The company that makes the software "says it sells the tool exclusively to governments" as though they're trying to take a moral stand and say "we only see it to the good guys". When in fact they sell to governments that are highly oppressive and corrupt. It's a farce.
We need to avoid the slippery slope of blaming the tools. There are open source and commercial solutions that implement much of the same functionality. If you blame the tools Hacking Team or NSO or whomever, disappears into the oblivion, and two more spawn to take their place. Meanwhile we build a popular opinion that these things are dangerous and need to be restricted or regulated. Software ends up as the new "burg…
There's a reason this company is charging hundreds of thousands of dollars to target only 10s of phones...
I wouldn't downplay the gatekeeper aspect of these companies and the technical investment it takes for non technical governments to do this stuff.
But generally I agree that attempting to control it via the tools is a bad idea or merely putting the blame on the tools is missing the bigger picture. Plus limiting zero day sales will only harm legitimate security research and encourage unrealistic pen testing.
Mexico's government is the primary issue here. They have a serious human rights abuse issue at various layers of government.
But that said if we're going to try to protect these people from abusive government tactics, since it happens in secrecy and their 'self-regulation' totally fails to stop abuse (even in the US), then there is some value on pushing back against these more sophisticated companies that sell the high end tools that are harder to detect. Since it is a niche market at the moment and a niche expensive skillset... Unlike guns in the US that will be everywhere regardless of gun control, since it's the biggest gun exporter and gun ownership rate in the world, we can hold these companies to a higher degree of responsibility.
Eventually though it will have to come down to holding the governments responsible and pushing back by protecting our software.
The fact NSO has publicly said they will continue to sell to Mexico despite the clear evidence here that they are not following their stated policy of only targeting cartels, criminals, and terrorists... Then clearly they are shady as hell and their stated policy is bullshit.
NSO is hardly without fault here. Unlike the AK47 analogy used in this article which are sold once and then the manufacturer loses control of how its used, this exploitation software needs to be updated with new zero days, new RAT software for new iOS/Android versions, and support/training staff. NSO has chosen to continue offering these services so they are just as much liable as far as I'm concerned.