The Spanish PM and the defence minister were infected by Pegasus (in Spanish)
eldiario.es
eldiario.es
But, I wonder if there's another story here: nearly all world leaders have a target-able device with cameras, microphones, GPS, and personal and professional conversations (and therefore contact lists) which they carry with them 24/7. At what point does the risk outweigh the convenience? I'm not sure what the solution is, but I wish that smartphones were not seen as a default necessity for everybody. Risks such as Pegasus are introduced, and it seems hard to go back to how things were.
What we have now for work devices with manageable profiles seems to me to be a good balance that should possible to harden enough for extreme cases as well.
On the other hand "run of the mill" phones that you can hand to a teenager (or use as a backup phone) don't need ultra-security and the cost that comes with it.
Really low end devices would probably be secure by simple virtue of not having enough features to enable hacking.
Ideally, you'd want to build your own phone where you control the supply chain form hardware to software running on it. I do believe the US president has a custom NSA hardened phone.
Our phones are still pre-seatbelts, pre-crush zones, pre-lead-free gas, pre-standardized controls and signal lights, etc.
Our phones only meet electrical and rf safety standards. When one phone model one time had a bad battery, it was a big deal. But if someone steals your retirement, oh well.
Nearly all VIP's insist on at least have their private phone as well, if not simply refusing to carry / use the issued devices.
Maybe this is someone a large country could develop internally themselves? Create their own fork of Android, private app store, etc etc?
They are not. But that mythology, that they are, is central to the problem. I just posted on almost exactly this point in another thread [1] that I'll paste here;
> (From OP[1]) Ultimately, if the technology is not serving you, you have the choice to not use it.
This is worthy of a book or PhD research project in itself. The person who states this in terms that resonate with me with is Vint Cerf. I will quote a little but also paraphrase him in my own way by saying;
"At one time if you didn’t have a horse it was hard to make a
living. But the important right in that case was the right to make
a living, not the right to a horse. Today, if I were granted a
right to have a horse, I’m not sure where I would put
it. Technology is an enabler of rights, not a right itself" [2]
As I see it, if we are to respect the more fundamental human rights of
"life, liberty and security of person" then the greater human right
may be NOT to be connected to the internet. It is freedom from
technologies at least insofar as we are free to manage our own affairs
and engagement.Other than the European "Right to be forgotten" and legislation protecting us from surveillance and tracking, I'm not aware of any popular formulations of this general principle other than Vint Cerf's.
Right now I think people are being forced to stable horses in their backyards, at the behest of landowners, and under the false premise that you need one for work.
Horses were also useful for knights, but not most people in Europe. Herders in Mongolia and other planes areas made good use of horses as well. None of this translated to more than a small part of the world though. We have a romantic view of the cowboy, and just before the mass migration from farms to the city happened horses started taking over so we think of them as the backbone of the farm, but they generally were not.
For long distances the human on foot beats the horse. A horse is useful either if you have a lot to haul, or you have a system of trading so you can always have a fresh horse to ride.
It's just a metaphor, right? Forget about the horses already. :)
(Sorry for the tacky puns, I cant keep this up furlong...I'm knackered)
States are part of the security attack vector and Pegasus is just a signal of what is really happening in the field. Pesonally I was involved in selling exploits since late 90s.
This shows not a lot of leaders are aware of the security risks of using conventional communication.
Or rather, because it is more easy to circumvent requirements of public record and archival laws.
What I keep asking myself in any case... why is the European Union unable or unwilling to fund an open source software suite that covers all needs of a modern IT environment? For literally everything that's needed, there are open source solutions - Firefox and Thunderbird for communication, LibreOffice for office needs, AOSP for phones, Linux as an OS, Samba for managing PCs and laptops... that would be a real, tangible benefit for hundreds of millions of people, not to mention a huge saving in costs for software licenses.
They absolutely do care about stuff where ordinary people can save money, thanks to the EU we got a hard cap on CC fees (0.3%!) and free phone roaming EU-wide, for example.
Providing a basic computer software environment would save a lot of money for the population and especially it would also massively reduce electronic waste and lock-in effects. Windows 11 for example won't run on machines without TPMs enabled [1].
