Live data from Hacker News

NSO group iPhone zero-click, zero-day exploit captured in the wild

citizenlab.ca

721–730 of 886 posts

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#721

Earlier quoted context omitted.

There's multiple responses echoing this idea that it's a defense company like any other and thus an evil we'll have to accept exists. That may be true, but these companies (NSO group is by no means worse than the rest of them, just more notorious) have been caught over and over again, selling these "weapons" to dictators, companies, etc, who in turn use them to spy on journalists and activists, not terrorists or anyt…

So then, by this logic, once you've worked for NSO Group or the like, there's no way back for you. How then, can someone reform or "see the light"? Is someone once tainted, always tainted? Or do they have to do 10 years in the NFP space before we see them as worthy? The problem is that by walling off developers who participate in these activities, we essentially force them to continue these activities. I'm not sure t…

It’s not like we don’t accept that people change, but stigma is useful for both discouraging starting there or staying. If your first job out of college or the military is a defense contractor, oil company, Palantir, etc. a lot of people will sympathize with needing to make rent. If you’re still there a decade later, they’ll assume you’re okay with what they do.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#722

Earlier quoted context omitted.

Darknet Diaries had an episode about them a while back. It’s a good listen (as that podcast always is). https://darknetdiaries.com/episode/100/

I just got finished listening to the most recent episode of Darknet Diaries this morning on the way into the office! It was about similar companies to the NSO group: https://darknetdiaries.com/episode/137/

I listened to the first half this morning. Was thinking about going back and watching the NSO group episode he mentioned again. Then I get to work, and the first thing I see is this link.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#723
post #46

Clearly putting the NSO group on the Commerce Department blacklist didn't go far enough. These scumbags belong in the Hague(metaphorically at least).

>Clearly putting the NSO group on the Commerce Department blacklist didn't go far enough Somewhere in a nondescript subterranean hangar north of vegas an unacknowledged aerial platform is getting an itchy nose

Please don't suggest that people should be murdered with drone-launched missiles for making software. Making software is a peaceful act, regardless of what purpose that software serves.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#725

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

It gives me the impression that you find "the tech community" to be a cohesive collective that has the organization to switch gears in a given direction. I wonder why you expect it to be like that. In reality, "the tech community" is extremely diverse and not cohesive at all. For one example, a large proportion of developers are barely making enough money to pay their most basic bills. They don't have enough mental s…

I’m in the Tech Community. I’m fine with the NSO group. (Which, btw, is owned by U.K. Novalpina Capital, and managed by a firm out of Luxembourg. But for some reason you all here aren’t obsessed with those countries.)

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#726
post #681

Earlier quoted context omitted.

Maybe it depends on the country, but private companies cant generally get warrants to infringe on people's rights afaik. If justified is interpreted as 'legally justified', then it would make sense that only government agents could be justified to act in this manner. Of course, government agents are known to operate outside the law as well.

I wouldn’t assume that private companies and individuals cannot get warrants. However, they look very different. The major distinction is that when a private party requests an injunction allowing them to e.g. trespass on their neighbor’s land, the court will require notice and a hearing for the defendant. So, if a chemical plant needs to do earth works on a neighbor’s land to prevent a collapse, etc. the judiciary ma…

yea, the justice system is quite the misnomer way too often

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#727
post #577

Earlier quoted context omitted.

There is a nice PBS documentary about Pegasus's NSO https://www.pbs.org/wgbh/frontline/documentary/global-spywar... . It looks like NSO is backed up by the Israeli government. They say their software is only sold to governments which were previously vetted, but the reality is that most of the time they sell to authoritarian states which monitor and persecute people opposing the regime.

The way this works is that in addition to the more colorful clients, you absolutely need to make sure that you have a sufficient number of clients among law enforcement and security services in countries with a decent(-ish) track record regarding human rights. This way, your products and services are not obviously illegal. You can even tell your employees that your products and services are saving lives because it's…

I propose that government can sell CIAndroid phones with competitive advantages like low price or "reduce taxes by 10%" app.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#728

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

I dont think its the "tech community" being okay with this application of the tech as much as it is fear of standing up to Israelis in any way. Imagine you own a infosec company and an applicant with excellent skills applies. You look at the CV in detail before the interview and you see that they proudly declare their NSO background. Tell me what will you do? Cancel the interview? How comfortable would you be to deny…

Nah. Joining NSO or such displays a moral "flexibility" and/or a lack of judgement that pretty much precludes the individual from taking on significant responsibility.

Imagine having a business handling privacy relevant data and when someone asks about your stance on data security you have to admit you hired people who are okay with keeping the whole planet insecure for their own benefit.

I know, I know, in my more cynical moments I see it your way as well. But that doesn't make it right.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#729

Earlier quoted context omitted.

All that's different now is that the script kiddies have grown up.

I really don't think that's true - the state of appsec and security awareness in general has really improved a lot, and all of the major platforms (windows included) are much much more secure now by default than in the activeX era. It's definitely not the case that anyone can just throw together an iPhone zeroday, which is why the price of these exploits is so much higher.

Not today, anyway. Otherwise we'd still have jailbreaks, which were zero-day exploits used knowingly and non-maliciously.

Apple hired at least a few of the best jailbreakers.

Re: NSO group iPhone zero-click, zero-day exploit captured in the wild

#730
post #678

Wow, so much discussion of Apple and their software, and so little of NSO group and why they're even a thing. I just want to add this: these people operate pretty much in the open. They're not ashamed of it either, or else they wouldn't put it on their CV: https://www.linkedin.com/company/nso-group/people/ That right there tells me that we as "the tech community" are way too okay with this sort of application of the…

Actual headline: mentions NSO group and nothing about Apple. Top comment (+50 comments): Why do we talk about Apple so much and so little about NSO group. The absurdly pro-Apple PR on HN is tough to bear. I have to say it's so overt it made me more hostile to Apple (NSO is obviously a worthy topic, but we do discuss it).

To be fair, when I made my post I had to go through 3 pages of threads to verify there was indeed, at that moment, very little discussion about NSO, and mostly discussion about remedies and how bad apple is handling imessage. But I'm glad that enough other people seem to care. :)
Post reply on HN