Earlier quoted context omitted.
Look, if you don't know how legal standing works, that's one thing. But to reject the explanation provided to you and to cite your own ignorance as a legitimate source of disbelief while you poo-poo away a dispositive fact isn't reasoning.
Apple knows since at least 2016 of NSO activities on their devices and servers, while selling this image of privacy competence. This long period of inaction, from 2016 to now is unacceptable.
Apple sues NSO Group to curb the abuse of state-sponsored spyware
81–90 of 477 posts
Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware
#82Earlier quoted context omitted.
You talk to a lot of people who use Qubes day to day? I do. What have you heard about how Qubes life is?
I am gladly using Qubes myself as a daily driver. Can't recommend it enough.
Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware
#83Earlier quoted context omitted.
Beyond merely selling their products to Israel, the NSO Group itself is an Israeli firm, founded by ex-Israeli intelligence, and whose products are subject to Israeli national export controls. https://en.wikipedia.org/wiki/NSO_Group That's a level of sponsorship way beyond simply being a customer... that's state espionage served with a side of profit. It's evil when the USA does it, it's evil when the Russians do it,…
None of this seems like 'sponsorship' to me, it seems more like 'restriction' or 'regulation'. 'Sponsorship' implies that someone is providing a level of funding beyond just being a paying customer. Is there any evidence that the government of Israel (or any of the other governments you mention) are actually providing loans or share capital to NSO Group?
you get my point?
Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware
#84It is great to see this happen. It's also fascinating that the crux of the Apple's case against NSO hinges on NSO engineers that accepted iCloud's terms and conditions. From related NYT article: > The sample of Pegasus gave Apple a forensic understanding of how Pegasus worked. The company found that NSO’s engineers had created more than 100 fake Apple IDs to carry out their attacks. In the process of creating those a…
Is it great? The lawsuit is Apple trying to enforce the iCloud EULA to stop reverse engineering. While NSO Group created hacking tools, and then did some questionable things with them, do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? Put another way, if it was someone HN liked , would we still say this is actually good? Because c…
for commercial interactions in particular between two businesses? Yes, absolutely. How else are two entities supposed to come to legally binding terms without a contract? I'm all for a little bit of lenience when an end user didn't read the terms but you think NSO group doesn't have a lawyer and just scrolls down and clicks accept?
The little guy isn't always right because he's little. If the little guy hacks my software to sell spyware to dictators and war criminals you bet I want the right to take him to court
Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware
#85It is great to see this happen. It's also fascinating that the crux of the Apple's case against NSO hinges on NSO engineers that accepted iCloud's terms and conditions. From related NYT article: > The sample of Pegasus gave Apple a forensic understanding of how Pegasus worked. The company found that NSO’s engineers had created more than 100 fake Apple IDs to carry out their attacks. In the process of creating those a…
Is it great? The lawsuit is Apple trying to enforce the iCloud EULA to stop reverse engineering. While NSO Group created hacking tools, and then did some questionable things with them, do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? Put another way, if it was someone HN liked , would we still say this is actually good? Because c…
In particular, by any standard, it certainly seems reasonable for Apple (or even companies we don't like) to prevent the use of its own tools and accounts for the purposes of attacking its products and attacking its customers. Especially when the attackers have explicitly promised not to do so.
Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware
#86Earlier quoted context omitted.
I was the victim of a state-sponsored attack. I took it to court. I tried to subpoena the contents of the government agents' iPhones but Apple came and filed a Joinder in Motion and sent expensive lawyers to lie to the judge about the judge's power to subpoena digital evidence. The lawyer specifically told me all he does is go around the country and lie to judges to get them to cancel subpoenas. We introduced the T+C…
Perhaps you may want to ask https://eff.org for help.
Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware
#87Earlier quoted context omitted.
I was the victim of a state-sponsored attack. I took it to court. I tried to subpoena the contents of the government agents' iPhones but Apple came and filed a Joinder in Motion and sent expensive lawyers to lie to the judge about the judge's power to subpoena digital evidence. The lawyer specifically told me all he does is go around the country and lie to judges to get them to cancel subpoenas. We introduced the T+C…
US based? I understand if you can't divulge any specifics, but I'm always curious about the nature of these attacks, e.g. we know certain types of journalists/activists are often targeted.
Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware
#88Earlier quoted context omitted.
I am gladly using Qubes myself as a daily driver. Can't recommend it enough.
Hey, my Qubes friends keep using it too. I'm not saying it's un-usable. Is dys-usable a word?
In my opinion, most of the HN audience would be able to use it to their benefit.
Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware
#89It is great to see this happen. It's also fascinating that the crux of the Apple's case against NSO hinges on NSO engineers that accepted iCloud's terms and conditions. From related NYT article: > The sample of Pegasus gave Apple a forensic understanding of how Pegasus worked. The company found that NSO’s engineers had created more than 100 fake Apple IDs to carry out their attacks. In the process of creating those a…
Is it great? The lawsuit is Apple trying to enforce the iCloud EULA to stop reverse engineering. While NSO Group created hacking tools, and then did some questionable things with them, do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? Put another way, if it was someone HN liked , would we still say this is actually good? Because c…
0) The defendant's can be sued under California law because they accepted the EULA.
1) California law makes businesses liable for damages incurred by their unlawful business practices.
2) Business practices which violate any California or federal law are unlawful business practices in California.
3) The defendant violated the federal computer fraud and abuse act by hacking into users phones.
4) Apple incurred damages to their reputation and from expenses related to mitigating the hacking of their users.
5) Therefor the defendant is liable for Apple's damages under California law.
So the defendant could have been fine if they just done reverse engineering, or even if they developed the hacking tools, but actually using the tools against Apple's users in violation of the CFAA was going too far.
https://www.apple.com/newsroom/pdfs/Apple_v_NSO_Complaint_11...
Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware
#90Legal methods are a crutch at best. Apple would be wise to put forth the same budget into their security team's research and development and properly address these weaknesses.
Ok normally I’d just let something like this go but I just have to pull my hair out when I see a comment like this. The attack surface of software as complicated as a modern operating system (iOS or MacOS, etc.) is simply too large to lockdown without dramatically hurting the user experience (assuming you could actually achieve a lockdown in the first place!!). Let’s, just for a second, propose that apple went full M…