[1] https://support.microsoft.com/en-us/windows/enable-tpm-2-0-o...
Reducing electronic waste is a key issue that the EU will need to tackle rather sooner than later. At the moment, Windows 11 won't run on old computers without TPM 2.0, which will render all PCs without one to either electronic waste or a constant security threat despite that the machines could otherwise run Linux perfectly fine - but no one outside of a bunch of nerds will run Linux on them because the software state of desktop Linux is just abysmal compared to the well-polished offerings of Apple and Microsoft.
Additionally, right now almost all economic and public activity depends on Microsoft to an unhealthy degree. We couldn't even get Microsoft to supply GDPR-compliant versions of MS Teams for schools during the pandemic, it's extremely hard to disable telemetry on anything Microsoft. Microsoft simply does whatever the fuck it wants and can get away with it, simply because there is no meaningful competition for anything they offer. And that dependency is extremely bad - just imagine the 45th coming back as the 47th in two years. The CoJ tore down two "agreements" for data transfer already because it cannot be assured that the US government does not steal our data (or worse, serve us malware) based on a secret NSL.
Europe needs independence, not just from Russia and China where it's long overdue, but also from the US.
They are actually funding and working on it: https://ec.europa.eu/info/departments/informatics/open-sourc...
For a modern IT environment used by a business, such a system is absolutely necessary
and it should be only used for non-sensitive stuff, and with a removed battery when it's not needed
any sensitive stuff just can't be safe on the current phone OSes imo
Not to mention the fact we really ought to make selling and buying of that hardware a crime in as many places as possible.
"fighting for peace is like fucking for virginity"
then again ...
Something about it being important to know the capabilities of your friends and your enemies, and to test the quality of your intelligence and counterintelligence assets before it becomes critical: you don’t want to start stupid wars you can’t win, nor waste money fighting wars to end the non-existent threat of non-existent WMDs.
I can’t tell the difference between espionage that gets overlooked, espionage that gets chest-thumping and wailing and gnashing of teeth, and espionage that gets kinetic responses, but I assume there must be such divisions.
Yes. That's exactly what NSA, GCHQ, MI6 etc are tasked to do.[1]
The problem came when foreign intelligence got confused with domestic intelligence. This is further compounded by the change in procurement of specialist technologies that the army or government offices might once have had. In the 80s a prime-minister would communicate with a special "scrambler" (supplied by the security services and designed against foreign espionage). Today everyone uses the same gear made in China, and the market for offensive cyberweapons is both international and privatised.
Here is a quote from [2]
"" For complex reasons the US embargo on Huawei, while looking like
a trade dispute, more or less proves this. Simply; western phones
have backdoors and remote controls for western governments. Chinese
phones have backdoors for Communist Party intelligence
apparatus. Each spies on their own citizens and everybody is happy
(except the citizens that end up in camps). It's the presence of the
other's spyware within the respective borders/markets that is the
problem, do you see?
So when these powers fell out, or failed to reach agreement on data
sharing, this escalated into an issue with clear symmetry. We see
that products by Apple, Google or Amazon are to be trusted no more
than Huawei handsets. Indeed, the safest phone for a Chinese citizen
is probably an Apple iPhone, whereas the safest phone for a western
civilian would be a Huawei, because historically, people are most
risk from their *own* government's domestic surveillance than a
foreign government's international surveillance. ""
The upshot of this is that offensive cyberweapons, which are
indiscriminate, persistent, reusable and infinitely replicatable at
near zero cost (all the worst qualities of a weapon on par with
bioweapons) affect all strata of society. Politicians, military
generals, schoolteachers and pizza delivery guys are equally exposed.
This marks a significant transition that blurs the boundaries between
civil and military war, as the current Russo-Ukraine conflict shows.
We're all soldiers now.[1] https://www.theguardian.com/notesandqueries/query/0,5753,-20...
Yes, you can claim that that last category just hasn't been caught yet. But there are some, like the US and Israel, that have been caught several times while others have, so far, escaped notice. Is Belgium so much smarter, or are they maybe just not doing as much?
