WhatsApp forces Pegasus spyware maker to share its secret code
arstechnica.com
arstechnica.com
Interesting approach. The court could probably care less about Israeli restrictions as it's a different country.
Officially US govt blacklisted Pegasus https://arstechnica.com/tech-policy/2021/11/us-blacklists-ma.... However, I wouldn't be surprised if some US spy agencies are still using it. If that's the case, Pegasus might try asking US intel agencies to block the case on the basis of disclose of classified info or harming national interests.
It would be interesting to see if all of the sudden "something happens" and the case is mysteriously dropped.
Far easier to just request and obtain the resulting intelligence from partner intelligence organizations who are using it.
Arms-length collection is less legally perilous.
But which does bode poorly for any assertion of national security in US courts! "Are you using this software?" "Officially, no." "Then on what basis do you claim national security?"
No need to follow the law if you have a secret court where no one has standing to challenge your actions.
There are no illuminati.
There are powerful institutions, who nonetheless fear other powerful institutions.
In this case, intelligence preferring to remain out of the courts and newspapers.
There are no illuminati.
Interesting psyops to conflate corruption with "illuminati"..Before FISA, they generally just did it, without asking anyone.
And press reports on intelligence operations led directly to the Church/Pike Committees, which led to EO 11905/12036.
Oh, and they went back to doing it after a few decades.
And the fact that subsequent Executive Orders explicitly loosened the reigns on intelligence collection (and assassination with respect to "terrorists") indicates that yes, the original orders did restrict intelligence operations.
They don't "fear" other powerful institution. Just like chess players, they "game" with each other.
There can also be a future time in which something even stronger exists!
It's annoying to get low-effort whatabout'isms that are justifications for inaction on the basis that nothing will ever change.
It has and it can.
Although, having considered these topics over the years, I am skeptical that we will do better. Humans are flawed. Truth and justice are hard to achieve, even with the best intentions. Anyone involved with these topics -- judges, prosecutors, lawmakers -- should have a very high sense of humility in what they are doing. Often they do not.
Couldnt they ask to spy on a phone owned by them to try to learn how the phones are infected?
> people who go through life expecting informal variant idioms in English to behave logically are setting themselves up for a lifetime of hurt.
The majority of the world is not American, and presumably the majority of Americans don't use the incorrect phrase, so why should the rest of the world cater for a minority within a minority by putting their butchered phrase on equal footing with the correct phrase?
You aren't helping anyone when you correct them on this.
I stopped correcting people on stuff like this 20 years ago, but sadly haven’t been able to stop myself caring :-/ “Expresso” still grates
It's a crime against humanity to not correct grammar.
You are just being stubborn and trying to adhere to an outdated standard. Upgrade or get replaced.
It's on the person receiving the correction or criticism to ignore it if they wish. Not on people to be silent.
For a formal linguistic example, see the concept of compound words. The meaning of the compound word does not equal the meaning of any of the constituent words. Often because the definition of the constituent words has drifted over time while usage of the compound word remained fixed.
You may unilaterally think that's wrong because you wish to impose a set of rules on language that others don't share, but that's not how meaning works. A sentence is just a string of bits. Meaning comes from a shared consensus about how to parse those bits into meaning.
'A set of rules' is called grammar. It may have arisen organically and out of 'shared consensus' but today languages only make sense when we maintain that grammar.
Imagine if the positions of the words in the above sentence were randomly jumbled up. It'd make no sense at all.
English is somewhat more lax than other languages about grammar (stemming from its extremely wide usage) while still being able to get the point through, but striving for correct grammar should always be a goal, even if 'the point has got through'.
Many other stricter and older Indo-European languages that haven't experienced as many changes as English has, can be machine-parsed like a programming language. Sanskrit and Latin come to mind.
But "could care less" isn't random. It is an idiom that has the same meaning as "couldn't care less". If you fed it into a LLM it would know what you mean because meaning is created from global context. Meaning is not some kind of programming language where you input the rules of grammar and the definition of each constituent word, and then out pops the meaning of the sentence. It is impossible to derive meaning that way because meaning is constructed by shared consensus about what collections of words mean in different contexts according to common usage.
That is what I meant by 'English is lax enough about its grammar that "the point still gets through"'. 'Could care less' being wrong but semantically understood is exactly along the lines of 'could of' being wrong but semantically understood as 'could've', or the frequent confusion between 'their' and 'they're', or even any other confusion between homophones in written text.
Certainly, most Anglophones know enough English to read past these sorts of mistakes and still understand the underlying meaning (i.e. semantics) from context, but they are all incorrect, full stop.
