Live data from Hacker News

Apple sues NSO Group to curb the abuse of state-sponsored spyware

apple.com

71–80 of 477 posts

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#71
post #7

It is great to see this happen. It's also fascinating that the crux of the Apple's case against NSO hinges on NSO engineers that accepted iCloud's terms and conditions. From related NYT article: > The sample of Pegasus gave Apple a forensic understanding of how Pegasus worked. The company found that NSO’s engineers had created more than 100 fake Apple IDs to carry out their attacks. In the process of creating those a…

I was the victim of a state-sponsored attack. I took it to court. I tried to subpoena the contents of the government agents' iPhones but Apple came and filed a Joinder in Motion and sent expensive lawyers to lie to the judge about the judge's power to subpoena digital evidence. The lawyer specifically told me all he does is go around the country and lie to judges to get them to cancel subpoenas. We introduced the T+C…

US based? I understand if you can't divulge any specifics, but I'm always curious about the nature of these attacks, e.g. we know certain types of journalists/activists are often targeted.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#72
This is amazing publicity for NSO.

Is NSO is able to crack Apple security you can bet the NSA, Chinese, Russians as well as Israel's Mossad is doing much the same.

With this lawsuit, Apple is basically admitting that they need lawyers and not engineers to combat the hacking.

But suing NSO would not stop the other agents from hacking Apple.

That is why it is best that Apple spend $100 million or more to cybersecurity harden their software.

In addition, Apple should offer $1 million awards for breaking their security.

One should also ask, how many lives were saved from terrorist attacks by NSO. That would be an interesting story.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#73
post #62

Earlier quoted context omitted.

I was the victim of a state-sponsored attack. I took it to court. I tried to subpoena the contents of the government agents' iPhones but Apple came and filed a Joinder in Motion and sent expensive lawyers to lie to the judge about the judge's power to subpoena digital evidence. The lawyer specifically told me all he does is go around the country and lie to judges to get them to cancel subpoenas. We introduced the T+C…

> Apple came and filed a Joinder in Motion and sent expensive lawyers to lie to the judge about the judge's power to subpoena digital evidence. If a lawyer makes an argument in court about the law governing a case (as opposed to the facts of the case), and the judge accepts the argument, and the judge's decision survives all its appeals, then the lawyer's argument is, by definition, true. EDIT: I'm objecting here to…

>"If a lawyer makes an argument in court about the law governing a case (as opposed to the facts of the case), and the judge accepts the argument, and the judge's decision survives all its appeals, then the lawyer's argument is, by definition, true. "

This is a Kafkaesque and wrong understanding of the legal system. There are all sorts of errors of law and errors of fact that are non-appealable.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#74

Legal methods are a crutch at best. Apple would be wise to put forth the same budget into their security team's research and development and properly address these weaknesses.

Ok normally I’d just let something like this go but I just have to pull my hair out when I see a comment like this. The attack surface of software as complicated as a modern operating system (iOS or MacOS, etc.) is simply too large to lockdown without dramatically hurting the user experience (assuming you could actually achieve a lockdown in the first place!!). Let’s, just for a second, propose that apple went full M…

I co-sign this whole comment and answer the rhetorical question: $50MM for an exploit chain would not stop a state-level adversary. Their alternatives for these kinds of operations is human intelligence; they'd pay more just in health benefits to staff those operations.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#75
post #7

It is great to see this happen. It's also fascinating that the crux of the Apple's case against NSO hinges on NSO engineers that accepted iCloud's terms and conditions. From related NYT article: > The sample of Pegasus gave Apple a forensic understanding of how Pegasus worked. The company found that NSO’s engineers had created more than 100 fake Apple IDs to carry out their attacks. In the process of creating those a…

Is it great? The lawsuit is Apple trying to enforce the iCloud EULA to stop reverse engineering. While NSO Group created hacking tools, and then did some questionable things with them, do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? Put another way, if it was someone HN liked , would we still say this is actually good? Because c…

I am a straight-up GPL coder and advocate, and I find this line of reasoning, difficult to support. Additionally, it is a habit of lying, thieving security people to use every inch of freedom that GPL-advocates give them.. really torn here

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#76

Earlier quoted context omitted.

