Live data from Hacker News

WhatsApp forces Pegasus spyware maker to share its secret code

arstechnica.com

121–130 of 170 posts

Re: WhatsApp forces Pegasus spyware maker to share its secret code

#121

Earlier quoted context omitted.

> You may unilaterally think that's wrong because you wish to impose a set of rules on language that others don't share, but that's not how meaning works. 'A set of rules' is called grammar. It may have arisen organically and out of 'shared consensus' but today languages only make sense when we maintain that grammar. Imagine if the positions of the words in the above sentence were randomly jumbled up. It'd make no se…

> Imagine if the positions of the words in the above sentence were randomly jumbled up. But "could care less" isn't random. It is an idiom that has the same meaning as "couldn't care less". If you fed it into a LLM it would know what you mean because meaning is created from global context. Meaning is not some kind of programming language where you input the rules of grammar and the definition of each constituent word…

> But "could care less" isn't random. It is an idiom that has the same meaning as "couldn't care less".

That is what I meant by 'English is lax enough about its grammar that "the point still gets through"'. 'Could care less' being wrong but semantically understood is exactly along the lines of 'could of' being wrong but semantically understood as 'could've', or the frequent confusion between 'their' and 'they're', or even any other confusion between homophones in written text.

Certainly, most Anglophones know enough English to read past these sorts of mistakes and still understand the underlying meaning (i.e. semantics) from context, but they are all incorrect, full stop.

Re: WhatsApp forces Pegasus spyware maker to share its secret code

#122
post #7
post #4

Earlier quoted context omitted.

I doubt US spy agencies still use it in any official capacity. Far easier to just request and obtain the resulting intelligence from partner intelligence organizations who are using it. Arms-length collection is less legally perilous. But which does bode poorly for any assertion of national security in US courts! "Are you using this software?" "Officially, no." "Then on what basis do you claim national security?"

I don't know much in this space, but if I'm the US Gov I'm happy that all of the attention is on Pegasus and not other (presumably) tens (hundreds) of similar programs out there.

[dead]

Re: WhatsApp forces Pegasus spyware maker to share its secret code

#123
post #47

Earlier quoted context omitted.

The US government has jurisdiction over all US dollars. That's how sanctions work.

Geez, no? Sanctions work only if the sanctioning entity has power. If the US govt sanctions you, they can tell all banks in the world that if they touch your (virtual) money they'll be sanctioned too. If some podunk dictatorship no one did business with announced "Any bank doing business with xxpor will be barred from working in our country!" then many banks will probably say "Fine, you're a tiny economy that we don'…

[dead]

Re: WhatsApp forces Pegasus spyware maker to share its secret code

#124

Earlier quoted context omitted.

I think Project Zero would count as offensive work in this regard; they are actively trying to find problems in other systems, rather than trying to stop other people trying to find problems in their systems.

Project Zero is an offensive team doing defensive work.

But their work is essentially penetration testing and exploit development. That usually counts as offensive side. They are not designing and building secure-by-design stuff, for example.

They are known for breaking stuff, and everyone wants to be the same.

Goal might be defensive in everything cyber security researchers do, but that was not my point.

Re: WhatsApp forces Pegasus spyware maker to share its secret code

#125

Earlier quoted context omitted.

Plenty of people working on the defensive side are famous, sometimes even more famous than those who do offensive work. Take, for example, Google Project Zero, or the numerous people on “infosec Twitter” who are almost invariably doing defensive work. People who do exploit development tend to be a lot more quiet about what they do and where they work.

Project Zero is not defensive. Infosec Twitter has both sides. I do agree with you that defense is a large part of the industry. My perspective is even that most organizations are looking for “defense” roles. The field is very wide (e.g., folks working on cryptography to sec ops).

It is defensive, but for the best guys out there, the carrot is on offensive side. You are not getting rewarded for doing perfectly secure systems, unless you work in very big company.

It means that most of the average guys build defense, and then the best guys test them and pick the money when something is found. While we could prevent most issues if those best guys help on building the systems instead.