I don't agree. Correctness is strictly determined by common usage. You're viewing language through the lens of a software engineer, where there are logical rules and primitives that combine together to construct outputs from inputs. Language isn't logically airtight like this. "Could care less" shouldn't be thought of as three words. Think of it as one single new word with its own meaning that has no necessary connection to the meaning of the constituent parts that make it up. Just like compound words and other idioms.
Happy to agree to disagree, especially when there is this much teeth-gnashing about how 'correct' this usage is—just within this thread. My point about 'could of' was even brought up elsewhere.
> Language isn't logically airtight like this.
But it is—or at least, people make it so. In a world where what people say or write is regularly misconstrued/misinterpreted and lands them in jail, or persecuted, or even killed, I believe clarity, accuracy, (factual and syntactic) correctness, and honesty should be something that every writer should strive toward. Someone else brought up contronyms—which I believe ought to be avoided as much as possible because of their potential to cause much confusion even with context ('sanction' is a very powerful example).
This sort of wishy-washy 'it is correct because people understand it' only reminds me of 'alternate facts'. I don't like it and I wish people wouldn't put up with it.
It does in my English though, and it really really grates when I hear it. Just because a minority of people have started abusing the language doesn't mean I have to go along with it.
> compound words
Compound words like "afternoon" where the two words themselves make sense together? "couldcare" might be a compound word, but "could care" isn't. Plus, if I start to say "after noon" to mean "mid morning" then get pissed off when people call me out on my language butchery then perhaps my minority take and desire to impose it on the rest of the world would make me the person in the wrong.
Flammable on the hand comes from "flammare", which means for something to catch fire, and is intransitive instead, i.e. the subject is the one catching fire.
The actual opposite of inflammable is uninflammable, which I reckon is only in British English at this point and mostly lost in American English.
Something in flames is "enflammé" (there is the en- prefix ^^).
Still, I do find "I could care less" to be less of a contronym and more of an "Americanism". I'm quite used to it by now, and shall thereby sanction its use.
And yet here we are.
To paraphrase David Mitchell (https://www.youtube.com/watch?v=om7O0MFkmpw), the problem is not so much the prevelance of American English, which in a lot of situations makes sense. eg. "sidewalk" makes a lot of sense, perhaps more, than "pavement" for the place that a pedestrian walks at the side of a road. "Parking lot" for a lot of land that is reserved for parking etc. The issue is that "could care less" means the opposite of what people intend them to mean, and they're just expecting the people listening to interpret what they mean.
> His bearing towards male acquaintances, of whom he knew little or nothing and could care less, ...
Here, "could care less" refers to how little he knows about the male acquaintances, and is effectively saying he cares even less than the little he knows. When we see people write "could care less', they don't write it in the same context, at all.
And then:
> It is impossible that he could care less.
This is clearly a different way to write "couldn't care less", and is again not how we see people use the phrase "could care less".
That being said, "could care less" is definitely a thing of the last 10-20 years and is not going anywhere.
Pure, distilled, thought provocation.
Thank you.
Apparently, the social & political elites worldwide are tripping themselves over to purchase licenses from these CSVs that cost millions.
Conspiracy theories notwithstanding you’d see a sealed court filing and not “something happens.”
Why would a US court have any jurisdiction over a foreign Israeli spyware vendor that has already been blacklisted by the US government?
And why would Israel send their spyware source code to WhatsApp even if they lose the case?
If they didn't respond, they'd lose by default, and the court could order any assets the US can get their hands on seized. If they're getting paid in NIS by countries outside of Israel, the currency conversion happens with dollars as the intermediary. There's the US's window.
On the other hand, if they were paid in US dollars, but in cash, that wouldn't establish jurisdiction, nor could it be seized, if the transfer happened outside US territory?
These are just pieces of paper, they don't provide any kind of jurisdiction. The American banking system may refuse to serve me perhaps, but it's not the dollars that give the American government any control. Hell, several countries outdid e the USA use American dollars as an official currency, but that doesn't make them vassal states to the USA.
If you got a pile of dollars in the US, you did business in the US and if that business has any tenuous connection to what the courts are after you about, we have jurisdiction.
If you don't like it you have to run to China, Russia, Iran, etc.
I let you have one guess which entity gives those pieces of paper their value.
The USA can print and lend dollars to control the value of the currency on the global marketplace. When trading outside of the USA, people give the bills their value.
