iPhone flaw exploited by second Israeli spy firm
reuters.com
reuters.com
The smaller firms are just alphabet soup remixes of the larger ones. I wouldn't be surprised if they have the same owners, same staff, same offices -- just with a different logo at the top of a second set of business cards.
[0] https://www.haaretz.com/israel-news/tech-news/.premium.HIGHL...
> Years prior, NSO had formed an ethics committee, made up of a bipartisan cast of former U.S. foreign-policy officials who would advise on potential customers. After the Khashoggi killing in 2018, its members requested an urgent meeting to address the stories circulating about NSO involvement. Hulio flatly denied that Pegasus had been used to spy on the Washington Post columnist. Pegasus systems log every attack in case there is a complaint, and — with the client’s permission — NSO can perform an after-the-fact forensic analysis. Hulio said his staff had done just that with the Saudi logs and found no use of any NSO product or technology against Khashoggi. The committee nonetheless urged NSO to shut off the Pegasus system in Saudi Arabia, and it did. The committee also advised NSO to reject a subsequent request by the Israeli government to reconnect the hacking system in Saudi Arabia, and it stayed off.
> Then, the following year, the company reversed course. Novalpina, a British private-equity firm, acting in cooperation with Hulio, purchased Francisco Partners’ shares of NSO, with a valuation of $1 billion — more than five times more than it was when the American fund acquired it in 2014. In early 2019, NSO agreed to turn the Pegasus system in Saudi Arabia back on.
> Keeping the Saudis happy was important for Netanyahu, who was in the middle of a secret diplomatic initiative he believed would cement his legacy as a statesman — an official rapprochement between Israel and several Arab states. In September 2020, Netanyahu, Donald Trump and the foreign ministers of the United Arab Emirates and Bahrain signed the Abraham Accords, and all the signatories heralded it as a new era of peace for the region.
> But behind the scenes of the peace deal was a Middle East weapons bazaar. The Trump administration had quietly agreed to overturn past American policy and sell F-35 joint strike fighters and armed Reaper drones to the U.A.E., and had spent weeks assuaging Israel’s concerns that it would no longer be the only country in the region with the sophisticated F-35. Pompeo would later describe the aircraft deals in an interview as “critical” to obtaining M.B.Z.’s consent to the historic move. And by the time the Abraham Accords were announced, Israel had provided licenses to sell Pegasus to nearly all the signatories.
> Things hit a snag a month later, when the Saudi export license expired. Now it was up to the Israeli Defense Ministry to decide whether or not to renew it. Citing Saudi Arabia’s abuse of Pegasus, it declined to do so. Without the license, NSO could not provide routine maintenance on the software, and the systems were crashing. Numerous calls among Prince Mohammed’s aides, NSO executives, the Mossad and the Israeli Defense Ministry had failed to resolve the issue. So the crown prince placed an urgent telephone call to Netanyahu, according to people familiar with the call. He wanted the Saudi license for Pegasus renewed.
> Prince Mohammed had a significant amount of leverage. His ailing father, King Salman, had not officially signed on to the Abraham Accords, but he offered the other signatories his tacit blessing. He also allowed for a crucial part of the agreement to move forward: the use of Saudi air space, for the first time ever, by Israeli planes flying eastward on their way to the Persian Gulf. If the Saudis were to change their mind about the use of their airspace, an important public component of the accords might collapse.
> Netanyahu apparently had not been updated on the brewing crisis, but after the conversation with Prince Mohammed his office immediately ordered the Defense Ministry to have the problem fixed. That night, a ministry official called NSO’s operations room to have the Saudi systems switched back on, but the NSO compliance officer on duty rebuffed the request without a signed license. Told that the orders came directly from Netanyahu, the NSO employee agreed to accept an email from the Defense Ministry. Shortly afterward, Pegasus in Saudi Arabia was once again up and running.
