US puts NSO Group on trade blacklist
ft.com
ft.com
The U.S. was willing to look the other way when NSO was selling its crap to e.g. the UAE, an American ally.
In my opinion, NSO fucked up twice: first, by selling to America police departments, thereby putting it on one side of a partisan issue. Second, by helping subvert democracy in India, thereby pissing off its allies in State. The first mistake made them persona non grata. The second removed the protection their being Israeli granted.
Forgot about that. Almost certainly.
I doubt it was an explicit deal. NSO was protected, to a degree, because State didn't want to piss off Israel. (I don't think the IC ever came to bat for them.) But systematically screwing with American allies, democracies at that, and then getting undeniably caught, makes one difficult to defend. The French part not only contributed to this erosion of their defensibility, but may have made throwing them under the bus diplomatically advantageous.
Source: https://twitter.com/BarakRavid/status/1455178005500805120
The U.S. government doesn't care about anything. The people who join, make it to and remain at the Foreign Service, the 13,000-odd professionals who make up the bulk of the State Department, tend to care deeply about it. That doesn't trump national interest. And at the end of the day, a political appointee is in charge. But it's a human factor that can tip issues on the knife's edge.
> The U.S. government doesn't care about anything.
An essential point. Below excerpts a great article that addresses it, by Jeremy Shapiro of the State Department, Brookings, and elsewhere:
http://mideast.foreignpolicy.com/posts/2013/12/05/how_the_us...
People often talk about the government as if it were a human being. It 'thinks,' it 'believes,' and sometimes it even 'knows' -- or 'should know.' Critics frequently demand that the government should understand and learn certain key facts or lessons of history. But of course the government is not an individual. It is rather a vast constellation of people and institutions, and as such it learns information and processes knowledge quite differently than do individuals. Most importantly, government 'knowledge' about foreign policy issues is not learned or deduced. Rather, it is formed through a process of bureaucratic or political compromise between often conflicting theories or goals.
The result is that the government does not think and learn in clear and consistent ways. First, the government often lacks logical consistency. As a collection of people and institutions, the government is much more capable than individuals of holding deeply inconsistent beliefs. If, as F. Scott Fitzgerald said, '[t]he test of a first-rate intelligence is the ability to hold two opposing ideas in mind at the same time and still retain the ability to function,' then the government is a genius. The U.S. government can 'know,' for example, that it is simultaneously both the leading global advocate for Internet freedom and the leading violator of privacy on the Internet.
Second, the government often relies on old information or disproven ideas. Changes in conditions on the ground or new academic insights are less likely to affect government thinking than personnel changes or domestic political developments. The U.S. government can therefore continue to know that nuclear weapons threaten to spread like a virus even if it has continually over-predicted the spread of such weapons.
Third, the government often lacks forward thinking. An important rule of governance holds that once agreement is reached on step one of the policy process, stop arguing over future questions until they are posed. This means even deep divisions over next moves are papered over until they become immediately relevant, often causing inconsistent behavior or long delays to work through internal disputes. Accordingly, the U.S. government can decide to invade Iraq without really discussing whether the goal is democratization or simple regime change.
Freedom and privacy are orthogonal.
You can have Freedom without privacy.
Hereafter, why not, they're already blacklisted (in the US) anyway
Edit: I apparently didn't read closely enough
That's essentially everything. Including mainstream x86 and ARM implementations. And Linux. And Windows. and iOS. And most foreign software, since nearly everything includes various libraries, which have Americans writing code for them.
This is the same list Huawei was added to.
Practically speaking, it also means they and their affiliates will have a difficult time maintaining bank accounts and getting financing.
toothless is toothless no matter if it is wrapped in state level dressings.
Implementing IT with no access to US vendors would be a PITA. No Microsoft Windows or Office, no Google Apps, no Red Hat, no Apple .... How could that be done? Will some flavor of Linux suffice? Would it be in compliance with their license?
Is that how they are? Seriously, I wonder about their organizational culture. Many security firms are very corporate. Many such firms in Israel come out of their military, which suggests a different culture. Some are a bunch of hackers, but it would be hard to be effective in selling to and retaining large institutional customers, or even running your own organization from day to day. And how large are they?