You can substitute a suitcase with a million dollars for a suitcase full of gold or a suitcase full of diamonds, or a suitcase full of Pokémon cards. Outside the official banking system, the value of paper money is whatever the people trading perceive it to be. In some cases, that value can be larger than a million dollars (i.e. in countries where their own currency is in a free-fall, where the government is trying to limit the supply of foreign currency, but people want to exchange their local currency for something more stable; people in Argentina, Lebanon, Sri Lanka, and Turkey might want to do that).
If, for whatever reason, Russia pays for North Korean drones to murder Ukrainians, there's absolutely nothing the American government can do about that.
Ironically paper money is the way to "escape" sanctions, because anyone around the world knows that that 100 dollar bill can be exchanged for goods and services. And it doesn't even have to involve a bank, just another person who recognizes the value of that paper, in a chain of transactions. Depending on the hassle you may need to pay more..
To seize somebody's gold you'd have to go physically get it. To seize their dollars you just go say hi to their bank. Unless you're an "enemy combatant" the US isn't going to go do extraordinary rendition on your assets, so you're pile of foreign gold is safe.
The reach of the American legal system is long, you don't have to do much as a foreign entity to put you under our umbrella.
Are you a French wine maker that wants to sell to America? You better be using USD with a friendly bank to pay for things like import fees/tariffs (or the American company you work with better do that). Sure you can deal only in Euros if you want, but at some point there's a conversion to USD when you sell to Americans. Middle Eastern Oil Company? Same thing. German Car company? Same. Brazilian fruit farm? Same. How about importing your Coca Cola products, and iPhones? Buying ads from Google? USD and a US-friendly banks are everywhere in the global economy because the US is such a big market.
Those banks will be banned from US commerce if they work with the NSO and don't hand over the NSO's money, and will lose tons of "innocent" business (like those nice wine makers in France). Their governments probably have treaties with the US, so they don't have a legal choice anyways. The US influence is viral.
On the other hand, if someone used a local bank in their country to transact with an entity in China, and China demanded their assets in that bank be seized because they defamed a revolutionary hero [1], I would expect that country to block that seizure, regardless of how the bank itself might feel. I.e. they would demand any seizures comply with their local laws, similar to how extraditions (are supposed to) work, and not let other countries essentially steal from their citizens. Or looking at it a bit different, a bank can't take from its customers on behalf of a foreign country, since locals laws, unless they explicitly allow that taking, would consider it theft.
[1] https://www.reuters.com/article/us-china-lawmaking-idUSKBN1H...
Edit as reply because "I'm posting too fast" (thanks HN for not telling when I can post again by the way):
> Discussion about the US dollar misses the point. They do it because they can
I'd argue it doesn't miss the point, but rather, hides the true cause - that as you say, they do it because they can (as quickly becomes obvious when no other currency has this viral jurisdictional effect).
But I'm curious if anyone has ever tried suing their bank, in a non-US court, alleging that their seizure of their assets was illegal under local law. I can understand a bank rolling over for the US government, but it would be interesting to see if and how their legal system would justify it. Especially for something that is not a crime in their country.
They do it because they can, basically we all live under the influence of the US empire, they can put pressure on most banks of they really want to, and if they really want to, details like which currency was used will not stop them.
https://www.theguardian.com/world/2020/nov/28/hong-kong-carr...
> If they got paid in Turkish liras, but through a bank under US influence, those liras would also get seized, wouldn't they?
Yea except no one wants Liras. They want USD (and sometimes Euros). So whoever accepts those liras will want USD, and they’ll transfer them to the USD-backed banking system, and back to the original points. Because again, how do you have access to high-volume USD/lira forex markets without using a US-blessed banking system.
The reality is that international finance largely runs on USD, and orbits US banks. One of the main international influence efforts the Us considers is a stable currency. So much so that other nations use USD as a formal currency. The US exerts significant political pressure and political capital to ensure that everyone needs USD in their economy. America literally made international treaties with every oil producing nations requiring oil to be sold in USD just to ensure that every country needed to inject USD into their economy.
> I can understand a bank rolling over for the US government, but it would be interesting to see if and how their legal system would justify it.
They’d justify it by having laws that say they’d reciprocate and recognize US crimes. It’s what the international community does.
Even for physical cash, they might claim jurisdiction. Dollars are sometimes best understood as a particularly degenerate form of US government bonds.
I for one would trend toward banning cryptocurrency even if it weren't a complete waste of energy.
Never thought about it that way, well said.
The harm is happening in the US, to WhatsApp's customers (among other places). The US court has jurisdiction.
Whether any remedy could be applied is independent of the court's findings.
Israel able to get away with being a frenemy to the West but there are limits.
They can of course choose to ignore the lawsuit, if their principals want to never enter the US again, which is frankly recommended for all their employees given their operations are prima facie criminal in nature.
