The secret Uganda deal that has brought NSO to the brink of collapse
arstechnica.com
arstechnica.com
One prosecutor, who is fighting for indepenend judiciary and against her political boss, head prosecutor Minister of Justice, smaller party Coalition member, got notification her iPhone has been hacked multiple time by Pegasus. She angried the rulling coalition, after she wanted to investigate illegal vote by mail election, that didnt take place at the end but cost Poland 23 mil USD.
The other person that was hacked more than ten times, is famous attorney, previous politician. He was an attorney of opositionfuhrer Donald Tusk, former PM. He was representing multiple high level clients that were suing the government, including one that was scammed by the head of rulling party Law and Justice. Hacking took place in times of campaign before elections.
Poland is such a crazy country right now. If you can write an email to ur congressman to fight for biggest US investment in Poland, TVN tv station that sheds light on this corrupt government. They are trying to make the owner (Discovery) sell TVN, worth one billion USD
> One prosecutor, who is fighting for
> The other person that was hacked more than ten times, is famous attorney
As usual, the EU and the powerful countries who make business there have not made much about it.
People complain about the west enabling the Chinese communist leadership, but it's the same for every corrupt government.
You do realise the only reason Poland and Hungary still have voting rights in the EU are because they mutually block sanctions against the other one, don’t you?
The recovery funds are blocked and the EU executive is suing Poland for violation of the block law. I think they are doing as much as they can. Obviously from the point of view of a citizen of the EU just expelling Poland would be better - the extension championed by the UK was a terrible mistake after all - but it’s sadly not an option.
For example: Infineon is building a 100M€ plant in HU. The German government(s) could pressure german companies not to do business in countries where democracy is endangered, or where human rights are violated, but it has chosen to not exercise any kind of moral suasion.
HU or PL are not Apartheid-era South Africa, but there is more you can do as a freaking head of government then make a "we are worried" statement.
It’s not biased if the information is accurate, did the hacking take place or not?
That doesn’t mean I’m against your side, or for their side. I have no idea, I’m not polish. Both sides must account for their actions, but one side doing bad things doesn’t in any way justify the other doing bad things. That would be what-about-ism. If the ruling party in Poland used Pegasus to hack opposition phones, that’s scandalous and entirely on-topic for a thread about Pegasus.
This was clearly the plan all along. Such companies live and die by their low profiles. Was probably not the founders' first such company nor will it be their last.
Next step will be to close up, take the contacts, clients, capital, the lessons learned and the cream of the staff to whatever mercenary, unethical piece of crap they make next.
This is why killing the industry as a whole is so important. It'll mean going after the owners, suppliers and employees/contractors with naming/shaming, coordinated sanctions, criminal charges, designated persons lists etc. until their reputations are trash. No bank would fund it, no parters would supply it and no one with any talent would ever contemplate such a catastrophic career move in future.
And no government of any geopolitical significance would ever support such actions. These kinds of people, and their skills/tools, are FAR too useful.
All those actions mentioned by OP dissuade talent, since when you are on the top you have tons of interesting choices. Why work somewhere you are actually ashamed of to even mention. Why on top of that working for amoral goals that make world a much worse place, innocent people get killed just because of your work etc.
Those talents will find some work easily. Maybe even for competition. But its the right move, the more the better.
If anything it will make recruitment by significant governments easier.
A better question is that while these companies are basically cyber weapons companies, what do the truly big players have: the US and China? We got a glimpse with the viruses targeting hard drive firmware and others, but maybe they are lazy because they get to enforce backdoors.
Top talent will make way more in private firms, it's the only way to make a ton of money. Government pay is basically capped. The government pay also encourages the government employees to hire contractors, because that's how you get side benefits (not bribes! tooootallly not bribes), like ultra cushy jobs for relatives, a "consulting" job once you get sick of the government, etc.
I'd say it's like aerospace contractors. Just wayyyy to high tech for a government project and mediocre pool. Even NASA can't efficiently design complicated engineering projects, and they probably are the only government agency with a good reputation and decent people.
