[HN Gopher] U.S. State Department phones hacked with Israeli com...
___________________________________________________________________
U.S. State Department phones hacked with Israeli company spyware
Author : amadeuspagel
Score : 680 points
Date : 2021-12-03 17:05 UTC (5 hours ago)
(HTM) web link (www.reuters.com)
(TXT) w3m dump (www.reuters.com)
| jimnotgym wrote:
| TlDr. Weapons designed to use against baddies can also be used
| against goodies
| maltalex wrote:
| I don't understand the focus on NSO in these stories. If U.S
| State Department personnel in Uganda were shot from an M-16,
| would the headline mention "an American arms manufacturer"? No,
| because it's ridiculous.
|
| For better or worse, NSO's product is a weapon. How is it any
| different from an M-16? Where is the outrage towards the people
| who used this weapon against the State Department?
| user-the-name wrote:
| > No, because it's ridiculous.
|
| Is it really.
| dang wrote:
| Could you please stop posting unsubstantive and/or flamebait
| comments to HN? You've been doing it a lot, unfortunately,
| and we ban that sort of account.
|
| https://news.ycombinator.com/newsguidelines.html
| sangnoir wrote:
| NSO doesn't "sell" cyberweapons - they lease them and provide
| logistical support (including running the cloud
| infrastructure). This confers a lot more knowledge on where and
| how the weapons are used, and adds a lot more culpability.
|
| The situation is less "M-16 and rounds sold once-off", and more
| of a turnkey armed drone (or surveillance drone, if you're
| charitable) service provided to governments, where the
| missiles, fuel, and airbases are provided by a private party on
| an ongoing basis. It's more of a tailored service, than a sale
| of goods.
| bell-cot wrote:
| In National Security contexts, the "get angry at the weapon
| seller" response is very strongly correlated with how advanced
| (in technology, power, and scarcity) the weapon is perceived to
| be.
|
| For an "average soldier" weapon, such as an M-16 - $Company
| isn't likely to catch much grief - unless they're selling a
| considerable quantity of them, or to an extremely notorious
| buyer. Similar for a cyberweapon - but an "everyday" one, which
| wouldn't be a big surprise for a C-list ransomware group to
| use.
|
| Vs. NSO's stuff seems to be the sort of top-tech goodies which
| A-list nation states use to maintain & enjoy their A-list
| status. Whether any actual harm results from this incident...
| publicly letting a bunch of "the wrong sorts" into that
| exclusive clubhouse is getting NSO into really deep do-do with
| "the regulars".
| tschwimmer wrote:
| Perhaps you are unaware of the nature of global arms control
| and how much work goes in to prevent scenarios exactly like
| this.
|
| Small arms proliferation is much harder to control, but yes
| there has been extensive reporting on Operation Fast and
| Furious where US gun sellers were allowed to sell to Mexican
| cartels under ATF supervision. [0] Those guns were used against
| both US and Mexican citizens, including fatally against 1 US
| Border Patrol Agent in 2010.
|
| Looking farther back, during the Falklands war in the early 80s
| there was much controversy over the Exocet anti-ship missile,
| which was manufactured and sold by France. When these missiles
| were successfully used against British warships near the
| Falklands, Britian successfully lobbied for France to stop
| selling them to the Argentinians.[1]
|
| So yes, it's actually very common to put the responsibility of
| how their products are used on arms manufacturers. It's a good
| thing and it keeps the world safer.
|
| [0]https://en.wikipedia.org/wiki/ATF_gunwalking_scandal
| [1]https://www.bbc.com/news/magazine-17256975
| walrus01 wrote:
| It's my understanding that NSO runs centralized command and
| control servers that their "clients" are granted access to, for
| both the on-device payload installation and also data
| exfiltration.
|
| They do not give the software to their clients to go use
| somewhere in the world fully independently (self hosted payload
| dropper, C&C, etc)
|
| They're a direct participant in the network traffic. Unlike a
| dumb purely offline piece of hardware like a M4 rifle or
| similar.
| montblanc wrote:
| So selling an F-15 to the Saudis (like the U.S is doing in
| droves) is more morally justifable because what exactly..?
| After the plane is sold the Saudis are independent with it?
| (they aren't really btw. I'm sure there's maintenance and
| buying parts etc).
| walrus01 wrote:
| I am also not in favor of selling advanced weaponry to the
| saudis or pretty much any non-democratic regime. The US has
| a very poor historical track record of supporting strongmen
| that do brutal things. Pinochet. Suharto. MBS. I could
| write a very long list.
| phatfish wrote:
| None one else was talking about F-15s or drones in this
| thread. The only mention was of weapons that even civilians
| can buy is some countries and do not come with a support
| contract attached.
|
| IMO the US selling F-15s or drones to the Saudis is very
| similar. The US shouldn't be supporting the Saudis
| murdering civilians with F-15s, and Israel should not be
| supporting hacking tools that enable other governments (or
| private organizations) to murder people they dont like.
| [deleted]
| montblanc wrote:
| I find it very unlikely they knew about state department
| phones. Why bring up M4 rifles all the time? That's not how
| the U.S or any other arms seller makes money at all. The big
| money comes from planes, drones, etc. 350 billion worth over
| 10 years just to Saudi Arabia alone https://en.wikipedia.org/
| wiki/2017_United_States%E2%80%93Sau....
| Sporktacular wrote:
| Speak plainly. Are you suggesting this is a company being
| unfairly singled out just because it's Israeli?
| montblanc wrote:
| It being Israeli is definitely a big part of why this story
| is so huge. Why do you think it's making huge headlines then
| - what's your theory? The fact that 8 American diplomats got
| their phones hacked?
| jimbob45 wrote:
| I'm in agreement with you. I don't see any indication that the
| Israelis specifically made this weapon to target US interests,
| nor do I see any indication that the Israelis are
| discriminating between the US and any other nation, nor do I
| see anything that leads me to believe that we aren't
| potentially using this ourselves against other nations.
|
| Fuck NSO, for sure. But I'm just not sure Israel should be held
| accountable for the actions of a private corporation with no
| apparent political motivations, just as in your M-16 example.
| tomjakubowski wrote:
| The Israeli state regulates the export of NSO Group's
| software. So yeah, they do have some responsibility here.
|
| https://www.haaretz.com/israel-news/tech-news/israel-will-
| re...
| jimbob45 wrote:
| If it's specifically, then I'd agree with you. If it's just
| broadly (such as how the US unilaterally doesn't trade with
| countries currently in the midst of war), then I'm not so
| sure.
| dmix wrote:
| It's more like a PMC ala Wagner than selling an M-16. They
| essentially run the technical side of operations and provide
| the talent.
| brendoelfrendo wrote:
| Ah, I like this analogy. NSO's role isn't so much selling a
| weapon as it is selling "cyberwarfare as a service."
| montblanc wrote:
| > I don't understand the focus on NSO in these stories
|
| What's to understand ? It's an Israeli company. Enough said. If
| it was an American or German company no one would have cared.
| Why the obsession with Israel? It's a complicated phenomena. I
| think it has to do with the role Jews played in Christianity
| (Jesus' death etc) and the holocaust but that's just my 2
| cents.
| Tronno wrote:
| Israel is ostensibly a Western ally, yet they sell weapons
| that are used to attack Western nations and their citizens.
| Can you see why some people might consider that a problem?
