Live data from Hacker News

The secret Uganda deal that has brought NSO to the brink of collapse

arstechnica.com

31–40 of 142 posts

Re: The secret Uganda deal that has brought NSO to the brink of collapse

#31
post #21
post #4

Which is odd because NSO made many assurances to the US govt they were in control of the tech and that US nationals were not to be included. Looks like they weren't in as much control as they stated they were.

US nationals have never been protected. If you make an international phone call the government can track it[1]. If its internal they can't without a warrant NSO built in a complete block of +1 phone numbers. But those US diplomats were not using +1. Which itself is a security issue that i'm sure is already being discussed at the state department [1] https://www.usatoday.com/story/news/2015/04/07/dea-bulk-tele...

Seems silly to call it a security issue when the bulk of the day to day activities for many state department employees is working closely with local nationals. Do you really want to make your average Ugandan caterer make an international call to the US in order to coordinate food delivery for an embassy event?

Re: The secret Uganda deal that has brought NSO to the brink of collapse

#32
post #21

Earlier quoted context omitted.

US nationals have never been protected. If you make an international phone call the government can track it[1]. If its internal they can't without a warrant NSO built in a complete block of +1 phone numbers. But those US diplomats were not using +1. Which itself is a security issue that i'm sure is already being discussed at the state department [1] https://www.usatoday.com/story/news/2015/04/07/dea-bulk-tele...

Seems silly to call it a security issue when the bulk of the day to day activities for many state department employees is working closely with local nationals. Do you really want to make your average Ugandan caterer make an international call to the US in order to coordinate food delivery for an embassy event?

And the fact that you're not likely to answer a call from an international number because it'll probably look more like spam.

Also, for them to have a +1 number outside the USA means they have to be on a USA network and then roaming onto a local network. This presents dozens of problems, such as often not being able to get the best connection, not being able to get data connections, not being able to get any local support, and it costing a small fortune.

All the embassy employees I have ever known have gone full native with all of their technology etc.

Re: The secret Uganda deal that has brought NSO to the brink of collapse

#33
post #21

Earlier quoted context omitted.

US nationals have never been protected. If you make an international phone call the government can track it[1]. If its internal they can't without a warrant NSO built in a complete block of +1 phone numbers. But those US diplomats were not using +1. Which itself is a security issue that i'm sure is already being discussed at the state department [1] https://www.usatoday.com/story/news/2015/04/07/dea-bulk-tele...

Seems silly to call it a security issue when the bulk of the day to day activities for many state department employees is working closely with local nationals. Do you really want to make your average Ugandan caterer make an international call to the US in order to coordinate food delivery for an embassy event?

Having a "caterer and friends" local dumbphone and an international phone for actual business doesn't seem unreasonable.

Re: The secret Uganda deal that has brought NSO to the brink of collapse

#34

I commented previously that the Uganda case was the first truly legitimate application of NSO's tech and the first one that wasn't actually a scandal, as it was by a state without a mature domestic intelligence capability going to market to buy tools of one, to spy on actual spies in its borders. It seems this particular NSO case is being used as bargaining leverage to discredit Israel's position in the Iran nuclear…

You're absolutely right, and I don't think anyone else has made that point. The problem was the spies they tried to fuck with were American spies and American wasn't going to stand for that. As you say, NSO are now just a toy, and if they are destroyed thanks to this, no-one is going to give a fuck.

Re: The secret Uganda deal that has brought NSO to the brink of collapse

#35
post #4

Which is odd because NSO made many assurances to the US govt they were in control of the tech and that US nationals were not to be included. Looks like they weren't in as much control as they stated they were.

I think NSO are scapegoats, because how hard is it for a country to setup up a honeypot device to analyse NSO'a attack vectors and then copy it for their own use whilst being able to blame it on NSO? I say this because I've had stuff done to my phones in the past, one strange incident with a "hacked" phone was selecting an AirBnB, which I believe directed me to a few of their "safe" houses. Other examples, include ba…

> but listening in to people sleeping can elucidate what might be on their mind!

Once you go conspiracy there’s no end to what seems possible…

Re: The secret Uganda deal that has brought NSO to the brink of collapse

#37

Earlier quoted context omitted.

Seems silly to call it a security issue when the bulk of the day to day activities for many state department employees is working closely with local nationals. Do you really want to make your average Ugandan caterer make an international call to the US in order to coordinate food delivery for an embassy event?

Having a "caterer and friends" local dumbphone and an international phone for actual business doesn't seem unreasonable.

Presumably, linked to what the sibling said, any actual business probably ought to go over high-security data connections anyways if it's going to go over any mobile network at all. No telling who's tapping into telecom systems in third-world countries, and normal phone calls probably go in the clear no matter what the registered phone number or roaming agreement is for the device.

Re: The secret Uganda deal that has brought NSO to the brink of collapse

#38

Earlier quoted context omitted.

I think NSO are scapegoats, because how hard is it for a country to setup up a honeypot device to analyse NSO'a attack vectors and then copy it for their own use whilst being able to blame it on NSO? I say this because I've had stuff done to my phones in the past, one strange incident with a "hacked" phone was selecting an AirBnB, which I believe directed me to a few of their "safe" houses. Other examples, include ba…

> but listening in to people sleeping can elucidate what might be on their mind! Once you go conspiracy there’s no end to what seems possible…

Its not conspiracy, if you consume a few grams of lecithin before bed, your dreams will be based on what you saw just before bed. So if you can use a phone to make sounds or says things to someone in their sleep at pertinent moments, you could start having a conversation with them in their sleep or just trigger them to see what they say! You should try it, its fascinating!

Re: The secret Uganda deal that has brought NSO to the brink of collapse

#39
>when Google reverse-engineered the hack used against American diplomats in Uganda, they found an elegant, tiny piece of code that adapted software from 1990s Xerox machines to fit a so-called Turing machine — essentially a complete computer — into a single GIF file.

LOL at describing PDFs as "adapted software from 1990s Xerox machines"

https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...

Re: The secret Uganda deal that has brought NSO to the brink of collapse

#40
post #39

>when Google reverse-engineered the hack used against American diplomats in Uganda, they found an elegant, tiny piece of code that adapted software from 1990s Xerox machines to fit a so-called Turing machine — essentially a complete computer — into a single GIF file. LOL at describing PDFs as "adapted software from 1990s Xerox machines" https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...

Having spent some time with OCR and scanning recently, I'd have to agree.

A lot of news articles are describing JBIG2 as something archaic, when it seems to be as relevant and commonplace as ever. (see MRC, for a modern application)

Post reply on HN