Ok normally I’d just let something like this go but I just have to pull my hair out when I see a comment like this. The attack surface of software as complicated as a modern operating system (iOS or MacOS, etc.) is simply too large to lockdown without dramatically hurting the user experience (assuming you could actually achieve a lockdown in the first place!!). Let’s, just for a second, propose that apple went full M…

> The attack surface of software as complicated as a modern operating system (iOS or MacOS, etc.) is simply too large to lockdown without dramatically hurting the user experience (assuming you could actually achieve a lockdown in the first place!!). https://qubes-os.org

You talk to a lot of people who use Qubes day to day? I do. What have you heard about how Qubes life is?

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#77
post #76

Earlier quoted context omitted.

> The attack surface of software as complicated as a modern operating system (iOS or MacOS, etc.) is simply too large to lockdown without dramatically hurting the user experience (assuming you could actually achieve a lockdown in the first place!!). https://qubes-os.org

You talk to a lot of people who use Qubes day to day? I do. What have you heard about how Qubes life is?

I am gladly using Qubes myself as a daily driver. Can't recommend it enough.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#78
post #46

Earlier quoted context omitted.

I am all for Hanlon's razor. But it reads to me as: Apple legal team has to act because Facebook suit (and the info made public) makes it impossible to say that "Apple was not aware" of such and such details. To me it is much easier to believe the above, compared to your "Apple is only now seeing this info, and only now is aware, and only now can act".

Look, if you don't know how legal standing works, that's one thing. But to reject the explanation provided to you and to cite your own ignorance as a legitimate source of disbelief while you poo-poo away a dispositive fact isn't reasoning.

Apple knows since at least 2016 of NSO activities on their devices and servers, while selling this image of privacy competence.

This long period of inaction, from 2016 to now is unacceptable.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#79
post #67

Earlier quoted context omitted.

Is it great? The lawsuit is Apple trying to enforce the iCloud EULA to stop reverse engineering. While NSO Group created hacking tools, and then did some questionable things with them, do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? Put another way, if it was someone HN liked , would we still say this is actually good? Because c…

> those inane licenses no one reads, do we really want them to legally binding? What all would be possible if software EULAs weren't legally binding? One thing that EULAs typically do is reduce liability for the company producing the software. Imagine if Google/Apple were liable for damages from all the miscommunications caused by autocorrect?

EULAs are also used to protect IP, such as by prohibiting reverse engineering. Preventing reverse engineering would prevent modding games, fixing bugs in software that aren't supported anymore, security analysis, etc... In my view, it'd be a net negative for society.

Re: Apple sues NSO Group to curb the abuse of state-sponsored spyware

#80
post #7

It is great to see this happen. It's also fascinating that the crux of the Apple's case against NSO hinges on NSO engineers that accepted iCloud's terms and conditions. From related NYT article: > The sample of Pegasus gave Apple a forensic understanding of how Pegasus worked. The company found that NSO’s engineers had created more than 100 fake Apple IDs to carry out their attacks. In the process of creating those a…

Is it great? The lawsuit is Apple trying to enforce the iCloud EULA to stop reverse engineering. While NSO Group created hacking tools, and then did some questionable things with them, do we really want those inane licenses no one reads, and everyone scrolls down to hit [agree]; do we really want them to legally binding? Put another way, if it was someone HN liked , would we still say this is actually good? Because c…

It's not just the iCloud terms of service, though — they're using that to strengthen the case that NSO agreed to the jurisdiction of California courts but they're relying on the CFAA and especially the claim that the access to the users' device was not authorized by that user.

It would be really interesting to see what precedent comes out of this case and especially how that would affect a future case where Apple claims a violation of their terms of service but the user fully consented to that use.

Post reply on HN