|
| Your accusations of anti-semitism are unwelcome and without
| merit.
| mola wrote:
| Uganda is not a US enemy. NSO is a disgusting money grab
| and a threat for democracies. But, they never sold to any
| nation which is a US enemy. Uganda is not a US enemy.
| Israeli government, which grants the export licenses is not
| that dumb.
|
| Allies spy on eachother all the time. that's a given any
| sovreign state knows and takes into account.
| ryneandal wrote:
| There are also numerous instances of their intelligence
| forces spying on us, an ally.
|
| - https://apnews.com/article/israel-jonathan-pollard-
| espionage... -
| https://www.politico.com/story/2019/09/12/israel-white-
| house...
| xxpor wrote:
| Everyone spies on everyone, no one is actually shocked by
| that. The US does it too (see the interception of Angela
| Merkel's phone calls...)
|
| The key is you don't get caught doing it, because it
| removes plausible deniability.
| montblanc wrote:
| You are being a demagogue here. It's 8 phones that were
| hacked, by someone in Uganda - a friendly country to the
| U.S, with NSO probably not knowing and Israel as a state
| definitely not knowing. Was any of the 8 Americans harmed
| physically btw?
|
| I don't care if it's unwelcome to you...I call it as I see
| it and you're not doing a great job convincing me
| otherwise.
| gowld wrote:
| Is there another popular spyware company being used by rogue
| states to perform terrorist attacks?
| montblanc wrote:
| What is your definition of rogue states? The U.S sells
| weapons to the Saudis in hundreds of billions https://en.wi
| kipedia.org/wiki/2017_United_States%E2%80%93Sau....
|
| So I should believe the U.S thinks it's OK to sell F-15
| planes but not OK to sell software? I'm gonna assume yes,
| there are probably other players in cyber warfare who sell
| to these countries, probably also the U.S.
| JumpCrisscross wrote:
| > _the U.S thinks it 's OK to sell F-15 planes but not OK
| to sell software?_
|
| The U.S. thinks it's okay to sell F-15s that don't attack
| Americans and not okay to sell software that attacks
| Americans. As a, granted, American, I'm not seeing the
| incoherence.
| montblanc wrote:
| Attacks Americans? Come on now, don't go overboard sir.
| JumpCrisscross wrote:
| > _Attacks Americans?_
|
| I was delineating why the U.S. is fine with selling
| weapons to _e.g._ Saudi Arabia but would not be happy
| about those same weapons being sold by Russia to Iran.
| You seemed confused on that point. There isn 't a grand
| philosophy. It's international relations. It's anarchy.
| The U.S. government promotes American and allied
| interests.
|
| Separately, yes, if you're hacking the State Department,
| you're attacking the U.S. This is consistent with how
| cyberterrorism is treated by DNI since at least 2014.
| montblanc wrote:
| This wasn't done by NSO knowingly. I have no reason not
| to believe them on that, they have a financial and
| strategic interest not to piss America off that bad. Also
| - Uganda is not Iran, it's a friendly country.
| Unfortunately someone there decided to use it against
| American diplomats which is unfortunate.
| KMag wrote:
| > This wasn't done by NSO knowingly.
|
| In the past month or so, there was a front page story on
| HN about NSO and a journalist, detailing evidence that
| NSO-controlled servers served up the exploit to the
| journalist's phone. This suggests that the NSO group has
| less of an arms-length relationship with their clients
| than they let on. It seems that at least for some
| clients, they're running some variant on exploits-as-a-
| service.
| montblanc wrote:
| That still doesn't mean they knew about this. How would
| they even know it were American phones? Its very possible
| it were some IPhone with a Ugandan sim card. How do you
| know who's using it - do the Ugandans tell you? It's a
| very real possibility NSO servers simply show some
| Ugandan number. I have no more knowledge on this than
| anyone here but I don't find it realistic NSO would take
| this chance.
| JumpCrisscross wrote:
| > _doesn 't mean they knew about this_
|
| Mitigating but not exonerating. (Also, unknown and
| possibly unknowable.) NSO are still selling cyberweapons
| hitting the United States. If they didn't give a shit
| about keeping an eye on their kit, that's a negligent gap
| in oversight by Jerusalem.
|
| It's a good thing we have a talking-not-shooting
| relationship with Israel. The U.S. would be within its
| rights to launch a proportional counterattack were that
| not the case. If Israel doesn't deal with this properly,
| there's a decent chance we'll see calls for criminal
| penalties and targeted sanctions.
| boomboomsubban wrote:
| DarkMatter seems to have done basically the same as NSO,
| except with an even more explicit US connection.
| bauruine wrote:
| > DarkMatter is under investigation by the F.B.I. for
| crimes including digital espionage services, involvement
| in the Jamal Khashoggi assassination, and incarceration
| of foreign dissidents.[28] The F.B.I. is also
| investigating current and former American employees of
| DarkMatter for possible cybercrimes.
|
| Doesn't look like they only target Israeli companies.
| loeg wrote:
| The US provides substantial financial, military, and
| political aid to Israel, that it does not provide to Germany.
| montblanc wrote:
| The U.S basically protects the whole of Europe by
| subsidizing NATO. It's probably in the trillions. Sorry but
| Trump had a point there. What it gives Israel is peanuts
| compared to that. Without U.S support to Europe who knows
| what happens, maybe the Russians and Chinese start looking
| at Europe as easy prey to pick on. Also the obsession with
| Israel isn't a uniquely American thing, it's the same in
| France and Canada and Germany and basically any Western
| country.
| mullingitover wrote:
| The attacks on NATO are such a weird thing. US support of
| NATO isn't a charity operation, there are strategic and
| economic benefits to the US from NATO participation that
| greatly exceed the expenses.
|
| If the argument is that the United States shouldn't be a
| global power, that it should dismantle the US military
| and be a demure, multilateral player in the international
| space, sure, attack NATO. However, attacking NATO while
| saying the US should be a _stronger_ international player
| is contradictory.
| montblanc wrote:
| I'm not attacking NATO. I'm saying the U.S is subsidizing
| Europe's defense in the trillions (if we count since WW2
| end). It could be beneficial to the U.S, or not. I'm only
| saying U.S aid to Israel is not unique and is peanuts
| compared to the NATO subsidy. People here like saying
| they are super focused on Israel because of the 3 billion
| annual subsidy the U.S gives to Israel. I call bullshit
| on that.
| mullingitover wrote:
| The NATO relationship effectively turns Europe into
| vassal states - we don't have German or French bases on
| US soil, only the US gets that out of NATO. So it's a
| 'subsidy' only in the sense that the US is protecting its
| property.
|
| People get angry about the Israel aid not because of the
| volume of funding, but because of the human
| rights/colonialism problems that the US subsidizes. I
| personally feel that way, but at the same time I
| understand the realpolitik deal with Israel - I believe
| the purpose of keeping Israel there is to prevent some
| version of the Ottoman Empire from re-forming.
| whimsicalism wrote:
| Only if you count general American military spending as
| supporting Germany more than Israel?
|
| Otherwise, US absolutely provides far more military
| spending to Israel than to Germany, it's not really
| comparable.
| montblanc wrote:
| > Only if you count general American military spending
|
| Of course I do. Europe has no real army. France kinda has
| an army and the U.K got out. If America didn't provide a
| military umbrella Europe would need to actually build a
| real army (Europe's contributions to NATO are pitiful).