The only interesting thing about these vendors is that their weapons are in active, constant use, but it's not that obvious to the victims.
Um, the Apollo Program... or did you mean cost efficient?
Mercenaries are a better analog. Are you saying that soldiers of fortune make better soldiers? Better armies?
The public vs private sector debate isn't as simple or settled as you suggest. For example, and more on topic, given relatively modest salaries the NSA has produced some of the most capable, respected hackers in existence. Creating a parasitic new industry just isn't necessary. Creating risks to global stability isn't either.
Facebook banned all NSO employees from Facebook. The Israeli courts forced Facebook to unban them.
https://www.calcalistech.com/ctech/articles/0,7340,L-3837077...
What a brave approach. Especially in regards to employees. This would close down every other major US company.
[1] https://twitter.com/norbertmao/status/1463364241688305664
I still think the Americans are just mad they got owned by Uganda. I'd bet this isn't the first time they have scored points against the low expectations of their "advisors," either so: well played. Point Uganda. I think this is a really funny precedent, and I can't believe I'm defending either of them, but the arguments back just aren't powerful when compared to demand for the tools of sovereignty, and we should give the conseqeunces of that due consideration.
How do you intend to support your claim that the 11 US diplomats and employees from the US embassy are spies (and thus are supposedly legitimate targets in your view)?
Nowhere does it say US spies were the targets. And no other story on this subject has presented evidence of that either.
Whether these particular people were spies, it seems like proper counter-intelligence to track all diplomats pretty closely because at least some of them are going to be intelligence operatives.
In this instance, Israel needs the US, Pegasus was Israel's technical gorilla in the spy world, and it got used on the US by someone they sold it to. This level of fallout given that is not unexpected; Israel cares more about maintaining ties with the US than they do about a given tool, company, or to enable Ugandan spying operations.
Curious, do you happen to know what such spies do?
I'm wondering if it's just a reporting the news, talking to people and collecting information that can be legally obtained.
Whether they collect it overtly or covertly is the issue here.
The USG had an "agreement" with Israel that NSO products wouldn't be used against the USG. Uganda did.
So the USG is making it clear to Israel that they have to rein in NSO and other "private enterprise" spy product providers.
How can usage of a Mossad / IDF tool be considered legitimate? Just because the ruling party in a state decides so, doesn't mean this has any bearing on human rights or _legitimacy_.
China is eradicating Uyghur culture and running for-profit concentration camps. These are legitimate uses of their Governmental powers. Does that make them ethical? Of course not.
Technology like this is dystopian and anti-humanity. There is no way that this technology is profitable, exported and somehow used for "legitimate" purposes. The entire enterprise is predicated on making vulnerable people more vulnerable. The end result is more Khashoggi awfulness, how could it NOT be?
I think many of us may fear a transnational government, yet we have transnational organized crime, transnational companies, transnational communication networks, etc. at some point, I hope we also get more transnational governance to balance some of those other entities.
For example, you could secure access and get insight into a terrorist ring using encrypted messengers, once the necessary paperwork has been done, reviewed and approved by an independent judge. Phone taps and internet taps worked great until everything became encrypted. Hard drives that cannot be accessed, conversations that cannot be monitored, you name it; the governments of the world have a difficult decision to make after about 120 years of easy access to criminal's conspiracies.
I'm not sure if there's any system of government in the world I'd currently trust with this power, but it's not inherently impossible to use these tools ethically. At the end of the day, governments are desperate for a solution for the encrypted nature of modern data and communications and don't think that there are any other solutions than either allowing the police to hack or banning/restricting encryption. I'm not sure which option I prefer, but I believe (fear) either will become the accepted norm within our lifetimes.
In general, I am against government overreach, so I agree with a lot of what you said.