> You really think they won't be able to aquire what they need?
They expose themselves to lawsuits - they are trying to operate in the legal business domain. And again, acquisition is only a fraction of IT (see the GP).
https://prospect.org/world/barack-obamas-legacy-is-narendra-...
Like, yeah, I want nuclear weapons to be abolished. But if NSO were selling briefcase nukes to everyone interested, I wouldn’t say, “but what about the SAC?”
The fact of the matter is, given the way the world works, you probably don't want to piss off the US Treasury Department.
Certainly NSO can't complain about being victims of unfairness and government abuse.
What's that saying? "Better late than never."? Or how about "Never let perfect be the enemy of good."?
Obviously the US intelligence agencies knew about this well before the public did... and while I'm not quite ready to put this all on the goodwill of the Biden administration, it's also a reminder that civilian leadership changes do effect change, despite all the "Deep State" nonsense going on these days.
You believe it is nonsense? I figured it was just generally understood that the President is more or less powerless really at this point, This is not new under Trump, hell this really was that way before 9/11 but accelerated ALOT after.
NSA, CIA, FBI, etc do not really answer to elected officials, I am surprised people still believe they do
The USA system was designed to balance powers between the three branches of government.
Turns out there is a fourth branch: Bureaucracy
In fact, the US people specifically don't want and prevent a monarchy, as you say ...
> The USA system was designed to balance powers between the three branches of government.
> Turns out there is a fourth branch: Bureaucracy
Bureaucracy isn't a fourth branch, it's the laws made by prior governments. You don't get to start fresh; you are the steward of an ongoing institution. The American people, through representatives, made laws that define what the executive branch must, can, and cannot do. Bureaucracy is, in a sense, the execution of those laws. A new president may not like those laws, but that's the job - to carry out the will of the people.
No the US Congress in their political cowardliness passes objectives they wish to see, they then empower unconstitutionally the executive branch to create numerous "administrative laws" to achieve those objectives.
The Supreme Court refuses to strike down these vague laws as unconstitutional, which over the decades has grown the bureaucracy exponentially until we have at present what is in effect a 4th branch of government not answerable to any of the 3 official branch, not with out wide reaching reform, and upending of governmental structure.
>>You don't get to start fresh;
This is where the I wish Jefferson would have gotten his way.. "The question Whether one generation of men has a right to bind another, seems never to have been started either on this or our side of the water… (But) between society and society, or generation and generation there is no municipal obligation, no umpire but the law of nature. We seem not to have perceived that, by the law of nature, one generation is to another as one independent nation to another… On similar ground it may be proved that no society can make a perpetual constitution, or even a perpetual law. The earth belongs always to the living generation… Every constitution, then, and every law, naturally expires at the end of 19. years. If it be enforced longer, it is an act of force and not of right." -- Thomas Jefferson...
We should start fresh every 19 years
Those are just indicators. The rest of the comment could still be great, but I can't read everything.
yes that is also known as the Deep State, which the grand parent claims is "nonsense"
"Deep State" implies more than acknowledging the bureaucracy. It's the claim that the bureaucracy is unresponsive to, or even controlling over, our elected leaders. (And presumably, the courts, though I don't tend to see that part addressed in common tellings.)
If you don't believe the latter bit, using the term "deep state" unnecessarily tarnishes the credibility of your argument. (Federal bureaucracy is a more neutral term.)
It's like if you pulled someone random off the street and made them CEO of a Fortune 500. Do you think the entire org would just turn on a dime and listen to them? No chance.
So sure it may not be outright insubordination, but the result is the same
They can also use other levers to ensure any they dislike fails, etc....
This is the deep state, where if the bureaucracy does not like a policy they can and do resist it.
As for simply installing uneducated people in the bureaucracy instead, that's how you end up with the Soviet Union.
Also I resist the idea that attaining a degree, any degree, qualifies as "educated" and anyone that has not attained a degree is "uneducated" that type of credentialism leads to all kinds of negative outcomes, and false assumptions. Which is the metric the media uses to label the electorate is "educated" or "uneducated". There are a huge number of people that have high levels of informal education, and there are people that have degree's that one can objectively argue are uneducated by any reasonable measure.
