Live data from Hacker News

US judge finds NSO Group liable for hacking journalists via WhatsApp

reuters.com

191–200 of 306 posts

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#191

Earlier quoted context omitted.

Do these firms target US citizens without a US warrant?

You don’t need a warrant to target US citizens unless you are the government.

The arrangement is that UKs GCHQ spies on US citizens and shares the info with CIA/NSA .

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#192

Darknet Diaries did a few podcast episodes on the NSO group from the perspective of people who have directly interacted with or have been the target and it really puts it into perspective how horrific they are. They operate under the protection of the US and are directly allowed to spy on US citizens without any recourse whatsoever. One particularly grotesque case was the illegal wire tapping of Ben Suda after launch…

> or take the cases to court just to drop it so they can tell the ICC that they did make an attempt to prosecute, which is a loophole that disallows the ICC to take up those cases.

As an aside, it should be noted that this wouldn't be sufficient to trigger complimentary at the ICC if its obvious the investigation was not in good faith. The icc can ignore any domestic investigation it believes was not a serious attempt to investigate.

Like it'd be a pretty silly court if you could get out of everything by running your own sham investigation.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#193

I thought Whatsapp and signal share the same encryption

It was a buffer overflow in a VOIP stack: * https://www.theverge.com/2019/5/14/18622744/whatsapp-spyware... Interestingly enough, Signal (and others) had the same sort of vulnerability on Android from a WebRTC stack: * https://googleprojectzero.blogspot.com/2020/08/exploiting-an... The big issue in both cases is that the exploit was triggered before the user answered the call. I think the moral here is that a secure…

Was the spyware persistent? That is, would a reboot clear it? Not that it matters. Presumably, the attackers were so motivated they would re-infect the device the moment they saw it go dark.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#194

Earlier quoted context omitted.

It was a buffer overflow in a VOIP stack: * https://www.theverge.com/2019/5/14/18622744/whatsapp-spyware... Interestingly enough, Signal (and others) had the same sort of vulnerability on Android from a WebRTC stack: * https://googleprojectzero.blogspot.com/2020/08/exploiting-an... The big issue in both cases is that the exploit was triggered before the user answered the call. I think the moral here is that a secure…

The other moral here is to stop using memory unsafe languages. It's just so incredibly dumb that we keep making excuses for this.

Does Rust make RCE impossible?, I don't think it does.

There is the option of not having data and code sharing the same stack, that seems like a better solution to me but that's such an option is not usually talked about.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#195
post #109

Earlier quoted context omitted.

note for signal users: in settings, you can disable link previews and automatic media download.

Why are link previews a problem? Presumably I only generate previews for links I've vetted.

It seems like most of the exploits come down to blowing up a parser of one data format or another. Myriad from which to choose, they are written in C for historical reasons, and probably play fast and loose with validation in the name of performance.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#196
post #179

Darknet Diaries did a few podcast episodes on the NSO group from the perspective of people who have directly interacted with or have been the target and it really puts it into perspective how horrific they are. They operate under the protection of the US and are directly allowed to spy on US citizens without any recourse whatsoever. One particularly grotesque case was the illegal wire tapping of Ben Suda after launch…

I refuse to use Israeli tech in my stack if at all possible. I don't see how someone could use software like Snyk and not put themselves at risk (founders are ex-IDF Unit 8200). Especially in the area of security, it seems like using Israeli tech is inviting the wolf straight into the hen house. No thanks.

[flagged]

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#197

Earlier quoted context omitted.

The US hosts and protects firms that are better at this than NSO, and not just because they're smart enough not to be in the news.

Why was this dead? If anything, Thomas' reputation here should at least entitle him to being heard.

My fellow showdeader, Click the time on the dead post and press “vouch”

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#198
post #85

I'm not a lawyer so maybe I'm misunderstanding something but the plaintiff is Whatsapp, not the journalists. This isn't really about holding NSO Group accountable for hacking journalists at all The fact journalists were compromised seems only incidental, the ruling is about weather or not NGO Group "exceeded authorization" on WhatsApp by sending the Pegasus installation vector through WhatsApp to the victims and not…

Given the nature of who the stakeholders are, the neatest way to achieve an end is to target authorization. It focuses on the how instead of the who or what.

This reduces embarrassment for stakeholders, protects sources and methods, and sends a message.

The law is as broad as can be. If it were a US National instead of NSO Group, some crazy calculation of damages would be used to extract a plea in lieu of a thousand months in prison.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#199
post #179

Darknet Diaries did a few podcast episodes on the NSO group from the perspective of people who have directly interacted with or have been the target and it really puts it into perspective how horrific they are. They operate under the protection of the US and are directly allowed to spy on US citizens without any recourse whatsoever. One particularly grotesque case was the illegal wire tapping of Ben Suda after launch…

I refuse to use Israeli tech in my stack if at all possible. I don't see how someone could use software like Snyk and not put themselves at risk (founders are ex-IDF Unit 8200). Especially in the area of security, it seems like using Israeli tech is inviting the wolf straight into the hen house. No thanks.

Yes, I think the pager attack is also an interesting case study. It's one thing to execute a supply chain compromise for information gathering, where the target may never know what happened. On the other hand, flaunting your abilities in that area will just lead you to being cut out of supply chains.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#200
post #152
post #85

I'm not a lawyer so maybe I'm misunderstanding something but the plaintiff is Whatsapp, not the journalists. This isn't really about holding NSO Group accountable for hacking journalists at all The fact journalists were compromised seems only incidental, the ruling is about weather or not NGO Group "exceeded authorization" on WhatsApp by sending the Pegasus installation vector through WhatsApp to the victims and not…

i dont think users of whatsapp would have standing against people hacking whatsapp to get their data. whatsapp owns the systems, so its up to whatsapp to sue

The thing of value isn’t in WhatsApp in this case.

You can’t sue a dude for stealing a screwdriver to break into your home with. Your tort is the act against you.

Post reply on HN