However, let us say I have a court order to surveil person X - how am I ever going to get all the information when they could be communicating via a phone call, SMS, iMessage, whatsapp, gmail, facebook messenger, signal, telegram, discord and a myriad of other mechanisms with a myriad of identities. The easiest solution for me (the snooper) would be to surveil your entire phone, including click history and screenshots when feasible. No?
Once again, let us forget the person side for a minute. Let us talk about someone with genuine need to surveil. How will ever do it with today's technology? It aint easy.
On the flipside, a snooper will always have to do a monumental and maybe impossible amount of work to break a one-time pad by chipping away at the security that surrounds it.
What makes security tech fundamentally different? Why should it be easy to break? A warrant lets someone search my belongings; it does not compel me to give law enforcement the information they are seeking.
> A warrant lets someone search my belongings; it does not compel me
> to give law enforcement the information they are seeking.
This is the issue. An investigator's limited permission to search a specific aspect of one's belongings does not infringe upon one's right to be secure in the remainder of his belongings. At least, not in the context of nations which have explicitly granted that right.LOL at describing PDFs as "adapted software from 1990s Xerox machines"
https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
JBIG2 has been in the news periodically for a different sort of problem - you can't trust it to accurately represent what was scanned:
https://www.theregister.com/2013/08/06/xerox_copier_flaw_mea...
A lot of news articles are describing JBIG2 as something archaic, when it seems to be as relevant and commonplace as ever. (see MRC, for a modern application)
Basically, you scan a paper document. It contains a mixture of line art, text, and photographs—“mixed” types of content. You can segment it and use different codecs to encode these different segments, and then combine the results in a PDF.
> Essentially, 1990's algorithms used in photocopying and scanning compression are still lurking in modern communication software, with all of the flaws and baggage that come with them.
https://arstechnica.com/information-technology/2021/12/googl...
Given than JBIG2 wasn't standardized until 2000, and that the Apple vulnerability was in their implementation (vs the standard) I just don't understand this characterization.
NSO built in a complete block of +1 phone numbers. But those US diplomats were not using +1. Which itself is a security issue that i'm sure is already being discussed at the state department
[1]https://www.usatoday.com/story/news/2015/04/07/dea-bulk-tele...
Also, for them to have a +1 number outside the USA means they have to be on a USA network and then roaming onto a local network. This presents dozens of problems, such as often not being able to get the best connection, not being able to get data connections, not being able to get any local support, and it costing a small fortune.
All the embassy employees I have ever known have gone full native with all of their technology etc.
Like the whole business around US military bases and Strava.
With an Ugandan sim comes the security of the Ugandan mobile network and its employees
But given the number of countries under nanpa, I bet they filter at the area code level. Can’t turn away that sweet Dominican Republic opportunity.
How does data work if you get NSO’d? There’s gotta be some Canadians facing massive mobile phone bills because of NSO shenanigans.
But from what I can see, nanpa is also a Japanese word for something that sounds like random approaches on women in malls, etc. for dating. I forget the term in English.
> NSO has always told its customers that US phone numbers are off-limits. In this case, all 11 targets were using Ugandan numbers, but had Apple logins using their state department emails, according to the two US officials.
That's why you do recon before targeting somebody.
Do you suppose they just sprayed the malware onto random phones?
I get the impression that Pegasus is meant to be used in a very targeted way, at people you have identified before, and have some reason to spy on. If you do that way, what are you chances of wanting to target somebody else, and accidentally getting 11 US embassy employees?
NSO promised oversight, they can't just weasel they way out by saying "there's no way would could have implemented effective oversight".
I highly doubt that israel the country wanted this turn of events, for the simple reason they are not stupid and the cost-benefit ratio of this seems bad for them.
They won’t want to be seen as reining in Israeli military overreach because there’s a feeder pipeline from the Israeli military into both politics and the weapons industry. It’s the same people running the country that are selling these weapons.
Well… obviously? How else could Israel treat him?
Yes and sort of and no.
The thing with weapons is that occasionally you sell them to people you end up fighting. Take the Falklands war - Argentina was using American, French, and British weapons to fight the British. It happens, it's a bit of egg on everyone's face, but it is what it is.
