Live data from Hacker News

US judge finds NSO Group liable for hacking journalists via WhatsApp

reuters.com

151–160 of 306 posts

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#151

Earlier quoted context omitted.

People have to start assuming that any communication method in use is compromised. There’s just no way on earth orgs like the NSA would throw their hands up in the air and not find multiple different avenues into an app like signal. Its one of the most downloaded messaging apps. Investment into compromising it is very worth while. People should just assume everything involving a cell phone or computer is inherently i…

Password managers are such a high target that I wonder how we’ve convinced people to put all their passwords in the same software.

Back to using the same password everywhere then.

Bitwarden is already a big step up from what most people are doing, then if you want to hide from gouvernement you better make sure you save your password on extremely secured device. But that's another treat level from the average Joe.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#152
post #85

I'm not a lawyer so maybe I'm misunderstanding something but the plaintiff is Whatsapp, not the journalists. This isn't really about holding NSO Group accountable for hacking journalists at all The fact journalists were compromised seems only incidental, the ruling is about weather or not NGO Group "exceeded authorization" on WhatsApp by sending the Pegasus installation vector through WhatsApp to the victims and not…

i dont think users of whatsapp would have standing against people hacking whatsapp to get their data.

whatsapp owns the systems, so its up to whatsapp to sue

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#153
post #113

Earlier quoted context omitted.

With end-user-device-controlled e2ee, the only information available to law enforcement is metadata. With a warrant, they could seize your device (or the backups, if unencrypted)

Unfortunately, I don’t think end-to-end encryption guarantees much when it comes to legal intercept in proprietary messaging apps. The intercept functionality could be done in the client and capture data, not just metadata.

Why hasn't any evidence of such client-side interception ever been surfaced? Reversing apps and software has been done since forever, and has been used to discover things the app-makers don't want made public - such as unannounced new products, but this happens perennialy with Apple & OS updates, and upcoming features in apps that are behind flags.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#155

It is hard to believe that NSO group is allowed to operate. They sell technology to horrible places, they cause death torture, and a host of less horrible things. Yet they are protected by the US and Israel, which I believe is the case that they have backdoors into all of it, and getting the targets to actually install this malware on their own saves a lot time. All good, except for the actual real world victims.

[deleted]

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#159
post #137

Earlier quoted context omitted.

[flagged]

I mean, that’s true of most businesses and industries, big and small? The average person has no idea what Oracle or SAP exists, or that they are multibillion dollar companies. Most people don’t know you can just go buy plastic and composites at TAP, and all sorts of things at McMaster. Most people don’t even know who builds commercial vehicles besides like Peterbilt maybe. Is there an argument you are making that Met…

[deleted]

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#160

Earlier quoted context omitted.

> send drones to kill terrorists The part that you miss is, are they only killing "terrorists" extrajudicially? To take that propaganda at its face value is to ask, what else could they be killing brown people for, if not terrorism?

I didn't say if I think that drone killing is justified or not, since I have no opinion on that - I don't know enough to form an opinion. I only say that since the government have the right to send killing drone it doesn't make sense to raise pitchforks against phone hacking

I don't get what's happening in this thread. This is a pretty clear statement: hacking isn't worse than the killing that the government is already allowed to do. It's a pretty straightforward argument which for some reason seems to be being misunderstood.

I'll gently push on the premise though: hacking isn't worse for the victims than death, obviously, but I think it's possible weaponizing of exploits does more total damage. Both collateral, due to the manufacturing of exploits which ultimately leak and harm a bunch of unrelated actors, and because the marginal hacking is lower cost, practically and politically. So a given attack is likely to be used against groups we'd recognize less clearly as "terrorists" / deserving of the harm / etc.

Post reply on HN