Earlier quoted context omitted.
They are just using the EULA as the basis for claiming jurisdiction. They are actually suing not to stop reverse engineering but rather to recover damages incurred by unlawful business practices. Basically their argument is that: 0) The defendant's can be sued under California law because they accepted the EULA. 1) California law makes businesses liable for damages incurred by their unlawful business practices. 2) Bu…
>0) The defendant's can be sued under California law because they accepted the EULA The Court has personal jurisdiction over Defendants because, on information and belief, they created more than one hundred Apple IDs to carry out their attacks and also agreed to Apple’s iCloud Terms and Conditions (“iCloud Terms”), including a mandatory and enforceable forum selection and exclusive jurisdiction clause that constitute…
Apple sues NSO Group to curb the abuse of state-sponsored spyware
221–230 of 477 posts
Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware
#222Earlier quoted context omitted.
They are just using the EULA as the basis for claiming jurisdiction. They are actually suing not to stop reverse engineering but rather to recover damages incurred by unlawful business practices. Basically their argument is that: 0) The defendant's can be sued under California law because they accepted the EULA. 1) California law makes businesses liable for damages incurred by their unlawful business practices. 2) Bu…
>> They are just using the EULA as the basis for claiming jurisdiction. IANAL but it's always seemed to me that if I reject the terms of a EULA then the EULA doesn't apply to me. Pushing the "button" does not mean anything because only the EULA gives it meaning and I reject that. 50 years from now if someone is doing software archaeology and they go to install some software from a long gone company, who does clicking…
> The mental assent of the parties is not requisite for the formation of a contract. If the words or other acts of one of the parties have but one reasonable meaning, his undisclosed intention is immaterial except when an unreasonable meaning which he attaches to his manifestations is known to the other party.
Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware
#223Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware
#224Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware
#225Earlier quoted context omitted.
You’re not wrong about the impossibility of perfect security. But Apple is praising and promising to support independent security research in this press release. Meanwhile they have a reputation among independent security researchers for being standoffish, opaque, slow to respond, and even outright hostile in suing Corellium. They settled that suit but the reputation remains. Apple is the most valuable company in the…
Seconded. There are many, many low hanging fruits that would substantially improve Apple users' security that Apple has not yet implemented, for example delivering Safari updates independently from macOS updates and having a seamless auto-update mechanism equivalent to every other modern browser. Apple repeatedly claims that most malware targets Android, which is true, but it includes Play Store adware and side-loade…
Also, Apple's sandboxing settings and permission managing makes the most malware pretty useless with App store policies (no sideloading), so only RCE exploits are kinda useful.
What it comes to iMessages, that is the most interesting channel with Safari to deliver exploits, iMessage without user interaction and Safari with some. All you need to know is that target is using iPhone. Other non-default applications as target introduces new challenges. iMessage and Safaring being part of OS updates might indicate, that they are handled differently compared to other apps - is security policy same, worse or better? Is there larger attack interface to system by using these apps?
Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware
#226Earlier quoted context omitted.
They are just using the EULA as the basis for claiming jurisdiction. They are actually suing not to stop reverse engineering but rather to recover damages incurred by unlawful business practices. Basically their argument is that: 0) The defendant's can be sued under California law because they accepted the EULA. 1) California law makes businesses liable for damages incurred by their unlawful business practices. 2) Bu…
>0) The defendant's can be sued under California law because they accepted the EULA The Court has personal jurisdiction over Defendants because, on information and belief, they created more than one hundred Apple IDs to carry out their attacks and also agreed to Apple’s iCloud Terms and Conditions (“iCloud Terms”), including a mandatory and enforceable forum selection and exclusive jurisdiction clause that constitute…
Maybe the most interesting thing about this is how it proves that their code signing system is worthless. If the same bad actor can get a hundred Apple IDs to sign literal malware with, why are they imposing this burden on random small developers?
Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware
#227Earlier quoted context omitted.
>0) The defendant's can be sued under California law because they accepted the EULA The Court has personal jurisdiction over Defendants because, on information and belief, they created more than one hundred Apple IDs to carry out their attacks and also agreed to Apple’s iCloud Terms and Conditions (“iCloud Terms”), including a mandatory and enforceable forum selection and exclusive jurisdiction clause that constitute…
Nerds always want to interpret the law in some strict pedantic fashion, but in practice this is almost never how it works. Law is not applied stupidly or mechanically, you can't fashion yourself some ad hoc workaround unless you're extremely certain about what you're doing, preferably with a mountain of precedent behind you.
That doesn't mean the nerds are wrong to want what they want.
Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware
#228Earlier quoted context omitted.
I like how suddenly the intense legal minuate are the most important details of a system as if we're in a contract law class, as opposed to the obvious point that in general these agreements are fairly obvious
Making up rules without thinking about the consequences of those rules is a Bad Idea.
Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware
#229Earlier quoted context omitted.
Making up rules without thinking about the consequences of those rules is a Bad Idea.
Edge cases aren't consequences; they're trivia. And at the the of day, our legal system is governed by humans who interpret and argue. Until humans are perfect, we'll never write a perfect law.
Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware
#230Earlier quoted context omitted.
Their website is still up, posting news, hosted on AWS on one of the us-west AZs. The US is going at them with less vigor than a whack-a-mole torrent site de jure. > In any case, this is a civil suit in federal courts. Even if State wanted to intervene, it would have to do so through informal channels. But didn't we just agree that the federal court system is pretty toothless here without the support of the state dep…
The federal court could only ever do what a federal court could do which is levy sanctions or judgments against NSO property.