Live data from Hacker News

Government Spyware Targets Mexican Journalists and Their Families

mobile.nytimes.com

31–39 of 39 posts

Re: Government Spyware Targets Mexican Journalists and Their Families

#31
post #15
post #9

Earlier quoted context omitted.

We need to avoid the slippery slope of blaming the tools. There are open source and commercial solutions that implement much of the same functionality. If you blame the tools Hacking Team or NSO or whomever, disappears into the oblivion, and two more spawn to take their place. Meanwhile we build a popular opinion that these things are dangerous and need to be restricted or regulated. Software ends up as the new "burg…

I don't understand this argument. If you build and sell tools that enable online surveillance, you bear a special responsibility not to sell them to people who will abuse them. Building surveillance tools and selling them to repressive governments is blameworthy. Equally blameworthy, but rarely remarked upon, is the practice of selling generic computing infrastructure that you know will be used to build surveillance…

How do we apply that special responsibility to open source software? Say, Metasploit.

I'm proficient with both commercial and open source tools, and in most cases the open source ones are more powerful.

Not saying enabling isn't a shameful act, but it is a slippery slope. As you pointed out, at what point does AWS need to start investigating customer workloads.

Re: Government Spyware Targets Mexican Journalists and Their Families

#32
post #9

The company that makes the software "says it sells the tool exclusively to governments" as though they're trying to take a moral stand and say "we only see it to the good guys". When in fact they sell to governments that are highly oppressive and corrupt. It's a farce.

We need to avoid the slippery slope of blaming the tools. There are open source and commercial solutions that implement much of the same functionality. If you blame the tools Hacking Team or NSO or whomever, disappears into the oblivion, and two more spawn to take their place. Meanwhile we build a popular opinion that these things are dangerous and need to be restricted or regulated. Software ends up as the new "burg…

> We need to avoid the slippery slope of blaming the tools

If you are designing, developing, marketing and delivering a tool for surveillance to a government agency, you have a pretty good idea of what it will be used for.

I think you also have a pretty good idea that all governments, to a greater or lesser degree, cheat. They'll pinky-swear to use it only against teh terra, or pedophiles, or drug dealers, or sidewalk-spitters if that gets people's dander up. And then they use it against anyone who threatens the current power arrangement.

So yes, I blame NSO, Hacking Team, and the rest of them. They deserve the blame, because they design, develop, market and sell these things knowing full well the use to which they will be put. They also know these tools will leak and be used by third parties, because that's how this works and they analyze third party malware themselves.

Arms dealers are awful people, no matter who's flag they wave.

Re: Government Spyware Targets Mexican Journalists and Their Families

#33
post #31
post #15

Earlier quoted context omitted.

I don't understand this argument. If you build and sell tools that enable online surveillance, you bear a special responsibility not to sell them to people who will abuse them. Building surveillance tools and selling them to repressive governments is blameworthy. Equally blameworthy, but rarely remarked upon, is the practice of selling generic computing infrastructure that you know will be used to build surveillance…

How do we apply that special responsibility to open source software? Say, Metasploit. I'm proficient with both commercial and open source tools, and in most cases the open source ones are more powerful. Not saying enabling isn't a shameful act, but it is a slippery slope. As you pointed out, at what point does AWS need to start investigating customer workloads.

Metasploit is free software. We're talking about a commercial enterprise deliberately profiting from enabling surveillance.

Re: Government Spyware Targets Mexican Journalists and Their Families

#34
post #15

Earlier quoted context omitted.

I don't understand this argument. If you build and sell tools that enable online surveillance, you bear a special responsibility not to sell them to people who will abuse them. Building surveillance tools and selling them to repressive governments is blameworthy. Equally blameworthy, but rarely remarked upon, is the practice of selling generic computing infrastructure that you know will be used to build surveillance…

The only solution then is not to sell them at all because a government that can't gain the tools directly will simply set up a blind to do the procurement and there is only so much research you can do on your customers before you start to lose money on a sale.

I don't agree that that's the only option, but I think selling offensive security technology is so complicated and fraught that I'll never do it myself. So, "don't sell to governments" is definitely one viable option.

Re: Government Spyware Targets Mexican Journalists and Their Families

#35
post #23

Earlier quoted context omitted.

How about any organization (distinct group of humans)?

Governments are distinctly different than most other organizations, primarily because they can force you to do something you don't want to do. Corporations can't do this (unless there is a monopoly on a needed utility (water company, etc). Even cartels and gangs are terrible because they act as a government in small/local areas, but have incredibly unfair punishments when people don't comply. Governments are ultimate…

I know what you mean.

I don't suppose you think differently, but in general: I think it's worth reminding ourselves that "a government" is made up of multiple people, which may be largely influenced by distinct cliques, whether or not those cliques are within the government. It may be the case that real danger lies predominantly within those cliques.

Re: Government Spyware Targets Mexican Journalists and Their Families

#36

The company that makes the software "says it sells the tool exclusively to governments" as though they're trying to take a moral stand and say "we only see it to the good guys". When in fact they sell to governments that are highly oppressive and corrupt. It's a farce.

...not to mention any definition of "good guys" tends to fade at scale. When you're selling to governments it will either leak or be used directly for anti-humanitarian ends.

I mean just look at the recent NSA leak. It's the same "conspiracy" patterns we've seen for ages.

Hell, the best kept secrets in front of the western world remain the secret cults of rome. Those sonsofbitches knew how to hype a secret. Probably not possible with the internet!

Re: Government Spyware Targets Mexican Journalists and Their Families

#37
post #17

Earlier quoted context omitted.

Also consider that the Mexican government and "cartels" have a lot of overlap. Local governments and municipal police departments in particular.

I would add some state governments too.

From what I've heard, there are extensive connections between the Sinaloa cartel and the Mexican federal government too. The cartels laundered over a billion dollars one year through the state-owned oil company Pemex, for example. It's even been alleged [0] by ex-cartel leaders that the US government props up the Sinaloa cartel with weapons and other material support, since in general the Sinaloa cartel tends to be less outrageously brutal toward civilians than for instance Los Zetas (whose founders unsurprisingly studied at the infamous School of the Americas [1]).

[0] http://www.businessinsider.com/the-us-government-and-the-sin...

[1] https://en.wikipedia.org/wiki/Western_Hemisphere_Institute_f...

Re: Government Spyware Targets Mexican Journalists and Their Families

#38
post #15
post #9

Earlier quoted context omitted.

We need to avoid the slippery slope of blaming the tools. There are open source and commercial solutions that implement much of the same functionality. If you blame the tools Hacking Team or NSO or whomever, disappears into the oblivion, and two more spawn to take their place. Meanwhile we build a popular opinion that these things are dangerous and need to be restricted or regulated. Software ends up as the new "burg…

I don't understand this argument. If you build and sell tools that enable online surveillance, you bear a special responsibility not to sell them to people who will abuse them. Building surveillance tools and selling them to repressive governments is blameworthy. Equally blameworthy, but rarely remarked upon, is the practice of selling generic computing infrastructure that you know will be used to build surveillance…

> Equally blameworthy, but rarely remarked upon, is the practice of selling generic computing infrastructure that you know will be used to build surveillance infrastructure.

Truly, Linus Torvalds is a monster for enabling the NSA.

Post reply on HN