| How much would it cost the Europeans to do that? Going
| back since WW2 that's easily in the trillions.
| whimsicalism wrote:
| Given that the US actively engages in military operations
| in defense of Israel, I would say that it not reasonable
| to attribute a larger share of the spending to Germany
| rather than Israel?
| montblanc wrote:
| What military operations would those be?
| xxpor wrote:
| Stuxnet and the intervention in Syria just off the top of
| my head.
| montblanc wrote:
| The intervention in Syria? That's a military operation
| done by the U.S for Israel? How did you come up with
| that? If there's no Israel tomorrow the entire region is
| still messed up with possibly tens of millions of new
| refugees flooding Europe. It's not all about Israel.
| FDSGSG wrote:
| As opposed to the absolutely massive US military presence
| in Germany?
| trasz wrote:
| There is no military danger Europe would need protecting
| from. The only thing US is subsidising is itself: all
| those trillions go directly back to US and benefit US,
| not Europe.
| FDSGSG wrote:
| There are currently around 35000 American service members
| deployed to Germany.
| trasz wrote:
| That's Germany providing its land, for free, to the US.
| Those forces are not protecting Germany from any existing
| military danger, they are just projecting US power and
| protecting its interests.
| fortran77 wrote:
| The US rebuilt Germany and continues to support them to
| this day militarily.
| snowwrestler wrote:
| U.S. weapons manufacturers receive a lot of criticism too, both
| domestically in the U.S. and internationally.
|
| The comments here focus on NSO because the story is about what
| NSO did. This is computer tech kind of community so you're
| going to see more computer weapon stories here than stories
| about improper use of rifles.
| montblanc wrote:
| The U.S sells super sophisticated weapons such as attack
| drones, F-15s or nuclear submarines. The tech behind these
| things is probably super interesting and there's a lot of
| software involved. If you look at the comments here, around
| 90% of them don't care about the tech at all but focus on
| bashing Israel. This isn't a tech story.
| chucksmash wrote:
| It would certainly be a news story if someone used a U.S.
| built submarine to attack the U.S. State Department.
| montblanc wrote:
| You do realize it was Ugandans who actually ordered the
| hack yes?
| hxkandbe wrote:
| Uganda used a US submarine to hack the US State
| Department?
| hxkandbe wrote:
| Is this a joke?
| fnordfnordfnord wrote:
| Unlike a firearm which has no intelligence or software, NSO
| retains significant control over their product.
| montblanc wrote:
| U.S drones and F-15s don't have software?
| sva_ wrote:
| > For better or worse, NSO's product is a weapon. How is it any
| different from an M-16? Where is the outrage towards the people
| who used this weapon against the State Department?
|
| It is highly unlikely that NSO group actually gives out their
| exploits, based on what we know about previous exploitations
| that have become known. It's more like they offer an interface
| to execute their exploits on a given target. The fact that they
| can block entities from using their service, after having had
| access to it (like they supposedly did in this case), very
| strongly supports this hypothesis. Hence they're offering a
| service, to use weapons for (or rather, in the name of) some
| (government) entity that pays them money to do so.
|
| Imagine bombing-as-a-service, as an instance. That's much more
| like it, and your argument doesn't hold in that case.
| JumpCrisscross wrote:
| > _don 't understand the focus on NSO in these stories. If U.S
| State Department personnel in Uganda were shot from an M-16,
| would the headline mention "an American arms manufacturer"? No,
| because it's ridiculous._
|
| No, because it isn't novel, it's not wide reaching, it's not at
| arm's length and it cannot be stopped.
|
| Stuxnet, a novel American-Israeli cyber weapon, purpose built
| to hit Iran, was _absolutely_ billed as such. And it was
| received differently, by Iran, than would be _e.g._ an
| American-made gun fired by Iraqis at Iranian surrogates.
|
| NSO is making and selling cyberweapons. They're doing it now.
| These weapons are hitting the U.S. government and its allies to
| an unknown extent. And they can be turned off, right now, if
| Jerusalem orders it.
|
| U.S. persons being shot in Uganda by Kalashnikovs are none of
| these things. It's not novel. Nobody wonders if the Ugandans
| are going to show up, guns blazing, in Arlington. And Moscow
| can't remotely disable the guns.
| [deleted]
| octopoc wrote:
| Unlike an M-16, hacks can be conducted remotely, they can be
| used to plant evidence, conduct blackmail, and lots of other
| things where most people would never know a hack was involved.
|
| Also, there's outrage towards NSO because Israel is supposedly
| an American ally. Israel needs American support, and yet Israel
| freely allows Israeli corporations to sell services American
| enemies. And this isn't an isolated company--there are other
| Israeli hacking companies that target Americans, such as Black
| Cube.
| montblanc wrote:
| Uganda is not an American enemy.
| brendoelfrendo wrote:
| Weapon merchants get flack all the time for selling their wares
| to... we'll call them "rivals," but it could be any state or
| organization not in the US's sphere of influence.
|
| NSO gets particular flack because they're inextricable from the
| weapon they sell. If an M-16 is used to shoot someone,
| provenance is probably harder to prove; weapons change hands
| all the time, or are smuggled to ne're-do-wells via the black
| market. But everyone using Pegasus, as far as we know, is an
| NSO client; NSO made the choice to provide that software,
| including NSO support and NSO services.
| eecc wrote:
| Nope, that's a bad analogy. A manufacturer that produces and
| sells thousands if not millions of items won't be deemed as
| complicit as one building a nuke that somehow lands in your
| enemies' lap.
|
| That's pretty obvious and it's disingenuous that you're trying
| to steer the conversation in that direction
| boomboomsubban wrote:
| >In a public response, NSO has said its technology helps stop
| terrorism and that they've installed controls to curb spying
| against innocent targets. For example, NSO says its intrusion
| system cannot work on phones with U.S. numbers beginning with the
| country code +1.
|
| So the point is to stop terrorism and to do that they've
| immediately ruled that all Americans aren't terrorists. That
| doesn't seem like a good metric of determining if someone is a
| terrorist, and makes me doubt their other controls are any
| better.
| JumpCrisscross wrote:
| > _the point is to stop terrorism and to do that they 've
| immediately ruled that all Americans aren't terrorists_
|
| The alleged point is to sell software that stops terrorism.
| Pissing off America is a good way to stop being able to sell
| your software.
| discreditable wrote:
| Funny enough this reminds me of the ransomware that doesn't
| work if a cyrillic keyboard is installed.
| https://krebsonsecurity.com/2021/05/try-this-one-weird-trick...
| fmajid wrote:
| If you are a Russian hacker, you probably don't want to piss
| off a Russian mobster who has the capability to take you out,
| and the contacts within Russian intelligence to identify you.
| fibbberMEN wrote:
| Someone else linked that one, it's hilarious and unsurprising
| really. Lots of people purposefully avoid certain OSes
| (mostly linux distros) as well out of respect NOT because of
| population/userbase of the OS. Lots of discussion on
| worm/trojan development forums over the years.
| snarf21 wrote:
| "We promise we don't work on numbers with +1" :wink: :wink:
| comrh wrote:
| NSO has repeatedly shown that their statements are pretty much
| worthless. It's just damage control. I wouldn't put any stock
| in the "we avoid +1 numbers" to even be real.