So over all I reject completely on different levels the entire premise of your comment
Instead they give the executive branch broad "goals" to achieve to be achieve by means and methods to be determined by the unelected administrative state
This unchecked power is also not an democratic ideal.
And taking the most favorable view of the Biden administration on this move, "Biden punishes foreign private competitor to US intelligence agencies" wouldn't be a sign of him addressing US intelligence.
I know that in this case puts the whole thing in a bad light, but still as a principle assumed innocence is worth preserving IMHO.
Isn't this black listing a shot across the bow?
This is the U.S. Treasury. The concerns you're worried about have been contemplated.
If they really wanted to stop this kind of activity, they'd sanction the individuals involved. This would deter others from forming a successor - would you accept an extremely well paid job if there was a risk that the US will put you on its official international shitlist for that?
That's not how the Entity or SDN lists work. Every individual ever employed by NSO Group is going to start having difficulties with their bank and securities accounts starting today. Affiliation with a blacklisted entity moves you from "person who does not generate hits on OFAC" to "person who does." For many institutions, that's a dealbreaker.
You can't get around a blacklist by shutting down shop and re-starting under a new name. These are old, battle-hardened tools originally designed to go after state actors. The loopholes have been thoroughly explored.
I certainly wouldn't send technology subject to export control to anyone I knew to be a part of NSO Group or any successor.
If you're an employee receiving salary payments from NSO, expect your bank to be unhappy with you.
Just like a NYT article accusing you of being a terrorist does not carry any official repercussions, it will certainly ruin your banking relationships.
Since checking all manner of sanction, exclusion, risk, etc. lists published by the government is trivially automatable it is basically a minimum standard, and even the simplest KYC systems are going to flag customers that appear on any of these. For more significant clients additional databases and analyst resources will be used that are likely to uncover a relationship with such entities, especially a simple and easy to check one like prior employment.
This is a world with few black and white rules, and banks are mostly not outright prohibited from providing services to high-risk customers. But higher and higher levels of approval will be required, and the bank will have to go into the situation knowing that they will incur extra costs in terms of analyst time, compliance work, and ultimately liability of potentially huge amounts of money. It will be difficult, although maybe not impossible, to convince a bank to work with you. Everything will end up costing you more. You will have to be very cautious because banks will sometimes change their risk evaluations and decide to terminate the relationship, and you will have to figure out how to start your banking relationship over somewhere else.
While all of this is required under various laws (federally things like the BSA, PATRIOT act, etc), statutes are intentionally vague about the requirements both because banks are encouraged (and pretty much required) to perform internal research and development to improve their AML/KYC methods, and because the system operates in part on secrecy - bank clients need to not know how AML/KYC analysis works in much detail or they may find a way to structure around it. Banks also share information with each other and with governments, much of which is done under strict confidentiality agreements for several different reasons.
Banks that get this wrong can lose hundreds of millions and occasionally even billions of dollars, so there's a lot of hesitance to take on risk. It's also generally perceived that enforcement is becoming more aggressive over time, not less.
Source: https://www.mckinsey.com/business-functions/risk-and-resilie...
FWIW It is practically illegal for banks to discuss their AML/KYC practices, nobody is going to go into detail about this.
Being employed, or even having been employed, by an entity on the BIS's Entity List will make doing business in U.S. and in U.S. dollars expensive and tedious. At the very least, you will impose ongoing additional costs for every financial institution you interact with.
Yes, there are other designations which would carry even worse repercussions.
I would not be silly enough to think this means less unconditional support for Israel in general, though. NSO Group just specifically got too toxic.
It would never have happened without good Western journalism. Basically NSO was allowed to operate unless they screw up. Which they did with all the scandals, making Israeli look like crooks.
Israelis themselves prided themselves on invading but with every intention to not take Egyptian land. Israelis weren’t driven out, they beat Egypt to show their power and created a good relationship with them. No Israeli I have ever talked to says half of Egypt should have been theirs or the US drove them out, they always make a point they bargain and prefer peace.
