. Just kill the whole sector IMO.
Seriously, if you are a journalist investigating anything that might upset the powers that be in a nation-state, don't use any online technology and for gods sake not a mobile phone.
https://blog.cryptographyengineering.com/2021/07/20/a-case-a...
Considering how tightly integrated iMessage is with iOS, it doesn't seem likely that it will really be fixed in an easy manner.
As it stands, the most recently published information about the exploits were in the image parsers. So any app that used the default image parsers may have been affected, but might not have the same ability to escalate the exploit via other exploits. Plus you get back to the lack of ubiquity of the app, and the difficulty in targeting.
Literally worth millions of dollars on the wholesome greymarkets these days, possibly the most prized, just in case anyone was wondering.
A lot of dragons lurking in the dark there.
Wonder what's blocking the client side. Power efficiency? No target market since cheap LTE sticks can be had for under 20€ apiece?
Do they just sell, or operate the hacking software for their clients? If they operate it, is it illegal for an Israeli company to hack an American citizen (I assume it is illegal in America, but how about Israel?)
Is the sale of hacking software regulated in any way?
I don’t know about regulations in the field. All I know is that “US gov buys a lot of X, therefore it X is not regulated” is not a convincing argument.
This is not legal advice, obviously.
If the government tried to ban certain types of software from being made/distributed, they would either make a law that’s never enforced (like the obviously unconstitutional DMCA anti-circumvention law), or a law that’s immediately struck down by the courts.
An interesting point. Given the vendor and customers for NSO's products, Federal law (in the US) would apply, rather than state law.
That said, an interesting parallel would be possession of burglary tools[0], which is a crime in many places in the US. However, given that "burglary tools" are generally just tools (e.g., bolt cutters), intent or mens rea[2] becomes important.
Presumably, a similar argument could be made about tools like nmap, nc, ettercap, metasploit, etc., since they can be used for legitimate purposes, even though they're also used for site intrusions/compromises.
NSO's tools, presumably, are mostly used for the latter rather than the former. I'm guessing (IANAL) that's one of the rationales used to restrict sales/exports.
Is that a convincing argument to criminalize activity and saddle it with strict liability[1]? I'm not so sure, but I'm also not a DOJ lawyer.
All that said, I don't think it's all just "marketing copy." As with most things, context and nuance matter. I make no judgement WRT the appropriateness of such restrictions, as I'm not in possession of all the facts.
Even so, while I tend toward the free flow of information, there is something to the idea that if you're caught at the back door of a jewelry store late at night with bolt cutters, that implies mens rea much more than having bolt cutters in the toolbox in your garage. YMMV.
[0] https://codes.findlaw.com/ny/penal-law/pen-sect-140-35.html
[1] https://www.law.cornell.edu/wex/strict_liability
[2] https://www.law.cornell.edu/wex/mens_rea
Edit: Fixed typo.
Even with regards the restricting import, the government is largely limited to sanctioning particular actors involved in the transaction.
I’m really a bit surprised that this isn’t more widely understood on HN. Anybody who operated a web server in the 90s is likely to know about Bernstein vs DoJ, and even if you operate one today you’re still likely to encounter the idea of an “export cipher”.
I misunderstood your point. I (mistakenly) thought that your reference to "marketing copy" related to the US Government's justification of restrictions on tech exports, not NSO's sales pitches.
My apologies.
The scene has been set again in Afghanistan. It isn’t ICBMs but it’s not a virtuous circle when you are dealing with weaponry.
https://www.cbsnews.com/news/interview-with-ceo-of-nso-group...
They've also made other claims that only make sense if they do.
https://www.techdirt.com/articles/20210723/22444547234/nso-g...
> "Das BKA hat nach Angaben der stellvertretenden Behördenleiterin sichergestellt, dass keine sensiblen Daten bei der Firma NSO landen würden. So würden Hashwerte für Telefonnummern vergeben, damit das Unternehmen die Zielpersonen nicht identifizieren könne."
They claim that this way the NSO Group would not be able to identify the victims. Obviously that is a fat lie, as a phone number hash could trivially be brute-forced, even on a home pc.
From the sounds of it, NSO Group does not give out the zeroday exploits, but rather do the dirty work of exploiting/infecting the victim themselves, and then hand over control. But the writing is pretty vague.
Seeing all these democratic countries, including my home country support this kind of stuff by buying their malware, is extremely disheartening to me, when there is clear evidence that it is being misused by authoritarian governments. It also makes me feel powerless.