| boomboomsubban wrote:
| > I wouldn't put any stock in the "we avoid +1 numbers" to
| even be real.
|
| That part I believed. Setting up their software to not target
| the US seems like the kind of move they'd make. Claiming it's
| so they don't target innocent people is bullshit.
| bogwog wrote:
| Seriously, they're pretty much the Mark Zuckerberg of their
| industry.
| submeta wrote:
| I'd rather compare Zuckerberg to the Sackler family who
| knew how addictive and harmful their painkiller Oxycotin
| was, yet ignoring all evicence, making billions of dollars.
| Zuckerberg knows how bad Facebook and Instagram is, how
| harmful to individuals and society alike, yet ignoring that
| and making billions.
|
| Edit: Replaced ,,social media" with ,,Facebook and
| Instagram"
| dylan604 wrote:
| Why did you feel the need for the edit? I would agree
| with the blanket use of social media. Twitter is no
| better. Do we know enough about the inner working of
| TikTok to know they aren't doing similar?
| indymike wrote:
| That is not fair to Mark Zuckerberg.
| rory wrote:
| They're pretty much the General Butt Naked of their
| industry.
| [deleted]
| notsureaboutpg wrote:
| America (who are effectively the world police) have decided to
| have pretty poor metrics to determine who is a terrorist, so
| they set the precedent for this kind of stuff.
|
| Random government officials in Iran cannot be considered
| terrorists because of a an embassy hostage situation from 50
| years ago during a revolution in the country. If they can, then
| so can nearly every Chinese government official, every current
| Russian government official who was high up in the USSR, every
| current official in Iraq and Afghanistan, half the political
| leadership of Lebanon, Vietnam, etc.
| md_ wrote:
| As an obvious statement: I think this should be interpreted
| similarly to some ransomware not infecting devices with RU
| keyboards: it's just about avoiding difficult regulatory
| environments.
|
| The analogy, of course, goes further. Though unlike most
| ransomware companies, NSO has British and American VC funding.
| shireboy wrote:
| Most people don't know that the first bit of an area code is
| the evil bit. https://en.wikipedia.org/wiki/Evil_bit
| s_dev wrote:
| So I just have to buy a US phone to evade detection from NSO?
| And why didn't that logic work for US State Dept phones?
|
| I'm honestly of the opinion there is nothing that NSO can say
| that isn't outright lying. This isn't a normal company in
| anyway.
| shmatt wrote:
| * A US Phone will route your call via NSA servers[1], so yeah
| thats OK from the US governments side
|
| * Publicly at least, NSO acknowledges there are state level
| agreements, the latest one with France, to block entire
| country codes from Pegasus (in return, France has stopped all
| legal action against NSO)
|
| * According to Israeli Channel 12 reporting on this tonight,
| the official NSO response also includes the statement that
| the accused numbers in the report were not +1 numbers. Their
| so called "customers" were targeting US government employees
| using African area codes. NSO claim they have completely
| disconnected said customers from the system
|
| [1] https://en.wikipedia.org/wiki/Room_641A
| dkjaudyeqooe wrote:
| Phone hardware is not tied to any particular number.
|
| So you just need a SIM with a US number and use that for all
| your evasion needs.
| _jal wrote:
| Yeah, this.
|
| They started off with the arrogance of a liar who thought
| they were immune from consequences. Now they're looking more
| like the kid who is actually in trouble only now realizing
| nobody trusts them to identify the sky color, let alone
| defend themselves.
|
| Anything and anyone coming out of that shop is tainted.
| smnrchrds wrote:
| I remember reading that some Russian (private sector)
| computer viruses did not attack computers whose language and
| locale were set to Russia. It's never about ethics. It's
| always about making as much money as possible without pissing
| off powerful people and entities.
| madars wrote:
| Yep, Krebs on Security wrote "Try This One Weird Trick
| Russian Hackers Hate" --
| https://krebsonsecurity.com/2021/05/try-this-one-weird-
| trick...
| prox wrote:
| I had this with a Chinese app. Works well on a Chinese
| language phone, downloads an extra package if not.
| patrickyeon wrote:
| Crudely, we would say "don't shit where you eat". I've
| heard from the early (as in, 80's) hacking days some of the
| people in the US would never hit targets in their own
| state, as there wasn't good federal-level enforcement nor
| inter-state collaboration. Of course that would backfire
| today because you're immediately commiting crimes across
| state lines...
| diebeforei485 wrote:
| > And why didn't that logic work for US State Dept phones?
|
| These were Foreign Service officers stationed in Uganda, so
| their phones had local Ugandan phone numbers. Some of them
| were working out of DC but - given the nature of the State
| Department (which is like America's foreign affairs
| department) - probably traveled very frequently and so
| maintained a Ugandan phone number as well, to save on roaming
| fees when making calls in Uganda (saving money for the
| taxpayer) and also so Ugandan officials can contact them
| easily.
|
| This is not unlike Apple hardware engineers who travel
| frequently to China and have a Chinese number in addition to
| their main US number, so people in the factory can
| communicate with them easily.
|
| > So I just have to buy a US phone [number] to evade
| detection from NSO?
|
| This is NSO's claim. Presumably because they want to make it
| difficult for anyone to sue them in a US court. It's
| plausible but I don't necessarily believe them either.
|
| I want this company bankrupted out of existence, personally.
| Apple's lawsuit against them may well result in that outcome.
| boomboomsubban wrote:
| >And why didn't that logic work for US State Dept phones
|
| They had Ugandan numbers, as they lived in Uganda.
| Apofis wrote:
| These people are in for a world of hurt, the State Department
| tells the CIA what to do.
| [deleted]
| JumpCrisscross wrote:
| > _State Department tells the CIA what to do_
|
| Your broader point is correct, but no, it doesn't. The CIA is
| an independent agency [1]. It reports to the DNI [2].
|
| [1] https://en.wikipedia.org/wiki/Independent_agencies_of_the
| _Un...
|
| [2] https://en.wikipedia.org/wiki/Director_of_National_Intell
| ige...
| Apofis wrote:
| Yes, but who dictates where and how they can play overseas?
| JumpCrisscross wrote:
| > _who dictates where and how they can play overseas?_
|
| The Director and Deputy Director of the CIA.
| the_only_law wrote:
| Heh, that showdown sounds like it would make for a hell of a
| book decades later.
| TriNetra wrote:
| NSO has a deal with US Telecom to grow its market share
| throughout the world and hence the +1 statement. /s
|
| Maybe NSA wants every important call goes through USA network
| (and hence a deal with NSO) - makes the job easier for three
| letter agencies.
| SamuelAdams wrote:
| Reminds me of how some ransomware looks for if your default
| keyboard language is Russian. If so then it exits, doing
| nothing.
| tut-urut-utut wrote:
| OK, so the best way to protect privacy is to get US-based
| phone number and install Russian keyboard as a default.
| TriNetra wrote:
| And it should have a list of sites blocked by Chinese
| regime downloaded as discovered by Lithuania [0], for even
| grater privacy.
|
| 0: https://news.ycombinator.com/item?id=28616683
| turings wrote:
| I would not be surprised if it's an Israeli company behind using
| NSO to steal it.
|
| There's Lusha too and it's stealing info in plain sight. It's
| basically stealing information and completely violating any GDPR
| or Californian law. Here is a good spiel of the whole thing tying
| their _founder_ to all the apps that steal information:
| https://wwws.nightwatchcybersecurity.com/2020/02/20/another-...
