On the other hand, perhaps the hardware/OS designs of iOS and Android devices are fundamentally flawed, when viewed from a security-first perspective.
NYT journalist hacked with Pegasus after reporting on previous hacking attempts
161–170 of 330 posts
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#162Earlier quoted context omitted.
>The government’s ability to prevent software distribution is limited significantly by the first amendment. Selling “a tool for hacking” is fine, selling “a tool for committing crime” would be illegal, but that distinction just comes down to picking the right marketing copy. The government can however restrict the import and export of software quite broadly. An interesting point. Given the vendor and customers for NS…
The sales pitch is basically the only thing that can make it illegal, because it’s illegal to knowingly do anything for the purpose of assisting somebody else commit a crime. That’s why it would be illegal to have a “burglary tools” section at a hardware store, even if they only difference between that and any other hardware store is words on a sign. Even with regards the restricting import, the government is largely…
I misunderstood your point. I (mistakenly) thought that your reference to "marketing copy" related to the US Government's justification of restrictions on tech exports, not NSO's sales pitches.
My apologies.
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#163Earlier quoted context omitted.
My understanding is they sell it, after the Israeli gov't (Israeli Defense Ministry) vets the sale. It is operated by the client. NSO has claimed they do not have any info on targets by the purchaser, and has no way to find out post-sale. https://www.cbsnews.com/news/interview-with-ceo-of-nso-group...
A german article[0] claimed that only a hashvalue of the telephone number is transmitted to NSO Group: > "Das BKA hat nach Angaben der stellvertretenden Behördenleiterin sichergestellt, dass keine sensiblen Daten bei der Firma NSO landen würden. So würden Hashwerte für Telefonnummern vergeben, damit das Unternehmen die Zielpersonen nicht identifizieren könne." They claim that this way the NSO Group would not be able…
So I don't see how a government hiring someone to hack someone else is not complicit.
Unless if that government branch had the legal right to execute that hack. Because if they were legally able to, but were unable to themselves, it makes sense to hire someone to do the job for them (if that is legal?)
I am quite in awe how for example exploit brokers like Zerodium and Thaddeus Grugq are allowed to sell their services to oppressive regimes, and getting away with it (a clear case of morally bankrupt). They are powerful weapons, and should be treated as such (export controlled etc).
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#164So how do we protect our privacy from the advance of technology? It doesn't seem possible. Just going after NSO is useless.
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#165Earlier quoted context omitted.
> So how do we protect our privacy from the advance of technology? It doesn't seem possible. Just going after NSO is useless. Like we do with anything else: These are crimes, but we are stuck in the mindset of the nascent Internet, when it was a growing experiment, a subculture in our society, harmless, and we wanted to nurture it and give it maximum freedom. Those days are long gone. The Internet is completely integ…
Why a new agency? This is already very much within the FBI’s jurisdiction. Why is the international surveillance of U.S. journalists and their sources not visibly a priority? In my opinion it’s a matter of policy. This comes from the top down. Bringing justice to international actors opposing democratic ethics is regrettably less of a priority today than enforcing highly publicized and politicized criminal cases.
Based on an estimate of the design of organizations: Sometimes you expand an existing function within an organization, sometimes you add a sub-organzation (e.g., a division), sometimes you create a new organization. Which, when, and why? Standard CEO fare. A couple basic considerations off the top of my head:
Organizations have priorities. As one example, the story (I can't promise perfect details here) is that the US Air Force has always had the priority of pilots - it's run by pilots, they are glorified - strategic bombers and air superiority (air-to-air) fighter planes. Tasked also with providing close air support for ground soldiers, drones for surveillance, and orbital operations, they don't quite get around to those needs: They want bombers and air superiority fighters, flown by pilots, so that's what gets attention, that's what they invest in researching, developing, and buying - F-35's, B-21's, etc. (name a high-price uber-tech platform they've built for close air support, surveillance, or space). For close air support, they insist the F-35 will do it well enough as a secondary function, and want to cut other options - 'well enough' is not the language of priority. It's a constant battle to get them to deliver on these other needs. Partly for that reason, the Marines provide their own air support and the Army has helicopters - they have different priorities than the Air Force - and the US created a separate Space Force.
Organizations also have competencies, which affects the expertise of leaders, the acquired deep organizational knowledge, the asset investments, the organizational structure, and the culture - systems engineers have a different culture than movie actors. If the people in the executive meeting know storage but not networking, you can imagine the results for the networking function. Consider recruiting, training, mentoring, and promotion for networking personnel. Just consider office locations, which will be near the storage talent and facilities, but not near the Internet exchange and networking talent hotbed.
The FBI's priority has been terrorism. Catching domestic terrorists seems much different than investigating cybercrime. The FBI leaders have little expertise in the latter; the entire organization is built around the former. The agent training and skills needed for cybercrime and terrorism seem completely different, the assets needed seem completely different (field offices versus high-performance, highly secure computing centers). I would guess the culture would be very different, with cybercrime placing a very high priority on intellectual ability seated in a room, not interpersonal skill (interviews, etc.), tactical decisions, and physical action around the world. My impression is that a different agency, or at least a major FBI division that reports directly to the top, is needed.
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#166Earlier quoted context omitted.
His confinement to the Embassy of Equador since 2010 amply qualify as both imprisonment and torture [0]. If you like to argue that it does not literally qualify then I suggest you don't in the interest of not wasting everybody's time. [0] https://www.bbc.com/news/world-48473898
Nils Melzer dismissed the fact that he was free to leave by making the analogy that someone in shark tank is "free to leave" their boat - but what is the analogy to being eaten by sharks here? Just the normal experience of being in prison in the UK? Is it the position of the UN that every person in prison in the UK is being "tortured"?
https://www.theguardian.com/media/2021/sep/27/senior-cia-off...
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#167So how do we protect our privacy from the advance of technology? It doesn't seem possible. Just going after NSO is useless.
Rejecting the smartphone might be a start.
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#168Earlier quoted context omitted.
Rejecting the smartphone might be a start.
Many restaurants only provide menus via smartphones. Sporting events only accept electronic tickets. How can you reject it, practically?
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#169I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima... ) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling.
Really? Seems blurred enough to me that even some sort of ML would spit out wrong characters.
Re: NYT journalist hacked with Pegasus after reporting on previous hacking attempts
#170I really hope the blur on the picture ( https://citizenlab.ca/wp-content/uploads/2021/10/Hubbard-Ima... ) isn't hiding anything actually important because that can almost certainly be de-blurred with the right tooling.