[0] https://www.tagesschau.de/investigativ/ndr-wdr/spaeh-softwar...
So I don't see how a government hiring someone to hack someone else is not complicit.
Unless if that government branch had the legal right to execute that hack. Because if they were legally able to, but were unable to themselves, it makes sense to hire someone to do the job for them (if that is legal?)
I am quite in awe how for example exploit brokers like Zerodium and Thaddeus Grugq are allowed to sell their services to oppressive regimes, and getting away with it (a clear case of morally bankrupt). They are powerful weapons, and should be treated as such (export controlled etc).
https://www.theverge.com/2021/10/22/22740155/commerce-depart... ("New US rules on spyware exports try to limit surveillance tech like Pegasus")
edit: and HN thread
https://news.ycombinator.com/item?id=28933981 ("U.S. tightens export controls on items used in surveillance of private citizens")
This part doesn't matter much in practicality. Like it is illegal for the US gov't to spy on their citizens. It is illegal for the UK to spy on their citizens. So the NSA made a deal with the UK. They spy on us, we spy on them, and exchange the info. There, the US didn't break the law and neither did the UK. They worked around it.
We live in a shadowy world.
https://www.theguardian.com/world/2013/nov/20/us-uk-secret-d...
https://www.theverge.com/2016/11/23/13718768/uk-surveillance...
It's therefore easier to get a friendly government to do the hacking and to pass on the discovered info, which side-steps any legal accountability.
Let’s not mince words, this is officials of the United States of America conspiring with foreign hostile [0] powers to undermine the rights and security of the American public. It’s treason, and an incoming president with the stones required could arrest much of the former administration’s “intelligence community” leadership in midnight raids via the insurrection act.
[0] Foreign intelligence services are, by design, hostile powers even if they belong to an ally. The UK is an ally, but GCHQ is a hostile agency from the perspective of the United States public which these agencies supposedly serve.
> Chairman of the Joint Chiefs of Staff Mark Milley took steps to prevent then-President Donald Trump from misusing the country's nuclear arsenal during the last month of his presidency, according to a new book by The Washington Post's Bob Woodward and Robert Costa obtained by NBC News.
> The book, set to be released Sept. 21, also recounted a phone conversation Milley had with House Speaker Nancy Pelosi after the Jan. 6 violence at the Capitol, which Pelosi blamed on an "unhinged" Trump. Pelosi said in January that she spoke to Milley about "preventing an unstable president from initiating military hostilities or accessing the launch codes and ordering a nuclear strike."
> "I can guarantee you, you can take it to the bank, that there'll be, that the nuclear triggers are secure and we're not going to do — we're not going to allow anything crazy, illegal, immoral or unethical to happen," Milley told her, according to a transcript of the call obtained by the authors.
> "The president alone can order the use of nuclear weapons. But he doesn't make the decision alone. One person can order it, several people have to launch it," he said later in the conversation.
> After the call, Milley summoned senior officers from the National Military Command Center to go over the procedures for launching nuclear weapons, the book said. He told the officers that if they got a call, "you do the procedure. You do the process. And I'm part of that procedure," he said — making sure he was in the loop on any planned military actions, the book said.
https://www.nbcnews.com/news/military/milley-acted-prevent-t...
There is no constitution. Take the politics out of it. This is treason.
It would be treason for Milley to countermand a legal order, but asking for key servicemen to review the details of an admittedly complicated bit of military law and to prepare themselves for exactly what decision they might need to make in realtime - nothing illegal about that.
Sure they could, but they won't. No president will, if for no other reason then out of fear that the next one from the opposite party will do the same to their administration. Unless they outright shoot someone in front of witnesses, I don't expect this ever to happen, regardless of the level of corruption.
Nor would the Insurrection Act be in any way needed or relevant to arresting former (or current) intelligence officials for either actual treason, or any illegal conspiracy with allied intelligence services regarding surveillance.
No US law enforcement is going to honor an Israeli subpeona I believe, and vice versa.
It isn't a crime to exploit your own property.
Presumably, the hacking was done by Saudi authorities from SA, using NSO-developed tools. Citizenship of the target is not very relevant, but it does matter where "the event" happened.
If the reporter was in Saudi Arabia when the hack happened, then Saudi laws apply and essentially Saudi government gets to set conditions on whether it was legal or not, and if it was forbidden by their laws, then what consequences (if any!) that should have.
