Live data from Hacker News

Amazon Shuts Down NSO Group Infrastructure

vice.com

221–230 of 260 posts

Re: Amazon Shuts Down NSO Group Infrastructure

#221

Earlier quoted context omitted.

Doesn't cloudfront generally act like cloudflare? Ie. We don't inspect your content. Law enforcement are the only people who can stop us hosting a site.

clouflare stopped being like that long ago. they publicly posted that they will take down stuff they makes the ceo worry, and they will inspect what your users are reading/sharing - and notify agencies with powers and guns when they find stuff from now/then on. - no longer a dumb pipe, no longer neutral, actually active in directing law enforcement to take you down and possibly take people out.

I just have to wonder if people downvote this thinking it's not possibly true, or they just don't like what is said.

Link to relative info is posted on another comment (https://news.ycombinator.com/item?id=27884821) - but for those who have not read it, here is an excerpt from a 2019 cloudflare post/statement:

"...what we have done to try and solve the Internet’s deeper problem is engage with law enforcement and civil society organizations to try and find solutions. Among other things, that resulted in us cooperating around monitoring potential hate sites on our network and notifying law enforcement when there was content that contained..."

So I stand by the statement, I can't see any other way to read it.

Re: Amazon Shuts Down NSO Group Infrastructure

#222
post #133

Earlier quoted context omitted.

> If it is the U.S., then obviously no, the NSA is an arm of the state. Some here in the states don't exactly feel like the people running the USG have the people's best interests at heart. Common folk across countries probably have more in common with each other than with the ruling elite. State-sponsored terrorism is a thing - and has been for a LONG time. And US citizens are targets as well as non-citizens.

It requires indoctrination to believe the US as an aggregate sovereign brand functions with the interest of US people in mind. Nothing about US foreign policy suggests that. Very little about the Federal government’s domestic policy does.

Said indoctrination is baked into school, movies, sports events, and every fiber of the country's dialog.

Some will never leave the Matrix.

Re: Amazon Shuts Down NSO Group Infrastructure

#223

Earlier quoted context omitted.

Doesn't cloudfront generally act like cloudflare? Ie. We don't inspect your content. Law enforcement are the only people who can stop us hosting a site.

clouflare stopped being like that long ago. they publicly posted that they will take down stuff they makes the ceo worry, and they will inspect what your users are reading/sharing - and notify agencies with powers and guns when they find stuff from now/then on. - no longer a dumb pipe, no longer neutral, actually active in directing law enforcement to take you down and possibly take people out.

Why is this being downvoted? It's demonstrably true.

https://blog.cloudflare.com/why-we-terminated-daily-stormer/

Re: Amazon Shuts Down NSO Group Infrastructure

#224

Earlier quoted context omitted.

It's a little more complicated than that in Cloudflare's case. The debate isn't really relevant to AWS/CloudFront or anyone else, but Cloudflare has famously had a policy of not kicking off any customers as long as they abide by US law. The CEO publicly identifies as a free speech absolutist. (Malware/phishing/etc. is still removed, since it's illegal.) The CEO publicly broke their policy on this on two occasions: th…

> Malware/phishing/etc. is still removed, since it's illegal. They are known for protecting DDoS-for-hire and Cryptolocker services.

It's a gray area. They sometimes reverse proxy frontend portals for those services, but not the services themselves. Sometimes the frontend won't have anything obviously illegal.

Anything that's actively serving malware or phishing pages is removed.

Re: Amazon Shuts Down NSO Group Infrastructure

#225

Earlier quoted context omitted.

Never assume malice where ignorance and incompetence would suffice instead. Those two things are actually not the same thing at all, depending on how you define “willful.”

It's malice but from a different aspect; willful malice in the name of 'cost cutting'.

Malice is the wrong term for it even if we accept the premise. (I do not but that is another can of worms.) Malice implies a desire to hurt people. It would be utilitarian callousness if anything, negligence if there were legal obligations shirked. There is no law against just poor customer service like being a jerk isn't illegal.