What has been interesting of late is the mass evictions of known Russian spies from even the smallest of nations like Belgium. And of course, Russian has been throwing out Western agents at an equal rate these last few weeks. There are a lot of spies on desk duty right now...
Because they are all customers themselves.
It’s just that these countries start crying when they get hit with their own medicine.
You mean the customers of such malware (even if not necessarily Pegasus in particular)?
E.g. the German government bought FinFisher licenses, the German federal police bought Pegasus licenses. France was reportedly in late talks with NSO to buy Pegasus when the latest scandal hit that included Pegasus apparently having been used against Macron (tho the French government denies it was about to buy Pegasus). The UK might have been a customer too - at the very least the UK government hosted NSO at a trade show.
Aside from buying spyware, governments are keen on spying not just on foreigners but also their own citizens, in the EU too, e.g. the EU Data Retention Directive [0] or the German "remote forensic software" which is commonly known as the "Staatstrojaner" ("state trojans") which is basically the same as Pegasus just in blue. Or in the UK Theresa May's "snooper charter" (which eventually became the "Investigatory Powers Act").
Being thwarted, partially, this time, for the moment, in one location, doesn't change anything.
Do you deny the essential assertion that states seek to surveil, and get what they want? Does this speedbump change that?
Well I assert that is a delusional optimistic outlook unsupported by any evidence in the history of states so far recorded.
Only if you ignore half the evidence. Runaway authoritarianism is as common a failure mode as states which strait jacket themselves into irrelevance.
They don't always get away with everything they want on the first try, but they always want and they always try and the acceptable standard norm always progresses only in one direction. Wins in the other direction are local wins against, not examples of some state actually deciding they don't want.
They also said they'd only use a special Pegasus version that would be within the law, laws that they made and that then had to be severely limited later on by the Bundesverfassungsgericht (German constitutional court) again and again. If the government parties back then (one of which is still leading the new federal government coalition, both of which are leading different state legislators, 14 out of 16) had their way back then, things would be a lot worse.
If "they" (for various theys, as in federal government, state governments, federal/state police, intelligence services including internal ones such as the Verfassungsschutz and the MAD) actually did abide by the law is another matter E.g. they (intelligence services, in particular the BND) "helped" the US spy on German citizens including politicians via the XKeyscore program, and only admitted what was already known thanks to journalists, or even less actually, and didn't comment on anything else even when questioned by the German parliament, doing the whole "national security" yadayada or "I cannot recall".
In a day and age where government agencies write guides on how to carry out "parallel construction"[0], and after all that Snowden and others revealed, I am a bit skeptical when "they" tell the citizens that "they" only bought spyware but never used it, or only bought spyware with undisclosed modifications that allegedly made it lawful (under framework of law that indeed is of a questionable constitutionality in itself, and which had major parts struck or severely limited by courts) - a claim nobody was ever able to check thus far.
The ground is shifting with Israel’s (albeit forced) hesitance to criticise Russia too loudly. Prior to a few weeks ago, maintaining security ties outweighed NSO’s nuisance factor. (In Europe. The U.S. is already fed up with NSO.)
Proper attribution? So other's don't have to do a quick Wikipedia check to remind them which one is Pegasus.
This is no longer a safe assumption. Trans-Atlantic coöperation is at a high. This satisfies deep American geostrategic aims, ones far deeper than those around Israel.
The case had already escalated to the EU.
I guess this could come from the previous government, rogue elements of the state, or an international actor, but I wonder if we wil be told when and if it is found out.
This is clearly a use-case of military espionage, not of an intrusive police state.
Leaving questions of tools and their creators aside, who is making these decisions and why?
If the public could look into the installed executable, map out its internals, see the attack vector,... then some countermeasures could be developed by interested people.
Sunlight is the best disinfectant.
Even if you patch one exploit and analyze the malware, there are plenty more to be found, and it seems like they develop custom made malware solutions for each one.
"Technical Analysis of Pegasus Spyware" [PDF]:
https://info.lookout.com/rs/051-ESQ-475/images/lookout-pegas...
But honestly what do you expect? Any nations military will always stockpile weapons. Malware isn’t just “controlled like weapons” they ARE weapons.