> The next morning, a courier from the Defense Ministry arrived at NSO headquarters delivering a stamped and sealed permit.
1) The purchase was done as a leveraged purchase, very odd in the Israeli high tech/startup world. maybe even unprecedented. NSO is about to default on said debt
2) Novalpina are now at odds with Hulio, blaming him on trying to move all of the debt to 3 of the companies "healthy" subsidiaries. Apparently NSO is built like a maze, with lots of smaller companies, some of those aren't on the US ban list, and Hulio is trying to move all of the debt to them. The Israeli courts are now in the mix, trying to figure out who owns what
Unfortunately I couldn't find an article in english, but here is one in Hebrew with the ability to Google Translate
What a shame on every computer scientist involved and every one who is an expert in this domain and. Is staying silent.
You know these efforts don’t work without the involvement of academics and venture capitalists and skilled programmers. And what did they create? A tool that was used to spy on a dissident journalist in order to put together a savage assassination operation.
Shame on the Saudis and shame on their Israeli enablers.
This was the incident that made US authorities go after NSO. I remember reading that these diplomats were actually involved in espionage.
If those were Ugandan spies in the US they could have gotten dissappeared.
Second - how did the US attack Uganda?
I think your comment sounds a bit biased that’s all. If you share some light - happy to accept the points raised.
Offensive intelligence operations that the US has been conducting in Uganda are, well, offensive in nature, and are thus an attack. Not all attacks are an act of war.
> I think your comment sounds a bit biased that’s all. If you share some light - happy to accept the points raised.
I don't see how it is biased. The US applying sanctions on Uganda after they got caught spying by Ugandan counter-intelligence (under other pretenses, of course) is massively hypocritical. As far as I know using economic pressure to coax a country into accepting espionage is a new low. The US is trying to normalize and establish as basic expectations that weaker countries should just let it spy on them, and that's hypocritical above and beyond the norm.
We don't disappear people under diplomatic cover, we PNG them just like everyone else does. And when we do catch foreign agents without diplomatic cover, we imprison them. Why kill a useful asset that could be traded for someone on our team?
Offensive counterintelligence involves manipulation or long-term disruption of adversaries. Hacking someone's phone doesn't qualify, that's just normal defensive counterintelligence.
>We don't disappear people under diplomatic cover, we PNG them just like everyone else does.
Sure.
>nd when we do catch foreign agents without diplomatic cover, we imprison them. Why kill a useful asset that could be traded for someone on our team?
We both know that's not true. When it's more useful to trade them, that's done. When you want to send another signal, the US is not shy at all about killing them.
What information is this based on? I don't have any particularly strong opinions on this subject, but I can't recall ever reading about anything like this.
The one concrete detail you mention is 'Yuri Noseko' [Nosenko], who seemingly was a defector imprisoned for three years on suspicion of being a spy and then released. I'm not sure how this substantiates any of your claims. It appears to do the opposite.
If Uganda was spying on the US in the US, then you would have a point. That's not what happened.
That's what they want everyone to think so that they can use it to excuse their antisocial behaviour.
Tonga, Samoa, Solomon Islands, Fiji, Peru, Mongolia... there's a very long list of countries that don't.
The ones that don’t have intelligence capabilities are probably the exception rather than the rule, and I doubt they’re doing out of good will vs just not having the resources for it.
The U.S. isn't complaining as much as shutting down a threat vector. Shooting back isn't hypocritical.
Also, you get the right to complain when you're allies, just as Germany had the right to complain when the NSA was caught tapping Merkel.
You may also be aware that Israel invaded territory in 1967 which it continues to occupy in flagrant violation of "international law," and that this occupation continues to be violently resisted.
Those are a few of the more salient reasons why Israel is a hotbed of military/cyber/border/security technology. It's all developed, tested, and deployed against a vulnerable occupied population, then sold to the "friendly" (ahem) nations of the world.
If you think the NSO/KSA/and others are the only one's at it, think again.