If the reporter was in USA at the time, then it would be reasonable to apply US jurisdiction and try and investigate it as a crime in USA. However, Saudi Arabia can refuse to cooperate and even if USA prosecutors identify the culprits and convict them, Saudi Arabia can refuse to extradite them and choose to protect them. In essence, if it's not a random foreign criminal but someone from the actual foreign government that has harmed USA citizens in USA, it's not really a criminal matter as much as a diplomatic one, where all the other aspects of USA-Saudi relationships matter much more than any facts about the actual case; USA can choose to make a big deal out of it or ignore it, but historical precedent shows that it likely will be ignored as the Department of State considers all the other factors of Middle Eastern politics as much more important, SA could likely get away with literal murder (e.g. Khashoggi), not just some hacks.
In a similar manner, perhaps you could argue that NSO is an accomplice in that crime (I'm not saying that this would succeed - in general, arms exporters are not considered liable for whoever the purchasing country harms), but that essentially comes down to (a) whether USA prosecutors are willing to pursue this, and (b) whether Israel is willing to cooperate, as in the absence of specific treaties it would be legitimate for Israel to say "NSO did not violate our laws, we won't enforce any foreign judgements about this event"; if so, then any action would be limited to seizing whatever assets NSO has in USA (if any!) and/or trying to capture the involved people (if specific people can be identified) when they are traveling outside of Israel somewhere within the reach of USA. USA could apply diplomatic pressure to get Israel to restrict NSO, however, it doesn't seem likely that USA wants it so much to actually try and change that.
For another of your questions, sale of hacking software can be regulated by countries in whatever way each country wishes. In this case, as far as I understand, Israel treats is as essentially an equivalent of "arms export" where NSO has to obtain approval from Israel government for their foreign customers, but in this case it is not contested that NSO did have all the required approvals to sell their tools to Saudi Arabia.
In general, countries do hire mercenaries/private military contractors/etc, and it is not considered anything special, and many powerful countries (including e.g. the USA) routinely use mercenaries in their campaigns. the "sending" nation may restrict their people and companies from mercenary actions abroad if they choose to, but if e.g. Israel is okay with their company hiring out as a "mercenary" (the term usually implies directly participating in a conflict while being armed and excludes any other support such as training, logistics, software, etc, but for the sake of argument let's assume it applies here) for Saudi Arabia then there would be nothing unusual about that - for example, Saudi Arabia has used thousands of mercenaries in Yemen.
If the specific individuals commit something that's a crime in USA then USA can try to put them on trial, but that works exactly the same no matter if they're Saudi citizens working Saudi government or serving in Saudi military, or foreigners contracted out to Saudi government as "mercenaries"; in both cases it's up to the local government whether they want to hand them over (effectively betraying their own "employees") or refuse.
They can be held personally responsible in USA criminal courts no matter if they're civilians or uniformed SA government employees - if a foreign government agent does something on your soil, you can (and should) apply standard criminal law can no matter if they're an uniformed employee in their service or not - for example, the Russian officers UK charged with Salisbury Novichok poisonings. However, USA courts can't enforce any judgements without cooperation of the host countries.
And Saudi Arabia can arbitrarily ignore the victims' complaints, foreign charges and convictions and their enforcement if they want, no matter if the violators civilians or uniformed government employees, that's only a difference if SA chooses to make that distinction. Uniforms would imply some differences in their rights according to Geneva convention if they would be captured as prisoners of war in an active armed conflict, but this is not an active armed conflict and they have not been captured as PoWs.
With respect to extradition or local prosecution Saudi Arabia can arbitrarily extend their protection to whomever they choose to, no matter what their status or citizenship is - if they have not made e.g. a bilateral treaty with USA where they agree that they will extradite such people, they do not have to do so.
Interesting podcast on NSO group from darknet diaries.
Yet a company like NSO weaponizes and abuses all sorts of vulnerabilities they get their hands on and sell it to thugs around the world who then use it against Americans and the same politicians couldn't care less
An android tablet connecting to wifi hotspots only, or even lan only, with minimal software, and a dumb phone are more secure than iphone.
Iphones are a standardized attack surface. Apple prefers vulnerabilities not to be found than to be discovered and patched, leading to NSO holding on their discovered vulnerabilities for longer.
