Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

691–700 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#691
post #577

Earlier quoted context omitted.

There is a nice PBS documentary about Pegasus's NSO https://www.pbs.org/wgbh/frontline/documentary/global-spywar... . It looks like NSO is backed up by the Israeli government. They say their software is only sold to governments which were previously vetted, but the reality is that most of the time they sell to authoritarian states which monitor and persecute people opposing the regime.

The way this works is that in addition to the more colorful clients, you absolutely need to make sure that you have a sufficient number of clients among law enforcement and security services in countries with a decent(-ish) track record regarding human rights. This way, your products and services are not obviously illegal. You can even tell your employees that your products and services are saving lives because it's…

Enabling lawful interceptions would only dry half the swamp, the other half being clandestine intelligence operations on foreign targets.

No way any reputable OS vendor would agree to enable, for example, Dutch intelligence services spying on Russian citizens living in the UK.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#692

Earlier quoted context omitted.

There's multiple responses echoing this idea that it's a defense company like any other and thus an evil we'll have to accept exists. That may be true, but these companies (NSO group is by no means worse than the rest of them, just more notorious) have been caught over and over again, selling these "weapons" to dictators, companies, etc, who in turn use them to spy on journalists and activists, not terrorists or anyt…

> have been caught over and over again, selling these "weapons" to dictators, companies, etc Meanwhile, a nice silent worm propagates among their network... I have 0-faith that the version they have sold to bad actors is clean when they probably are begging you to take their software into your internal network.

How convenient. It almost makes the dead journalists seem like a win!

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#693

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

It gives me the impression that you find "the tech community" to be a cohesive collective that has the organization to switch gears in a given direction. I wonder why you expect it to be like that. In reality, "the tech community" is extremely diverse and not cohesive at all. For one example, a large proportion of developers are barely making enough money to pay their most basic bills. They don't have enough mental s…

> In reality, "the tech community" is extremely diverse and not cohesive at all.

I really dislike this phrasing "the X community" which seems to be so popular nowadays. Lumping together many millions of people worldwide who have a single thing in common–how did people end up using the word "community" to describe that?

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#694
post #592

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

In the current environment of Internet-powered inane mob behavior, we should try to avoid pointing the mob at individuals.

I disagree entirely. I regularly name specific people from "git blame" in bug reports calling out unethical behavior.

Just because you got a paycheck for it doesn't suddenly make the behavior ethical.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#695

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

people will put experience on their resume building literal bombs etc. why would this be any different, it is really a non-issue in comparison

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#696

Earlier quoted context omitted.

It does if we grant the two the same assumptions. If we assume that serious, unjustified harm would occur by failing to act, and they are in a reasonable position to act… then I’d say a private company is equally justified in doing the same thing. However, you’re assuming the government is justified merely because it’s the government.

Do you think private companies should be allowed to, say, arrest people?

Depending on the circumstances, absolutely. Assuming that serious unjustified injury or death would occur if they failed to act, there should be some legal window in which they’re allowed to prevent the harm. Private companies (and individuals) should not be required to stand by helplessly while people are hurt.

Indeed, legally, private individuals and companies are allowed to act in emergencies. For example, I generally should not break into my neighbor’s home. However, I am legally allowed (and morally obligated) to forcibly enter their residence if their house is on fire, or they’re being attacked by a burglar, etc. and I am able to prevent some of the harm.

Of course, if we assume we’re talking about situations where the government needs a warrant, the legality becomes more complicated. At what point does something become an emergency? I would say it’s not an emergency if there is time to inform the government and to let the government prevent the injury. If we assume the government is unwilling or unable to act, then the window for action should expand by some measure.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#697

Earlier quoted context omitted.

Much of this stuff is classified as a weapon, and thus really sold by the Israeli government, not by the company. It's no different from a MANPADS that sometimes is used to destroy a Ka-52 over Ukraine, and sometimes is used to shoot down a civilian airliner - that is to say it's directed by the foreign policy (and foreign policy errors) of the manufacturing country. There's no reason to expect the world to disarm an…

There's multiple responses echoing this idea that it's a defense company like any other and thus an evil we'll have to accept exists. That may be true, but these companies (NSO group is by no means worse than the rest of them, just more notorious) have been caught over and over again, selling these "weapons" to dictators, companies, etc, who in turn use them to spy on journalists and activists, not terrorists or anyt…

Regulation at all is hard enough, expecting it to work by social norm is just impossible. Even more so in a country where all women do 22 months mandatory millitary training and all men do 36.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#698
post #678

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

Actual headline: mentions NSO group and nothing about Apple. Top comment (+50 comments): Why do we talk about Apple so much and so little about NSO group. The absurdly pro-Apple PR on HN is tough to bear. I have to say it's so overt it made me more hostile to Apple (NSO is obviously a worthy topic, but we do discuss it).

[deleted]

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#699
post #689

Earlier quoted context omitted.

Yeah, every single US soldier who voluntarily stepped on Iraqi soil should be sent to the ICC and tried for war crimes. Some of them would be exonerated for being too stupid/brainwashed to understand that they were committing criminal acts. Others wouldn't. However, those who develop the NSO spyware are middle class Israeli citizens who easily could get a well-paying job at a less repugnant company. There are no exte…

I don't know- I imagine deserting your brothers in arms (which may include your literal brother or sister) would be akin to deserting your family in a deadly situation. Regardless of how stupid the causes, once you're in the shit and people are at risk that you care about, the reasons you're there probably arent your biggest concern. The people that should be held accountable are the ones who orchestrated and perpetu…

I mean, to follow that analogy, yeah people absolutely should abandon their families if the families are out there actively murdering innocents.

The person saying that they're only staying to murder with their families because they care about them is not a redeeming quality, and they should definitely be held accountable and not excused for their crimes.

For the record, I consider any armed person outside their home country should be considered as a terrorist and a militia and treated as such. There is no reason someone from country A should be carrying a weapon in country B and attacking people there. This is 100 times even more valid when country B has not authorized this.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#700
post #527

Earlier quoted context omitted.

It takes a while. At Google at least, new systems in android are required to be built in rust and there are major efforts to rewrite significant systems. But it takes time and rewrites are dangerous in other ways. And you need all the tooling to handle everything else an engineer does beyond simply writing code. From where I sit, it also feels like the industry has really only coalesced around "the only real solution…

But it's already been a while...

How long do you think it is reasonable to go from "we are now in agreement that rewriting stuff is the right call" to "all media processing code is written in a memory safe language"?
Post reply on HN