Live data from Hacker News

Apple sues NSO Group to curb the abuse of state-sponsored spyware

apple.com

161–170 of 477 posts

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#161

Legal methods are a crutch at best. Apple would be wise to put forth the same budget into their security team's research and development and properly address these weaknesses.

Surprised to see this coming from the person that killed freenode with questionable bullying involving lawyers and "life ruining" consequences...

Hypocrisy at it's finest...

For the record. I'm not sympathetic to NSO group either.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#162
post #89

Earlier quoted context omitted.

They are just using the EULA as the basis for claiming jurisdiction. They are actually suing not to stop reverse engineering but rather to recover damages incurred by unlawful business practices. Basically their argument is that: 0) The defendant's can be sued under California law because they accepted the EULA. 1) California law makes businesses liable for damages incurred by their unlawful business practices. 2) Bu…

Nit (maybe moot): > 4) Apple incurred damages […] from expenses related to mitigating the hacking of their users. This sounds like no one should be a security researcher for they risk paying companies to implement the security the company should have implemented anyway. Put another way, that also sounds like the corporate open source push, "We love open source because we don't have to support it, the community will!"…

>This sounds like no one should be a security researcher for they risk paying companies to implement the security the company should have implemented anyway.

No, read again, this only refers to damages from unlawful activity. "White hat hackers" need not fear.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#163

If you think that israel is doing anything not sanctioned by the US government you are mistaken. In Israel NSO cant make a move without 7 agencies regulating it. This is considered a weapon sale. The same weapons the US are sponsoring israel and buy them from israeli industry. There is no way NSO will fail from this. So eula or whatever these are matters between states for national security interests.

The only thing I can add to what you said is another cynical thought of mine, starting with the question of why would Apple waste the money in this case? And the only answer I can come up with is that they need to re-establish their image of "security". I can't help but feel with various actions taken by them in recent times this being anything more than theatre unfortunately. If they prevail, I wonder if it will simply be a case of Blackwater renaming themselves.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#164
post #89

Earlier quoted context omitted.

They are just using the EULA as the basis for claiming jurisdiction. They are actually suing not to stop reverse engineering but rather to recover damages incurred by unlawful business practices. Basically their argument is that: 0) The defendant's can be sued under California law because they accepted the EULA. 1) California law makes businesses liable for damages incurred by their unlawful business practices. 2) Bu…

Nit (maybe moot): > 4) Apple incurred damages […] from expenses related to mitigating the hacking of their users. This sounds like no one should be a security researcher for they risk paying companies to implement the security the company should have implemented anyway. Put another way, that also sounds like the corporate open source push, "We love open source because we don't have to support it, the community will!"…

I don't know of any legitimate security research group that hacks user accounts they don't own.

NSO hacked devices they didn't own and infected them with spyware. Apple had to pay to repair / replace those devices.

I don't see how this sets any sort of precedent with security researchers are liable for the costs of fixing vulnerabilities that they uncover.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#166
post #38

Earlier quoted context omitted.

One could interpret this as the software is "sponsored" by the governments that finance their operations and purchase their products. This would be countries like Saudi Arabia, Mexico, Germany, and Kazakhstan, not necessarily Israel. Though the fact the US has sanctioned an Israeli business does seem to have potential implications on Israeli policy. [1] [1] https://www.reuters.com/technology/us-blacklists-four-compan…

Beyond merely selling their products to Israel, the NSO Group itself is an Israeli firm, founded by ex-Israeli intelligence, and whose products are subject to Israeli national export controls. https://en.wikipedia.org/wiki/NSO_Group That's a level of sponsorship way beyond simply being a customer... that's state espionage served with a side of profit. It's evil when the USA does it, it's evil when the Russians do it,…

The very wikipedia article you linked to says that the NSO Group is owned by " Novalpina Capital" They describe themselves this way:

> Novalpina Capital is an independent European private equity firm that focuses on making control equity investments in middle market companies throughout the continent. Novalpina Capital has a solution-orientated, entrepreneurial approach to investing and creating value in its portfolio companies.

