Live data from Hacker News

Apple sues NSO Group to curb the abuse of state-sponsored spyware

apple.com

341–350 of 477 posts

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#341
post #164

Earlier quoted context omitted.

I don't know of any legitimate security research group that hacks user accounts they don't own. NSO hacked devices they didn't own and infected them with spyware. Apple had to pay to repair / replace those devices. I don't see how this sets any sort of precedent with security researchers are liable for the costs of fixing vulnerabilities that they uncover.

> I don't know of any legitimate security research group that hacks user accounts they don't own. nit: "user accounts to which they're not authorized" I work with friends' accounts all the time provided they authorized me to do so and provided I'm permitted to do so as part of the vuln disclosure program terms and rules of engagement, though I usually split the bounty with them in a meaningful way to make it worth th…

I know of several cases of reverse engineering of a bunch of hardware where the hardware is only available to a very limited subset of professionals. To gain access you either need to join that class and break the terms under which the devices are provided, get someone else to break the terms they agreed to or to steal a device (which for obvious reasons is at a somewhat different level than breach of terms and conditions). It is pretty clear that these restrictions exist to avoid reverse engineering of a - trivial - protection that makes making compatible products impossible, and which in turn protects a non-trivial revenue stream.

Apple is not really all that different. If they believe that suing to prevent reverse engineering is going to stop the bad guys they are delusional, I suspect that they are fully aware of this and are engaging in a very expensive bit of theater here: the NSO Group is not going to be overly impressed by this, whether they win or lose the case. If they lose they will be open to a damage claim, which in turn will have to be enforced through a court in a different country, if they win Apple will lose far more than just this case, they will lose the battle against everybody that wishes to engage in reverse engineering.

Another thing I suspect is that Apple is either very much concerned about the image/reputation damage, their supposedly highly secure platform/environment appears to be less secure than Apple wanted you to believe and a click-through EULA is not going to impress a law breaking entity, they probably should have anticipated that. And Apple may believe that other law breaking entities are going to stop doing their thing if they win this lawsuit, I'm a bit more pessimistic about that. Legal action is not a good way to recover from a technical failure, Apple needs to update their threat model and act accordingly.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#342

Earlier quoted context omitted.

Nit (maybe moot): > 4) Apple incurred damages […] from expenses related to mitigating the hacking of their users. This sounds like no one should be a security researcher for they risk paying companies to implement the security the company should have implemented anyway. Put another way, that also sounds like the corporate open source push, "We love open source because we don't have to support it, the community will!"…

>This sounds like no one should be a security researcher for they risk paying companies to implement the security the company should have implemented anyway. No, read again, this only refers to damages from unlawful activity. "White hat hackers" need not fear.

I wouldn't be so sure about that. The difference between white hat and black hat is usually only determined once the destination of the results of the activity is known. Plenty of bug bounty programs appear to be one element in the marketplace for valuing an exploit. If the bounty isn't high enough your 'white hat' may well change the color of their hat.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#343
post #7

It is great to see this happen. It's also fascinating that the crux of the Apple's case against NSO hinges on NSO engineers that accepted iCloud's terms and conditions. From related NYT article: > The sample of Pegasus gave Apple a forensic understanding of how Pegasus worked. The company found that NSO’s engineers had created more than 100 fake Apple IDs to carry out their attacks. In the process of creating those a…

Is it great? The lawsuit is Apple trying to enforce the iCloud EULA to stop reverse engineering. While NSO Group created hacking tools, and then did some questionable things with them, do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? Put another way, if it was someone HN liked , would we still say this is actually good? Because c…

I'm pretty sure you can reverse engineer most Apple things without ever signing their EULA. Maybe not those that require an iCloud account though.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#344

Earlier quoted context omitted.

