Is there no regulatory or compliance requirements for surveillance software? Instead of blaming the victims of pegasus, we should focus our attention on the lack of actions from key policymakers and regulatory bodies. It is not possible for every individual to be a technical expert when it comes to malware removal, but we can reduce the likelihood of misusing surveillance software by creating an ethical framework aro…
> Is there no regulatory or compliance requirements for surveillance software? Nope! It's not even clear if Pegasus and its employees broke any laws. (Though I would love to see CFAA and copyright law tested against this.) Optimistically, this might be the wake-up call to change that.
Pegasus spyware found on journalists’ phones, French intelligence confirms
51–60 of 101 posts
Re: Pegasus spyware found on journalists’ phones, French intelligence confirms
#52Is there no regulatory or compliance requirements for surveillance software? Instead of blaming the victims of pegasus, we should focus our attention on the lack of actions from key policymakers and regulatory bodies. It is not possible for every individual to be a technical expert when it comes to malware removal, but we can reduce the likelihood of misusing surveillance software by creating an ethical framework aro…
Is it that nobody is filing these or just that the revelations are too new and that the lawyers are just beginning to spin up?
Re: Pegasus spyware found on journalists’ phones, French intelligence confirms
#53Slight OT: the malware indicators of compromise that Amnesty International released have no license, thereby prohibiting use in other projects as far as I understand. https://github.com/AmnestyTech/investigations/issues/11 If anyone can help on that front it'd be much appreciated.
IANAL but arguably, those indicator files are merely lists of information, and therefore are not subject to copyright. They are not, on their own, a creative work. https://www.nolo.com/legal-encyclopedia/types-databases-that...
Re: Pegasus spyware found on journalists’ phones, French intelligence confirms
#54Earlier quoted context omitted.
IANAL but arguably, those indicator files are merely lists of information, and therefore are not subject to copyright. They are not, on their own, a creative work. https://www.nolo.com/legal-encyclopedia/types-databases-that...
But that page says things like "[when] no judgment is needed to decide which names and addresses should be included". Surely somebody decided what are the things for a classifier to look for, and that would be a creative decision?
In the same sense, recipes are not copyrightable. The thought that goes into composing them may be creative, but the list of ingredients itself is not subject to copyright.
Re: Pegasus spyware found on journalists’ phones, French intelligence confirms
#55Earlier quoted context omitted.
One man's journalist is another man's .... ;-)
And the same invariable lie is always used, "oh, don't worry, we're only going to use this against the bad guys". Bad guys only exist in a world without nuance.
Re: Pegasus spyware found on journalists’ phones, French intelligence confirms
#56" Bredoux added: “It takes a bit of time to realise it, but it’s extremely unpleasant to think that one is being spied on, that photos of your husband and children, your friends – who are all collateral victims – are being looked at; that there is no space in which you can escape. It’s very disturbing.” " Welcome to the future! It's pretty much the same as the past, only more effective.
Re: Pegasus spyware found on journalists’ phones, French intelligence confirms
#57" Bredoux added: “It takes a bit of time to realise it, but it’s extremely unpleasant to think that one is being spied on, that photos of your husband and children, your friends – who are all collateral victims – are being looked at; that there is no space in which you can escape. It’s very disturbing.” " Welcome to the future! It's pretty much the same as the past, only more effective.
A depressing thought experiment a professor once posited many years ago....Hitler comes to power in the internet era and now has state of the art tools to find people of certain traits, vs manpower and spies to discover them. Ability to go through your entire lives digital footprint. Every picture. Every video you've created, or viewed on a website. Every location you've visited, how long you were there, and who was…
Re: Pegasus spyware found on journalists’ phones, French intelligence confirms
#58Earlier quoted context omitted.
The Pegasus thing didn't even survive a reboot, it was reinstalled by using the 0-day again on a fresh boot. Replacing the image would have done nothing if they were flashing a version that still had the iMessage vulnerability.
But if that imessage vulnerability was FOSS and you could flash your own image, you could fix it and move on with your life.
1. the vulnerability wasn't FOSS. It was kept under wraps because otherwise it would get discovered and apple would patch it
2. what makes you think that amateurs working in their free time can patch 0days faster than the vendors themselves?
Re: Pegasus spyware found on journalists’ phones, French intelligence confirms
#59" Bredoux added: “It takes a bit of time to realise it, but it’s extremely unpleasant to think that one is being spied on, that photos of your husband and children, your friends – who are all collateral victims – are being looked at; that there is no space in which you can escape. It’s very disturbing.” " Welcome to the future! It's pretty much the same as the past, only more effective.
A depressing thought experiment a professor once posited many years ago....Hitler comes to power in the internet era and now has state of the art tools to find people of certain traits, vs manpower and spies to discover them. Ability to go through your entire lives digital footprint. Every picture. Every video you've created, or viewed on a website. Every location you've visited, how long you were there, and who was…
The ship already sailed on the whole "ubiquitous gaze" thing.
Re: Pegasus spyware found on journalists’ phones, French intelligence confirms
#60Earlier quoted context omitted.
> it would be easy to guarantee that you can get a rootkit-free phone The problem in this case is that you get the malware installed through a no-click required iMessage and not a "supply chain" attack on the image your phone is running on. How would that help?
It could help by simply being sufficiently different . The only reason this type of malware is such a widespread problem is the large monoculture of potential targets. Just like in agriculture (e.g. potatoes, bananas), a monoculture allows a single pathogen to affect an entire crop. In security this is a class break [1]. Utilizing different software implementations limits the scope of this type of attack. The current…