Live data from Hacker News

Apple sues NSO Group to curb the abuse of state-sponsored spyware

apple.com

91–100 of 477 posts

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#91
post #66

Earlier quoted context omitted.

None of this seems like 'sponsorship' to me, it seems more like 'restriction' or 'regulation'. 'Sponsorship' implies that someone is providing a level of funding beyond just being a paying customer. Is there any evidence that the government of Israel (or any of the other governments you mention) are actually providing loans or share capital to NSO Group?

my brother has vans sponsorship. he gets shirts and shoes, not money ;) you get my point?

I agree that the word 'sponsorship' has been quite diluted, as you point out, but it should mean something more than 'be a customer of'. Do I sponsor my local sports team when I buy tickets to a game? Am I sponsoring Netflix by subscribing? Do I sponsor my local government by paying property taxes? On the flip side, does my government sponsor me by granting a driver's license?

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#92
post #67

Earlier quoted context omitted.

Is it great? The lawsuit is Apple trying to enforce the iCloud EULA to stop reverse engineering. While NSO Group created hacking tools, and then did some questionable things with them, do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? Put another way, if it was someone HN liked , would we still say this is actually good? Because c…

> those inane licenses no one reads, do we really want them to legally binding? What all would be possible if software EULAs weren't legally binding? One thing that EULAs typically do is reduce liability for the company producing the software. Imagine if Google/Apple were liable for damages from all the miscommunications caused by autocorrect?

There’s a difference between clauses in an EULA that release the software vendor from liability and those that impose additional liability on the user. I think it’s perfectly fine for an EULA or “non-warranty warranty” to be included in open source software. If a person or a company wants to release software and they should be able to do so without being held liable for damages caused by the user’s improper use of the software.

On the other hand, if a click-through license can expose users to a potential lawsuit then that fundamentally changes the regime we all live in. It creates a world where the countless pieces of software we all use on a daily basis become hidden legal threats, lurking in the shadows like so many snakes waiting to strike. That’s not a world I want to live in and I think most HNers would agree.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#93
post #7

It is great to see this happen. It's also fascinating that the crux of the Apple's case against NSO hinges on NSO engineers that accepted iCloud's terms and conditions. From related NYT article: > The sample of Pegasus gave Apple a forensic understanding of how Pegasus worked. The company found that NSO’s engineers had created more than 100 fake Apple IDs to carry out their attacks. In the process of creating those a…

I was the victim of a state-sponsored attack. I took it to court. I tried to subpoena the contents of the government agents' iPhones but Apple came and filed a Joinder in Motion and sent expensive lawyers to lie to the judge about the judge's power to subpoena digital evidence. The lawyer specifically told me all he does is go around the country and lie to judges to get them to cancel subpoenas. We introduced the T+C…

> and they are certainly allowed to violate T+Cs even when a violation of a T+C is a criminal act (which it is in many jurisdictions).

Is violating a T&C criminal in the US, if the violating action itself is not a crime? I have not heard of this. Are there any examples that can be linked to? I thought it was always a civil matter.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#94
post #73
post #62

Earlier quoted context omitted.

> Apple came and filed a Joinder in Motion and sent expensive lawyers to lie to the judge about the judge's power to subpoena digital evidence. If a lawyer makes an argument in court about the law governing a case (as opposed to the facts of the case), and the judge accepts the argument, and the judge's decision survives all its appeals, then the lawyer's argument is, by definition, true. EDIT: I'm objecting here to…

> "If a lawyer makes an argument in court about the law governing a case (as opposed to the facts of the case), and the judge accepts the argument, and the judge's decision survives all its appeals, then the lawyer's argument is, by definition, true. " This is a Kafkaesque and wrong understanding of the legal system. There are all sorts of errors of law and errors of fact that are non-appealable.

I think poster above is right, certainly with respect to the legal system in the USA.

In the USA you often get one direct appeal - an appeal by right - and then if that fails, a discretionary appeal by a more superior court.

I've seen some bone-headed decisions made by the trial judge, then the same error made by the appellate judges, and you know the superior court would reverse, but they only take 0.01% of the cases they see every year and so they just don't have time to fix every mistake. So some really stupid legal decisions become "the law of the case" simply because society doesn't have the funds to pay more judges to check the work of lesser judges.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#96
post #15

Only curbing "abuse" implies that "normal use" of state-sponsored spyware remains kosher.

> Apple believes privacy is a fundamental human right, and security is a constant focus for teams across the company.

This in the press release. It is missing the bit ”except in China.”

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#97

Earlier quoted context omitted.

Ok normally I’d just let something like this go but I just have to pull my hair out when I see a comment like this. The attack surface of software as complicated as a modern operating system (iOS or MacOS, etc.) is simply too large to lockdown without dramatically hurting the user experience (assuming you could actually achieve a lockdown in the first place!!). Let’s, just for a second, propose that apple went full M…

You’re not wrong about the impossibility of perfect security. But Apple is praising and promising to support independent security research in this press release. Meanwhile they have a reputation among independent security researchers for being standoffish, opaque, slow to respond, and even outright hostile in suing Corellium. They settled that suit but the reputation remains. Apple is the most valuable company in the…

Seconded. There are many, many low hanging fruits that would substantially improve Apple users' security that Apple has not yet implemented, for example delivering Safari updates independently from macOS updates and having a seamless auto-update mechanism equivalent to every other modern browser. Apple repeatedly claims that most malware targets Android, which is true, but it includes Play Store adware and side-loaded malware; if you only take RCE exploits, which are the relevant class of malware here, one could argue Android is as secure, or more secure than iOS. I would argue the latter, given that Safari and iMessage (as well as integrated WebKit webviews, like Apple Music) seem like the primary attack vectors, and the ones used by NSO; and that security updates to those components, unlike the Android equivalents, are delayed to match Apple's preferred iOS release schedule, instead of being autoupdated separately and transparently to the user.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#98
post #7

It is great to see this happen. It's also fascinating that the crux of the Apple's case against NSO hinges on NSO engineers that accepted iCloud's terms and conditions. From related NYT article: > The sample of Pegasus gave Apple a forensic understanding of how Pegasus worked. The company found that NSO’s engineers had created more than 100 fake Apple IDs to carry out their attacks. In the process of creating those a…

Is it great? The lawsuit is Apple trying to enforce the iCloud EULA to stop reverse engineering. While NSO Group created hacking tools, and then did some questionable things with them, do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? Put another way, if it was someone HN liked , would we still say this is actually good? Because c…

> do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding?

In this case the contract was made between two businesses. Consumers deserve protection because they are naturally disadvantaged. Companies with fully staffed legal departments really have no excuse.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#99
post #78

Earlier quoted context omitted.

Apple knows since at least 2016 of NSO activities on their devices and servers, while selling this image of privacy competence. This long period of inaction, from 2016 to now is unacceptable.

It's as if you don't get the point about legal standing. Apple can only take action now because of a court deciding that Facebook's TOS forum clause is actually binding. If they filed the case prior to such a holding, it'd have been dismissed.

Sounds to me like GP really WANTS this to be “telling”, when in reality it obviously isn’t.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#100

Legal methods are a crutch at best. Apple would be wise to put forth the same budget into their security team's research and development and properly address these weaknesses.

Their lawyers are probably on retainer, or just straight up in house counsel. I doubt it costs them any more than a rounding error.
Post reply on HN