Live data from Hacker News

Apple sues NSO Group to curb the abuse of state-sponsored spyware

apple.com

241–250 of 477 posts

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#241

Earlier quoted context omitted.

Is it great? The lawsuit is Apple trying to enforce the iCloud EULA to stop reverse engineering. While NSO Group created hacking tools, and then did some questionable things with them, do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? Put another way, if it was someone HN liked , would we still say this is actually good? Because c…

> do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? for commercial interactions in particular between two businesses? Yes, absolutely. How else are two entities supposed to come to legally binding terms without a contract? I'm all for a little bit of lenience when an end user didn't read the terms but you think NSO group doesn't h…

> but you think NSO group doesn't have a lawyer and just scrolls down and clicks accept?

I see this in companies I work for all the time, so, yes, I can see that being the case here.

(I'm not saying that's a good or professional thing.)

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#242
>make products/services more secure

>sue others to make them stop trying to hack your products/services

Chooses the second one. I'm pretty sure this is just a PR stunt for Apple to try to appeal and brand themselves as "oh, we stand for security" and all the other bullshit.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#243
post #89

Earlier quoted context omitted.

They are just using the EULA as the basis for claiming jurisdiction. They are actually suing not to stop reverse engineering but rather to recover damages incurred by unlawful business practices. Basically their argument is that: 0) The defendant's can be sued under California law because they accepted the EULA. 1) California law makes businesses liable for damages incurred by their unlawful business practices. 2) Bu…

>0) The defendant's can be sued under California law because they accepted the EULA The Court has personal jurisdiction over Defendants because, on information and belief, they created more than one hundred Apple IDs to carry out their attacks and also agreed to Apple’s iCloud Terms and Conditions (“iCloud Terms”), including a mandatory and enforceable forum selection and exclusive jurisdiction clause that constitute…

> I'm not a legal expert but shouldn't that be stupidly easy to deny?

Anything is easy to deny.

Denial isn't sufficient to win the point.

> We can fully prove our claims.

Saying “we can fully prove our claims” is stupid easy. Being able to is harder.

> This is assuming NSO were far- sighted enough to actually create such a paper trail

But they probably weren't, because they didn't anticipate being sued in California based on jurisdiction gained via the iCloud T&C.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#245

We need to target the pos engineers and management at NSO, Finfisher, Hacking Group etc. who sell their souls for a fast buck. These pricks are likely already setting up the next corporate front for when this one collapses. Let's make the mercenary business a cripplingly expensive line of work.

"target them"? What are you proposing?

Based on context, and the phrase “expensive”, I assume they mean they want prosecution/legal action against the individual engineers and management. Not threatening

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#246

We need to target the pos engineers and management at NSO, Finfisher, Hacking Group etc. who sell their souls for a fast buck. These pricks are likely already setting up the next corporate front for when this one collapses. Let's make the mercenary business a cripplingly expensive line of work.

"target them"? What are you proposing?

An often cited rule on HN is that you should assume the most charitable interpretation... Parent might be suggesting that those that make money on NSO Group's spyware should be treated in the same way that we treat others that make money on deeply immoral or illegal businesses. E.g it is not illegal to optimize online casinos to suck money out of gambling addicts, but many of us thinks that it is immoral.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#247

We need to target the pos engineers and management at NSO, Finfisher, Hacking Group etc. who sell their souls for a fast buck. These pricks are likely already setting up the next corporate front for when this one collapses. Let's make the mercenary business a cripplingly expensive line of work.

"target them"? What are you proposing?

Firstly, chill. Secondly, focus attention on them so they feel the legal, civil and reputational consequences (in line with the theme of this entire post) of their career choices. Draining a disgusting industry of expertise that it couldn't exist without.

They made their choices. Their victims had none.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#248
post #233

Earlier quoted context omitted.

When did anyone mention code signing or developer accounts?

What did you suppose they needed a hundred Apple IDs for?

The article doesn’t say. I’m curious to find out myself.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#249
post #233

Earlier quoted context omitted.

When did anyone mention code signing or developer accounts?

What did you suppose they needed a hundred Apple IDs for?

Sending the malware via iMessage, assuming the flaw was part of iMessage and not standard SMS.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#250

Earlier quoted context omitted.

>0) The defendant's can be sued under California law because they accepted the EULA The Court has personal jurisdiction over Defendants because, on information and belief, they created more than one hundred Apple IDs to carry out their attacks and also agreed to Apple’s iCloud Terms and Conditions (“iCloud Terms”), including a mandatory and enforceable forum selection and exclusive jurisdiction clause that constitute…

> I'm not a legal expert but shouldn't that be stupidly easy to deny? Anything is easy to deny . Denial isn't sufficient to win the point. > We can fully prove our claims. Saying “we can fully prove our claims” is stupid easy. Being able to is harder. > This is assuming NSO were far- sighted enough to actually create such a paper trail But they probably weren't, because they didn't anticipate being sued in California…

The burden of proof should fall on Apple in an ideal world. Maybe a court ruling that one stupid checkbox at the end of a digital 10,000 word document isn't sufficient proof might be a good idea?
Post reply on HN