Live data from Hacker News

WhatsApp forces Pegasus spyware maker to share its secret code

arstechnica.com

51–60 of 170 posts

Re: WhatsApp forces Pegasus spyware maker to share its secret code

#51
post #43
post #36

Earlier quoted context omitted.

Because the NSO group handles dollars. If they didn't respond, they'd lose by default, and the court could order any assets the US can get their hands on seized. If they're getting paid in NIS by countries outside of Israel, the currency conversion happens with dollars as the intermediary. There's the US's window.

How is "Because the NSO group handles dollars" related to "the court could order any assets the US can get their hands on seized"? Presumably, if they were getting paid in bars of gold, the US could seize those too, if they could get their hands on them, no? On the other hand, if they were paid in US dollars, but in cash, that wouldn't establish jurisdiction, nor could it be seized, if the transfer happened outside U…

If you do business in the US you're subject to jurisdiction. If you're a foreign bank, to transact with anyone in the US you have to do business in the US. The court orders the bank to fork over somebody's cash, they do because they have to and the alternative is disconnecting themselves from the rest of the financial system. Several Swiss banks got the death penalty because they failed to be quite as isolated and secretive as advertised (i.e. they had agents in the US doing business)

To seize somebody's gold you'd have to go physically get it. To seize their dollars you just go say hi to their bank. Unless you're an "enemy combatant" the US isn't going to go do extraordinary rendition on your assets, so you're pile of foreign gold is safe.

The reach of the American legal system is long, you don't have to do much as a foreign entity to put you under our umbrella.

Re: WhatsApp forces Pegasus spyware maker to share its secret code

#52
post #47

Earlier quoted context omitted.

The US government has jurisdiction over all US dollars. That's how sanctions work.

If I bring a suitcase full of dollars home with me from a trip to the US (assuming I make it through border control with that much cash), I don't see what kind of jurisdiction the USA would have over me for simply owning dollars. These are just pieces of paper, they don't provide any kind of jurisdiction. The American banking system may refuse to serve me perhaps, but it's not the dollars that give the American gover…

Your local bank won't protect you from the American judicial system. If they get a court order they'll just fork over your assets. Your bank wants to maintain it's ability to exchange funds with American banks. The American banking system will refuse to serve your bank if they refuse to comply. Or more like they'll just order JP Morgan or whomever to fork over your bank's cash because that's how banks interact with each other.

If you got a pile of dollars in the US, you did business in the US and if that business has any tenuous connection to what the courts are after you about, we have jurisdiction.

If you don't like it you have to run to China, Russia, Iran, etc.

Re: WhatsApp forces Pegasus spyware maker to share its secret code

#53
post #41

Earlier quoted context omitted.

Meh. The same goes for police work and even more so for military. And cyber is a very wide range. A lot of roles are simply about training personnel in security principles and procedures, implementing data classification etc. Not everyone deals directly with attacks. Most of the work is preventative. In our company probably less than 20% of people who technically work in cyber, although that's in part because our SOC…

> Most of the work is preventative. Current work culture is bizarre in cyber security. I am not personally very fan of it. Nobody wants to work on defensive side. You are not getting either fame or money if you do your work well. The expectation is that you do your work perfectly. There is no actually measurements in place to prove that your good code prevented 100 data breaches! But on the other hand, if you are on…

Your view on cyber security seems to be painted by bug bounty programs. But I agree that the offensive side is more sexy than the defensive side, but it easy to forget that in the end, we are all really working on defense

Re: WhatsApp forces Pegasus spyware maker to share its secret code

#54
post #43
post #36

Earlier quoted context omitted.

Because the NSO group handles dollars. If they didn't respond, they'd lose by default, and the court could order any assets the US can get their hands on seized. If they're getting paid in NIS by countries outside of Israel, the currency conversion happens with dollars as the intermediary. There's the US's window.

How is "Because the NSO group handles dollars" related to "the court could order any assets the US can get their hands on seized"? Presumably, if they were getting paid in bars of gold, the US could seize those too, if they could get their hands on them, no? On the other hand, if they were paid in US dollars, but in cash, that wouldn't establish jurisdiction, nor could it be seized, if the transfer happened outside U…

How would they get paid? Almost every bank in every us-allied countries would have to comply to hand over the money. The US banking regulations apply overseas because those banks want to interact with US entities. That's the nature of the US-Dollar economy.

