Earlier quoted context omitted.
Oh, but you see, NSO targets only "terrorists and criminals", so if you're a law-abiding citizen with nothing to hide, there's nothing to be concerned about. Right? It's not like there's any regimes out there where, say, casual investigative journalism or opposition politics would ever land you with criminal or terrorist charges, no sirree.
In Hungary, for example, which is an EU country and democracy (i.e. there are elections), investigative journalists have been targeted with Pegasus by the government.
NSO group iPhone zero-click, zero-day exploit captured in the wild
651–660 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#652Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…
> That right there tells me that we as "the tech community" are way too okay with this sort of application of the tech. The tech we're all so convinced will "make the world a better place." This calls for a larger discussion of individual choices of every one of us. It would not be an easy discussion, because things are far from simple, and yet every one of us should actively think, instead of falling into the whatab…
I don't know if I would have courage to stop working in Russian military IT tech if I were a sole provider for a family of three.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#653Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…
There is a nice PBS documentary about Pegasus's NSO https://www.pbs.org/wgbh/frontline/documentary/global-spywar... . It looks like NSO is backed up by the Israeli government. They say their software is only sold to governments which were previously vetted, but the reality is that most of the time they sell to authoritarian states which monitor and persecute people opposing the regime.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#654Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…
I wonder why you expect it to be like that.
In reality, "the tech community" is extremely diverse and not cohesive at all.
For one example, a large proportion of developers are barely making enough money to pay their most basic bills. They don't have enough mental space to even know what NSO is...
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#655Its super interesting to me how much its emphasized that you shouldn't use Lockdown Mode unless you are a journalist or otherwise in direct palpable danger. They really do try to talk you out of it. Its curious, because there's very little difference in functionality (as experienced by the user) other than disabling a lot of Apple nonsense from running in the background expanding your attack surface. And everybody pa…
I use Lockdown Mode on my Mac because I don’t use iMessage, FaceTime, or other apple services on that device. It’s literally just a computer for software dev and maybe YouTube videos. I haven’t noticed any difference with web content either, but I also use Firefox / Chrome instead of Safari. What I would really like to see is options. For example on iOS I use shared photo albums, so it would be nice to keep that feat…
Lockdown mode only affects Safari. If you use another browser, it doesn't make any difference.
Here are some features that are disabled in Safari when lockdown mode is enabled:
- JIT
- Remote fonts
- WebAssembly
- WebGL
- WebRTC
- PDF Viewer
- MP3 Playback
- Gamepad API
- Web Audio API
- Speech Recognition API
- MathML
- JPEG 2000
- MediaDevices.getUserMedia()
You can configure most of those in Firefox and Chrome, but it has to be done manually and cannot be disabled easily on a per-site basis like in Safari.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#656Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…
There is a nice PBS documentary about Pegasus's NSO https://www.pbs.org/wgbh/frontline/documentary/global-spywar... . It looks like NSO is backed up by the Israeli government. They say their software is only sold to governments which were previously vetted, but the reality is that most of the time they sell to authoritarian states which monitor and persecute people opposing the regime.
This strategy mostly works because the major operating system suppliers refuse to implement requested lawful intercept solutions for their consumer products. Instead, we end up with companies that try to fill the gaps, making a business of exploiting security flaws. It's possible for the OS vendors to completely dry this swamp, by offering competing services to law enforcement using the interfaces they already have (automated software updates, for example). The reputable clients would migrate rather quickly. These companies would be left with just the shady clients, making it much more difficult to justify their continued existence.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#657Earlier quoted context omitted.
There is a nice PBS documentary about Pegasus's NSO https://www.pbs.org/wgbh/frontline/documentary/global-spywar... . It looks like NSO is backed up by the Israeli government. They say their software is only sold to governments which were previously vetted, but the reality is that most of the time they sell to authoritarian states which monitor and persecute people opposing the regime.
To sell the software, they need approval from Israel’s govt, as the software is treated as a weapon
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#658Earlier quoted context omitted.
In Hungary, for example, which is an EU country and democracy (i.e. there are elections), investigative journalists have been targeted with Pegasus by the government.
Elections != democaracy. In Russia, there are also elections. So are they in Syria, and so on.
But for Hungary - I've been there multiple times in the last few years, know a few people, and I have no trouble believing he won democratic elections.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#659Earlier quoted context omitted.
It’s an attack vector because it’s convenient. If iMessage didn’t exist people would email you exploits.
Are there zero click exploits in email?
There probably still are and it’s possibly some three letter agencies or bad actors know about them.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#660Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…
It gives me the impression that you find "the tech community" to be a cohesive collective that has the organization to switch gears in a given direction. I wonder why you expect it to be like that. In reality, "the tech community" is extremely diverse and not cohesive at all. For one example, a large proportion of developers are barely making enough money to pay their most basic bills. They don't have enough mental s…