Re: Amazon Shuts Down NSO Group Infrastructure

#226
post #23
post #3

Shouldn’t there be an outcry against the suppression of free speech? When Facebook or Google blocks extremist propaganda, it’s a big thing. What jurisdiction’s laws were broken by this company?

> Shouldn’t there be an outcry against the suppression of free speech? Only if someone was one of the many people who don't understand what Free Speech is or incorrectly think of rights only in terms of themselves and people they like, not for those who they don't. In this case, Amazon is exercising their own Free Speech rights. Free speech necessarily (and as a matter of law) means the freedom to not speak and to no…

To me this looks exceedingly similar to Marsh vs. Alabama but in a virtual world

Re: Amazon Shuts Down NSO Group Infrastructure

#227
post #54
post #28

Anyone notice that this statement from NSO in the article doesn't make sense: "NSO does not operate its technology, does not collect, nor possesses, nor has any access to any kind of data of its customers." If this is true, how do we have a singular list of all phone numbers penetrated? If there was this type of "segmentation" or firewall between NSO and its clients, why was there this huge central data leak? NSO is…

They are trying to claim that the service is so fully automated that it is the client that does the selection of the target. They claim that their system does not require any fine-tuning from their side, etc. And that's totally bullshit.

“It should be noted that no ethically-trained software engineer would ever consent to write a DestroyBaghdad procedure. Basic professional ethics would instead require him to write a DestroyCity procedure, to which Baghdad could be given as a parameter.” - Nathaniel Borenstein

Quoted at https://blog.codinghorror.com/your-favorite-programming-quot...

Re: Amazon Shuts Down NSO Group Infrastructure

#228

Earlier quoted context omitted.

> Apple might take this more seriously instead of having some PR flack write marketing copy What are they supposed to do?

Take security a lot more serious than they currently do. They've had some seriously embarrassing security holes in their software the last few years. Also, they could increase the payout for their bug bounty. Why report to apple for a 0-day when you can make $1 million from these guys? It's not like Apple doesn't have the cash.

Apple takes security more seriously than almost any other vendor in the entire world. It's in a small club of vendors that operates at the literal frontier of what computer science knows about building security into commercial products. No reasonable argument about what Apple can do start from the premise that they don't take the problem seriously.

They aren't above criticism. They do some things well that Google doesn't do as well, and vice versa; it would be good if everyone could level up to highest standards set by any in the club. It's totally fine to point these things out.

As for the bounty payout thing, I highly recommend you track down a talk from someone that has run a vulnerability/exploit market; there are a couple. The economics of selling vulnerabilities to the grey market are nowhere nearly as simple as they appear in ordinary message board threads. In particular: Apple offers a fixed, lump sum payment, where every market I'm aware of offers tranched payments that end when a vulnerability is burned.

Re: Amazon Shuts Down NSO Group Infrastructure

#229
post #13

Earlier quoted context omitted.

There is another point if view, and that is that corporate marketing should not take precedence over correct use of language. Some languages tend to be more strict about this. I think it's particularly common to see English play fast and loose with the language compared to other languages. In Sweden, for example you will see media write Iphone, because it's a name, and names are capitalised. The same goes for Digital…

Another point of view: DigitalOcean.com works but Digital Ocean.com does not.

Red Hat is canonical (pun not intended) name but its website is redhat.com

Re: Amazon Shuts Down NSO Group Infrastructure

#230
post #178

Earlier quoted context omitted.

Yes! Let’s stay in a present where Israeli hackers-for-hire can help dictatorships capture and murder dissidents. At a minimum we should demand transparency and accountability from all of these scale-enabling organizations.

Obviously I am not in favour of that either. Making takedowns automatic on any user report means the dictators take down the apps of the dissidents. In the absence of AI that would necessarily have to be good enough to also radically change society and the economy, the only solution I can even think of is a big increase in funding for the policing of apps. Who exactly would fund that? Governments would want to use su…

Why can’t we we reduce cloud provider margins and use that money to fund it!

I mean — why is this not obvious? Force these companies to adhere to certain regulatory standards - the minimum of which is transparency and accountability.

Post reply on HN