An android device with no modem (baseband) is definitely more secure. Throw in a hardware switch for camera, mics, and wifi, which iphones will never have.
0: https://www.politico.com/story/2018/05/21/trump-phone-securi...
Texts shouldn't be difficult, just disable on the carrier end. MDM might be able to restrict it further just in case. With iMessage you can just not sign in to an Apple ID. Or use MDM.
I am assuming you use a killswitch VPN to your trusted network. NYT for this journalist.
My proposed setup is 3 devices: hotspot, android device without baseband, dumbphone. Hotspot would be the weak link here, security wise, but is easier and cheaper to replace. Nothing on dumbphone would be encrypted.
If I were a journalist, I would consider this alternative to being hacked. Remember he even knew there were at least attempts to hack his devices, years in advance.
They are just biting the "apple is the most secure alternative" propaganda.
The only way out of this mess is actually correct code on actually correct hardware. Maybe you have to run Linux and Android at the top to run existing apps, but somewhere below there you need a supervisor that makes security guarantees that are actually true. You can't just port a monolithic C kernel onto hardware that's struggling to be faster than the competition and call it good.
Journalists need to buy communications equipment that doesn't come with that "NO WARRANTY OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE" line in the EULA. Sadly, it is not for sale.
I won't hire anyone if they show any sort of activism at work.
A better comparison would be to ask if I would hire someone who worked for the East German Stasi, or someone who had helped to build the systems used to identify, target and kidnap dissidents in mainland China.
Edit: Additionally, no, I would not hire an ammunition manufacturer who produced ammunition knowing that the entirety of his output was exclusively purchased by a government for the exclusive purpose of assassinating those who were non-violently opposed to said government.
This kind of dystopia sucks and I am gonna push back as much as I can. OP's tone was definitely about activism and I can't stand behind it at all.
Also ammunitions producers have no idea where the ammunitions are used. It could be for saving lives in a hostage situation or assassination. Don't blame Intel for making processors that are then mounted on missiles that kill people. This is exactly what's wrong with illiberal ideology.
Once the rockets are up
Who cares where they come down?
That's not my department
Says Wernher Von BraunA friend had a professor at uni who'd been recruited to join a deep-sea scientific mission which was an absolutely incredible opportunity: a phenomenally well-appointed ship, newly constructed, a large scientific crew, and funding was completely assured.
He went on the project, returned home, and read much later in the paper that he'd been part of the cover mission for the recovery of the sunken Soviet submarine K-129, aboard the Glomar Explorer. According to the professor, he'd had absolutely no inkling of that mission.
https://en.wikipedia.org/wiki/Glomar_Explorer
That's one method.
The one used by Saddam Hussein as he executed (so to speak) his 1979 coup was rather more direct, and is explained here by Christopher Hitchens:
https://youtube.com/watch?v=CR1X3zV6X5Y
During WWII, numerous individuals turned on their own countrymen, comrades, and fellow Jews, as Quislings, collaborators, and capos, through a mix of threats and rewards.
And of course, various paths toward corruption are seen all the time in gangs, business, government, institutions, and other contexts.
That said, I'd have a very hard time working with anyone who is still working for a Facebook, Google, Amazon, Oracle, Palantir, AT&T, Verizon, or numerous other firms in the surveillance capitalism space today.
This should not be misconstrued as a partisan issue. Those who desire these outcomes will make every attempt to conflate it with one political movement or another. They'll appeal to auth sensibilities and moral panics.
It must be made clear that these represent efforts by the powerful to squash dissent and free society. It is an attack on the rest of humankind.
Is everyone who worked on this stuff also an enemy of mankind?
I am attacking the underlying tone of political activism in hiring committees. This seems deeply oppressive to me and signals 'internal rot' in corporations.
That said, surely you can agree the removal of comments we don't like is undemocratic. Further, no one user is the boss of this site's moderators. Here's a relevant article [1]: moderators are human too :)
[1] - https://www.newyorker.com/news/letter-from-silicon-valley/th...
This is despite being members of the IDF
https://www.richardsilverstein.com/2014/09/12/israels-nsa-st...
Motto: "At least we're less evil than Unit 731, right?"
The US gov't provides billions, yearly, in monetary aid and guaranteed loans to Israel specifically for military funding. Sure, most of that has earmarks, but that's the way the game is played.
