Live data from Hacker News

Amazon Shuts Down NSO Group Infrastructure

vice.com

141–150 of 260 posts

Re: Amazon Shuts Down NSO Group Infrastructure

#141

Everybody is coming down on NSO but why aren’t we asking more about the clients? Who is spying on “CEOs, politicians, religious leaders, union bosses”? And once these people are compromised, what are they being asked to do?

NSO (and its infrastructure) are the vulnerable single point of control. That's in fact part of the service they're offering, whether they realise it or not: outsourcing blame, exposure, culpability, and liability. Something like how a re-entering spacecraft is fitted with a sacraficial ablative heat shield. The shield's job is to absorb punishment, often destroying itself in the process, protecting the more valuable payload.

The problem with this model is that NSO are, as with heat shields, replaceable. A new target will appear to take its place.

But that too will draw attention, it will have to assemble talent (leadership, engineering, sales, operations), and will itself have vulnerabilities. As I suggested in a thread yesterday, playing in the field of dirty ops raises prospects for piercing the corporate shield of liability for all those involved: the firm, its personnel, investors, creditors, suppliers, and where identifiable, clients.

Re: Amazon Shuts Down NSO Group Infrastructure

#142
post #137

Earlier quoted context omitted.

Did they reply in the negative or just not respond?

How does it matter? No response is a response and in this kind of situation it is explicit "I will not do anything and I'm dishonest enough to not acknowledge that.".

I was curious, not being cynical toward sloshnmosh. Much can be inferred from Amazon's choice of reply.

Re: Amazon Shuts Down NSO Group Infrastructure

#143

Earlier quoted context omitted.

I wouldn’t be so quick to rush into a future where Amazon takedowns are as easy as YouTube DMCA requests.

Yes! Let’s stay in a present where Israeli hackers-for-hire can help dictatorships capture and murder dissidents. At a minimum we should demand transparency and accountability from all of these scale-enabling organizations.

I guess your founder and CEO being victim of something similar helps in these decisions. Or not.

Re: Amazon Shuts Down NSO Group Infrastructure

#144
post #3

Shouldn’t there be an outcry against the suppression of free speech? When Facebook or Google blocks extremist propaganda, it’s a big thing. What jurisdiction’s laws were broken by this company?

Not convinced that using the service to distribute malware, on behalf of odious third party governments for antidemocratic purposes, is protected by free speech demands. It's not speech, is it?

> It's not speech, is it?

That's besides the point. And BTW yes, distributing data can constitute speech.

Free speech has nothing to do with providing services to antidemocratic entities.

Re: Amazon Shuts Down NSO Group Infrastructure

#145
post #23

Earlier quoted context omitted.

> Shouldn’t there be an outcry against the suppression of free speech? Only if someone was one of the many people who don't understand what Free Speech is or incorrectly think of rights only in terms of themselves and people they like, not for those who they don't. In this case, Amazon is exercising their own Free Speech rights. Free speech necessarily (and as a matter of law) means the freedom to not speak and to no…

I don't understand the line where lots of people are seemingly outraged about people using online platforms to disseminate propaganda and extremist materials. (ie. most recently Google Drive) NSO group seems to be a not-so-nice company. But why does what they do justify blackballing, while similar companies (say BlueCoat or any of a dozen companies that provide solutions to hack on behalf of the police) are ok?

I believe your confusion is insincere.

There's a difference between someone being banned for stating the fact:

> Jewish people have dramatically disproportionate income, wealth, and power in the United States. They're eager to levy that charge against White people, but they don't allow White people to levy that charge against them.

... and a deeply powerful, monied Israeli group getting banned for hacking into innocent people's phones and computers both for blackmail and for profit.

Re: Amazon Shuts Down NSO Group Infrastructure

#146
post #98

Earlier quoted context omitted.

Cloudflare has taken voluntary action on sites 2 (or 3?) times now. They can no longer claim complete neutrality. I don't know about Cloudfront.

It has nothing to do with "neutrality", they have Terms of Service like every single service provider in the world. If you violate them, there goes your infra. Spreading malware is almost certainly a violation of AWS' ToS (Amazon engs, correct me if needed)

It's a little more complicated than that in Cloudflare's case. The debate isn't really relevant to AWS/CloudFront or anyone else, but Cloudflare has famously had a policy of not kicking off any customers as long as they abide by US law. The CEO publicly identifies as a free speech absolutist. (Malware/phishing/etc. is still removed, since it's illegal.)