I'd like you to define how US policy is "antisemitic". Why are these horrible US antisemites giving Israel military aid and money?
I was speaking more so to this first part of their statement. Someone making this claim is very uninformed on geopolitics.
The kind of lobbyists in Washington are not rooting for the secular state of Israel, but pretty much specifically for the orthodox Haradrim, or the kind of Neftali Bennet.
Equally so, Israelis hating Arabs don't preclude them propping up the criminal Saudi state, and a small portion of Saudi elites who hate Turkey.
[EDIT] Oh damn, when did Jordan rocket up the list of US aid recipients? I gotta start keeping up with geopolitical shenanigans again, I'm clearly behind the times. But yes, the Egypt thing was, if not publicly the case, one of those open-secret things that're taken for granted in poli-sci and policy circles, like "Israel has nukes", or "the US removing MRBMs from Turkey was part of the deal for keeping Soviet nukes out of Cuba". The US pays Egypt not to mess with Israel.
The US did not support Israel past the original vote, rather it tried to push a series of measures that would have been detrimental to Israel. At the time Israel was far more reliant on the USSR.
Anyway, the US policy at the time was determined by the State Department which was very anti-Israel for various reasons. Truman overrode them for the US vote, but was too busy with other affairs to set policy afterwards.
Trump moved the US embassy to Jersusalem, and the US gives billions of aid to Israel. What is your criteria for "antisemitism"? If accepting the capital of Israel, giving money, military aid, is your definition of antisemetic it dimimishes Nazis activity if you group aid into "bullying" and "antisemitism".
I don't think that accurately describes US policy anymore, if it ever did. Modern day US administrations have withdrawn from the world, and that means their ME policies are not determined by reality, but by domestic ideologies and domestic political considerations.
> NSO and a smaller Tel Aviv-based company, Candiru, were among four companies added by the US commerce department on Wednesday to its so-called entity list, which would restrict exports of US technology to the companies.
From https://www.commerce.gov/news/press-releases/2021/11/commerc...
> The Entity List is a tool utilized by BIS to restrict the export, reexport, and in-country transfer of items subject to the EAR to persons (individuals, organizations, companies) reasonably believed to be involved, have been involved, or pose a significant risk of being or becoming involved, in activities contrary to the national security or foreign policy interests of the United States. For the four entities added to the Entity List in this final rule, BIS imposes a license requirement that applies to all items subject to the EAR. In addition, no license exceptions are available for exports, reexports, or transfers (in-country) to the entities being added to the Entity List in this rule. BIS imposes a license review policy of a presumption of denial for these entities.
General Entity List descriptions are available at https://www.bis.doc.gov/index.php/policy-guidance/lists-of-p...
It seems like it mostly restricts them from using US made tech and punishes US companies that supply them.
Meaning NSO Group could not buy tech to build nuclear warheads in their backyard, but otherwise they are good to use any 'usual' US-made software.
Other commenters say it is significantly harder for companies in that list to banks because of that list. Is that true?
It’s also not super easy to find banks willing to work with companies publicly blacklisted by the US government.
What is going on in Israel where there are this many companies engaging spyware for sale to any customer who simply has enough funds to buy them? What's the commonality here? Is these NSO stories in in Israeli media?
Lastly what is meant by "military grade spyware." That sounds like marketing fluff.
There is no need to transfer any wealth from NSO and the code is both illegal and secret, anyways.
Edit: it should not be that obvious, but I don't think NSO will close shop because the trademark was flagged. Rename to meta, or something like that.
The NSA and other government agencies seem to not be attractive from the point of view of a great place to work and the money to be made in the private sector in the US alone is thin. . . economic forces dictate that supply will meet demand especially when the demand is rich middle eastern wealth.
There is no obvious "red team" or similar career for these people in the US to help defend the nations systems for a fee. All government contracts for cybersecurity go out in tenders that prioritize entities that can navigate the complex logistics of filing a response with the Government and working their way.
That's the biggest concern for me seeing this pattern emerge. On the specific entity here, the NSO group being blacklisted, that will change little. There is a systemic risk of us continuing to lose great talent to more attractive ventures.
