Live data from Hacker News

Apple sues NSO Group to curb the abuse of state-sponsored spyware

apple.com

101–110 of 477 posts

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#101
post #7

It is great to see this happen. It's also fascinating that the crux of the Apple's case against NSO hinges on NSO engineers that accepted iCloud's terms and conditions. From related NYT article: > The sample of Pegasus gave Apple a forensic understanding of how Pegasus worked. The company found that NSO’s engineers had created more than 100 fake Apple IDs to carry out their attacks. In the process of creating those a…

Is it great? The lawsuit is Apple trying to enforce the iCloud EULA to stop reverse engineering. While NSO Group created hacking tools, and then did some questionable things with them, do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? Put another way, if it was someone HN liked , would we still say this is actually good? Because c…

What is great is it could bring some much needed clarity on the subject.

A ruling against the EULA might bring some clarity to the limits of powers tech companies have over us.

A ruling for the EULA might shine a light the power these companies DO have and force governments to bring in laws to curb them.

It is not a good situation, where Apple / Microsoft could turn around and say to someone who broke the EULA or perhaps even to someone who didn't, we are revoking our agreement you can no longer use our software. Leaving them virtually unemployable in many sectors, and similarly they are in the position to absolutely cripple the vast majority of businesses with the same tactics.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#102
post #50

Earlier quoted context omitted.

Ok normally I’d just let something like this go but I just have to pull my hair out when I see a comment like this. The attack surface of software as complicated as a modern operating system (iOS or MacOS, etc.) is simply too large to lockdown without dramatically hurting the user experience (assuming you could actually achieve a lockdown in the first place!!). Let’s, just for a second, propose that apple went full M…

> I’m sorry but there’s no world where Apple can make perfect security i think everyone knows that perfect security is not possible, the operative word being ‘perfect’. i think what we want is for apple to ‘actually try’ to provide security, in some way that results in security order of magnitudes better than we enjoy today, which would still be miles and miles away from ‘perfect’, vulnerable to nation state actors e…

Can you point to a single instance of a cellphone vendor who takes security more seriously than Apple?

Put a different way, is there any device with a high monthly active user count that has a higher cost to purchase a black market exploit than the iPhone?

Apple can always do better. It should also scare the living hell out of us that they’re currently the best in the world.

My point is that if Apple can’t secure your phones, who can? It’s enough to make one think about security through obscurity.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#103

Legal methods are a crutch at best. Apple would be wise to put forth the same budget into their security team's research and development and properly address these weaknesses.

Would your solution to weapons exporting to have everyone buy a bigger bunker? Doesn't it just make more sense to control the export of weapons?

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#104
post #7

It is great to see this happen. It's also fascinating that the crux of the Apple's case against NSO hinges on NSO engineers that accepted iCloud's terms and conditions. From related NYT article: > The sample of Pegasus gave Apple a forensic understanding of how Pegasus worked. The company found that NSO’s engineers had created more than 100 fake Apple IDs to carry out their attacks. In the process of creating those a…

Is it great? The lawsuit is Apple trying to enforce the iCloud EULA to stop reverse engineering. While NSO Group created hacking tools, and then did some questionable things with them, do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? Put another way, if it was someone HN liked , would we still say this is actually good? Because c…

hmmm, I mean if we have to agree to things that are supposedly legally binding, I would like them to be so. If they are not legally binding, I would like to know that and not have to agree to them.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#105

Earlier quoted context omitted.

I was the victim of a state-sponsored attack. I took it to court. I tried to subpoena the contents of the government agents' iPhones but Apple came and filed a Joinder in Motion and sent expensive lawyers to lie to the judge about the judge's power to subpoena digital evidence. The lawyer specifically told me all he does is go around the country and lie to judges to get them to cancel subpoenas. We introduced the T+C…

> and they are certainly allowed to violate T+Cs even when a violation of a T+C is a criminal act (which it is in many jurisdictions). Is violating a T&C criminal in the US, if the violating action itself is not a crime? I have not heard of this. Are there any examples that can be linked to? I thought it was always a civil matter.

https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act

Yes it is a federal crime, but was recently limited by https://en.wikipedia.org/wiki/Van_Buren_v._United_States

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#106
We need to target the pos engineers and management at NSO, Finfisher, Hacking Group etc. who sell their souls for a fast buck. These pricks are likely already setting up the next corporate front for when this one collapses. Let's make the mercenary business a cripplingly expensive line of work.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#107
post #78

Earlier quoted context omitted.

Apple knows since at least 2016 of NSO activities on their devices and servers, while selling this image of privacy competence. This long period of inaction, from 2016 to now is unacceptable.

It's as if you don't get the point about legal standing. Apple can only take action now because of a court deciding that Facebook's TOS forum clause is actually binding. If they filed the case prior to such a holding, it'd have been dismissed.

What if Facebook never filed? Would Apple never be able to act on this?

If they would have acted, why didn't they do it before Facebook?

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#108

Earlier quoted context omitted.

Ok normally I’d just let something like this go but I just have to pull my hair out when I see a comment like this. The attack surface of software as complicated as a modern operating system (iOS or MacOS, etc.) is simply too large to lockdown without dramatically hurting the user experience (assuming you could actually achieve a lockdown in the first place!!). Let’s, just for a second, propose that apple went full M…

You’re not wrong about the impossibility of perfect security. But Apple is praising and promising to support independent security research in this press release. Meanwhile they have a reputation among independent security researchers for being standoffish, opaque, slow to respond, and even outright hostile in suing Corellium. They settled that suit but the reputation remains. Apple is the most valuable company in the…

Recently

https://arstechnica.com/information-technology/2021/09/three...

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#109

Earlier quoted context omitted.

Is it great? The lawsuit is Apple trying to enforce the iCloud EULA to stop reverse engineering. While NSO Group created hacking tools, and then did some questionable things with them, do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? Put another way, if it was someone HN liked , would we still say this is actually good? Because c…

> do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? for commercial interactions in particular between two businesses? Yes, absolutely. How else are two entities supposed to come to legally binding terms without a contract? I'm all for a little bit of lenience when an end user didn't read the terms but you think NSO group doesn't h…

(Not a lawyer, but this is the correct answer)

As much as people might look at this and think Apple is being heavy-handed, it comes down to the fact that iCloud, iOS, and the App Store are their IP and they can (within legal limits) set whatever terms they please.

Especially for these sorts of arrangements, it seems like a problem to me if the platform/IP owner doesn't have absolute, final discretion over what happens.

Giving them the right to destroy your business at any time or at least try very hard to make it unprofitable shouldn't be a surprise to anyone.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#110
I’ve been heavily critical of Apple for their on device scanning plans but credit where it’s due. This act hopefully exposes the sheer abuse of Public funds to find and exploit vulnerabilities and somehow those same vulns find themselves in the commercial domain, available to the fucking despots in the Middle East and wherever else?

It’s about time those that took the oath to protect the nation from harm step up and do so instead of creating a million more problems by shipping these exploits off to a later time while they sit on them.

Post reply on HN