Live data from Hacker News

US judge finds NSO Group liable for hacking journalists via WhatsApp

reuters.com

201–210 of 306 posts

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#201
post #152

Earlier quoted context omitted.

i dont think users of whatsapp would have standing against people hacking whatsapp to get their data. whatsapp owns the systems, so its up to whatsapp to sue

What? So if someone robs a bank and empties my safety deposit box I can't sue them because it was the bank that had the money, not me?

Different scenario. The bank is a bailor — they have an duty of care for property in their possession that you retain ownership to.

You can sue the thief for stealing your property and the bank for negligent bailment. Same concept as a valet crashing your car.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#202

Earlier quoted context omitted.

I don't think it's off topic, we're talking about companies spying. Unsourced, maybe, though I suspect Thomas is a reliable enough source.

It has nothing to do with the OP. Honestly he always jumps in to do whataboutism on Israel posts. He didn’t say who he was talking about, it doesn’t add and only detracts from the discussion here.

I strongly doubt the intent here was whataboutism. Rather, it was more to indicate that things get a lot worse than this; it's just not in the spotlight so not many people know about it.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#203
post #179

Earlier quoted context omitted.

I refuse to use Israeli tech in my stack if at all possible. I don't see how someone could use software like Snyk and not put themselves at risk (founders are ex-IDF Unit 8200). Especially in the area of security, it seems like using Israeli tech is inviting the wolf straight into the hen house. No thanks.

[flagged]

I don’t use Intel either (at least as my main processor).

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#204
post #179

Darknet Diaries did a few podcast episodes on the NSO group from the perspective of people who have directly interacted with or have been the target and it really puts it into perspective how horrific they are. They operate under the protection of the US and are directly allowed to spy on US citizens without any recourse whatsoever. One particularly grotesque case was the illegal wire tapping of Ben Suda after launch…

I refuse to use Israeli tech in my stack if at all possible. I don't see how someone could use software like Snyk and not put themselves at risk (founders are ex-IDF Unit 8200). Especially in the area of security, it seems like using Israeli tech is inviting the wolf straight into the hen house. No thanks.

[flagged]

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#205

Earlier quoted context omitted.

It was a buffer overflow in a VOIP stack: * https://www.theverge.com/2019/5/14/18622744/whatsapp-spyware... Interestingly enough, Signal (and others) had the same sort of vulnerability on Android from a WebRTC stack: * https://googleprojectzero.blogspot.com/2020/08/exploiting-an... The big issue in both cases is that the exploit was triggered before the user answered the call. I think the moral here is that a secure…

Was the spyware persistent? That is, would a reboot clear it? Not that it matters. Presumably, the attackers were so motivated they would re-infect the device the moment they saw it go dark.

No and you've provided a good reason why it doesn't have to.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#206

Earlier quoted context omitted.

It has nothing to do with the OP. Honestly he always jumps in to do whataboutism on Israel posts. He didn’t say who he was talking about, it doesn’t add and only detracts from the discussion here.

I strongly doubt the intent here was whataboutism. Rather, it was more to indicate that things get a lot worse than this; it's just not in the spotlight so not many people know about it.

Does it get worse? He didn’t actually leave a source. NSO is certainly the most nefarious known agency.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#207

Earlier quoted context omitted.

Password managers are such a high target that I wonder how we’ve convinced people to put all their passwords in the same software.

Depends on your threats. I’m more worried about financial scams than I am anything related to government. Password managers with random passwords are an excellent guard against that threat. If I were worried about state actor threats, any keys or passwords would be memorized.

I'm not sure that would be a good idea. Do you, personally, want to be the weak link in the chain to something a nation state wants?

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#208

Earlier quoted context omitted.

I strongly doubt the intent here was whataboutism. Rather, it was more to indicate that things get a lot worse than this; it's just not in the spotlight so not many people know about it.

Does it get worse? He didn’t actually leave a source. NSO is certainly the most nefarious known agency.

They are but I can corroborate that they are not nearly the only player in this space. Google has done its research on several more of them: https://blog.google/threat-analysis-group/commercial-surveil....

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#209

Earlier quoted context omitted.

The other moral here is to stop using memory unsafe languages. It's just so incredibly dumb that we keep making excuses for this.

Does Rust make RCE impossible?, I don't think it does. There is the option of not having data and code sharing the same stack, that seems like a better solution to me but that's such an option is not usually talked about.

It makes this kind easy pivot to RCE impossible. Attacks these days are generally more sophisticated than simple buffer overflows, fwiw. Targeting function pointers from a heap overwrite gives the same capabilities.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#210

Earlier quoted context omitted.

I strongly doubt the intent here was whataboutism. Rather, it was more to indicate that things get a lot worse than this; it's just not in the spotlight so not many people know about it.

Does it get worse? He didn’t actually leave a source. NSO is certainly the most nefarious known agency.

I think the key word there is “known” which I appreciate you saying.

We still don’t know who created Bitcoin, what are the odds there are more… effective? groups than NSO operating in the US? I’d say greater than zero.

Post reply on HN