Earlier quoted context omitted.
So then, by this logic, once you've worked for NSO Group or the like, there's no way back for you. How then, can someone reform or "see the light"? Is someone once tainted, always tainted? Or do they have to do 10 years in the NFP space before we see them as worthy? The problem is that by walling off developers who participate in these activities, we essentially force them to continue these activities. I'm not sure t…
It’s not like we don’t accept that people change, but stigma is useful for both discouraging starting there or staying. If your first job out of college or the military is a defense contractor, oil company, Palantir, etc. a lot of people will sympathize with needing to make rent. If you’re still there a decade later, they’ll assume you’re okay with what they do.
NSO group iPhone zero-click, zero-day exploit captured in the wild
741–750 of 886 posts
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#742Earlier quoted context omitted.
>Clearly putting the NSO group on the Commerce Department blacklist didn't go far enough Somewhere in a nondescript subterranean hangar north of vegas an unacknowledged aerial platform is getting an itchy nose
Please don't suggest that people should be murdered with drone-launched missiles for making software. Making software is a peaceful act, regardless of what purpose that software serves.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#743Earlier quoted context omitted.
It’s not like we don’t accept that people change, but stigma is useful for both discouraging starting there or staying. If your first job out of college or the military is a defense contractor, oil company, Palantir, etc. a lot of people will sympathize with needing to make rent. If you’re still there a decade later, they’ll assume you’re okay with what they do.
Don't hate the player hate the game. At the end of the day it's the policy makers that choose to look the other way
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#744Earlier quoted context omitted.
Oh, but you see, NSO targets only "terrorists and criminals", so if you're a law-abiding citizen with nothing to hide, there's nothing to be concerned about. Right? It's not like there's any regimes out there where, say, casual investigative journalism or opposition politics would ever land you with criminal or terrorist charges, no sirree.
In Hungary, for example, which is an EU country and democracy (i.e. there are elections), investigative journalists have been targeted with Pegasus by the government.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#745I don't need to be able to accept iMessage messages from random numbers. I'd be happy to enable "Prevent messages from unknown numbers" for example. Is this possible?
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#746Earlier quoted context omitted.
There is a nice PBS documentary about Pegasus's NSO https://www.pbs.org/wgbh/frontline/documentary/global-spywar... . It looks like NSO is backed up by the Israeli government. They say their software is only sold to governments which were previously vetted, but the reality is that most of the time they sell to authoritarian states which monitor and persecute people opposing the regime.
The ties to government are a red herring. Hacking into people’s private phones and computer systems is generally immoral and illegal. It generally continues to be immoral and illegal when governments do it. Except it also becomes more outrageous, because governments are supposed to protect us from this sort of thing.
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#747Clearly putting the NSO group on the Commerce Department blacklist didn't go far enough. These scumbags belong in the Hague(metaphorically at least).
>Clearly putting the NSO group on the Commerce Department blacklist didn't go far enough Somewhere in a nondescript subterranean hangar north of vegas an unacknowledged aerial platform is getting an itchy nose
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#748Earlier quoted context omitted.
AFAIK Israeli government audits NSO and stuff, but they are separate... And Intellexa (authors of Predator I think?) doesn't even get audited because it's "not israeli" on paper
The important part is export control - i.e. deciding who can buy the stuff: https://en.wikipedia.org/wiki/NSO_Group
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#749Earlier quoted context omitted.
Because it turns off a lot of functionality people like: https://support.apple.com/en-us/HT212650 This is a classic challenge for security: every feature expands the attack surface, but users often pick what to buy based on those features.
Isn't there something like a 50% performance hit too, since it turns off a lot of optimizations?
Re: NSO group iPhone zero-click, zero-day exploit captured in the wild
#750Earlier quoted context omitted.
The OS vendors refuse to implement lawful intercept capability because there is no such thing as a lawful intercept capability. There is only intercept capability for any purpose because ROM bootloaders and secure enclaves cannot vet the lawfulness of a request to subvert their owners. You can make a phone relatively secure against people trying to break into it, but only if it has unique access keys for the owner. I…
>The Saudis have one very big lever they can use to force the west to do what it wants: gas prices. The United States gets most of its petroleum from Canada. Saudi Arabia accounts for only 7% of U.S. petroleum and crude oil imports. Source: https://www.eia.gov/energyexplained/oil-and-petroleum-produc...