> do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? for commercial interactions in particular between two businesses? Yes, absolutely. How else are two entities supposed to come to legally binding terms without a contract? I'm all for a little bit of lenience when an end user didn't read the terms but you think NSO group doesn't h…

(Not a lawyer, but this is the correct answer) As much as people might look at this and think Apple is being heavy-handed, it comes down to the fact that iCloud, iOS, and the App Store are their IP and they can (within legal limits) set whatever terms they please. Especially for these sorts of arrangements, it seems like a problem to me if the platform/IP owner doesn't have absolute, final discretion over what happen…

They can try. But that's not the same as succeeding, let's not get ahead of the lawsuit, which will likely take a long time to resolve.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#345

Earlier quoted context omitted.

They support oppressive regimes with their products and services, thereby suppressing public revolts and preempting civil wars that doubtlessly would claim the lives of many. Very noble of them. /S

The U.S supports the same regimes. The U.S made huge weapons deals with UAE, Saudi Arabia and more. Selling actual fighting jets that destroy thousands of people, not some cyber app.

Very noble of the US as well, no doubt. Mercenaries and weapon merchants have earned their reputations.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#346
post #265

Earlier quoted context omitted.

How does that seem pedantic? It's incredibly straightforward. On the other hand, creating some kind of convoluted, contrived paper trail to claim that mysterious third parties were the ones to have physically pressed the "Accept" button on your 100 fake accounts and so you didn't even know there was a EULA seems kind of like it might actually be fraud.

I don’t see how this differs much from a common “clean room” reverse engineering strategy where one set of engineers accepts the eula and then writes down in excruciating detail exactly how the target item works, then a second set of engineers that have never seen the item in question (or accepted a eula) takes these detailed writings and uses them to reverse engineer the item in question. (A mere description of a de…

In the clean room reverse engineering case:

1a. one team examines the device and products a detailed specification of it

1b. another team works solely off that newly produced specification; this team has zero contact with the actual device

In this hypothetical case:

2a. a third party affiliate accepts the Apple EULA, and gives the Apple IDs to NSO Group

2b. NSO Group uses the Apple IDs as credential to obtain Apple services

Notice that in case 2b, NSO Group has actual contact with Apple in two ways. They used Apple IDs, and that they obtain Apple services. This didn't happen in the reverse engineering case.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#347
post #346

Earlier quoted context omitted.

I don’t see how this differs much from a common “clean room” reverse engineering strategy where one set of engineers accepts the eula and then writes down in excruciating detail exactly how the target item works, then a second set of engineers that have never seen the item in question (or accepted a eula) takes these detailed writings and uses them to reverse engineer the item in question. (A mere description of a de…

In the clean room reverse engineering case: 1a. one team examines the device and products a detailed specification of it 1b. another team works solely off that newly produced specification; this team has zero contact with the actual device In this hypothetical case: 2a. a third party affiliate accepts the Apple EULA, and gives the Apple IDs to NSO Group 2b. NSO Group uses the Apple IDs as credential to obtain Apple s…

Good points - thank you!

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#348

Earlier quoted context omitted.

What did you suppose they needed a hundred Apple IDs for?

The article doesn’t say. I’m curious to find out myself.

A detailed forensic report was published by Amnesty on some of the methodologies NSO used.

https://www.amnesty.org/en/latest/research/2021/07/forensic-...

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#349

Earlier quoted context omitted.

This sits so unwell with me, gives such limitless tyrannical & dictatorial control to a company. > As much as people might look at this and think Apple is being heavy-handed, it comes down to the fact that iCloud, iOS, and the App Store are their IP and they can (within legal limits) set whatever terms they please. Agreed. That's exactly what it seems like. And that sounds like immoral, unjustifiable, sickening hell.…

>This sits so unwell with me, gives such limitless tyrannical & dictatorial control to a company. Do you think Apple could get some "hackers" extradited if they don't live in the US? Its that old adage, one mans terrorist is another mans freedom fighter and some country's like Russia will point blank refuse extradition to the US as will other countries. Any business can put what they like in their terms and condition…

Personally, generally I could not be more uninterested in the international legal politics behind this all. None of it is at all progressive, none of it speaks to what humanity can or could do. It's the most anodyne, boring, real world, un-possible way to take the discussion. It's mired in endless fun-house mirrors of shit-show politics that hasn't wont and can't figure out how to adapt. I can't think of a single nation that shows leadership, that has anything interesting or useful to say, any means of embracing humanity, of raising potential.

