Live data from Hacker News

Six Palestinian organizations hacked with NSO Group’s Pegasus Spyware

frontlinedefenders.org

311–320 of 362 posts

Re: Six Palestinian organizations hacked with NSO Group’s Pegasus Spyware

#311

To be fair, it is quite murky to what extent groups like Al-Haq are associated with the PFLP (which, with its history of aircraft hijackings and suicide bombings, is undoubtedly a terrorist group). There is plenty of purported evidence of financial and personnel links out there, and I really doubt HN is the right forum to decide either way (unless someone is an expert).

>There is plenty of purported evidence

The name for this is "allegations," specifically "unconfirmed allegations," AKA "random BS."

Re: Six Palestinian organizations hacked with NSO Group’s Pegasus Spyware

#312

Earlier quoted context omitted.

Thank you for your courage to say that. It is also funny how often people forget why the riots start in the first place. So often it seems to be that the riots are precipitated by egregious abuse by settlers/army/police/Israeli policy. Abuse the people long enough and they will rage.

There was a case couple of years ago near Salfit (Palestinian town near the end of the road 5). First, someone "shot at security vehicle". I remember telling my wife after reading the news: "See what happens next". Of course, the barged into Salfit to "retrieve video recordings from CCTV cameras" shooting some mid-aged man in front of his family. It was already clear, what will happen next. In couple of days 19 y.o.…

>It was already clear, what will happen next.

Is it? The attempted murder of innocent people? Is that the sort of behaviour that should be accepted and tolerated? because it sounds like you are saying that.

Re: Six Palestinian organizations hacked with NSO Group’s Pegasus Spyware

#313
post #161

Earlier quoted context omitted.

Unless you count the oddly vague couple admissions extracted under torture from some random accountants as evidence of something, which you shouldn't because torture is not and shouldn't ever be considered a valid way to extract actionable information, being "fair" has nothing to do with what is being done here.

There is no evidence of torture whatsoever. This is a strange lie you keep posting with your link to 972mag, a biased Palestinian defense magazine. If you dig a little deeper at what the actual accountant's lawyer said - he said his client was seated in a chair with his hands tied behind his back during his initial arrest. Inventing a new name ("The shabah position") doesn't make it torture. Obviously the lawyer want…

> but remember that both accountants provided detailed testimony in an open court room - not from a torture chamber.

That’s not actually a counter argument for torture here. Tons of torture victims will walk into court and say everything they said in the torture chamber; the threat of continued torture of them and their loved ones is quite the motivator. History is littered with examples of torture victims “confessing” in court, often to crimes that were laughably made up.

Re: Six Palestinian organizations hacked with NSO Group’s Pegasus Spyware

#314
post #308

Earlier quoted context omitted.

> The nice thing about western countries is that they require due process of law. ...which was followed in this case. Israel routinely skirts "routine operation of law" assassinating innocent civilians abroad and refusing to apologize.

> assassinating innocent civilians abroad care to provide a source or evidence for this allegation?

https://en.wikipedia.org/wiki/Lillehammer_affair

Not to include the 4 innocent bystanders on the street killed by a Mossad car bombing (they're only terrorist attacks when they're not perpetrated by state security services I guess) when they actually found the right guy.

And to include civilian nuclear scientists are also that: civilians.

Re: Six Palestinian organizations hacked with NSO Group’s Pegasus Spyware

#315
post #15

Slightly OT - Isn't it obvious that NSO must be able to control every "copy" of Pegasus it sells? They wouldn't sell it unless they were absolutely sure it wouldn't be used against its own people and they have no problem selling to their arch enemies. NSO's defense has always been "we just sell the tech and can't be held responsible for what our clients do with it" (this was clear from the Darknet Diaries episode). I…

> They wouldn't sell it unless they were absolutely sure it wouldn't be used against its own people Why not? NSO Group is willing to sacrifice the lives of others for profit, so who’s to say that NSO Group would shy away from that?

They do care about 1 thing and thats Pegasus source code.

A Senior Engineer of theirs got caught and jailed trying to sell it for 50 Million Dollars[1]. I assume they don't want their index of exploits leaked

[1]https://www.securityweek.com/ex-nso-employee-accused-stealin...

Re: Six Palestinian organizations hacked with NSO Group’s Pegasus Spyware

#316

I dunno anything about these particular organizations so can't judge who is right here but the fact any country government can declare anybody they don't like a terrorist or another kind of criminal and have them cancelled or hunted in the whole world has long baffled me.

One major function of a government is the monopoly on "cancelling" or really the use of force. The nice thing about western countries is that they require due process of law. ...which was followed in this case.