The same people are playing both sides
It's not like the government doesn't purchase private sector cyber security. It's just 1 group of very smart people doing all the work for both sides
I think there might have been pressure on NSO as part of trial of Google|Fb.. against them. https://www.theverge.com/2020/12/22/22194930/microsoft-googl...
That is the link to episode 47 of dark net diaries.
I guess Hacker News has devolved into a place of talking over each other and downvotes.
It seems to me like you are overestimating the skills of people that just don't have any moral barrier while underestimating the skills of many proper security researchers. Companies like NSO are most of the time able to do what they do because they shake the right hands and get the right support (or the right people to look the other way), not because they have some special people that you can't find anywhere else.
The thing with this line of work is that one mans ethics becomes another mans sin. The tl;dr of that episode is that some of these people were led on to believe they were actually targeting criminals and terrorists. It later became clear that was not the case.
The road to hell is paved with good intentions and all that. It would surprise you that even the most noble of pursuits in engineering have very cruel applications in war.
I find it logically untenable that a 'prized mind' would not be completely aware of the types of things they were building and the intended usage thereof. If they aren't smart enough to figure it out, then we're not losing access to some particular genius. If they are smart enough to figure it out and continue to contribute to the work they have become complicit at best, and likely are an amoral psychopath.
Why do we carry these things in our pockets?
And I'm not convinced Signal or any other privacy protecting app is really useful. If we assume all cell phones are owned (or can be at any time) then the criminals own all the private keys on the phones as well.
It's impossible to have private communications with a cell phone.
All major OSes (regardless of formfactor) that a consumer uses are written in C.
All languages, including C, are "unsafe" if the standard is that software in said language can be written in an unsafe way. Writing an operating system, firmware, or embedded software is a fundamentally different category of activity from writing some CRUD app (other than unhelpfully sharing terms like "engineering", "language", and "software.") OSes are written in C because the task demands it; the reason that there isn't a Javascript-based kernel isn't an arbitrary one. Perhaps Rust will change the game at some point, however as it stands, it doesn't make any sense to draw a distinction between OSes written in so-called "unsafe" and "safe" languages.
Why should we have any expectation of privacy when we use a cell phone at all? It is triangualating your location 24/7 even if its not a smartphone. When/why did we expect them to be private in any way? How can you expect privacy when your location data is being broadcast and you're carrying a tracking device?
>Why do we carry these things in our pockets?
Its worth it for the tradeoffs.
This would make too many false positives, for which you'd have to do in person surveillance to verify.
>You don’t think they can identify phones in bulk collection? What evidence is there of that?
It doesn't matter if a cell tower can read your IMEI. It matters if that IMEI can be associated with your real name. Have you seen anyone's location data successfully correlated with a real identity when that location data doesn't include travel to residence or place of work? If you can solve this problem, you can sell it for more money than you could fathom.
Automatically, with dragnet surveillance? Not a chance, the search space is too huge. But if you think it's so easy, feel free to try building this and selling it, you would become the next billionaire.
There is no snark in facts. You’re connecting to a triangulating system that traces your location and expect privacy if you use some open source android distribution which you assume has zero bugs that others can't exploit and trace you. That is delusional. The device has a signature electronic radiation that is easily identifiable whenever its on, which you ignored as a method of tracing.
There is zero factual evidence that you can be private when using cell phones at all. It is a delusion with no basis. You don’t make any substantive arguments that proves privacy aside from hopeful/delusional assumptions that aren’t sourced or prove any privacy. You think buying a sim card with cash is enough to protect your identity when stores have cameras and your fingerprint is on cash? Where is your evidence that you are private?
>This seems like the government outsourcing controversial activities to Israel.
It certainly feels that way to me, as well. The US is in a sticky situation. This just feels like a standard burn. You're caught, now you're out. NSO made too much noise and got cut loose. Obviously the NSA and others are going to continue this kind of work.
I'd be much more worried if US government was found to be hacking/assassinating Saudi dissidents, because that would mean the leaders of the US government are completely incompetent. That's not to say it's not happening, just that it would be idiotic for the government to do that themselves when they can use foreign contractors instead.