> Its that old adage, one mans terrorist is another mans freedom fighter and some country's like Russia will point blank refuse extradition to the US as will other countries.

This is a great mentality, and I'd love to see more dynamic behind it. Alas. I see no nations espousing & helping the actual obvious Open Source & other progressive & pro-human, pro-enlightenment, anti-proprietary freedom fighters. I see no one standing up for more personal computing liberties. The international regime is hostile & un-comprehending of tech & it's possibilities, more interested in businesses & big tech than it is in trying to help good tech happen, which is the real oppression, the real struggle, one enacted via pervasive & harsh IP laws & seemingly ever-expanding copyright length. Sure, some nations celebrate punk-ish behavior & sticking it to the west, but I can think of precious few examples of nations actually helping the good. The recent AskHN about software/tech monastaries[1], & the complete worldwide lack of any answers whatsoever indicates to me that there is no real help or interest in the actual freedom fighters, anywhere in the world.

If you want to look at the law, I think today's example, of Russia telling 13 big tech companies they have to establish offices in Russia[2], is a near perfect example of how tech and law intersect. This is particularly menacing & threatening & scary, but it mirrors most of the relationship worldwide: aggressive, at ends, seeking constraint & control & dominance, no interest in growth or humans or improving the human-computer relationship. The law rarely serves the people, rarely amplifies possibility. It's here to insist that some antiquated self-obsessed notion of justice can be served, even when that justice so often only serves a fading out of touch law, or big vested interests, not the people.

Generally I consider myself extremely progressive & hopeful for what governance & governments can do and should do. And I think if government wanted to deploy tech to help the people, if it would stop allowing endless private control to reign, great things would happen (Ron Wyden for president, 2028). But right now trying to frame questions & challenges in terms of the law is not-great. The law affords deep & vast powers to it's vested interests & the ideas of law itself. Yet in your particular scenario, it also simultaneously jealously & vengefully guards actual access to it's means power, to the reigns of state-sponsored violence & enforcement. The question posed, about whether Apple could get access to this executive use of force, isn't particularly relevant to me, and I don't think it reflects on the widescale systematic bureaucratic control companies like Apple & the prevailing worldwide laws get to impose via EULAs against the people of humanity.

Some of the comments on Facebook getting the OK from federal US Court of Appeals to also try to sue the NSO Group[3] are somewhat in line with your questions & scenarios. The comments there talk to the ability to try to pursue legal action, but the inability to actually get the state/states to do anything about it. In some ways, this is an ideal case. It shows that a state that wanted to support freedom fighters, that wanted to support emancipatory, liberated, pro-personal computing, might be able to. There's just not a lot of good guys out there trying to help spring us free from the walled gardens we're locked in.

My apologies for not trying to take up the question better. I think there's interesting material here. But to me, these questions return us to a not-compelling legalistic mindset, a practical view, that isn't capable of adequately considering how entrapped humanity at large is by the corporation's abilities to write it's own rules, by the de-personalization & de-accessing of computing that the cloudification of the world has brought upon us, & consigned us into. Whether or not this tyranny has the power to cross international boundaries & come get us isn't a particularly interesting subproblem to me. Generally I feel like the world has conformed to the prevailing notions of corporate techno-sovereignty.

[1] https://news.ycombinator.com/item?id=29309794 (12 comments)

[2] https://www.reuters.com/markets/europe/moscow-says-13-foreig... https://news.ycombinator.com/item?id=29320398 (7 comments)

[3] https://www.reuters.com/technology/facebook-can-pursue-malwa... https://news.ycombinator.com/item?id=29323095 (15 comments)

Post reply on HN