|
| And they just raised $200M to continue spying. The investors
| probably have no clue https://techcrunch.com/2021/11/10/lusha-a-
| crowdsourced-data-...
|
| If we don't penalize crap like this, you encourage. And then it
| booms somewhere else.
| entom wrote:
| Holy shit! How's Simple Apps stuff not shutdown by GDPR? Either
| Simpler App is lying (thus GDPR kicks in) or Lusha. This is
| insane
| jiveturkey wrote:
| uh oh. That's a paddlin'
| kyahsworld wrote:
| I have credit card data information + MSR HID + but i dont know
| how to read or do the code metric etc in order to retrieve track
| 1 or 2
| walrus01 wrote:
| I'm waiting for the day that the US declares a foreign
| corporation as an "enemy combatant", as they have done with
| foreign citizen wahabbist jihadis and US citizens such as Anwar
| Al-Awlaki.
|
| Given the extent and depth of US-Israeli cooperation and ties,
| the precedeing theoretical is probably going to remain in the
| realm of theoretical.
| fmajid wrote:
| That's pretty much what they did with NSO, which is getting the
| Huawei treatment:
|
| https://www.theregister.com/2021/11/03/us_sanctions_spyware/
|
| reportedly, this has created havoc on NSO, since for instance
| none of the cloud providers can sell services to them to host
| their zero-days, among other logistics headaches. Their
| recently hired CEO resigned.
| BrianOnHN wrote:
| What's the consequence for destabilizing governments
| worldwide? Logistics headaches? Got it.
| fmajid wrote:
| The NSO guys are in it purely for the money. IIRC there was
| a deal on the cards for some investors to buy the company
| that fell apart because of the sanctions, so the NSO
| founders can no longer cash out.
|
| As for destabilizing governments, they are doing the
| opposite, they are helping authoritarian governments
| worldwide crack down on journalists and dissidents, or
| murder them in the case of Saudi Arabia and Jamal
| Khashoggi. Reportedly, after the Khashoggi murder, NSO
| yanked the Saudi account but was forced to reinstate it by
| Netanyahu who was pursuing diplomatic relations with them.
| lostlogin wrote:
| > I'm waiting for the day that the US declares a foreign
| corporation as an "enemy combatant"
|
| It's particularly interesting to watch as the company is based
| in a country that is a very close ally.
| galimaufry wrote:
| Ignorant question: is Israel literally an ally of the US? I
| know they are not in NATO or 5 Eyes, and I don't _think_ they
| have some other close agreement, like US and Japan.
| DaveExeter wrote:
| Israel is a client state of the USA. They are America's
| enforcers in the Middle East.
| vorpalhex wrote:
| That's factually wrong. Israel is it's own full state.
| shrimp_emoji wrote:
| The relations are green hearts, and the U.S. is
| guaranteeing independence.
| notsureaboutpg wrote:
| They basically declared the embargoed Iranian corporations as
| enemy combatants a while ago, if that's what you mean.
| md_ wrote:
| NSO's PE investors are big-time American and British funds.
|
| Just sayin'.
| bjourne wrote:
| According to Wikipedia, NSO is owned by by its two founders
| Omri Lavie and Shalev Hulio and Novalpina Capital. According
| to Sky News Novalpina Capital is getting liquidated and their
| stake in NSO will be sold to a third party:
| https://news.sky.com/story/pegasus-spyware-owner-
| novalpina-t...
| md_ wrote:
| Right. I can't tell if you're agreeing with me or not. :)
|
| Prior to Novalpina, it was Francisco Partners.
|
| Point being, NSO has received huge amounts of money from
| the kind of people who, well, YCombinator founders seek
| out.
| drusepth wrote:
| Didn't they get pretty close with Huawei when the previous
| president issued an executive order in response to state spying
| fears that:
|
| * banned the sale of any of their phones or networking products
| in the US
|
| * banned US companies selling product to Huawei
|
| * cut funding to wireless carriers using Huawei equipment
|
| ...and then pressured allied countries to do the same?
| goodpoint wrote:
| > Didn't they get pretty close with Huawei
|
| No, given that jihadists were kidnapped, tortured and
| murdered - all of this illegally.
| walrus01 wrote:
| The investigation into Huawei was going on for many years
| prior to 2016. It's not exactly an initiative of the previous
| president.
|
| I sat in briefings about Huawei and ZTE in 2007. Regretfully
| can't say more.
| deathhand wrote:
| Are you personally upset about the clear intelligence
| failures and extrfiltration of protected information?
|
| I've grown up watching this unfold and I'm shocked that the
| power groups seem to be so ineffectual at times that it's
| laughable(but that may be by design...)
| walrus01 wrote:
| It's an absolute shitshow from top to bottom. The people
| who know what they're doing in intelligence/counter-
| intelligence agency infosec/netsec (and within major DoS
| and DoD contractors) have been fully aware and ringing
| the alarm bells for years. The technologically
| unsophisticated politicians have been mostly ignoring it.
| adamrezich wrote:
| how much of the ignorance is willful?
| afterburner wrote:
| Just declare them a terrorist organization.
| starik36 wrote:
| I thought the exploited holes were patched by iOS at some point.
| How are these phones still getting hacked?
| 14 wrote:
| In past exploits were used for jailbreaking. Now they can be
| sold for 6 figures. The incentive to report vulnerabilities or
| even use them casually for jailbreaking has gone way down. I
| think the only way would be for Apple to offer 6 figure pay
| outs for the exploits. Maybe they could get a tax write off.
| odiroot wrote:
| Exploits are now a multi-billion dollar market. And iPhones can
| be obtained worldwide. You just need one person with
| questionable morals, good hardware hacking skills and a need
| for some hefty payout.
|
| There's a lot of buyers, Five Eyes, China, Russia and naturally
| companies like NSO.
| kitsunesoba wrote:
| People are notoriously bad at keeping their devices up to date,
| with some even intentionally disabling updates. This can be
| prevented by the IT department having MDM profiles with strict
| update enforcement in place, but I don't have much hope that
| the IT department of any given US government office is
| particularly capable or competent.
| brynx97 wrote:
| The article doesn't say if they were personal or work
| provided phones. Many people living/working overseas have
| work and personal phones. Also, almost all of those with
| personal phones get a local SIM, so they'd get a local non-US
| (not +1) phone number. I used to be an IT admin with DOS
| overseas. Updates were enforced, and phones were disabled if
| they were not upgraded to the most recent version. Starting
| in about 2019, mobile device security went into overdrive and
| is very serious now. Additionally, the MDM profiles are quite
| limiting, so this pushed most people to get personal phones.
| A huge pain for records retention.
| zibzab wrote:
| Because there is a never-ending supply of vulnerabilities in
| our smartphones.
|
| A system this complex can never be secure no matter what
| google/apple PR dep claims.
| ryneandal wrote:
| There's always another zero day
| mjamil wrote:
| Is anyone working on a microkernel design for privacy-sensitive
| devices (like phones) that would prevent outright this class of
| kernel-level arbitrary code execution exploits? We're stuck with
| iOS and Android for the foreseeable future, but is there hope
| that we'll get this right some day?
|
| Actually, would a microkernel design even be sufficient? Given
| that hackers exploit deserialization, memory safety, and variable
| type confusion issues, there's still plenty of avenues for data
| corruption and data leakage.