When you're a major arms dealer, you'll eventually end up selling guns to an enemy of your ally, or supposed ally.
I don't disagree with your point, simply saying that IMO the US doesn't take cyberattacks seriously precisely because it leads down a dark path with China (and probably Russia too if we're being honest).
All during the Cold War the USA and USSR engaged in various kinds of low-level sabotage against each other. Fortunately for us all, it didn't escalate out of control.
> In this case, all 11 targets were using Ugandan numbers, but had Apple logins using their state department emails, according to the two US officials.
it isn't that easy :) If you work on any major and/or popular software it is most probably used by State Dept (even if it is just an obscure part of some software stack that some State Dept LOB is using implicitly). Theoretically any software may have bugs/holes and thus be a part of such a spying.
I say this because I've had stuff done to my phones in the past, one strange incident with a "hacked" phone was selecting an AirBnB, which I believe directed me to a few of their "safe" houses. Other examples, include batteries going flat over night when asleep despite phone being switched off, not charging but was fully charged before it was switched off. The phone signal is weak when that took place so it would have burned through the battery amplifying the signal, but listening in to people sleeping can elucidate what might be on their mind!
A state born of hard-edged refugees escaping a world that had recently written them off to die, carried through several existential wars, and now they are EMPOWERING that same evil.
Also, please please do not trot out the "NSO isn't Mossad/IDF" nonsense. I wouldn't be surprised if all of this was a façade to penetrate the infrastructure of states that Israel wanted to monitor.
There has never been a more competent, sophisticated, and dedicated group than that of Israeli intelligence. To imagine that they would allow all this as an oversight without some state benefit is not something my brain can comprehend.
Rather I suspect they were selling it as hacking-as-a-service and the clients they had never actually got their hands on the software or any physical servers (apart from possibly NSO relays), rather everything probably passed through their servers hosted in Israel where they could control that +1 and +972 numbers were never targeted.
The people they had as client only cared as long as they got into the iPhones,etc they wanted, I doubt they cared if they had control of the software or not.
Have you not thought how US companies like MS, Apple, Google do stuff for the US govt, just like when it comes to financial sanctions on Russians, its the US asking the UK to do it. Look at the Ukraine and the NordStream2 pipeline between Germany and Russia, US leaned on the EU to make things difficult for Russia.
Look at the criticisms of China's HueWei spying using 5G networks, the fact HueWei hold more global 5G patents seems to be irrelevant to the US except its not because its a classic case of leap frogging in technology whilst older tech patents are milked.
Its what you would expect from the leading nation on this planet ie the US to engage in behaviour wise but all this US repression makes those countries double down and come back with something better.
NSO is just the latest fallout, but its nuanced and not everyone picks this up when reading the global news.
The US is end of empires time, its just natural just like Afghanistan is the only country on the planet to have never have been colonised by an outside force, namely Russia empire, British empire and US empire and how many people knew that?
You should google up the story of the Swiss company Crypto AG Tl;dr; bought by the CIA and the BND (German counterpart) in 1970 and sold security software to governments all around the world. With built in backdoors for the CIA and BND. It was the main source of foreign intel for decades for the CIA.
Once you go conspiracy there’s no end to what seems possible…
It's not about civil rights, it's ont about money laundring, its just about the US trying to keep ahead of everyone else.
I mean I guess 7.5% is technically “a fraction”, but I’m used to this phrasing meaning “a really tiny fraction”
If the US diplomats Uganda used the NSO technology to spy on are intelligence agents, they still possess diplomatic immunity. They are in Uganda with cover (as opposed to non-cover; that is, they are in country without being a public US goernment employee).
I should be clear I do believe they are being recaptured. I just don't understand how. In the pre digital world, most phone steals were inside jobs: somebody leaked info leading to a voicemail hack or a stingray type cell listen in. Post digital, i suspect a lot of things are still inside jobs, but on phone compromise feels like a problem moving platform solves.