But they have no motivation, because they get more money from other things.

Re: WhatsApp forces Pegasus spyware maker to share its secret code

#127
post #109

Earlier quoted context omitted.

Who exactly was punished by that EO? You are proving my point, even the most "push back" IAs have seen in terms of concrete actions against them led to... a directive that forbid them from murdering people in foreign countries. No actual consequences for anyone involved, no one got even a slap on the wrist in terms of actual consequences. And that's after the church committee, which revealed some super damning stuff.…

Are you really asking me to cite classified operations? And the fact that subsequent Executive Orders explicitly loosened the reigns on intelligence collection (and assassination with respect to "terrorists") indicates that yes, the original orders did restrict intelligence operations.

It sounds like you are claiming that IA’s have been punished for their abuses, but we’ll just have to trust you on it because the punishments were classified operations. Doesn’t make sense at all, unless you’re saying that the punishments were certain spy chiefs secretly murdered or something.

Re: WhatsApp forces Pegasus spyware maker to share its secret code

#128
post #3

> Initially, the NSO sought to block all discovery in the lawsuit, "due to various US and Israeli restrictions," but that blanket request was denied. Interesting approach. The court could probably care less about Israeli restrictions as it's a different country. Officially US govt blacklisted Pegasus https://arstechnica.com/tech-policy/2021/11/us-blacklists-ma... . However, I wouldn't be surprised if some US spy agen…

I would be very surprised if they were. Sanctions are no joke and there are plenty of Five Eye-aligned shops with similar capabilities.

Yep, here's TAG's (Threat Analysis Group) recent report on Commercial Surveillance Vendors (CSVs) making millions with SaaS-like business models: https://storage.googleapis.com/gweb-uniblog-publish-prod/doc...

Apparently, the social & political elites worldwide are tripping themselves over to purchase licenses from these CSVs that cost millions.

Re: WhatsApp forces Pegasus spyware maker to share its secret code

#129
post #4
post #3

> Initially, the NSO sought to block all discovery in the lawsuit, "due to various US and Israeli restrictions," but that blanket request was denied. Interesting approach. The court could probably care less about Israeli restrictions as it's a different country. Officially US govt blacklisted Pegasus https://arstechnica.com/tech-policy/2021/11/us-blacklists-ma... . However, I wouldn't be surprised if some US spy agen…

I doubt US spy agencies still use it in any official capacity. Far easier to just request and obtain the resulting intelligence from partner intelligence organizations who are using it. Arms-length collection is less legally perilous. But which does bode poorly for any assertion of national security in US courts! "Are you using this software?" "Officially, no." "Then on what basis do you claim national security?"

> Far easier to just request and obtain the resulting intelligence from partner intelligence organizations who are using it.

Couldnt they ask to spy on a phone owned by them to try to learn how the phones are infected?

Re: WhatsApp forces Pegasus spyware maker to share its secret code

#130

Earlier quoted context omitted.

> Imagine if the positions of the words in the above sentence were randomly jumbled up. But "could care less" isn't random. It is an idiom that has the same meaning as "couldn't care less". If you fed it into a LLM it would know what you mean because meaning is created from global context. Meaning is not some kind of programming language where you input the rules of grammar and the definition of each constituent word…

> But "could care less" isn't random. It is an idiom that has the same meaning as "couldn't care less". That is what I meant by 'English is lax enough about its grammar that "the point still gets through"'. 'Could care less' being wrong but semantically understood is exactly along the lines of 'could of' being wrong but semantically understood as 'could've', or the frequent confusion between 'their' and 'they're', or…

> but they are all incorrect, full stop.

I don't agree. Correctness is strictly determined by common usage. You're viewing language through the lens of a software engineer, where there are logical rules and primitives that combine together to construct outputs from inputs. Language isn't logically airtight like this. "Could care less" shouldn't be thought of as three words. Think of it as one single new word with its own meaning that has no necessary connection to the meaning of the constituent parts that make it up. Just like compound words and other idioms.

Post reply on HN