In the 90's I used to get hassled by the police with more frequent stop and searches pulled over when driving. Why? Because I was learning about firewalls over the dialup internet and of course, GCHQ have total surveillance but playing down capabilities is a valid military tactic.
Never under estimate the military or more importantly the security services in a country. Those shadowy operators who hate the spotlight!
It's funny this release comes out at the same time as the FBI's disclosure that they "tested" (aka purchased) Pegasus, NSO group's packaged exploit software. https://www.reuters.com/world/us/fbi-says-it-tested-israeli-...
Google. Outsources. Security.
The kind of thing that makes it seem miraculous that any of it is still standing.
More likely they're just checking against the stolen passwords database whenever the user logs in, as passwords are typically submitted in plain text.
Mind you with salt and pepper (roughly, ways to modify the hash and overcome rainbow tables) checking anything other than the very highest frequency passwords found would seem onerous.
That said, I cannot recall Google ever having a breach, a la Yahoo, Sony, and basically most other companies. Does that mean everyone else should use who Google is using?
If the CIA isn't allowed to do certain things for spying, so ... just have Israel spy on our populace and since we basically fund them and let them spy on us anyway, just make sure their database is open to us?
Where else is there 1) the talent and 2) the relative degree of trust?
There are a lot of stories from my childhood (of debatable ranking on the conspiracy scale) of the dirty pool and awful unconstitutional behavior by the CIA and other agencies.
It is my vague impression that the increased information awareness from the web tempered the bad behavior for a couple decades, but I think the old habits will start reappearing in "cyberspace" once they gain sufficient deniability, and people's live reach a level of "mortal" dependence on it.
There is plenty of criticism of Israel by The Guardian, Washington Post, New York Times, Reuters etc.
It's not the media's fault that the Democratic and Republican party are so pro-Israel.
[1] https://forward.com/culture/481124/with-no-land-ethuopian-je...
Our definition of 'not terrible' surely must be different.
I first became aware of the issues this community faces when the news broke last decade about the government sterilizing immigrant Ethiopian women without their knowledge or consent. A matter of record: https://www.haaretz.com/israel-news/.premium-ethiopians-fool...
Israel made some great things for this community and it made some awful things as well.
My point is that if you get your information only from the news than you are bound to get a biased picture of reality.
It was convienent for the regime to do this back then and they left those people to rot as second class citizens. Now that a cold war situation isn't applicable, where is Israel to airlift those in recent conflicts? What support do they get when they arrive? Stop playing out tired old stories from many decades ago, the past is the past, let's get current and see where the work is going?
>My point is that if you get your information only from the news than you are bound to get a biased picture of reality.
You have done nothing to show me that my assessment on this is wrong. Instead you've chosen this dishonest form of argument and been vague this entire time.
Tell us a story then from the ground? You've got a short post history on HN and since this seems to have struck a nerve for you, I'm quite certain you can tell us what good your country is doing for these people. I linked a colonial state news source, an American Jewish news source, and an Israeli news source. You've kept it to vague smears, I'm curious and I want to hear the opposing mindset. So far you've given me nothing of substance, I'm disappointed.
You basically described various "X eyes" programs. Western intelligence services are completely out of control.
My country (Denmark) was involved in a similar program with the NSA:
>Danish intelligence (FE) also helped the US agency to spy on the Danish foreign and finance ministries as well as a Danish weapons manufacturer. The FE also cooperated with the NSA on spying operations against the US government itself.
https://www.dw.com/en/danish-secret-service-helped-us-spy-on...
Regardless, I don't know what regulations you refer to when the US and China lead the charge on actively spying on the entire world. The US drags down with it many western countries. Which is how the "5 eyes" was created. And no one bats an eyelash.
After the US was exposed for what the NSA did against its allies, no one was persecuted and the Senate was powerless to do anything. All inquires were met with "classified". So, at best, the propaganda over there convinced one person that there are regulations restraining military intelligence and the CIA.