> “We always knew this thing had an expiration date,” he told the friend, complaining that some clients had asked to shift their contracts to lesser-known rivals, according to a person familiar with the conversation.
I guess if you have this perspective, you want to maximize revenues and IPO before your product gets misused and invites US sanctions.
I wonder what the reaction would be if this was a US company and not an Israeli one. Apple would still sue them, of course. But they couldn't be sanctioned by USG, right?
That's just false. The NSA bought the Swiss company Crypto AG and has been selling backdoored crypto devices all over the world for decades before being found out.
For hacking into a US official's phone without a warrant? They would go to jail.
My understanding is that various US private, political and government forces have been using Israeli private physical and cyber security/intelligence services like NSO against US targets in particular for that reason. For example:
https://en.wikipedia.org/wiki/Black_Cube#Iran_Nuclear_Deal_a...
"In 2017 aides to U.S. President Donald Trump had contracted with Black Cube in order to undermine the Iran Nuclear Deal by discrediting two of former Obama administration officials such as Colin Kahl and Ben Rhodes."
Why would you IPO this business? Disclosures associated with the IPO might accelerate the expiration date, you don't need the capital, and IPOs cost real money, which you could instead move into your own pockets. What does it bring — besides lowkey defrauding investors, who don't know what they're getting theirselves into, so they can be left with a worthless business at the end of the game?
According to TFA their real trouble comes from the massive loans they took in order to take the firm private. If CEO really said the above, he seems really squirrelly.
Isn't this why most spy agencies are very afraid to use their most prized assets in fear of revealing the assets?
"In recent weeks, for instance, Intel asked all its employees to cease any ongoing business relationships with NSO, one person familiar with the matter said. Intel said in a statement that it “complies with all applicable US laws, including US export control regulations”."
> The blacklisting, which came in November, means that NSO cannot buy any equipment, service, or intellectual property from US-based companies without approval, crippling a company whose terminals ran on servers from Dell and Intel, routers from Cisco, and whose desktop computers run on Windows operating systems, according to a spec sheet from a sale to Ghana, in West Africa
iOS is massive. Operating systems are massive, from an attack-surface perspective. NSO is hiring out of the Israeli intelligence pool: these are among the best security engineers in the world. They don't always find exploits (IIRC there are some versions of iOS they don't have hacks for at a given time), but the game is in their favor, simply because the OS is, well, the size of an OS.
See: https://www.apple.com/business/docs/site/AAW_Platform_Securi...
after $200mm in revenue, I love the cavalier nature of that. it humanizes the operation more than anything I've read
and NSO group is even at risk of defaulting on some loans, that it must have taken out for no reason aside from having extra totally fuckable capital to default on.
honestly, hope I run into this guy in Monaco and have a drink. just won't exchange contact information
There's no evidence the US has used NSO like tools to spy on the opposition (post Watergate, anyway).
Partial democracies or totalitarian regimes shouldn't be given these tools under any circumstances since they can't be trusted to only use them to investigate legitimate crimes. They will present some bona fide use scenario, then use the tools for other undisclosed purposes.
If NSO Group had an ounce of ethics, it wouldn't provide the software, but would request a dossier/brief which outlines, with evidence, the basis on which intrusion into the target device is sought. It would then have an agent carry out exploitation. Political "crimes" should be refused service.
Lol.
> In February 2019, an Israeli woman sat across from the son of Uganda’s president, and made an audacious pitch — would he want to secretly hack any phone in the world? [ ... ] for NSO, the Israeli company that created Pegasus, this dalliance into east Africa would prove to be the moment it crossed a red line, infuriating US diplomats and triggering a chain of events that would see it blacklisted by the commerce department, pursued by Apple, and driven to the verge of defaulting on its loans, according to interviews with US and Israeli officials, industry insiders and NSO employees.
Looks like Uganda tried to hack 11 US diplomats, which ended up giving away the game, and getting everyone upset — and for but a pittance in revenue.