Live data from Hacker News

Apple sues NSO Group to curb the abuse of state-sponsored spyware

apple.com

221–230 of 477 posts

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#221
post #89

Earlier quoted context omitted.

They are just using the EULA as the basis for claiming jurisdiction. They are actually suing not to stop reverse engineering but rather to recover damages incurred by unlawful business practices. Basically their argument is that: 0) The defendant's can be sued under California law because they accepted the EULA. 1) California law makes businesses liable for damages incurred by their unlawful business practices. 2) Bu…

>0) The defendant's can be sued under California law because they accepted the EULA The Court has personal jurisdiction over Defendants because, on information and belief, they created more than one hundred Apple IDs to carry out their attacks and also agreed to Apple’s iCloud Terms and Conditions (“iCloud Terms”), including a mandatory and enforceable forum selection and exclusive jurisdiction clause that constitute…

Nerds always want to interpret the law in some strict pedantic fashion, but in practice this is almost never how it works. Law is not applied stupidly or mechanically, you can't fashion yourself some ad hoc workaround unless you're extremely certain about what you're doing, preferably with a mountain of precedent behind you.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#222
post #89

Earlier quoted context omitted.

They are just using the EULA as the basis for claiming jurisdiction. They are actually suing not to stop reverse engineering but rather to recover damages incurred by unlawful business practices. Basically their argument is that: 0) The defendant's can be sued under California law because they accepted the EULA. 1) California law makes businesses liable for damages incurred by their unlawful business practices. 2) Bu…

>> They are just using the EULA as the basis for claiming jurisdiction. IANAL but it's always seemed to me that if I reject the terms of a EULA then the EULA doesn't apply to me. Pushing the "button" does not mean anything because only the EULA gives it meaning and I reject that. 50 years from now if someone is doing software archaeology and they go to install some software from a long gone company, who does clicking…

US contract law jurisprudence doesn't really seem to support you here.

> The mental assent of the parties is not requisite for the formation of a contract. If the words or other acts of one of the parties have but one reasonable meaning, his undisclosed intention is immaterial except when an unreasonable meaning which he attaches to his manifestations is known to the other party.

https://en.wikipedia.org/wiki/Lucy_v._Zehmer

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#224
Court has no jurisdiction over NSO. At most, it was foreign international persons who accepted iCloud's terms and conditions. They'd have to identify them, prove that they are linked to NSO, and in fact acting on behalf of NSO in their official capacity. And even after that, they'd just not travel under their real names, or even not travel at all, and that's that.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#225

Earlier quoted context omitted.

You’re not wrong about the impossibility of perfect security. But Apple is praising and promising to support independent security research in this press release. Meanwhile they have a reputation among independent security researchers for being standoffish, opaque, slow to respond, and even outright hostile in suing Corellium. They settled that suit but the reputation remains. Apple is the most valuable company in the…

Seconded. There are many, many low hanging fruits that would substantially improve Apple users' security that Apple has not yet implemented, for example delivering Safari updates independently from macOS updates and having a seamless auto-update mechanism equivalent to every other modern browser. Apple repeatedly claims that most malware targets Android, which is true, but it includes Play Store adware and side-loade…

One could also argue, that as Apple is commonly branded as "secure" alternative, and therefore high profile targets are potentially using their products. This might mean that interest is much higher for attackers on that side. They might not care so much about Android. Increased interest and effort means that more likely something is found.

Also, Apple's sandboxing settings and permission managing makes the most malware pretty useless with App store policies (no sideloading), so only RCE exploits are kinda useful.

What it comes to iMessages, that is the most interesting channel with Safari to deliver exploits, iMessage without user interaction and Safari with some. All you need to know is that target is using iPhone. Other non-default applications as target introduces new challenges. iMessage and Safaring being part of OS updates might indicate, that they are handled differently compared to other apps - is security policy same, worse or better? Is there larger attack interface to system by using these apps?

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#226
post #89

Earlier quoted context omitted.

They are just using the EULA as the basis for claiming jurisdiction. They are actually suing not to stop reverse engineering but rather to recover damages incurred by unlawful business practices. Basically their argument is that: 0) The defendant's can be sued under California law because they accepted the EULA. 1) California law makes businesses liable for damages incurred by their unlawful business practices. 2) Bu…

>0) The defendant's can be sued under California law because they accepted the EULA The Court has personal jurisdiction over Defendants because, on information and belief, they created more than one hundred Apple IDs to carry out their attacks and also agreed to Apple’s iCloud Terms and Conditions (“iCloud Terms”), including a mandatory and enforceable forum selection and exclusive jurisdiction clause that constitute…

> they created more than one hundred Apple IDs to carry out their attacks

Maybe the most interesting thing about this is how it proves that their code signing system is worthless. If the same bad actor can get a hundred Apple IDs to sign literal malware with, why are they imposing this burden on random small developers?

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#227
post #221

Earlier quoted context omitted.

>0) The defendant's can be sued under California law because they accepted the EULA The Court has personal jurisdiction over Defendants because, on information and belief, they created more than one hundred Apple IDs to carry out their attacks and also agreed to Apple’s iCloud Terms and Conditions (“iCloud Terms”), including a mandatory and enforceable forum selection and exclusive jurisdiction clause that constitute…

Nerds always want to interpret the law in some strict pedantic fashion, but in practice this is almost never how it works. Law is not applied stupidly or mechanically, you can't fashion yourself some ad hoc workaround unless you're extremely certain about what you're doing, preferably with a mountain of precedent behind you.

Nerds always want the law to be consistent. Lawyers are Machiavellian professionals trained in getting it to say "heads I win tails you lose" for their clients, and often succeed.

That doesn't mean the nerds are wrong to want what they want.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#228

Earlier quoted context omitted.

I like how suddenly the intense legal minuate are the most important details of a system as if we're in a contract law class, as opposed to the obvious point that in general these agreements are fairly obvious

Making up rules without thinking about the consequences of those rules is a Bad Idea.

Edge cases aren't consequences; they're trivia. And at the the of day, our legal system is governed by humans who interpret and argue. Until humans are perfect, we'll never write a perfect law.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#229

Earlier quoted context omitted.

Making up rules without thinking about the consequences of those rules is a Bad Idea.

Edge cases aren't consequences; they're trivia. And at the the of day, our legal system is governed by humans who interpret and argue. Until humans are perfect, we'll never write a perfect law.

"Perfection is impossible, therefore don't try" is a dodge.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#230

Earlier quoted context omitted.

Their website is still up, posting news, hosted on AWS on one of the us-west AZs. The US is going at them with less vigor than a whack-a-mole torrent site de jure. > In any case, this is a civil suit in federal courts. Even if State wanted to intervene, it would have to do so through informal channels. But didn't we just agree that the federal court system is pretty toothless here without the support of the state dep…

The federal court could only ever do what a federal court could do which is levy sanctions or judgments against NSO property.

Against US based NSO property, practically speaking.
Post reply on HN