Live data from Hacker News

Apple sues NSO Group to curb the abuse of state-sponsored spyware

apple.com

171–180 of 477 posts

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#172

Legal methods are a crutch at best. Apple would be wise to put forth the same budget into their security team's research and development and properly address these weaknesses.

As if there’s a magic button trillion dollar companies can buy that, when pushed, removed all security vulnerabilities from software and hardware, no matter how complex!

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#173

Earlier quoted context omitted.

Is it great? The lawsuit is Apple trying to enforce the iCloud EULA to stop reverse engineering. While NSO Group created hacking tools, and then did some questionable things with them, do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? Put another way, if it was someone HN liked , would we still say this is actually good? Because c…

A court can decide. Apple and many others have been harmed by this so it makes sense that somebody should be able to sue.

It seems many laws are written in the hopes everyone just agrees, but secretly hoping it is never challenged in court. The easiest hurdle put in place is standing in legal terms. That's one bit I have trouble with how laws are challenged is that if a bad law is enacted, it should be able to be challenged immediately through courts to knock it back vs having to wait for the first person to be directly affected by the law to also have the means to mount the legal challenge.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#174
post #7

It is great to see this happen. It's also fascinating that the crux of the Apple's case against NSO hinges on NSO engineers that accepted iCloud's terms and conditions. From related NYT article: > The sample of Pegasus gave Apple a forensic understanding of how Pegasus worked. The company found that NSO’s engineers had created more than 100 fake Apple IDs to carry out their attacks. In the process of creating those a…

Is it great? The lawsuit is Apple trying to enforce the iCloud EULA to stop reverse engineering. While NSO Group created hacking tools, and then did some questionable things with them, do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? Put another way, if it was someone HN liked , would we still say this is actually good? Because c…

> Put another way, if it was someone HN liked,

I'm sure no one reads TSLA EULAs either.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#175
post #89

Earlier quoted context omitted.

They are just using the EULA as the basis for claiming jurisdiction. They are actually suing not to stop reverse engineering but rather to recover damages incurred by unlawful business practices. Basically their argument is that: 0) The defendant's can be sued under California law because they accepted the EULA. 1) California law makes businesses liable for damages incurred by their unlawful business practices. 2) Bu…

>> They are just using the EULA as the basis for claiming jurisdiction. IANAL but it's always seemed to me that if I reject the terms of a EULA then the EULA doesn't apply to me. Pushing the "button" does not mean anything because only the EULA gives it meaning and I reject that. 50 years from now if someone is doing software archaeology and they go to install some software from a long gone company, who does clicking…

> 50 years from now if someone is doing software archaeology and they go to install some software from a long gone company, who does clicking the button form an agreement with? Will it be legal to try that software? Can existing software companies list people they have click-through agreements with? These things seem like a bad joke in practical terms.

I mean, this seems pretty easily addressed:

I can't sign a contract with a dead company, can I? Well, literally I can, but the agreement wouldn't be binding.

Same applies here. Unless the entity still exists, in which case congratulations, you're in a binding agreement lol

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#176
post #7

It is great to see this happen. It's also fascinating that the crux of the Apple's case against NSO hinges on NSO engineers that accepted iCloud's terms and conditions. From related NYT article: > The sample of Pegasus gave Apple a forensic understanding of how Pegasus worked. The company found that NSO’s engineers had created more than 100 fake Apple IDs to carry out their attacks. In the process of creating those a…

If this is ruled in Apple's favor, can that be a stepping stone to allow NSO to be charged with aiding in murder?

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#177
Apple sues NSO Group to curb the abuse of state-sponsored spyware

I'm quite cynical about this press release. The key point in the title is that Apple are cool with state-sponsored spyware, it's just abuse of it that bothers them. Also why did they wait so long to file this. I don't think it's because they lacked evidence until now. Perhaps they think such a lawsuit will is now expected of them otherwise they will lose face, and that they have the general backing of the public now. I remember some months ago showed that Apple already had grounds to sue for copyright infringement. Either way, Apple is stepping into a political minefield. Buy popcorn and expect fireworks. Big ones.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#178

If you think that israel is doing anything not sanctioned by the US government you are mistaken. In Israel NSO cant make a move without 7 agencies regulating it. This is considered a weapon sale. The same weapons the US are sponsoring israel and buy them from israeli industry. There is no way NSO will fail from this. So eula or whatever these are matters between states for national security interests.

You are extrapolating very tight Israeli state control of the Israeli arms industry (very true) to very tight US state control of the Israeli arms industry, which is not actually how the relationship works.

The US has influence over Israeli sales of Israeli-made arms, but this is costly to exert and only used sparingly. Historically, it's restricted to preventing Israeli arms sales to direct US rivals like China or Russia. When Israel sells guns to dictatorships in Africa or Southeast Asia that the US doesn't like, the Americans are perfectly willing to agree to disagree.

EULAs and other civilian contractual arrangements are important here because these weapons were used against US civilians and US civilian property. When Soltam howitzers kill villagers in Myanmar, the US executive branch doesn't give a damn; but as soon as a US corporation (Apple) has to pay for warranty returns the courts wake up and pay attention.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#179
post #164

Earlier quoted context omitted.

Nit (maybe moot): > 4) Apple incurred damages […] from expenses related to mitigating the hacking of their users. This sounds like no one should be a security researcher for they risk paying companies to implement the security the company should have implemented anyway. Put another way, that also sounds like the corporate open source push, "We love open source because we don't have to support it, the community will!"…

I don't know of any legitimate security research group that hacks user accounts they don't own. NSO hacked devices they didn't own and infected them with spyware. Apple had to pay to repair / replace those devices. I don't see how this sets any sort of precedent with security researchers are liable for the costs of fixing vulnerabilities that they uncover.

> I don't know of any legitimate security research group that hacks user accounts they don't own.

nit: "user accounts to which they're not authorized"

I work with friends' accounts all the time provided they authorized me to do so and provided I'm permitted to do so as part of the vuln disclosure program terms and rules of engagement, though I usually split the bounty with them in a meaningful way to make it worth their while.

Post reply on HN