Live data from Hacker News

Apple sues NSO Group to curb the abuse of state-sponsored spyware

apple.com

311–320 of 477 posts

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#311
post #262
post #249

Earlier quoted context omitted.

Sending the malware via iMessage, assuming the flaw was part of iMessage and not standard SMS.

But if they did that, Apple wouldn't need the EULA because then they could throw the CFAA at them.

... That's exactly what they did?

From the complaint:

>Count One

>Violations of Computer Fraud and Abuse Act

https://www.apple.com/newsroom/pdfs/Apple_v_NSO_Complaint_11...

The EULA is used to establish jurisdiction, and for the separate breach of contract claim. Apple has servers around the world, without the EULA the jurisdiction isn't necessarily obvious.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#312
post #290

Earlier quoted context omitted.

Ban them and their immediate family from everywhere: iCloud, Google, Instagram, Github, Cloudflare, Spotify, Steam, etc. Make them explain their kids that they can't play games on Xbox or listen to music on Spotify because their daddy is a terrorist.

Terrorist? Really? I think one can argue that they've likely saved many, many lives.

Whose?

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#313
post #233

Earlier quoted context omitted.

When did anyone mention code signing or developer accounts?

What did you suppose they needed a hundred Apple IDs for?

I have no idea why people are speculating about this. Unsurprisingly the publicly available complaint explains exactly what the Apple IDs were used for. https://www.apple.com/newsroom/pdfs/Apple_v_NSO_Complaint_11...

>50. On information and belief, Defendants created more than one hundred Apple IDs using Apple’s systems to be used in their deployment of FORCEDENTRY

>51. On information and belief, after obtaining Apple IDs, Defendants executed the FORCEDENTRY exploit first by using their computers to contact Apple servers in the United States and abroad to identify other Apple devices. Defendants contacted Apple servers using their Apple IDs to confirm that the target was using an Apple device. Defendants would then send abusive data created by Defendants through Apple servers in the United States and abroad for purposes of this attack. The abusive data was sent to the target phone through Apple’s iMessage service, disabling logging on a targeted Apple device so that Defendants could surreptitiously deliver the Pegasus payload via a larger file. That larger file would be temporarily stored in an encrypted form unreadable to Apple on one of Apple’s iCloud servers in the United States or abroad for delivery to the target.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#314
post #262

Earlier quoted context omitted.

But if they did that, Apple wouldn't need the EULA because then they could throw the CFAA at them.

I believe the CFAA is a criminal law, and charges would have to be brought by an AG. This is a civil case.

This is not correct, civil suits over CFAA violations are common.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#315
post #262

Earlier quoted context omitted.

But if they did that, Apple wouldn't need the EULA because then they could throw the CFAA at them.

Does the CFAA apply to an Isreali firm sending a text message from Isreal?

Yes, it can. You can find Apple's lawyers explanation in the complaint under the "JURISDICTION AND VENUE" heading https://www.apple.com/newsroom/pdfs/Apple_v_NSO_Complaint_11...

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#316
post #221

Earlier quoted context omitted.

>0) The defendant's can be sued under California law because they accepted the EULA The Court has personal jurisdiction over Defendants because, on information and belief, they created more than one hundred Apple IDs to carry out their attacks and also agreed to Apple’s iCloud Terms and Conditions (“iCloud Terms”), including a mandatory and enforceable forum selection and exclusive jurisdiction clause that constitute…

Nerds always want to interpret the law in some strict pedantic fashion, but in practice this is almost never how it works. Law is not applied stupidly or mechanically, you can't fashion yourself some ad hoc workaround unless you're extremely certain about what you're doing, preferably with a mountain of precedent behind you.

If the law not applied stupidly why the EULA is binding the client in the first place? We can't tell whether they clicked "I Agree" or it was just saved in the database as such. I think those EULA should be applicable to remove liability from Apple since they declare what they responsible for, but not to enforce rules on the clients which don't even read those EULAs and you can't prove they have "signed" it.

Regarding the lawsuit itself, it is just politics, they want to pretend as if they are on the good side of whatever the woke culture is right now and bashing Israel always gives some good points among the extreme progressives of silicon valley. NSO haven't done anything different to any other company dealing with hacking and spying and used by almost every government around the world. It is just that Apple is racist and coward so they will never sue the actual countries who use such tools or companies from "stronger" countries. Israeli company is a perfect scapegoat while they themselves will keep spying on their own users.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#317

>make products/services more secure >sue others to make them stop trying to hack your products/services Chooses the second one. I'm pretty sure this is just a PR stunt for Apple to try to appeal and brand themselves as "oh, we stand for security" and all the other bullshit.

Why do you think it's out of the question to do both? Their legal department aren't software engineers too at the same time.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#318
post #89

Earlier quoted context omitted.

They are just using the EULA as the basis for claiming jurisdiction. They are actually suing not to stop reverse engineering but rather to recover damages incurred by unlawful business practices. Basically their argument is that: 0) The defendant's can be sued under California law because they accepted the EULA. 1) California law makes businesses liable for damages incurred by their unlawful business practices. 2) Bu…

>0) The defendant's can be sued under California law because they accepted the EULA The Court has personal jurisdiction over Defendants because, on information and belief, they created more than one hundred Apple IDs to carry out their attacks and also agreed to Apple’s iCloud Terms and Conditions (“iCloud Terms”), including a mandatory and enforceable forum selection and exclusive jurisdiction clause that constitute…

Apple will have the IP addresses of every “I agree” click. Maybe some of them are traceable to NSO.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#319
post #146

If you think that israel is doing anything not sanctioned by the US government you are mistaken. In Israel NSO cant make a move without 7 agencies regulating it. This is considered a weapon sale. The same weapons the US are sponsoring israel and buy them from israeli industry. There is no way NSO will fail from this. So eula or whatever these are matters between states for national security interests.

Yes, the many US government 3 letter agencies would love to have full read access to every single iPhone in the world. It doesn't mean Apple needs to comply, or that doing so without a search warrant is legal in California

I think you are confusing the rights under US law of US citizens compared to everybody else in the world.

For example, as a New Zealand citizen, I don't expect to have many constitutional rights, nor do I expect I can easily enforce any residual rights I might have using the US justice system (especially against three letter agencies).

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#320

Earlier quoted context omitted.

Extradition has next to nothing to do with a civil EULA suit.

> Extradition has next to nothing to do with a civil EULA suit The following has been mentioned elsewhere in the thread. If NSO blows off the EULA suit, they'll be held in contempt of court. That tends to escalate into the type of thing for which one can be extradited.

They wont be held in contempt, the court will decide the case in their default. That's what happens when you don't appear for a civil lawsuit.
Post reply on HN