NSO Group is dead at this point. They fucked with the wrong people. Hacking human rights advocates is fine but when Presidents and PMs start getting their phones hacked I am sure they will implement legislation to outlaw this type of software.
Attacking NSO would be like attacking the Israeli government and you don't do that because your PM's shitty OpSec was exposed.
Enough is enough
41–50 of 135 posts
Re: Enough is enough
#42NSO Group is dead at this point. They fucked with the wrong people. Hacking human rights advocates is fine but when Presidents and PMs start getting their phones hacked I am sure they will implement legislation to outlaw this type of software.
Attacking NSO would be like attacking the Israeli government and you don't do that because your PM's shitty OpSec was exposed.
Re: Enough is enough
#43NSO Group is dead at this point. They fucked with the wrong people. Hacking human rights advocates is fine but when Presidents and PMs start getting their phones hacked I am sure they will implement legislation to outlaw this type of software.
Re: Enough is enough
#44They state: " NSO is a technology company. We do not operate the system, nor do we have access to the data of our customers " Yet they also state: " The list is not a list of targets or potential targets of Pegasus. " How do they know it is not a list of targets if they don't have access to their customer's lists of targets? None of this is trustworthy and neither are NSO.
Re: Enough is enough
#45NSO Group is dead at this point. They fucked with the wrong people. Hacking human rights advocates is fine but when Presidents and PMs start getting their phones hacked I am sure they will implement legislation to outlaw this type of software.
It’s an Israeli weapon, subject to arms control legislation. But that legislation can only be authored by Israel itself. So it doesn’t matter what other countries outlaw, Israel will continue to authorise NSO to sell the software to state actors around the world. Israel could always do with an extra friend or two and providing this software gains them a friend while costing them nothing.
Re: Enough is enough
#46This isn't even subtle. Their logic is so flawed that they should be embarrassed to hide behind it.
Re: Enough is enough
#47They state: " NSO is a technology company. We do not operate the system, nor do we have access to the data of our customers " Yet they also state: " The list is not a list of targets or potential targets of Pegasus. " How do they know it is not a list of targets if they don't have access to their customer's lists of targets? None of this is trustworthy and neither are NSO.
Re: Enough is enough
#48Another interesting example of a company choosing to simply route around the media. Not making a value judgement, but I'm seeing more companies opt to simply disengage and try to create their own narratives rather than go through the media via interviews/statements/etc.
Myself and my companies have gotten around streisand effect before by just ignoring everyone and then doing takedown requests a few weeks later. Nobody saves stuff if you don't react. They only save copies when you are seen as trying to delete the copies.
Re: Enough is enough
#49Pretty embarrassing response, honestly. If you specifically work in an area that can be used for sensitive purposes, you have a moral responsibility as to who you choose to sell to and what you choose to enable them to do. Moreover, if you're going to engage in moral indignation -- we can't possibly be responsible for what our customers do!!! -- then you can't end with a paragraph about how you're a league of superhe…
Re: Enough is enough
#50Pretty embarrassing response, honestly. If you specifically work in an area that can be used for sensitive purposes, you have a moral responsibility as to who you choose to sell to and what you choose to enable them to do. Moreover, if you're going to engage in moral indignation -- we can't possibly be responsible for what our customers do!!! -- then you can't end with a paragraph about how you're a league of superhe…
This is an abdication of responsibility and I agree the substance and tone of the response from them is really bad.
Just because you don't have direct customer data access does not mean that you don't hold some responsibility for how the tools you sell can and will be used. This is especially the case when you sell zero day security exploits in very high risk use cases.
This response suggests the culture on the inside is probably as bad as it looks from the outside. Based on this, I'd guess abuse of their tools is lot worse than what's publicly known.
A serious company operating in a high risk space would lead the messaging with and own the high risk issue directly and how they try to contain it in order to do pragmatic good in difficult areas. Instead we see a childish almost petulant, knee-jerk response that the bad things are 'not their fault' because they're just a software company.
These guys are just rationalizing their own bad behavior.