This doesn't account for anything in the black budget, which as you can imagine, probably includes quite a bit for this realm. With Israel currently considered an indispensable intelligence partner (and thusly an outsourced R&D partner), I find it hard to suspend disbelief enough to accept that U.S. taxpayers aren't funding Unit 8200 just because there isn't a line item in public budgets.
And the US and England were also spying on the journalist Julian Assange, and have kept him in prison and tortured him for over a decade. Ben Hubbard luckily just got hacked.
Ethical? No.
Legitimate? Hell no.
But then there is that excellent movie Spy Game....
A ban on the polio vaccination program in some Taliban territory and attacks on vaccine workers followed.
My favorite is the US AID CIA spy who goes into Afghanistan in the 1980s that is profiled in Charlie Wilson's war. Or the fake vaccination program they conducted with "humanitarian" NGOs and charities:
https://www.scientificamerican.com/article/how-cia-fake-vacc...
My favorite CIA journalists are the ones who worked for CBS and other publications and were involved in promoting Modern Art around the world with NGOs like MoMA, the Rockefeller and Ford Foundations:
https://news.artnet.com/art-world/artcurious-cia-art-excerpt...
https://daily.jstor.org/was-modern-art-really-a-cia-psy-op/
https://www.bbc.com/culture/article/20161004-was-modern-art-...
https://www.independent.co.uk/news/world/modern-art-was-cia-...
https://www.amazon.com/Cultural-Cold-War-World-Letters/dp/15...
https://www.amazon.com/ArtCurious-Unexpected-Slightly-Strang...
There is a humorous scene in Men In Black where they refer to Andy Warhol as a CIA spy.
"Mr. Assange has been deliberately exposed, for a period of several years, to progressively severe forms of cruel, inhuman or degrading treatment or punishment, the cumulative effects of which can only be described as psychological torture."
https://www.ohchr.org/EN/NewsEvents/Pages/DisplayNews.aspx?N...
So which of these imprisoned him? Presumably not Ecuador. The UK for agreeing to extradict him? Sweden? Similarly - what who was the perpetrator of the torture? Ecuador for not offering sufficiently spacious accomodation in the embassy?
It's like saying that a criminal on the run hiding out in the woods is being tortured.
https://www.theguardian.com/media/2021/sep/27/senior-cia-off...
Assange, as a bail jumper and fugitive, requested and received asylum from Ecuador.
He could have, at any time, left the Ecuadorian embassy. In fact, had he done so, he'd likely have been investigated, prosecuted and potentially convicted of the charges against him.
Had that come to pass, it's entirely likely that Assange would have completed any sentence of incarceration years ago and have been back to banging Swedish girls for quite a while.
As we'll see, Assange might be convicted of violating the Computer Fraud and Abuse Act[0] which, under these specific circumstances (n.b.: IANAL) would carry a sentence of not more than five years, with the opportunity to reduce that sentence[1] by more than six months, assuming he is not given parole.
As to the completely bogus "charges" of violating the Espionage Act of 1917[2], no journalist has ever been convicted under that law.
As such, had Assange not decided for himself to jump bail and become a fugitive, he would most likely have been a free man for at least several years right now.
[0] https://www.law.cornell.edu/uscode/text/18/1030
[1] https://www.carmichaellegal.com/federal-sentencing-reduction...
[2] https://en.wikipedia.org/wiki/Espionage_Act_of_1917
Edit: Fixed typo. I need to do better proofreading before I post. :(
>“That the CIA also conspired to seek the rendition and extrajudicial assassination of Julian Assange is a state-sponsored crime against the press,” she added.
>In response, the CIA and the White House began preparing for a number of scenarios to foil Assange’s Russian departure plans, according to three former officials. Those included potential gun battles with Kremlin operatives on the streets of London, crashing a car into a Russian diplomatic vehicle transporting Assange and then grabbing him, and shooting out the tires of a Russian plane carrying Assange before it could take off for Moscow. (U.S. officials asked their British counterparts to do the shooting if gunfire was required, and the British agreed, according to a former senior administration official.)
Saying he could've just come out at any time is absurd.
https://news.yahoo.com/kidnapping-assassination-and-a-london...
Timelines matter. I suggest you check yours. That is all.
It is a tainted and biased source. Use it as a source at your own peril.
Not to mention the UN's guy whose job is assessing whether a person is being tortured has repeatedly said that yeah, what's being done to him counts as torture.