There is no monopoly on this in the world, quite contrary. Known oppressive and corrupt regimes (I don't mean Israel) can forge whatever cases they want and create a lot of problems for their citizens abroad.

Re: Six Palestinian organizations hacked with NSO Group’s Pegasus Spyware

#317
post #117

Earlier quoted context omitted.

> Israel, a country that terrorizes Palestinians on the daily accuses They don't. Sending a Police Riot control unit against a group of people throwing stones and molotovs does not qualify as being terrorized. > accuses everyone that fights it as terrorists. If they hurt bystanding civilians (and they do) or funnel money for it (and they do) there is nothing wrong with that. > Maybe some are They are, Hamas, Hezbolla…

Ever wondered why those people are protesting? If you only follow the history of the region you’d quickly realize that Israel did (and does) terrorize their neighbors who in turn retaliated and the vicious cycle of vendettas on eachother continues to this day. What is realy cool about Israel is that they’re a democratic country and a large part of their country denounces all this violence, there is a way forward towa…

That isn't all true. Egypt was perhaps the Israel's most bitter enemy, yet they made peace. They have made peace with Jordan, SA and many others. Most of the nasty vendettas were removed from the cycle and do not continue today. Their worst enemy now is Iran who they actually got on with until about 35 years ago when they called Israel the Little satan. Above all i want you to think for a moment what would have happened to all the Jews living in Israel had they lost the first war of independence.

Re: Six Palestinian organizations hacked with NSO Group’s Pegasus Spyware

#318
post #177
post #167

Earlier quoted context omitted.

According to the link below it clearly was phishing https://en.wikipedia.org/wiki/2014_celebrity_nude_photo_leak...

From your own link: " ... such as phishing and brute-force attack guessing ..." Just take a moment to think about the brute force attack and whether that should have worked at this scale in the properly secure environment.

They caught the people responsible, and convicted them, as the Wikipedia page describes in detail at the end. The actual perpetrators acknowledged they'd sent phishing emails to gain access.

Whether or not there was brute force rate limiting available at the time (which seems unclear), that's not related to the specific events you brought up.

Re: Six Palestinian organizations hacked with NSO Group’s Pegasus Spyware

#319

Earlier quoted context omitted.

> Israel launched over 900 attacks on Gaza This has a super simple solution. 5 minutes after Gaza (Hamas, Islamic Jihad, whoever is in charge) stops bombing Israel with missiles and rockets (which it has done since 2007), there will be no more conflict in Gaza.

This is demonstrably false, as Israel has in the past completely ignored Hamas' ceasefires.

You can't expect Hamas to declare ceasefire after every attack then violate it again and Israel to just stand idle.

Re: Six Palestinian organizations hacked with NSO Group’s Pegasus Spyware

#320
post #42

> Front Line Defenders investigated 75 iPhones and found that 6 devices were hacked with NSO Group's Pegasus spyware Hacked iPhones?! I bet they were side loading apps! /s (relevant: https://techcrunch.com/2021/11/03/apple-craig-federighi-side... )

I think they're all iPhones because they have a reliable way of detecting it on iPhones (perform a backup and look at the backup on a computer). But at one point side loading was how the Android version was installed https://android-developers.googleblog.com/2017/04/an-investi...

Sounds like they bypassed the need for that altogether.

While I get the whole 'sideloading is a security threat' arguement, it really doesn't hold up to scrutiny when you can send malware to any phone via invisible SMS parsing bugs. Apple might have a leg to stand on if their history of threat mitigation wasn't so rocky[0] in the first place. The simple fact of the matter is that they're fighting an infinite war of attrition that's not in their favor. State actors and even private interests are now overwhelmingly capable of buying and implementing zero-day exploits, so a more logical security effort would aim to strengthen the kernel and, you know, actually mitigate these threats. Enforcing type-safety and memory safety at a lower level would be a good start, but Apple knows that isn't very marketable (and they have enough zombie XNU code in MacOS and iOS to constitute an new operating system altogether).

By this point, most people call me a security nihilist, paranoid schizophrenic, or an architecture astronaut. Maybe so, but modern threat models are built around pragmatism, not idealism. Apple can wave as many flags as they want, but seldom does that actually effect the overall security of iPhones. NSO will just reach into their catalog of stockpiled vulnerabilities and spin up a new build overnight. If Apple doesn't recognize this before it's too late, I reckon their OSes will become the modern Windows: confusing abstractions of well-understood concepts, with a dead-set focus on how the user perceives the OS, not how it actually functions.

[0] https://citizenlab.ca/2021/08/bahrain-hacks-activists-with-n...

Post reply on HN