Which is odd because NSO made many assurances to the US govt they were in control of the tech and that US nationals were not to be included. Looks like they weren't in as much control as they stated they were.
US nationals have never been protected. If you make an international phone call the government can track it[1]. If its internal they can't without a warrant NSO built in a complete block of +1 phone numbers. But those US diplomats were not using +1. Which itself is a security issue that i'm sure is already being discussed at the state department [1] https://www.usatoday.com/story/news/2015/04/07/dea-bulk-tele...
The secret Uganda deal that has brought NSO to the brink of collapse
31–40 of 142 posts
Re: The secret Uganda deal that has brought NSO to the brink of collapse
#32Earlier quoted context omitted.
US nationals have never been protected. If you make an international phone call the government can track it[1]. If its internal they can't without a warrant NSO built in a complete block of +1 phone numbers. But those US diplomats were not using +1. Which itself is a security issue that i'm sure is already being discussed at the state department [1] https://www.usatoday.com/story/news/2015/04/07/dea-bulk-tele...
Seems silly to call it a security issue when the bulk of the day to day activities for many state department employees is working closely with local nationals. Do you really want to make your average Ugandan caterer make an international call to the US in order to coordinate food delivery for an embassy event?
Also, for them to have a +1 number outside the USA means they have to be on a USA network and then roaming onto a local network. This presents dozens of problems, such as often not being able to get the best connection, not being able to get data connections, not being able to get any local support, and it costing a small fortune.
All the embassy employees I have ever known have gone full native with all of their technology etc.
Re: The secret Uganda deal that has brought NSO to the brink of collapse
#33Earlier quoted context omitted.
US nationals have never been protected. If you make an international phone call the government can track it[1]. If its internal they can't without a warrant NSO built in a complete block of +1 phone numbers. But those US diplomats were not using +1. Which itself is a security issue that i'm sure is already being discussed at the state department [1] https://www.usatoday.com/story/news/2015/04/07/dea-bulk-tele...
Seems silly to call it a security issue when the bulk of the day to day activities for many state department employees is working closely with local nationals. Do you really want to make your average Ugandan caterer make an international call to the US in order to coordinate food delivery for an embassy event?
Re: The secret Uganda deal that has brought NSO to the brink of collapse
#34I commented previously that the Uganda case was the first truly legitimate application of NSO's tech and the first one that wasn't actually a scandal, as it was by a state without a mature domestic intelligence capability going to market to buy tools of one, to spy on actual spies in its borders. It seems this particular NSO case is being used as bargaining leverage to discredit Israel's position in the Iran nuclear…
Re: The secret Uganda deal that has brought NSO to the brink of collapse
#35Which is odd because NSO made many assurances to the US govt they were in control of the tech and that US nationals were not to be included. Looks like they weren't in as much control as they stated they were.
I think NSO are scapegoats, because how hard is it for a country to setup up a honeypot device to analyse NSO'a attack vectors and then copy it for their own use whilst being able to blame it on NSO? I say this because I've had stuff done to my phones in the past, one strange incident with a "hacked" phone was selecting an AirBnB, which I believe directed me to a few of their "safe" houses. Other examples, include ba…
Once you go conspiracy there’s no end to what seems possible…
Re: The secret Uganda deal that has brought NSO to the brink of collapse
#36Were the US officials that Uganda was spying on diplomats, or "diplomats"?
Re: The secret Uganda deal that has brought NSO to the brink of collapse
#37Earlier quoted context omitted.
Seems silly to call it a security issue when the bulk of the day to day activities for many state department employees is working closely with local nationals. Do you really want to make your average Ugandan caterer make an international call to the US in order to coordinate food delivery for an embassy event?
Having a "caterer and friends" local dumbphone and an international phone for actual business doesn't seem unreasonable.
Re: The secret Uganda deal that has brought NSO to the brink of collapse
#38Earlier quoted context omitted.
I think NSO are scapegoats, because how hard is it for a country to setup up a honeypot device to analyse NSO'a attack vectors and then copy it for their own use whilst being able to blame it on NSO? I say this because I've had stuff done to my phones in the past, one strange incident with a "hacked" phone was selecting an AirBnB, which I believe directed me to a few of their "safe" houses. Other examples, include ba…
> but listening in to people sleeping can elucidate what might be on their mind! Once you go conspiracy there’s no end to what seems possible…
Re: The secret Uganda deal that has brought NSO to the brink of collapse
#39LOL at describing PDFs as "adapted software from 1990s Xerox machines"
https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
Re: The secret Uganda deal that has brought NSO to the brink of collapse
#40>when Google reverse-engineered the hack used against American diplomats in Uganda, they found an elegant, tiny piece of code that adapted software from 1990s Xerox machines to fit a so-called Turing machine — essentially a complete computer — into a single GIF file. LOL at describing PDFs as "adapted software from 1990s Xerox machines" https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
A lot of news articles are describing JBIG2 as something archaic, when it seems to be as relevant and commonplace as ever. (see MRC, for a modern application)