Live data from Hacker News

Enough is enough

nsogroup.com

71–80 of 135 posts

Re: Enough is enough

#71

They state: " NSO is a technology company. We do not operate the system, nor do we have access to the data of our customers " Yet they also state: " The list is not a list of targets or potential targets of Pegasus. " How do they know it is not a list of targets if they don't have access to their customer's lists of targets? None of this is trustworthy and neither are NSO.

You can't trust anyone, but... The Pegasus Project did change their statement from "thousands of numbers that were selected as targets by NSO’s Group clients" to "a list of phone numbers concentrated in countries known to surveil their citizens and also known to have been clients of NSO Group", and they specifically say: "The list does not identify who put the numbers on it, or why, and it is unknown how many of the phones were targeted or surveilled".

It sounds like the "list" is from HLR lookups, which get done all the time without NSO being involved.

If you think about it, none of NSO's clients would want NSO (or anyone else) to know who they are spying on in the first place, so it stands to reason that there'd not be a centralized list anywhere of targets for their software. I'm sure the list is real and all, but there's a distinct lack of clarity about how that list links to NSO and Pegasus specifically.

Now the other bit that the Pegasus Project did was look at phones they suspected of being compromised. I think that's telling in the sense of, "journalists, activists and business people are being targeted". That seems pretty credible, but NSO doesn't seem to be denying that aspect of the story.

Re: Enough is enough

#72
post #67

Pretty embarrassing response, honestly. If you specifically work in an area that can be used for sensitive purposes, you have a moral responsibility as to who you choose to sell to and what you choose to enable them to do. Moreover, if you're going to engage in moral indignation -- we can't possibly be responsible for what our customers do!!! -- then you can't end with a paragraph about how you're a league of superhe…

> Kashoggi's widows Plural?

In some cultures muslims can have four wives.

Re: Enough is enough

#73
These people and their employees need to be on terrorist watch lists, their assets and passports frozen, domains seized etc.

It is an absolute joke that the “Justice” department allows these organizations to operate freely and uncontested.

Re: Enough is enough

#74
post #12

Another interesting example of a company choosing to simply route around the media. Not making a value judgement, but I'm seeing more companies opt to simply disengage and try to create their own narratives rather than go through the media via interviews/statements/etc.

I have always had a suspicion that this is the most expedient course of action from a company's perspective: the velocity of media is so fast nowadays that any controversy will be forgotten by the next week.

Judging by the panicked responses by the media, I'd say NSO is in a unique position, and the media just has to accept this. What we will likely see soon is a shift in focus from the company itself to individuals perceived to be motivators or shot-callers within the org being called out by the media in an attempt to garner the attention that NSO so steadfastly claims to be denying going forward.

It's going to be interesting to see how this reversal of discourse carries out.

Re: Enough is enough

#75

Earlier quoted context omitted.

> "NSO is a technology company. We do not operate the system, nor do we have access to the data of our customers, yet they are obligated to provide us with such information under investigations." This is an abdication of responsibility and I agree the substance and tone of the response from them is really bad. Just because you don't have direct customer data access does not mean that you don't hold some responsibilit…

I think it’s worse than just abdicating responsibility. As if they just didn’t know bad things cound happen. They’re selling this software to literal tyrants. They knew full well what this would be used for.

I don't think they're claiming they didn't know bad things could happen. Their "Transparency and Responsibility Report" is essentially a detailed accounting of how they weighed that risk when licensing their software. I think one can certainly take issue with their approach, but they don't appear to be naive about the risks.

Re: Enough is enough

#76

Seems like NSO is saying "We don't operate our software directly, so stop asking us to be accountable for its use". Kind of like we accept that gun manufacturers have no liability if their guns are used in crimes. With these kinds of attacks becoming the new normal, security should be top of mind for everyone when buying a phone...

> Kind of like we accept that gun manufacturers have no liability if their guns are used in crimes.

Except the gun manufacturers are not aiming the gun for their customers.

Re: Enough is enough

#77
> break up pedophilia, sex, and drug-trafficking rings, locate missing

> and kidnapped children, locate survivors trapped under collapsed

> buildings, and protect airspace against disruptive penetration by

> dangerous drones.

Well, that's an interesting market niche if I've ever seen one.

Re: Enough is enough

#78

Earlier quoted context omitted.

Myself and my companies have gotten around streisand effect before by just ignoring everyone and then doing takedown requests a few weeks later. Nobody saves stuff if you don't react. They only save copies when you are seen as trying to delete the copies.

How do you sleep at night?

"On top of a pile of money with many beautiful ladies." --Rainier Wolfcastle (S06E18)

Re: Enough is enough

#79
post #7

> "NSO will thoroughly investigate any credible proof of misuse of its technologies, as we always had, and will shut down the system where necessary." From Wikipedia: "In October 2018 Citizen Lab reported on the use of NSO software to spy on the inner circle of Jamal Khashoggi just before his murder. Citizen Lab's October report[65] stated, with high confidence, that NSO's Pegasus had been placed on the iPhone of Sau…

Corporations do not have any moral at all. It is always virtue signaling when they pretend they do have.

While broadly I can agree with you, a corporation is still made up of people, and is lead by people. It’s perfectly possible for someone with a backbone to lead a corporation in a moral way.

Re: Enough is enough

#80

Earlier quoted context omitted.

Attacking NSO would be like attacking the Israeli government and you don't do that because your PM's shitty OpSec was exposed.

The only overtly pro-nomatterwhat-Israel government is the United States so at most 1 of the 193 countries in the United Nations would avoid regulating NSO on international relations grounds.

That is not true at all. The US is just as critical of Israel as many other countries.
Post reply on HN