Live data from Hacker News

Enough is enough

nsogroup.com

91–100 of 135 posts

Re: Enough is enough

#91
post #71

They state: " NSO is a technology company. We do not operate the system, nor do we have access to the data of our customers " Yet they also state: " The list is not a list of targets or potential targets of Pegasus. " How do they know it is not a list of targets if they don't have access to their customer's lists of targets? None of this is trustworthy and neither are NSO.

You can't trust anyone, but... The Pegasus Project did change their statement from "thousands of numbers that were selected as targets by NSO’s Group clients" to "a list of phone numbers concentrated in countries known to surveil their citizens and also known to have been clients of NSO Group", and they specifically say: "The list does not identify who put the numbers on it, or why, and it is unknown how many of the…

For those like me unfamiliar.

HLR: Home Location Register. A phone-number lookup service / protocol.

Re: Enough is enough

#92
post #35

Regarding the "list": Amnesty said 34 iPhones were forensically checked. 23 successfully had malware (specifically NSO's Pegasus) installed on them. The other 11 saw attempts at malware infection. [0] That's a 100% hit rate on their sampling of the "list". That makes this statement demonstrably false: "The numbers in the list are not related to NSO group." At this point, why would you even care to read the rest of th…

Upvotes are not endorsements. Usually, folks upvote because they think a post is noteworthy enough to warrant an extended discussion that the front-page affords.

Re: Enough is enough

#93

Translation: we are going to get away with it whether we spend money on PR or not, so we are going to save the money. Fuck You.

Also, presumably, the firm feels it has the support of its own major interests in this course of action.

NSO Group is ... rather well-connected. See for example https://theintercept.com/2016/10/17/how-israel-became-a-hub-...

Re: Enough is enough

#94

They state: " NSO is a technology company. We do not operate the system, nor do we have access to the data of our customers " Yet they also state: " The list is not a list of targets or potential targets of Pegasus. " How do they know it is not a list of targets if they don't have access to their customer's lists of targets? None of this is trustworthy and neither are NSO.

Is it relevant even if they are “just a technology company”?

“Pipe Bombs Inc.” is just a technology company. They don’t use their products, they just sell them to wackos. Where’s the harm in that?!

Re: Enough is enough

#95
post #63

Here are the significant threads to date. Additions are welcome. Pavel Durov listed in leaked Pegasus project data - https://news.ycombinator.com/item?id=27906667 - July 2021 (12 comments so far) Pegasus Project found numbers of Ten PMs, three presidents and a king - https://news.ycombinator.com/item?id=27904236 - July 2021 (17 comments) NSO Group Hacked - https://news.ycombinator.com/item?id=27902544 - July 2021 (78…

For those seeking a single-point summary and compilation of complex stories, Wikipedia is very often the best available source. No, it's not HN discussions but it is a best-current-information compilation.

https://en.wikipedia.org/wiki/Project_Pegasus_(investigation...

Re: Enough is enough

#96
post #79

Earlier quoted context omitted.

Corporations do not have any moral at all. It is always virtue signaling when they pretend they do have.

While broadly I can agree with you, a corporation is still made up of people, and is lead by people. It’s perfectly possible for someone with a backbone to lead a corporation in a moral way.

The cells in the body of a murderer could have stopped him/her, if they had seized the moment. But they did not. Thus there are endless philosophical arguments about free will to be had, but for practicality, we assume the outermost shell with the most control, is responsible for the inner components.

If we treat cooperation like persons, they should be judged and sentenced as person. Including restructuring of malformed processes and life-time-imprisonment for anti-social behaviour

Re: Enough is enough

#97

Earlier quoted context omitted.

This is an excellent point. "We're responsible for the good applications, just not the bad ones"

The modern commecial business corporation is ineherently a risk-externalising structure, which is specifically indicated in certain naming conventions, notably the "limited liability corporation". Legally it exists to sheild investors, as well as creditors and officers, from full personal liability. That has certain advantages, but as with all forms of impunity is subject to and the direct source of tremendous abuses…

>there's a version of Goodhart's Law [ https://en.wikipedia.org/wiki/Goodhart%27s_law ] buried in here somewhere

and/or:

* Campbell's law — https://en.wikipedia.org/wiki/Campbell%27s_law

* the Lucas critique —https://en.wikipedia.org/wiki/Lucas_critique

* the McNamara fallacy —https://en.wikipedia.org/wiki/McNamara_fallacy

Previous discussion of Goodhart's law on Hacker News: https://news.ycombinator.com/item?id=23762526

Re: Enough is enough

#98
> NSO will continue its mission of saving lives

Sounds exactly like Lt. Col. Jessep from A Few Good Men. The film teaches to never trust that line or those who utter it.

Re: Enough is enough

#99
I really hope that people who are in hiring positions here will make sure to never hire someone involved with this company.

Last time I said this, people said that's like accusing relatives for the actions of a e.g. a cousin. No, the people working there chose to work there and chose to disregard any morals for their paycheck. I hope the people working at this place will never find another job in this space, once NSO (hopefully) goes under. However, unfortunately this is unlikely because there is enough other companies doing essentially the same thing, who'd likely take those people on happily.

Re: Enough is enough

#100

Serious question: We talk always about companies like they are are organisms and not run by people making decisions. I see texts referring to group, company, people. Who's making the decisions and why don't we address them by name? Would this not make them more accountable if we did?

That ultimately becomes a metaphysical question about existence, though it also has elements of morality and pragmatism.

Names and concepts are ultimately just shared mental interfaces for refering to and interacting with things in our environment. Everything above the atomic (in the original philosophical sense, here physically quark, Plank-length, and quantum-energy levels) is comprised of collections of other things, and the behaviours of certain sets of things organised in specific ways is distinctive enough that we apply different labels to them, even when the underlying components are the same.

A tree is a collection of carbon, water, and trace elements, but is more than the sum of its parts. A chair or house (if made of wood) are made of tree but not tree. And so on.

Describing things as behaviourally consistent concepts has been a useful mental model for me.

The moral element comes into play where there's intentionality in organisation and a realisation of misdirection in general public understanding. Interests groups and lobbying organisations often present themselves as freestanding or general member organisations, but in truth are mostly representing the interests of their largest members (the MPAA, RIAA, and various software interest / piracy groups come to mind). These have an "ablative heat shield effect" in drawing fire away from the principle member firms themselves. (This is played out across many, many such instances, not just the three I've given.)

The modern business corporation is in fact specifically a risk-externalising engine, and both it and its executive leadership play that role in at least part. I'd just addressed that in an earlier comment on this thread:

https://news.ycombinator.com/item?id=27910464

Post reply on HN