Live data from Hacker News

Enough is enough

nsogroup.com

41–50 of 135 posts

Re: Enough is enough

#41
post #9

NSO Group is dead at this point. They fucked with the wrong people. Hacking human rights advocates is fine but when Presidents and PMs start getting their phones hacked I am sure they will implement legislation to outlaw this type of software.

Attacking NSO would be like attacking the Israeli government and you don't do that because your PM's shitty OpSec was exposed.

The only overtly pro-nomatterwhat-Israel government is the United States so at most 1 of the 193 countries in the United Nations would avoid regulating NSO on international relations grounds.

Re: Enough is enough

#42
post #9

NSO Group is dead at this point. They fucked with the wrong people. Hacking human rights advocates is fine but when Presidents and PMs start getting their phones hacked I am sure they will implement legislation to outlaw this type of software.

Attacking NSO would be like attacking the Israeli government and you don't do that because your PM's shitty OpSec was exposed.

This is actually one of the best reasons to hack another government.

Re: Enough is enough

#43
post #9

NSO Group is dead at this point. They fucked with the wrong people. Hacking human rights advocates is fine but when Presidents and PMs start getting their phones hacked I am sure they will implement legislation to outlaw this type of software.

What evidence is there that a PM has been hacked? Their number was on the list but haven't seen anything about Pegasus having been found on their devices.

Re: Enough is enough

#44

They state: " NSO is a technology company. We do not operate the system, nor do we have access to the data of our customers " Yet they also state: " The list is not a list of targets or potential targets of Pegasus. " How do they know it is not a list of targets if they don't have access to their customer's lists of targets? None of this is trustworthy and neither are NSO.

In another article - they apparently asked their clients whether they people named in the news stories had been targeted, and then they took their clients' word for it. Just comical. "Hey MBS, did you use our product to target Khashoggi? No? Great, that's a load off."

Re: Enough is enough

#45
post #29
post #9

NSO Group is dead at this point. They fucked with the wrong people. Hacking human rights advocates is fine but when Presidents and PMs start getting their phones hacked I am sure they will implement legislation to outlaw this type of software.

It’s an Israeli weapon, subject to arms control legislation. But that legislation can only be authored by Israel itself. So it doesn’t matter what other countries outlaw, Israel will continue to authorise NSO to sell the software to state actors around the world. Israel could always do with an extra friend or two and providing this software gains them a friend while costing them nothing.

It really doesn't cost them nothing - it makes them the target to offensive operations of other states. I'd be very, very surprised if NSO itself isn't hacked.

Re: Enough is enough

#46
"But our customers have to tell us who they target! It's in the signed contract! And I'm sure the people who lured a journalist into an embassy and murdered him are totally honorable people who would always disclose this to us!"

This isn't even subtle. Their logic is so flawed that they should be embarrassed to hide behind it.

Re: Enough is enough

#47

They state: " NSO is a technology company. We do not operate the system, nor do we have access to the data of our customers " Yet they also state: " The list is not a list of targets or potential targets of Pegasus. " How do they know it is not a list of targets if they don't have access to their customer's lists of targets? None of this is trustworthy and neither are NSO.

hmm.. "yet they are obligated to provide us with such information under investigations"

Re: Enough is enough

#48

Another interesting example of a company choosing to simply route around the media. Not making a value judgement, but I'm seeing more companies opt to simply disengage and try to create their own narratives rather than go through the media via interviews/statements/etc.

Myself and my companies have gotten around streisand effect before by just ignoring everyone and then doing takedown requests a few weeks later. Nobody saves stuff if you don't react. They only save copies when you are seen as trying to delete the copies.

How do you sleep at night?

Re: Enough is enough

#49

Pretty embarrassing response, honestly. If you specifically work in an area that can be used for sensitive purposes, you have a moral responsibility as to who you choose to sell to and what you choose to enable them to do. Moreover, if you're going to engage in moral indignation -- we can't possibly be responsible for what our customers do!!! -- then you can't end with a paragraph about how you're a league of superhe…

This is an excellent point. "We're responsible for the good applications, just not the bad ones"

Re: Enough is enough

#50

Pretty embarrassing response, honestly. If you specifically work in an area that can be used for sensitive purposes, you have a moral responsibility as to who you choose to sell to and what you choose to enable them to do. Moreover, if you're going to engage in moral indignation -- we can't possibly be responsible for what our customers do!!! -- then you can't end with a paragraph about how you're a league of superhe…

> "NSO is a technology company. We do not operate the system, nor do we have access to the data of our customers, yet they are obligated to provide us with such information under investigations."

This is an abdication of responsibility and I agree the substance and tone of the response from them is really bad.

Just because you don't have direct customer data access does not mean that you don't hold some responsibility for how the tools you sell can and will be used. This is especially the case when you sell zero day security exploits in very high risk use cases.

This response suggests the culture on the inside is probably as bad as it looks from the outside. Based on this, I'd guess abuse of their tools is lot worse than what's publicly known.

A serious company operating in a high risk space would lead the messaging with and own the high risk issue directly and how they try to contain it in order to do pragmatic good in difficult areas. Instead we see a childish almost petulant, knee-jerk response that the bad things are 'not their fault' because they're just a software company.

These guys are just rationalizing their own bad behavior.

https://zalberico.com/essay/2020/06/13/zoom-in-china.html

Post reply on HN