WhatsApp forces Pegasus spyware maker to share its secret code
101–110 of 170 posts
Re: WhatsApp forces Pegasus spyware maker to share its secret code
#102Earlier quoted context omitted.
> Most of the work is preventative. Current work culture is bizarre in cyber security. I am not personally very fan of it. Nobody wants to work on defensive side. You are not getting either fame or money if you do your work well. The expectation is that you do your work perfectly. There is no actually measurements in place to prove that your good code prevented 100 data breaches! But on the other hand, if you are on…
Plenty of people working on the defensive side are famous, sometimes even more famous than those who do offensive work. Take, for example, Google Project Zero, or the numerous people on “infosec Twitter” who are almost invariably doing defensive work. People who do exploit development tend to be a lot more quiet about what they do and where they work.
Re: WhatsApp forces Pegasus spyware maker to share its secret code
#103Earlier quoted context omitted.
It costs everyone time and effort to try to decode nonsensical input. It's a crime against humanity to not correct grammar.
Does it? I decode it instantly and understand the meaning just like I know what a "fishbowl" is. There is no "decoding" or even nonsensical input in this case. You are just being stubborn and trying to adhere to an outdated standard. Upgrade or get replaced.
Re: WhatsApp forces Pegasus spyware maker to share its secret code
#104Earlier quoted context omitted.
couldn't* care less
Much as it may pain you, “could care less” is an established idiom in American English that’s been in use for 70 years, and Webster’s dictionary has a whole page about it: https://www.merriam-webster.com/grammar/could-couldnt-care-l... , in which they say: > people who go through life expecting informal variant idioms in English to behave logically are setting themselves up for a lifetime of hurt.
> His bearing towards male acquaintances, of whom he knew little or nothing and could care less, ...
Here, "could care less" refers to how little he knows about the male acquaintances, and is effectively saying he cares even less than the little he knows. When we see people write "could care less', they don't write it in the same context, at all.
And then:
> It is impossible that he could care less.
This is clearly a different way to write "couldn't care less", and is again not how we see people use the phrase "could care less".
That being said, "could care less" is definitely a thing of the last 10-20 years and is not going anywhere.
Re: WhatsApp forces Pegasus spyware maker to share its secret code
#105Can anyone explain this case? Why would a US court have any jurisdiction over a foreign Israeli spyware vendor that has already been blacklisted by the US government? And why would Israel send their spyware source code to WhatsApp even if they lose the case?
Because the NSO group handles dollars. If they didn't respond, they'd lose by default, and the court could order any assets the US can get their hands on seized. If they're getting paid in NIS by countries outside of Israel, the currency conversion happens with dollars as the intermediary. There's the US's window.
Re: WhatsApp forces Pegasus spyware maker to share its secret code
#106Earlier quoted context omitted.
Because the NSO group handles dollars. If they didn't respond, they'd lose by default, and the court could order any assets the US can get their hands on seized. If they're getting paid in NIS by countries outside of Israel, the currency conversion happens with dollars as the intermediary. There's the US's window.
#BitcoinFixesThis
Re: WhatsApp forces Pegasus spyware maker to share its secret code
#107This is why I don't want to work in cyber security. You are dealing with dangerous people.
Meh. The same goes for police work and even more so for military. And cyber is a very wide range. A lot of roles are simply about training personnel in security principles and procedures, implementing data classification etc. Not everyone deals directly with attacks. Most of the work is preventative. In our company probably less than 20% of people who technically work in cyber, although that's in part because our SOC…
Re: WhatsApp forces Pegasus spyware maker to share its secret code
#108Earlier quoted context omitted.
If I bring a suitcase full of dollars home with me from a trip to the US (assuming I make it through border control with that much cash), I don't see what kind of jurisdiction the USA would have over me for simply owning dollars. These are just pieces of paper, they don't provide any kind of jurisdiction. The American banking system may refuse to serve me perhaps, but it's not the dollars that give the American gover…
> These are just pieces of paper I let you have one guess which entity gives those pieces of paper their value.
Re: WhatsApp forces Pegasus spyware maker to share its secret code
#109Earlier quoted context omitted.
FISA allows them to conduct it legally. It doesn't have anything to do with hiding. Before FISA, they generally just did it, without asking anyone. And press reports on intelligence operations led directly to the Church/Pike Committees, which led to EO 11905/12036.
Who exactly was punished by that EO? You are proving my point, even the most "push back" IAs have seen in terms of concrete actions against them led to... a directive that forbid them from murdering people in foreign countries. No actual consequences for anyone involved, no one got even a slap on the wrist in terms of actual consequences. And that's after the church committee, which revealed some super damning stuff.…
And the fact that subsequent Executive Orders explicitly loosened the reigns on intelligence collection (and assassination with respect to "terrorists") indicates that yes, the original orders did restrict intelligence operations.
Re: WhatsApp forces Pegasus spyware maker to share its secret code
#110Earlier quoted context omitted.
> Most of the work is preventative. Current work culture is bizarre in cyber security. I am not personally very fan of it. Nobody wants to work on defensive side. You are not getting either fame or money if you do your work well. The expectation is that you do your work perfectly. There is no actually measurements in place to prove that your good code prevented 100 data breaches! But on the other hand, if you are on…
Plenty of people working on the defensive side are famous, sometimes even more famous than those who do offensive work. Take, for example, Google Project Zero, or the numerous people on “infosec Twitter” who are almost invariably doing defensive work. People who do exploit development tend to be a lot more quiet about what they do and where they work.
I do agree with you that defense is a large part of the industry. My perspective is even that most organizations are looking for “defense” roles. The field is very wide (e.g., folks working on cryptography to sec ops).