| fulafel wrote:
| I'm not convinced microkernels are the answwr but we do have
| QubesOS.
| eightails wrote:
| Though currently Android-based, grapheneos is planning to move
| towards a microkernel + virtualisation model eventually. I'd
| imagine this is several years away at least, though.
|
| https://grapheneos.org/faq#roadmap
|
| There's also sel4, a security focused version of the l4
| microkernel which is apparently one of the only formally
| verified kernels.
|
| https://sel4.systems/About/
| junon wrote:
| Yep, a number of people are, myself included. OSDev channels
| have a few people who talk about it. The Fuchsia folks are
| around, too, and are quite friendly people. They probably have
| the most hopeful chance of a widespread release, though
| admittedly I worry about the affiliation with Google getting in
| the way of pro-consumerism. Just my opinion though.
| kevingadd wrote:
| User-space ACE would still be enough to do something like this.
| All sorts of user-space apps have the relevant permissions and
| are not secured against attacks to the necessary extent to stop
| a state level actor.
| bri3d wrote:
| Many of the kernel issues exploited in iOS are caused
| indirectly by its microkernel architecture, namely, the use of
| "ports" for kernel to kernel and kernel to user land IPC. For
| example: https://bugs.chromium.org/p/project-
| zero/issues/detail?id=21... .
|
| Microkernel vs monolithic kernel has little to do with this,
| IMO. The main issues are asynchronous complexity and memory
| safety.
|
| Also, a lot of your most sensitive data lives in userland. If
| someone gets access to the iMessage sandbox and the message
| database files, that's your most sensitive and privileged data
| gone, no kernel touched.
| stefan_ wrote:
| And the userland is the worst possible combination of
| technology imaginable for this purpose - a memory unsafe
| language with a ton of magic dynamic features. You get the
| horrible serialization issues from Java & Ruby with the same
| old heap, stack and integer overflows we've come to love in C
| and mix in some of the runtime control flow from C++.
| CameronNemo wrote:
| The Intel ME runs a microkernel but it is still exploitable
| (even if you "clean" it).
|
| SEL4 and Fuchsia seem to have a security focus, but whether
| that results in real world difficult to exploit devices is
| unclear.
| fsflover wrote:
| Perhaps something like this:
| https://www.crowdsupply.com/sutajio-kosagi/precursor.
|
| Or, just use Linux on the smartphone and harden it with a
| smartcard (Librem 5).
| Raqbit wrote:
| Google is, with Fuchsia: https://fuchsia.dev
| apayan wrote:
| I'm not aware of any microkernels for phones (I'm not sure that
| would help either), but Android has been sandboxing more and
| more processing [1] and started using some Rust at the system
| level [2] ever since the stagefright bug [3].
|
| 1: https://android-developers.googleblog.com/2019/05/queue-
| hard...
|
| 2: https://security.googleblog.com/2021/04/rust-in-android-
| plat...
|
| 3: https://en.wikipedia.org/wiki/Stagefright_(bug)
| vinniejames wrote:
| They shouldn't have anything to worry about, unless they have
| something to hide
| FredPret wrote:
| Seems like not-the-smartest move for Israel to mess with one of
| the few powerful entities that desires its continued existence
| ElDji wrote:
| and the one entity that give it wagons of usd.
| fnordfnordfnord wrote:
| Or the smartest move. They probably own more politicians than
| the NRA, the pharma ind, and and the aerospace ind combined.
| JohnWhigham wrote:
| This is just another incident in a long list that goes back
| decades of Israel getting carte blanche to do whatever they
| want to the US with little to no repercussion. The most famous
| probably being USS Liberty
| (https://en.wikipedia.org/wiki/USS_Liberty_incident)
| l33tbro wrote:
| Why would Israel be allowed to do whatever they want?
| theknocker wrote:
| Exactly, genius.
| kevingadd wrote:
| https://en.wikipedia.org/wiki/American_Israel_Public_Affair
| s...
| [deleted]
| dr-detroit wrote:
| There is 0 popular support for Israel and their "religion of
| peace". Biden got in soooo much trouble for saying he would
| divest during the election.
| Dma54rhs wrote:
| Everyone knows already nothing will happen, they will get slap
| on the wrist as usual and show goes on.
| varispeed wrote:
| Isn't the actual problem that a private company is using security
| holes that presumably Apple opened for three letter agencies to
| use?
| redman25 wrote:
| > NSO Group said in a statement on Thursday that it did not have
| any indication their tools were used but canceled the relevant
| accounts and would investigate based on the Reuters inquiry.
|
| Why would they cancel accounts without knowledge of wrongdoing?
| becuz99h wrote:
| They canceled them because "How about this weather, Janet?
|
| That's right, Bob! It'll be a cold one this week. Sportsball is
| next."
|
| What weasel words?
| q1w2 wrote:
| Aside from that obvious contradiction - this also indicates
| that the tools they deploy are either NSO hosted or use a
| licensing system to run.
|
| There was a recent Darknet Diaries episode that reported
| evidence that at least _some_ of the NSO tools are hosted
| services.
| shmatt wrote:
| I can't imagine something like this not being in the cloud.
| The potential for a customer to give their local NSA/8200 the
| tool to figure out the 0days used is too large
|
| Pegasus is only as good as its 0days are secret
| [deleted]
| gameswithgo wrote:
| Remember that this group's tools have been used to murder
| journalists, which they are unapologetic about.
| turminal wrote:
| Dead journalists can't close them down, but the US government
| can.
| Eelongate wrote:
| I think that remains to be seen.
| JumpCrisscross wrote:
| > _that remains to be seen_
|
| Oh man, for purely comical purposes I would _love_ to see
| NSO actually believe that.
| Eelongate wrote:
| In principle, America could drop Hellfire R9X sword
| missiles through the cars of every NSO employee. In
| practice, would American politicians have the nerve to go
| to war with NSO, when NSO probably infected all their
| phones years ago? How much dirt do they have on American
| politicians?
| vorpalhex wrote:
| So you think because NSO breached a few state department
| phones that they have the deep dirt on every sitting
| congress member?
| [deleted]
| Eelongate wrote:
| You think the iceberg is coincidentally only as deep as
| what we've presently heard? That we didn't have the full
| story yesterday, but today we definitely do?
|
| Well I hope you're right, but I don't think you are.
| vorpalhex wrote:
| Well how do you know the NSO hasn't replaced the sitting
| US President with a very convincing android?
|
| I mean, they are a very skilled set of engineers. You
| seem to grant them being able to hold onto very powerful
| secrets and use them for active blackmail. You even
| believe they've been operating actively against the US
| government for several years.
|
| If they can do all that, then replacing the sitting US
| president with a very convincing android isn't much
| harder! It is just as likely as the situation you
| propose.
| Eelongate wrote:
| NSO is skilled at hacking androids, not making them. You
| know that; you are arguing in bad faith.
| catlikesshrimp wrote:
| I can believe that a foreign hacking group, who can
| zeroclick the most widely used personal device to obey a
| remote control center, who sells this service to
| totalitarian regimes and to corrupt governments, has
| exfiltrated as much data as they can. They are careful
| enough to cover their tracks as part of the service.
|
| What I cannot believe is you dismiss concern over ongoing
| security risks, however exagerated, by suggesting a head
| of state might have been replaced by an android. Please
| don't troll.