«Painting a picture of progressively severe suffering inflicted on Mr. Assange from his prolonged solitary confinement, the Special Rapporteur upheld that it not only amounts to arbitrary detention, but also to torture and other cruel, inhuman or degrading treatment or punishment.»
https://news.un.org/en/story/2020/12/1079542
https://www.ohchr.org/EN/NewsEvents/Pages/DisplayNews.aspx?N...
https://www.bbc.com/news/world-48473898
https://www.nytimes.com/2019/05/31/world/europe/julian-assan...
If I say "Your bike lock doesn't have to be unbreakable, it just has to be strong enough that a rational thief will look for another target," that doesn't mean I think the thief is justified in stealing other people's bikes instead of yours.
This is not worth discussing, it's a factual observation. Are we supposed to compete for who can make the most indignant face?
As you probably know, these assertions are a big stretch for many people. Not everyone considers Assange a journalist. He was living in an embassy for most of those years, so while he was confined, it's not a prison and not torture. Hubbard isn't lucky; neither the US or UK have ever imprisoned and tortured a journalist from a major publication (unless I'm overlooking someone). There may be legitimate debate about Assange, but it's not credible to pretend that these are facts.
This was in the news just last month: https://www.thetimes.co.uk/article/soldiers-burst-in-the-bac...
> A Belfast-born writer who has been a consistent critic of IRA violence has revealed how the British Army subjected him to electric shock torture outside his family home in the early years of the Northern Ireland conflict.
> Journalist turned novelist Malachi O’Doherty describes in a new memoir how soldiers first threatened to shoot him, then dragged him through a hedge, kicked him and eventually resorted to inflicting electric shocks to try to extract information about the local IRA.
Did he have freedom to leave the embassy and go somewhere else, if not then it is a form of torture.
CIA also considered killing him.
https://www.theguardian.com/media/2021/sep/27/senior-cia-off...
When you are doing the information from the inside thing, you do need to get your players in line.
England?
I'm English ... and Welsh, Cornish, Scottish and tangentially Irish, not to mention German (check my username).
The country is called Britain, the Great thing is only to distinguish from the other Britain - Brittany (part of France). You might as well call everyone from the USA as Texans.
Julian Assange spent rather a long time here: https://www.google.co.uk/maps/@51.4992504,-0.1614713,3a,75y,...
He was not tortured in the embassy - he was a guest who gradually outstayed his welcome. He was always treated well. As you can see Harrods is just to the right. This is not the roughest place to be a prisoner in Christendom.
Whilst he was in there, there were always several Police stationed nearby. They stood in doorways and kept watch. Probably a boring job but nice and simple. The whole thing basically costed the UK tax payer a fair old wodge and obviously Ecuador too.
I know that area and what goes on because I run internets for some flats nearby.
Sorry, but this is absolutely nonsensical to me, how can you be all these nationalities? Were you born on the most insane round trip flight ever or what?
Edit: And sorry, as a Scot (One actually born there); 'the country' is not called 'Great Britain'. As a nationality we group identify as both $member-country and also British/members of the United Kingdom. The UK itself, is made up of four separate countries, Scotland, England, Wales and Northern Ireland. Great Britain is simply our name for 'the big island (and all the little ones) excluding ireland', the UK is the big island + NI. Holy cow where did you learn such nonsense? :/
My uncle has done quite a lot of research. Quite a lot. At the extreme 15 gens down, you get this in your Ahnentafel:
"26921. Alice15 John (14829). Her married name was Trelowarth (14829). She was born circa 1550. She married Robert Trelowarth (14828) on 3 Oct 1574 at Wendron, Cornwall, UK. She died circa 1603 at Wendron, Cornwall, UK."
Edit: Apologies, I see you say you are British, however I've never met a British person who would ever identify as coming from more than one of our member countries. An Englishman calling himself Welsh? A Scot calling himself English? I mean.. I find it unlikely somehow.. But, hey ho, I'm often wrong and presumably this was one of those occasions. No offence intended.
The other Britain is Brittany - https://en.wikipedia.org/wiki/Brittany. Have a look at the county names in Brittany and see if they look suspiciously like Devon and Cornwall.
My family/surname is Gerdes. In Scotland, that is rendered as Girders. Only you can pronounce it properly 8)
Edit: sigh, okay you are a little bit right, but besides of course the settling after the whole Gallic period, and the Brittons, the Normans, and the Saxons -- please, forget all that we are talking about the term GB right now and this only refers to the island.
Your point is?