So it's not just that they have a high level of expertise; there is a strong economic disincentive for firms to move tech business out of Israel.
usually the biggest problem with ip in israel, it's in case that there was investment into company/development by chief scientist. it comes with a lot of strings attached and requires payoff to transfer ip outside of state
Israel is #11 [0]
[0] https://en.wikipedia.org/wiki/List_of_countries_by_Nobel_lau...
However that doesn’t move Israel up much.
The Scandinavian countries are looking good as per usual.
No, why bother going all the way to Israel? They just do it in the US. When have regulations ever made a difference to surveillance?
https://www.theguardian.com/uk-news/2013/aug/01/nsa-paid-gch...
>When GCHQ does supply the US with valuable intelligence, the agency boasts about it. In one review, GCHQ boasted that it had supplied "unique contributions" to the NSA during its investigation of the American citizen responsible for an attempted car bomb attack in Times Square, New York City, in 2010.
>No other detail is provided – but it raises the possibility that GCHQ might have been spying on an American living in the US. The NSA is prohibited from doing this by US law.
NSO (and the smaller, anonymous companies) are famous for bringing in people from Israeli NSA (8200) or Mossad. Why? They're not just smart, they also have a bank of 0-days in their brains. Even if they're not bringing over actual code, they remember all of the 0-days they were exposed to. There is no way to stop them from "uploading" their knowledge to a new company with a 7 figure compensation package
At some point the UAE figured this out, and Dark Matter opened an office in Cyprus. Offering ex-8200 7 figures (in $) to come build cyber weapons for them, limiting their dependency on NSO and export licenses[1]. The Israeli Govt. was furious but it wasn't illegal to move abroad and work for a foreign country
[1]https://www.themarker.com/technation/.premium-1.7972249 - requires translation to english
Literally every tech company in Israel has people from 8200. I worked at a few mobile game companies, and each had 22 year old kids straight from the 8200.
In summary, the label of belonging to them means not that much in reality - rather one should look at length of service, age of entry and any subsequent / previous activities when they leave. (basically like any other cybersecurity job, really)
The more accurate description is - these cyber weapon companies bring in the 22 year olds that were building cyber weapons in 8200
Its an elite group of a couple hundred at most. who are then snatched up for their existing knowledge, even if they can't figure out how to find new exploits
NSO spyware isn't on their radar, because they simply aren't important enough to be a target. For dissidents, journalists and diplomats on the other hand, it could be a death sentence.
If device is jailbroken, and you apply root limit and other things to break standard features. Would it make it harder to exploit an ios?
I would imagine you can do default hardening like modifying the software version label so when the software queries it will be unable to automatically "arm" itself and apply persistence.
Are there any packages/places where this is already discussed?
If not, then I guess I will pick up some older iphone devices and play along - because it seems to be a great point - I highly doubt there is much sophistication in these malwares and there has to be some sanity checks that make it so that if you are targetted it will not "reveal" itself.
And of course the basic one of VPN, and forcing to change the DNS servers which the ios devices operates on.
in related news: * https://arstechnica.com/tech-policy/2022/02/report-nso-offer... * https://www.techdirt.com/articles/20220121/13492148329/spyin...
If your players in this hypothetical are Apple, NSO, Israel, and USG—each could probably have a pretty convincing list of arguments for and against. I could see it going either way.
They are already able to spy on their phone users if ordered by the right three letter agency, they don't need NSO/Pegasus for that.
And if they still do so, it would basically be official: "look a phone vendor that develop tools to spy on phone usage". Not a good marketing either.
For a more public facing version of this from the CIA, look at their unofficial Venture Capital wing: https://www.iqt.org/about-iqt/
You must remember the US' interest in spying and conquest is a rather unique trait. Most countries don't go looking for trouble worldwide.
That's interesting. Why do you think that?