| intunderflow wrote:
| Because the US government is one of the few groups that can put
| real pressure on them and they're in full panic mode
| fabianhjr wrote:
| And simultaneusly:
|
| - not have any indication their tools were used
|
| - canceled the relevant accounts
|
| Which "relevant" accounts if NSO's tools weren't used?
| seoaeu wrote:
| Presumably the full accusation is "Entity ABC used NSO tools
| _for XYZ_ ". So the reaction was to cancel ABC's account
| while NSO investigates whether ABC actually did use the tools
| for XYZ, or whether ABC was only using them for other
| (approved) purposes.
| BrianOnHN wrote:
| Regardless, NSO rules over international law.
| klabb3 wrote:
| Shrodinger's moderation. NSO has this magical zero-knowledge
| technology that:
|
| - When questioned about _a specific malevolent client_
| misusing their data, they cannot be held accountable because
| the client is running the ops and NSO has no access.
|
| - When asked how they ensure that _clients in general_ don 't
| go rogue and misuse (i.e. human rights & international law
| abuse) their service, they assure you they monitor them and
| turn off their access.
| Cyph0n wrote:
| I think it's pretty clear by now that they have 100%
| visibility into the entire exploitation chain for all of
| their customers. Their "official statements" mean nothing.
| christophilus wrote:
| Well, that wasn't predictable at all.
|
| In all seriousness, I hope this finally prompts our agencies to
| push for stronger security and better encryption rather than
| fighting it as they have for so long.
| SavantIdiot wrote:
| The Israel government gets a pass for anything they do. Whether
| it is lying about nukes or what they've done to Palestine. NSO is
| a feather in their cap.
| jjclint wrote:
| Sounds like you and some other "clever" souls have an axe to
| grind with Israel.
| boomskats wrote:
| > "clever"
|
| This is offensive. They outlined how they disagree with the
| Israeli _government_ pretty clearly in their comment.
| voz_ wrote:
| Please don't virtue signal, or state flame wars, or use this to
| posture some kind of agenda.
| birdyrooster wrote:
| Please don't mistake yourself for dang
| devmunchies wrote:
| I'm not seeing any virtue signaling.
| q1w2 wrote:
| These political flame comments don't belong on HN.
| dang wrote:
| Please do not take HN threads further into generic flamewar
| hell. It's not what this site is for, and it destroys what it
| is for.
|
| We detached this subthread from
| https://news.ycombinator.com/item?id=29432721.
| flyinglizard wrote:
| Why are you conflating Israel (a state) and NSO (a fully
| private company, owned by American private equity at some
| point)?
| [deleted]
| ignoramous wrote:
| _The Israeli Ministry of Defense licenses the export of
| Pegasus to foreign governments, but not to private entities._
|
| https://en.wikipedia.org/wiki/NSO_Group#Pegasus
| flyinglizard wrote:
| These export controls for weapons exist in much of the
| western world. Once granted a license, Israel has no legal
| say in how the product is used by the end user.
|
| It's all very routine and standard, not sure why people
| need basic explanations of what government export
| regulation is when the discussion is on Israel.
| [deleted]
| thekid314 wrote:
| It goes much deeper than that. For a while now Israel has
| been using NSO as an incentive for foreign relations with
| authoritarian regimes.
|
| https://www.theguardian.com/world/2021/jul/20/pegasus-
| projec...
|
| https://foreignpolicy.com/podcasts/foreign-policy-
| playlist/h...
|
| https://www.nytimes.com/2021/11/08/world/middleeast/nso-
| isra...
|
| https://www.haaretz.com/israel-news/tech-
| news/.premium.HIGHL...
|
| https://www.irishtimes.com/news/world/middle-east/how-
| israel...
|
| https://www.ft.com/content/24f22b28-56d1-4d66-8f76-c9020b
| 1b5...
|
| https://www.jpost.com/jpost-tech/what-does-the-nso-
| hacking-s...
| [deleted]
| JumpCrisscross wrote:
| > _Why are you conflating Israel (a state) and NSO (a fully
| private company, owned by American private equity at some
| point)?_
|
| Because Jerusalem has the power to stop, or at the very least
| regulate, NSO.
| classified wrote:
| The victims will be pleased to learn that they're all terrorists
| and criminals, as NSO keeps asserting that their spyware is only
| used against those.
| Iwan-Zotow wrote:
| "Hello, dog!" Said tail
| SavantIdiot wrote:
| Slapping down the NSO doesn't fix the problem. We should be glad
| we even know that their software exists, imagine if it was
| completely hidden from the public? The problem is that Apple
| needs to fix this. Security is an arms race, and the more
| visibility we have into where it is weak, the better for
| everyone. To paraphrase the motorcycle repair episode of Winter
| Steele, "You are stronger now for having been fixed." IMHO.
| shmatt wrote:
| Great commentary. The US is hopefully looking into why these
| employees are using iPhones + local SIM. And if that has been
| approved in the past, maybe re-think that
| elliekelly wrote:
| I don't think most Apple customers know or care so despite
| being ostensibly "privacy focused" Apple doesn't have much of
| an incentive to take action.
| fmajid wrote:
| Apple has demonstrated complacency on security issues.
| Stiffing security researchers on bug bounties is just one
| symptom, but so is the fact the market price for iOS exploits
| has cratered compared to Android ones.
| motohagiography wrote:
| Arguably, this is the real use case Pegasus was designed for. A
| government (Uganda) that does not have a large and mature civil
| service that would support a G7 level technical domestic
| intelligence agency went to market for the tools of one (NSO), so
| they can keep tabs on foreign intelligence agents (state
| department staff) in their country. I am not a fan of NSO at all,
| but this case sounds like they're providing sovereignty or
| statecraft as a service to a government that prefers to buy
| instead of build their security capability.
|
| When the game is defined as a competition for how to break its
| rules in the most unexpected ways and with the fewest
| consequences, Uganda appears to have joined in with aplomb. To me
| it's the first time an NSO story doesn't seem like a scandal.
| bjourne wrote:
| The "oh, but everyone is doing it!" argument. I don't for a
| second believe that other countries install spyware on foreign
| diplomats and other peoples phones. What NSO and the Israeli
| government is doing is rotten to the core and unless you have
| evidence of the contrary you cannot assert that other actors
| are doing the same thing.
| jimbob45 wrote:
| I know you're joking but for anyone that's not in on the
| joke:
|
| https://www.bbc.com/news/world-europe-24690055
| bjourne wrote:
| Wow! You found one instance of the US spying on a friendly
| government. That totally justifies NSO leasing spyware to
| authoritarian third world regimes! Carry on folks, nothing
| to see here.
| smoldesu wrote:
| It doesn't justify it, but if we're going to take a
| stance against spyware, we have to take a stance against
| _all_ spyware. That includes the home-rolled stuff that
| the NSA pushes out to Apple and Google.
| triactual wrote:
| No, we don't.
| smoldesu wrote:
| What makes that kind of hypocrisy okay?
| Thorncorona wrote:
| It seems if Israel is receiving money from the US
| government and Israel controls the usage of NSO group
| weapons that are being targeted at the American
| government then there are problems yea?
| smoldesu wrote:
| It's a catch-22. Telling other countries not to spy on us
| while we happily spy on others is a double standard.
