Live data from Hacker News

US judge finds NSO Group liable for hacking journalists via WhatsApp

reuters.com

161–170 of 306 posts

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#161
post #85

I'm not a lawyer so maybe I'm misunderstanding something but the plaintiff is Whatsapp, not the journalists. This isn't really about holding NSO Group accountable for hacking journalists at all The fact journalists were compromised seems only incidental, the ruling is about weather or not NGO Group "exceeded authorization" on WhatsApp by sending the Pegasus installation vector through WhatsApp to the victims and not…

> fake client to send some messages that the original application wouldn't be able to send which provide information about the target users' device

> I doubt I'm the only person here who has ever made an alternative client for something before

I think the distinction here for "exceeds authorisation" is pretty apparent. I don't read this judgement as being damning for people wanting to make their own clients.

They made a third party client for deliberately malicious purposes. If you go ahead and make a discord client with the intention of spamming or otherwise causing harm to its users, I think it's completely reasonable for you to get in trouble for that.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#162

Darknet Diaries did a few podcast episodes on the NSO group from the perspective of people who have directly interacted with or have been the target and it really puts it into perspective how horrific they are. They operate under the protection of the US and are directly allowed to spy on US citizens without any recourse whatsoever. One particularly grotesque case was the illegal wire tapping of Ben Suda after launch…

The US hosts and protects firms that are better at this than NSO, and not just because they're smart enough not to be in the news.

Do these firms target US citizens without a US warrant?

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#163

Darknet Diaries did a few podcast episodes on the NSO group from the perspective of people who have directly interacted with or have been the target and it really puts it into perspective how horrific they are. They operate under the protection of the US and are directly allowed to spy on US citizens without any recourse whatsoever. One particularly grotesque case was the illegal wire tapping of Ben Suda after launch…

The US hosts and protects firms that are better at this than NSO, and not just because they're smart enough not to be in the news.

Who are you talking about?

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#165

It is hard to believe that NSO group is allowed to operate. They sell technology to horrible places, they cause death torture, and a host of less horrible things. Yet they are protected by the US and Israel, which I believe is the case that they have backdoors into all of it, and getting the targets to actually install this malware on their own saves a lot time. All good, except for the actual real world victims.

[flagged]

We've banned this account for frequently posting flamewar comments, breaking the site guidelines, and ignoring our requests to stop.

If you don't want to be banned, you're welcome to email hn@ycombinator.com and give us reason to believe that you'll follow the rules in the future. They're here: https://news.ycombinator.com/newsguidelines.html.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#166
post #146

Earlier quoted context omitted.

I'd imagine they have a very limited market as in who they can sell their products and services to, for reasons that might make political power more interesting than valuation.

I don't know about that. Something I think a lot of people sleep on with this stuff is that most countries have multiple security agencies, and you generally cut deals with them individually. The market for this stuff is bigger than it looks.

That's probably a fair assumption too.

I was mostly thinking that the customers / clients you have and services you have to offer can be largely dependent by people in positions of power where having the right connections and influence might be the key difference between a service or product being viable.

For example - although not related to NSO - something like operation Trojan Shield required both Australian and Lithuanian cooperation due to fourth amendment interpretations.

Having a zero day in such cases is only part of the work and everything beyond that might be very much dependant on the strings you can pull.

But I can also see the argument that that would be something the government can figure out after they buy the product or service, so maybe I'm wrong on that and it's less important than I thought.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#167

I thought Whatsapp and signal share the same encryption

It was a buffer overflow in a VOIP stack: * https://www.theverge.com/2019/5/14/18622744/whatsapp-spyware... Interestingly enough, Signal (and others) had the same sort of vulnerability on Android from a WebRTC stack: * https://googleprojectzero.blogspot.com/2020/08/exploiting-an... The big issue in both cases is that the exploit was triggered before the user answered the call. I think the moral here is that a secure…

The other moral here is to stop using memory unsafe languages. It's just so incredibly dumb that we keep making excuses for this.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#168
post #70

Earlier quoted context omitted.

[flagged]

What other nation besides the USA and its 5-eyes lackeys willfully murders children almost every day in their own ‘self defense’? Got a list of states that murder more people than the USA/5-eyes and Israel right now?

Sudan, Ethiopia/Tigray, and Syria would all be recent (or ongoing) examples of non-primarily-US military conflicts where mass civilian death, including children, has been publicly evidenced. Each of these conflicts has seen one (or all) parties use self-defense as an argument.

(This doesn't somehow imply that anything is OK about the US's own role in global war, or anything in particular about the I/P conflict. But it's incorrect to treat US/Israel as uniquely competent or active in terms of immiserating the world's civilians and innocents.)

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#169
post #166

Earlier quoted context omitted.

I don't know about that. Something I think a lot of people sleep on with this stuff is that most countries have multiple security agencies, and you generally cut deals with them individually. The market for this stuff is bigger than it looks.

That's probably a fair assumption too. I was mostly thinking that the customers / clients you have and services you have to offer can be largely dependent by people in positions of power where having the right connections and influence might be the key difference between a service or product being viable. For example - although not related to NSO - something like operation Trojan Shield required both Australian and L…

My mental model of how this works --- and I have some (imperfect) evidence for it --- is that a given one of these firms (NSO or one of its competitors) has an addressable market of N countries each with an average of K security agencies, and basically all of those agencies pay subscription fees to be continuously in a position to do a CNE operation when they want to.

(Generally, I don't think countries just "buy exploits"; a significant component of the money in this space comes from "maintenance", so much so that I think it makes more sense to think of exploits as subscription services.)

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#170

Earlier quoted context omitted.

The US hosts and protects firms that are better at this than NSO, and not just because they're smart enough not to be in the news.

Do these firms target US citizens without a US warrant?

US citizens are routinely targeted by CNE operations enabled by commercial tools, yes.
Post reply on HN