Live data from Hacker News

Apple sues NSO Group to curb the abuse of state-sponsored spyware

apple.com

261–270 of 477 posts

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#261

Earlier quoted context omitted.

> and they are certainly allowed to violate T+Cs even when a violation of a T+C is a criminal act (which it is in many jurisdictions). Is violating a T&C criminal in the US, if the violating action itself is not a crime? I have not heard of this. Are there any examples that can be linked to? I thought it was always a civil matter.

https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act Yes it is a federal crime, but was recently limited by https://en.wikipedia.org/wiki/Van_Buren_v._United_States

This is correct, although most US States have their own version of CFAA which aren't so limited and don't include any exceptions or exemptions, either.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#262
post #249

Earlier quoted context omitted.

What did you suppose they needed a hundred Apple IDs for?

Sending the malware via iMessage, assuming the flaw was part of iMessage and not standard SMS.

But if they did that, Apple wouldn't need the EULA because then they could throw the CFAA at them.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#263

*Apple VP of SW Engineering: "Apple devices are the most secure consumer hardware on the market"* ... except for how Apple sends a copy of all of your data that passes through their servers to the NSA. No, I'm not espousing a conspiracy theory, this has been brought to light by Edward Snowden's revelations. Now, we don't know how much of the data on Apple phones gets sent to Apple's servers, so it's not literally eve…

Friendly heads-up: if you try to say anything negative about Apple here on Hacker News, people will tend to downvote you out of cognitive dissonance alone. It doesn't matter if what you're saying is the truth, the people here just really like to roleplay as security experts and pretend like Apple is somehow different from the other PRISM-compliant corporations.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#264
post #107

Earlier quoted context omitted.

It's as if you don't get the point about legal standing. Apple can only take action now because of a court deciding that Facebook's TOS forum clause is actually binding. If they filed the case prior to such a holding, it'd have been dismissed.

What if Facebook never filed? Would Apple never be able to act on this? If they would have acted, why didn't they do it before Facebook?

Yeah what if? What if I have lived in wonderland?

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#265
post #237
post #221

Earlier quoted context omitted.

Nerds always want to interpret the law in some strict pedantic fashion, but in practice this is almost never how it works. Law is not applied stupidly or mechanically, you can't fashion yourself some ad hoc workaround unless you're extremely certain about what you're doing, preferably with a mountain of precedent behind you.

"NSO can be sued under California law because they accepted the EULA" seems like a mechanical, strict, pedantic application of law though.

How does that seem pedantic? It's incredibly straightforward.

On the other hand, creating some kind of convoluted, contrived paper trail to claim that mysterious third parties were the ones to have physically pressed the "Accept" button on your 100 fake accounts and so you didn't even know there was a EULA seems kind of like it might actually be fraud.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#266
post #32

The framing of NSO as "state-sponsored" cannot be overstated, and Apple didn't miss the chance to do just that. A hard blow to Israel's policy just as much as it is to NSO itself.

The framing is "abuse" of state-sponsored spyware, not necessarily spyware in-and-of itself. As seen with PRISM, Apple has no problem putting state-sponsored spyware on millions of phones, so long as they (or the US government) doesn't consider it "abuse".

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#267
post #221

Earlier quoted context omitted.

>0) The defendant's can be sued under California law because they accepted the EULA The Court has personal jurisdiction over Defendants because, on information and belief, they created more than one hundred Apple IDs to carry out their attacks and also agreed to Apple’s iCloud Terms and Conditions (“iCloud Terms”), including a mandatory and enforceable forum selection and exclusive jurisdiction clause that constitute…

Nerds always want to interpret the law in some strict pedantic fashion, but in practice this is almost never how it works. Law is not applied stupidly or mechanically, you can't fashion yourself some ad hoc workaround unless you're extremely certain about what you're doing, preferably with a mountain of precedent behind you.

[deleted]

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#268

Earlier quoted context omitted.

I was the victim of a state-sponsored attack. I took it to court. I tried to subpoena the contents of the government agents' iPhones but Apple came and filed a Joinder in Motion and sent expensive lawyers to lie to the judge about the judge's power to subpoena digital evidence. The lawyer specifically told me all he does is go around the country and lie to judges to get them to cancel subpoenas. We introduced the T+C…

> and they are certainly allowed to violate T+Cs even when a violation of a T+C is a criminal act (which it is in many jurisdictions). Is violating a T&C criminal in the US, if the violating action itself is not a crime? I have not heard of this. Are there any examples that can be linked to? I thought it was always a civil matter.

Yes, for instance in Illinois there is a specific crime for violating terms of service:

720 ILCS 5/17-51(a-10)(1) Computer tampering

https://www.ilga.gov/legislation/ilcs/fulltext.asp?DocName=0...

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#269

Earlier quoted context omitted.

This sits so unwell with me, gives such limitless tyrannical & dictatorial control to a company. > As much as people might look at this and think Apple is being heavy-handed, it comes down to the fact that iCloud, iOS, and the App Store are their IP and they can (within legal limits) set whatever terms they please. Agreed. That's exactly what it seems like. And that sounds like immoral, unjustifiable, sickening hell.…

> Agreed. That's exactly what it seems like. And that sounds like immoral, unjustifiable, sickening hell. That Apple gets to hold all the cards, no one else on the planet gets any say in how a device might be used. I'm not a big proponent of IP, but you're basically saying it is immoral, unjustifiable, and sickening as hell that Apple enforces the rules that Apple wants on Apple products/services, which were created…

> Who should be making the rules if not the creator and maintainer of the product/service?

Many things should be up to them, but many things should be up to the buyer.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#270
post #262
post #249

Earlier quoted context omitted.

Sending the malware via iMessage, assuming the flaw was part of iMessage and not standard SMS.

But if they did that, Apple wouldn't need the EULA because then they could throw the CFAA at them.

Could be used for attempting to find metadata on users then, etc. there’s a few things I could guess.
Post reply on HN