> Novalpina Capital was established by Stephen Peel, Stefan Kowski and Bastian Lueken in 2017. The Founding Partners bring combined experience of 48 years in private equity investing, including senior positions in the European operations of leading global private equity investment firms, and have a shared history of working together for nearly a decade.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#167
post #89

Earlier quoted context omitted.

Is it great? The lawsuit is Apple trying to enforce the iCloud EULA to stop reverse engineering. While NSO Group created hacking tools, and then did some questionable things with them, do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? Put another way, if it was someone HN liked , would we still say this is actually good? Because c…

They are just using the EULA as the basis for claiming jurisdiction. They are actually suing not to stop reverse engineering but rather to recover damages incurred by unlawful business practices. Basically their argument is that: 0) The defendant's can be sued under California law because they accepted the EULA. 1) California law makes businesses liable for damages incurred by their unlawful business practices. 2) Bu…

>> They are just using the EULA as the basis for claiming jurisdiction.

IANAL but it's always seemed to me that if I reject the terms of a EULA then the EULA doesn't apply to me. Pushing the "button" does not mean anything because only the EULA gives it meaning and I reject that.

50 years from now if someone is doing software archaeology and they go to install some software from a long gone company, who does clicking the button form an agreement with? Will it be legal to try that software? Can existing software companies list people they have click-through agreements with? These things seem like a bad joke in practical terms.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#168
post #133

I guess I am getting cynical. What is the context in which trigger Apple to sue them now , and not any time before? And what if NSO Group closed the branch in US? I assume you cant really do anything to an Israeli company. Because half of it reads a lot like a PR pieces to me. And Apple easily gets the marketing message response they wanted. They are fighting " State Sponsored " spyware. The privacy message they are…

> What is the context in which trigger Apple to sue them now, and not any time before?

Apparently Facebook has a similar suit against NSO and just had a significant ruling go their way. NSO had claimed they were immune since they were acting as foreign government agent.

I’m guessing Apple was waiting to see how that ruling went before proceeding, since if NSO had won Apple would have to take a completely different approach.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#169

Earlier quoted context omitted.

Ok normally I’d just let something like this go but I just have to pull my hair out when I see a comment like this. The attack surface of software as complicated as a modern operating system (iOS or MacOS, etc.) is simply too large to lockdown without dramatically hurting the user experience (assuming you could actually achieve a lockdown in the first place!!). Let’s, just for a second, propose that apple went full M…

You’re not wrong about the impossibility of perfect security. But Apple is praising and promising to support independent security research in this press release. Meanwhile they have a reputation among independent security researchers for being standoffish, opaque, slow to respond, and even outright hostile in suing Corellium. They settled that suit but the reputation remains. Apple is the most valuable company in the…

> They do not appear to have the best security program in the world.

By what measure? That they don’t find all the security bugs? Have you seen what iOS exploit chains look like these days? They’re not exactly simple. I think there is literally no amount of money that could be spent that would eliminate all the security bugs in iOS, or Apple would be figuring out how to spend that much right now. So yes, you can always argue that they should spend more, and I’m sure they do spend more every time something like Pegasus happens, but it’s not some grand revelation. This is just how things are.

> Whatever Citizen Lab can do, Apple should be able to do better; they have a lot more resources and expertise.

At the tail, this doesn’t matter. Other people find bugs because there are always more bugs to be found. There will never be a situation where only Apple can find more bugs in its operating system.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#170
post #7

It is great to see this happen. It's also fascinating that the crux of the Apple's case against NSO hinges on NSO engineers that accepted iCloud's terms and conditions. From related NYT article: > The sample of Pegasus gave Apple a forensic understanding of how Pegasus worked. The company found that NSO’s engineers had created more than 100 fake Apple IDs to carry out their attacks. In the process of creating those a…

Is it great? The lawsuit is Apple trying to enforce the iCloud EULA to stop reverse engineering. While NSO Group created hacking tools, and then did some questionable things with them, do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? Put another way, if it was someone HN liked , would we still say this is actually good? Because c…

> While NSO Group created hacking tools, and then did some questionable things with them

Such as selling their software to the Saudi Government which in turn used the software in a highly targeted cyber attack leading to the grisly murder of a dissident journalist?

Post reply on HN