Live data from Hacker News

Apple sues NSO Group to curb the abuse of state-sponsored spyware

apple.com

251–260 of 477 posts

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#251
post #89

Earlier quoted context omitted.

They are just using the EULA as the basis for claiming jurisdiction. They are actually suing not to stop reverse engineering but rather to recover damages incurred by unlawful business practices. Basically their argument is that: 0) The defendant's can be sued under California law because they accepted the EULA. 1) California law makes businesses liable for damages incurred by their unlawful business practices. 2) Bu…

>0) The defendant's can be sued under California law because they accepted the EULA The Court has personal jurisdiction over Defendants because, on information and belief, they created more than one hundred Apple IDs to carry out their attacks and also agreed to Apple’s iCloud Terms and Conditions (“iCloud Terms”), including a mandatory and enforceable forum selection and exclusive jurisdiction clause that constitute…

That is why they included an alternative count of unjust enrichment. In the case the defense proves they never agreed to the user/license agreement then they will have also proven that they obtained Apple's software and accessed Apples services without a license and used them for their own profit and to Apples determent. Thereby unjustly enriching themselves.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#252

Earlier quoted context omitted.

> and they are certainly allowed to violate T+Cs even when a violation of a T+C is a criminal act (which it is in many jurisdictions). Is violating a T&C criminal in the US, if the violating action itself is not a crime? I have not heard of this. Are there any examples that can be linked to? I thought it was always a civil matter.

https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act Yes it is a federal crime, but was recently limited by https://en.wikipedia.org/wiki/Van_Buren_v._United_States

The CFAA includes this. I am not sure it's possible for US government actors to violate the CFAA unless they're violating some other law also. It seems very unlikely Congress intended to make T&Cs binding on law enforcement or intelligence investigations.

"This section does not prohibit any lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency of the United States, a State, or a political subdivision of a State, or of an intelligence agency of the United States."

https://www.law.cornell.edu/uscode/text/18/1030#

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#253

Earlier quoted context omitted.

Do you have some statistical evidence that macOS is fundamentally more insecure than other operating systems ? That would be surprising to me given many controls e.g. application signing I've not seen implemented on other platforms.

NSO seems to concentrate on making products for iOS

Because their targets are on iOS and exploits garner more money. That sounds like a signal that the supply of exploits are lower or the demand very high. This doesn’t, to me, seem to signal that it’s more insecure, in fact, it may signal that it’s more secure.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#254

>make products/services more secure >sue others to make them stop trying to hack your products/services Chooses the second one. I'm pretty sure this is just a PR stunt for Apple to try to appeal and brand themselves as "oh, we stand for security" and all the other bullshit.

Chooses both, as far as I can tell.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#255

Earlier quoted context omitted.

> I'm not a legal expert but shouldn't that be stupidly easy to deny? Anything is easy to deny . Denial isn't sufficient to win the point. > We can fully prove our claims. Saying “we can fully prove our claims” is stupid easy. Being able to is harder. > This is assuming NSO were far- sighted enough to actually create such a paper trail But they probably weren't, because they didn't anticipate being sued in California…

The burden of proof should fall on Apple in an ideal world. Maybe a court ruling that one stupid checkbox at the end of a digital 10,000 word document isn't sufficient proof might be a good idea?

> The burden of proof should fall on Apple in an ideal world

It does, but its not an element of a crime being proven, so the burden isn't “beyond a reasonable doubt”, but (as for most things in a civil case, though sometimes other standards apply) “preponderance of the evidence", for which you need to convince the court that, based on the evidence provided, the facts you need are more likely than not to be true.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#256

We need to target the pos engineers and management at NSO, Finfisher, Hacking Group etc. who sell their souls for a fast buck. These pricks are likely already setting up the next corporate front for when this one collapses. Let's make the mercenary business a cripplingly expensive line of work.

"target them"? What are you proposing?

[deleted]

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#258
post #38

Earlier quoted context omitted.

One could interpret this as the software is "sponsored" by the governments that finance their operations and purchase their products. This would be countries like Saudi Arabia, Mexico, Germany, and Kazakhstan, not necessarily Israel. Though the fact the US has sanctioned an Israeli business does seem to have potential implications on Israeli policy. [1] [1] https://www.reuters.com/technology/us-blacklists-four-compan…

Beyond merely selling their products to Israel, the NSO Group itself is an Israeli firm, founded by ex-Israeli intelligence, and whose products are subject to Israeli national export controls. https://en.wikipedia.org/wiki/NSO_Group That's a level of sponsorship way beyond simply being a customer... that's state espionage served with a side of profit. It's evil when the USA does it, it's evil when the Russians do it,…

Further to this there has been some recent coverage in the Israeli press about the strong relationship between NSO Group and the Israeli government. The gov used NSO and it's products as a lure to the Gulf states to bring them on-side as a wedge against Iran

https://www.haaretz.com/middle-east-news/.premium-with-israe...

> NSO is one of the most active Israeli companies in the Gulf, and its Pegasus 3 software permits law enforcement authorities to hack into cellphones, copy their contents and sometimes even to control their camera and audio recording capabilities

> Israel put NSO in touch with Arab states in the region, and Israeli representatives even took part in marketing meetings between intelligence officials in the Arab states and NSO executives. Some of the meetings were held in Israel.

Further reading on just how intertwined NSO group was with the government:

https://www.haaretz.com/israel-news/.premium.HIGHLIGHT-israe...

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#259
post #89

Earlier quoted context omitted.

They are just using the EULA as the basis for claiming jurisdiction. They are actually suing not to stop reverse engineering but rather to recover damages incurred by unlawful business practices. Basically their argument is that: 0) The defendant's can be sued under California law because they accepted the EULA. 1) California law makes businesses liable for damages incurred by their unlawful business practices. 2) Bu…

>0) The defendant's can be sued under California law because they accepted the EULA The Court has personal jurisdiction over Defendants because, on information and belief, they created more than one hundred Apple IDs to carry out their attacks and also agreed to Apple’s iCloud Terms and Conditions (“iCloud Terms”), including a mandatory and enforceable forum selection and exclusive jurisdiction clause that constitute…

> Judge: did you, NSO agree to the Terms and conditions by pressing "I Agree" > NSO representative: No, Your honor.

IANAL, but the general understanding is: "Ignorance is not a defence". If your legal advisors did not flag this up then I think you are probably entitled to ask for your money back when Apple kicks your butt.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#260

Anyone have a sense of the odds that the state secrets privilege gets invoked, and if so how damaging it's likely to be to Apple's case? Most examples involve a government entity being a party to the case, but the privilege did shut down a patent infringement suit between private entities not too long ago ( Crater v. Lucent ) [1]. [1] https://www.wired.com/2005/09/secrecy-power-sinks-patent-cas...

Very unlikely. If anyone is conscious of the United States' push for domestic surveillance, it's Apple. I imagine the reason this case took so long to draft is because it was a lateral effort involving lawyers, intelligence agencies and Apple's own corporate bigwigs. It's reflected in phrasing like "the abuse of state-sponsored spyware" rather than just "state-sponsored spyware" period. The only thing the government wants to do is arbitrate the case, because obviously they have an interest in maintaining their monopoly on surveillance.
Post reply on HN