Crazy stories happened here in France.
USA basically sent Alstom, a huge French company, to bankruptcy, then bought it for pennies, and then they tried to destroy Airbus. In both cases they used this right they gave themselves they call extraterritoriality.
The stories I mentioned are documented in this reportage: https://www.arte.tv/fr/videos/093798-000-A/la-bataille-d-air...
The video used to be available on YouTube at the following url : https://youtu.be/Sa22eu1FWyo but it seems it was set to private. Annoying revelations?
So if a US judge signs and an order and sends the order to an Israeli judge, the israeli judge enforces it (and vice versa).
At the end of the day, it’s between platforms (specifically iOS and Apple) and these exploit devs/traders, afaiu. That’s why Apple hates them. For better or worse, putting a torch under Apple’s ass is probably a good thing for the rest of us.
OTOH, you could argue that Apple should be more of top of these things and reward the security researchers better. Things are better than 20y ago, but still it’s probably more lucrative to sell exploits to these shady actors than to scrape the floor for peanuts in hope that mega corps will reward their discoveries.
Security researchers capable of finding these exploits aren't exactly starving for food. They could easily land a $500k+ job at any big tech company or make a similar amount bug bounty hunting.
It's mainly not "the wests" enemies contracting NSO, it is the west.
Politics.
I’d guess there are some deep benefits in having a strong partner selling this stuff compared to a rival. Not great for the target countries at all, but good for the Israeli and US intelligence apparatus.
https://www.washingtonpost.com/technology/2021/11/03/pegasus...
> "Fortunately for Obiang, coup-prone African governments rolling in oil but lacking in arms and intelligence to defend their bounty had a discrete alternative to the Pentagon and C.I.A. for defense support: Israel. Quietly, the Bush Administration encouraged Obiang to enter into security and commercial ties with Tel Aviv."
Azerbaijan is a similar example as US weapons sales were banned for human rights abuse reasons. A Wikileaked US State Dept cable stated (2009) "Through its close relations with Israel, Azerbaijan gets a level of access to the quality weapon systems it needs to develop its army that it can not obtain from the U.S. and Europe due to various legal limitations..."
If the dictatorial government funnels the oil money into the Western banking system, then the US turns a blind eye to this kind of thing (e.g. Saudi and UAE use of Pegasus to persecute pro-democracy activists) and if not, it's sanctions and regime change time.
You are dealing with dangerous people.
And cyber is a very wide range. A lot of roles are simply about training personnel in security principles and procedures, implementing data classification etc. Not everyone deals directly with attacks. Most of the work is preventative. In our company probably less than 20% of people who technically work in cyber, although that's in part because our SOC is outsourced.
Current work culture is bizarre in cyber security. I am not personally very fan of it.
Nobody wants to work on defensive side. You are not getting either fame or money if you do your work well. The expectation is that you do your work perfectly. There is no actually measurements in place to prove that your good code prevented 100 data breaches!
But on the other hand, if you are on offensive side, sometimes find cool bugs, you get fame and money. Does not matter if there is a long break sometimes. Your goodness is measures based on how much money you got.
What does it mean? People start doing bug bounties. They hoard tools only for themselves to make more money, instead of releasing them to improve general security. They keep small bugs themselves so that they can be used in exploit chains to get bigger bounties.
If the reputation of the company is based on the participations of the bug bounty program, they start doing less and less in-house engineering and outsource the cyber security testing for bug bounty platforms.
And vicious cycle starts.
They are known for breaking stuff, and everyone wants to be the same.
Goal might be defensive in everything cyber security researchers do, but that was not my point.
I do agree with you that defense is a large part of the industry. My perspective is even that most organizations are looking for “defense” roles. The field is very wide (e.g., folks working on cryptography to sec ops).
It means that most of the average guys build defense, and then the best guys test them and pick the money when something is found. While we could prevent most issues if those best guys help on building the systems instead.
But they have no motivation, because they get more money from other things.
Bookmark this post.
You can find details here
>https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zer...
Vulnerabilities in third party apps that are used to install Pegasus Apple has less control over.
there are many treaties on this. It gets complex, some countries will not turn criminals over if the death pentalty is would be used for example. However in general if you commit a crime you can't flee to a different country.
countries like north Korea and Russia are exceptions. Which is why malware so often comes from them. Anyone else and you are likely to be caught.
If I run an Internet-facing server, where is it deemed to be? Everywhere?
When are they "forced" to provide a simple and stable in time interop protocol stack ? (with reuse of irc,smtp,noscript/basic (x)html/etc?)
This one is not better than the other.