The CEO publicly broke their policy on this on two occasions: the neo-Nazi website The Daily Stormer, and 8chan. In each case, only after a long saga played out.

For The Daily Stormer: after they mocked the deceased victim of the Charlottesville rally, Cloudflare received public pressure to boot them but refused, and then the owner subsequently tried to troll them/the public by claiming Cloudflare executives secretly supported their ideology, causing them to finally be removed. (https://blog.cloudflare.com/why-we-terminated-daily-stormer/ )

For 8chan: Cloudflare received a lot of heat for not removing them after the first and second incidents of posters becoming mass shooters, eventually removing them after the third mass shooting. (https://blog.cloudflare.com/terminating-service-for-8chan/)

I forget the term/aphorism for this (like "double-bind", sort of), but they put themselves in an awkward position because they're probably one of the most neutral service providers out there - still far more than probably anyone else to this day - but by marketing themselves as 100% neutral, being only 99.99999% neutral created lots of lasting negative PR that people still regularly bring up.

Any other company would've kicked those people off way sooner and there would've been little to no publicity, because they routinely do such things, but now Cloudflare is hated by both the pro-censorship and the anti-censorship crowd. (See: https://en.wikipedia.org/wiki/Cloudflare#Mass_Shootings and everything below. It's quite a rollercoaster.)

Re: Amazon Shuts Down NSO Group Infrastructure

#147

Earlier quoted context omitted.

The media in Sweden use both by the looks of it. They do that for IKEA as well but it doesn't really make sense imo since it's an abbreviation of names. Both are made up language constraints anyway so I don't really see why the typographic rules of a language are more important than the equally artificial typographic rules of a company name.

You will definitely see both. You'll see things like Iphone being written by media sources that pride themselves on good writing, such as Dagens Nyheter. If you go to https://sv.wikipedia.org/wiki/Ikea the first sentence can be translated to English as: "Ikea Group, written by the company as IKEA Group, is a multi-national furniture company founded in 1943 by Ingvar Kamprad" Words such as TV started out in upper case…

They still write Iphone X, why not Iphone x? or Iphone 10? or Iphone tio? Roman numerals aren't really a part of the Swedish language after all. They write IOS or iOS, why not Ios? Is this not a normal enough word? It's just artificial rules replaced by a different set of artificial rules. Why not just use what everyone else uses, haha.

A bit of a meta discussion in a thread totally unrelated to this, sorry about that.

Re: Amazon Shuts Down NSO Group Infrastructure

#148

Earlier quoted context omitted.

It's malice but from a different aspect; willful malice in the name of 'cost cutting'.

How many FTEs should they have dedicated to triaging security complaints from (relatively speaking) randos on the Internet about their customers? Also, would you take that job? Some poor support person probably got this and punted because they couldn't pattern match to something in their handbook. For every thoughtful, detailed security report there are about 500 others that involve voices from appliances, self-xss,…

Not to worry, they'll replace their overworked human staff with sentiment analysis bots which will do an equally uneven job of sorting the wheat from the chaff, with even less hope of appeal.

Re: Amazon Shuts Down NSO Group Infrastructure

#149
post #137

Earlier quoted context omitted.

Did they reply in the negative or just not respond?

How does it matter? No response is a response and in this kind of situation it is explicit "I will not do anything and I'm dishonest enough to not acknowledge that.".

To me, a negative response says "We have evaluated our policy and decided that we will not stop this." A non-response says "A frontline agent didn't know how to make a call on a non-downtime ticket from a non-customer so now it's in a bureaucratic black hole and nobody has actually read your email and probably never will." Which is still crappy, but not really malicious in the same way.

Re: Amazon Shuts Down NSO Group Infrastructure

#150
post #62

Earlier quoted context omitted.

Their biggest customers are middle eastern governments according to the WaPo article. US certainly has bought the software but it's mostly Saudi, UAE, Qatar, etc. US has NSA so they don't really need some software. Middle eastern powers dont have the same type of technical expertise to develop their own in-house.

So should we consider the NSA a terrorism-aiding organization? edit: the tone is lost via internet; my own opinion on this: yes, it is.

Yes, we should
Post reply on HN