Facebook Wanted NSO Spyware to Monitor Users, NSO CEO Claims (2020)
1–10 of 16 posts
Re: Facebook Wanted NSO Spyware to Monitor Users, NSO CEO Claims (2020)
#2However, I'd also be willing to make a huge bet there is zero chance the FB CISO at the time was aware of who these representatives allegedly were or approved what they were doing unless it was threat intelligence. I don't think this will be the last muck thrown by this company.
Re: Facebook Wanted NSO Spyware to Monitor Users, NSO CEO Claims (2020)
#3It's like the one thing universally true about spies is they can never keep it g. As a security guy, this is why you don't get involved with dodgy companies. When the pressure is on, they will pull in everyone they ever spoke to and use you protecting your rep to try get leverage. Pretty clear how he's choosing to go out. However, I'd also be willing to make a huge bet there is zero chance the FB CISO at the time was…
Re: Facebook Wanted NSO Spyware to Monitor Users, NSO CEO Claims (2020)
#4Thanks for the downvotes appreciate it
Re: Facebook Wanted NSO Spyware to Monitor Users, NSO CEO Claims (2020)
#5Re: Facebook Wanted NSO Spyware to Monitor Users, NSO CEO Claims (2020)
#6It's like the one thing universally true about spies is they can never keep it g. As a security guy, this is why you don't get involved with dodgy companies. When the pressure is on, they will pull in everyone they ever spoke to and use you protecting your rep to try get leverage. Pretty clear how he's choosing to go out. However, I'd also be willing to make a huge bet there is zero chance the FB CISO at the time was…
This article is from the last year, so that is also good to note. The most recent issues weren’t that public yet.
Re: Facebook Wanted NSO Spyware to Monitor Users, NSO CEO Claims (2020)
#7Facebook bought WhatsApp in 2014.
Pegasus is built on a WhatsApp vulnerability.
Should Facebook have patched this 4 years ago, rather than try to pay a third party to exploit it?
Re: Facebook Wanted NSO Spyware to Monitor Users, NSO CEO Claims (2020)
#8Wait... This happened in 2017. Facebook bought WhatsApp in 2014. Pegasus is built on a WhatsApp vulnerability. Should Facebook have patched this 4 years ago, rather than try to pay a third party to exploit it?
Plus even soliciting a 3rd party gives you plausible deniability if someone comes asking you if you exploited the flaw yourself. Oh, to be a capitalist in the 21st century is to feel ALIVE!
Re: Facebook Wanted NSO Spyware to Monitor Users, NSO CEO Claims (2020)
#9You may think that case warrants an exception, but it sets a clear precedent and encourages the hoarding of zero-days.
I think it's extremely easy to believe Facebook would launch exploits at users because they already have.
[1] https://nakedsecurity.sophos.com/2020/06/12/facebook-paid-fo...
Re: Facebook Wanted NSO Spyware to Monitor Users, NSO CEO Claims (2020)
#10It's like the one thing universally true about spies is they can never keep it g. As a security guy, this is why you don't get involved with dodgy companies. When the pressure is on, they will pull in everyone they ever spoke to and use you protecting your rep to try get leverage. Pretty clear how he's choosing to go out. However, I'd also be willing to make a huge bet there is zero chance the FB CISO at the time was…
We also have zero evidence the people this guy talked to worked for Facebook. He could have been duped. He could be lying. It could have been two curious employees acting on their own.
What we can say is this guy lacks professional integrity. Throwing potential or actual clients under the bus in public is a sleazy move.