Are you a French wine maker that wants to sell to America? You better be using USD with a friendly bank to pay for things like import fees/tariffs (or the American company you work with better do that). Sure you can deal only in Euros if you want, but at some point there's a conversion to USD when you sell to Americans. Middle Eastern Oil Company? Same thing. German Car company? Same. Brazilian fruit farm? Same. How about importing your Coca Cola products, and iPhones? Buying ads from Google? USD and a US-friendly banks are everywhere in the global economy because the US is such a big market.

Those banks will be banned from US commerce if they work with the NSO and don't hand over the NSO's money, and will lose tons of "innocent" business (like those nice wine makers in France). Their governments probably have treaties with the US, so they don't have a legal choice anyways. The US influence is viral.

Re: WhatsApp forces Pegasus spyware maker to share its secret code

#55

Earlier quoted context omitted.

Much as it may pain you, “could care less” is an established idiom in American English that’s been in use for 70 years, and Webster’s dictionary has a whole page about it: https://www.merriam-webster.com/grammar/could-couldnt-care-l... , in which they say: > people who go through life expecting informal variant idioms in English to behave logically are setting themselves up for a lifetime of hurt.

I couldn't care less if there's a group of people misusing the phrase, logically "I could care less" means the exact opposite of "I couldn't care less". The majority of the world is not American, and presumably the majority of Americans don't use the incorrect phrase, so why should the rest of the world cater for a minority within a minority by putting their butchered phrase on equal footing with the correct phrase?

If I make a mistake like this, please correct me. That's one way I can improve. This attitude of just not correcting people is idiotic.

It's on the person receiving the correction or criticism to ignore it if they wish. Not on people to be silent.

Re: WhatsApp forces Pegasus spyware maker to share its secret code

#56

Can anyone explain this case? Why would a US court have any jurisdiction over a foreign Israeli spyware vendor that has already been blacklisted by the US government? And why would Israel send their spyware source code to WhatsApp even if they lose the case?

Because they are being sued in the US over conduct that happened in the US? It’s really not very difficult or special.

They can of course choose to ignore the lawsuit, if their principals want to never enter the US again, which is frankly recommended for all their employees given their operations are prima facie criminal in nature.

Re: WhatsApp forces Pegasus spyware maker to share its secret code

#57
post #3

> Initially, the NSO sought to block all discovery in the lawsuit, "due to various US and Israeli restrictions," but that blanket request was denied. Interesting approach. The court could probably care less about Israeli restrictions as it's a different country. Officially US govt blacklisted Pegasus https://arstechnica.com/tech-policy/2021/11/us-blacklists-ma... . However, I wouldn't be surprised if some US spy agen…

I would be very surprised if they were. Sanctions are no joke and there are plenty of Five Eye-aligned shops with similar capabilities.

Re: WhatsApp forces Pegasus spyware maker to share its secret code

#59
post #5

Is this a new precedent, that "legal" hackers that operate in two countries can be forced to divulge their vulns?

I hope so, the fact that attackers can hide behind international borders is an eternal thorn in the side of us blue teamers. Anyone who commits a crime in another country should be subject to that country seeking legal redress.

That is typically the case. If you commit a crime and flee to a different country, where you go will arrest you and turn you over to the country that you did the crime in.

there are many treaties on this. It gets complex, some countries will not turn criminals over if the death pentalty is would be used for example. However in general if you commit a crime you can't flee to a different country.

countries like north Korea and Russia are exceptions. Which is why malware so often comes from them. Anyone else and you are likely to be caught.

Re: WhatsApp forces Pegasus spyware maker to share its secret code

#60
post #41

Earlier quoted context omitted.

Meh. The same goes for police work and even more so for military. And cyber is a very wide range. A lot of roles are simply about training personnel in security principles and procedures, implementing data classification etc. Not everyone deals directly with attacks. Most of the work is preventative. In our company probably less than 20% of people who technically work in cyber, although that's in part because our SOC…

> Most of the work is preventative. Current work culture is bizarre in cyber security. I am not personally very fan of it. Nobody wants to work on defensive side. You are not getting either fame or money if you do your work well. The expectation is that you do your work perfectly. There is no actually measurements in place to prove that your good code prevented 100 data breaches! But on the other hand, if you are on…

Plenty of people working on the defensive side are famous, sometimes even more famous than those who do offensive work. Take, for example, Google Project Zero, or the numerous people on “infosec Twitter” who are almost invariably doing defensive work. People who do exploit development tend to be a lot more quiet about what they do and where they work.
Post reply on HN