| aunty_helen wrote:
| Imagine that sinking feeling in the NSO offices. Uncle Sam's
| coming...
| sixothree wrote:
| You sure about that?
| newbamboo wrote:
| " NSO says its intrusion system cannot work on phones with U.S.
| numbers beginning with the country code +1."
|
| Seems like they just need to add a similar patch for apple ids
| for emails ending in "state.gov". Not sure why this is such a big
| deal.
| [deleted]
| walrus01 wrote:
| which is pretty absurd since there's only a vague relationship
| in the modern SS7/PSTN between a phone's DID and where it might
| be physically located. In five minutes of work I could have a
| New Zealand number ring on my desk phone anywhere in the world.
| Scoundreller wrote:
| So it doesn't work on US phone numbers or doesn't work on +1
| country code?
|
| -confused Canadian because we share the +1 country code with
| USA under NANPA
| fmajid wrote:
| Presumably those phones had Ugandan numbers.
| kshacker wrote:
| Canadians go 'yay', finally some benefit of the big brother.
|
| PS: I don't buy the explanation btw
| asplake wrote:
| As someone who doesn't have a +1 number I find it hard to take
| this comment seriously. But could it be possible that some
| state department employees work outside the US?
| whatshisface wrote:
| Come on, think about it. Doesn't work for phone numbers
| starting with +1? So, anyone who buys the right sim card is
| immune? A team of professional hackers can't find the if-else
| in the attack binary that enforces that to disable it? They're
| selling software to cybersecurity teams on the assumption that
| they can't crack it?
| indymike wrote:
| > A team of professional hackers can't find the if-else in
| the attack binary that enforces that to disable it?
|
| It's probably easier than that. Seems like the kind of thing
| that would be in a config file (making this up, satire):
|
| [No Spying Allowed - please do not change]
|
| # Really, really, don't change this setting. We are not
| responsible if you do.
|
| +1 # USA
|
| +3542 # NSO Group
|
| > They're selling software to cybersecurity teams on the
| assumption that they can't crack it?
|
| No, I think they are telling journalists that their hands are
| clean, and it totally isn't their fault, not in a million
| years, that their customer changed their software.
| RealityVoid wrote:
| My understanding is that it's not _just_ a tool, but a whole
| infrastructure around it that the clients use. So presumably,
| before deploying to a target, it would need to go through NSO
| infrastructure, so they could vet there.
| illusivesaint wrote:
| Wow, Israeli's spying on their main sponsor?? Espionage is part
| of the political territory but hopefully this sets precedent to a
| change of optics. (Which probably not since Russia does it boldly
| for fun at this point).
| afterburner wrote:
| This was entirely predictable.
| cblconfederate wrote:
| Time to go back to rotary phones
| yodon wrote:
| As discussed 2 days ago here on HN
|
| https://news.ycombinator.com/item?id=29401454
| fabianhjr wrote:
| Just get calyxOS or any other privacy + security FOSS mobile
| operating system.
| tdhz77 wrote:
| NSA backdoors the peg spyware and Apple believes State Department
| has been hacked when in reality the information return has been
| manipulated. State Actors believe the information they received
| is legit, when it's actually what the US wants them to see. This
| is common knowledge that CIA had hands into the development of
| Pegasus. The media hasn't been able to keep up yet.
| cronix wrote:
| As an American, it's becoming harder for me to muster sympathy
| for an entity that actively discovers and exploits technological
| flaws to use against their adversaries while simultaneously
| purposefully not alerting the manufacturers in order to correct
| the flaws so they can continue to exploit them and then those
| flaws are subsequently discovered by others and used against
| them. Poor you.
| literallyaduck wrote:
| Let's cancel their foreign aid, 3 Billion and change, and put a
| trade embargo until they pay back all their foreign aid.
| [deleted]
| markus_zhang wrote:
| This is a typical "shadow government" symptom. You have forces
| working within the government that 1) have their own agendas; 2)
| have connection to international communities, usually military-
| intelligence ones; 3) have almost zero regulation; 4) even many
| high ranking government officials don't know about them because
| they are brotherhood-like closed circles.
|
| This reminds me of Operation Gladio or Propaganda Due but
| domestic. Same playbook, different players.
| KennyBlanken wrote:
| Implying that Israeli spying on the US is some fringe "shadow
| government" sub-group of the Israeli government is strange
| given a long, long history of high profile Israeli spying
| incidents against the US.
|
| https://en.wikipedia.org/wiki/Lawrence_Franklin_espionage_sc...
|
| https://en.wikipedia.org/wiki/Jonathan_Pollard
|
| https://en.wikipedia.org/wiki/Ben-Ami_Kadish
|
| https://en.wikipedia.org/wiki/Jack_Parsons_(rocket_engineer)
|
| Then there's the time they stole nuclear material from us
| https://en.wikipedia.org/wiki/The_Apollo_Affair
|
| Then there's the time they slaughtered several dozen US navy
| and NSA personnel with repeated attacks on an unarmed vessel
| because they didn't like that we were watching them:
| https://en.wikipedia.org/wiki/USS_Liberty_incident
| ginja wrote:
| The US spies on its European allies all the time, and I'm
| sure they spy on Israel too, so that's not super surprising.
|
| As for the USS Liberty, some do argue that it was
| intentional, but both the Israelis and Americans ended up
| agreeing that it was a mistake. The US is no stranger to such
| mistakes either, even more egregious ones like when they
| killed close to 300 civilians aboard a regular passenger
| flight following an approved route and in contact with ATC
| (Iran Air 655).
|
| In the end both the US and Israel are amoral states that act
| only according to their economic and strategic interests and
| I feel that this unites them. I wish it didn't, though.
| colordrops wrote:
| They _officially_ decided it was a mistake, as it did
| neither government any good to officially announce that it
| was intentional. But the sailors that were on the ship say
| otherwise.
| stjohnswarts wrote:
| And the European allies spy on the USA, rinse and repeat.
| Lammy wrote:
| Why would the tail wag the dog? America benefits so much from
| all the R&D (in e.g. encryption) that can't happen on US
| soil. They are not our enemy in any way :)
|
| https://en.wikipedia.org/wiki/Report_to_the_Secretary_on_the.
| ..
|
| https://www.nybooks.com/articles/2001/09/20/the-truth-
| about-...
| keewee7 wrote:
| The USS Liberty incident happened 52 years ago.
|
| >because they didn't like that we were watching them
|
| That is the American conspiracy theorist interpretation of
| the incident that (understandably) also gained traction among
| a few of the survivors. The Israelis disagree.
|
| It was most likely a case of mistaken identity. Just like
| friendly fire incidents. Friendly fire incidents happen all
| the time, including between US forces in the recent Iraq and
| Afghanistan conflict.
| darwingr wrote:
| The Liberty was also very far from where the Americans had
| told the Israelis where it would be. Finding the ship there
| was unexpected and calls to confirm its identity were not
| being answered.
| albatross13 wrote:
| Oy vey what an antisemtic statement, assuming Israeli
| forces are incapable of knowing friend from foe.
| jack_riminton wrote:
| It's not in the least bit anti-semitic and to suggest so
| is inflammatory
| albatross13 wrote:
| You suggesting me pointing out antisemitism online being
| inflammatory is actually deeply antisemtic and a white
| supremacist dog whistle.
| Minor49er wrote:
| The survivors said that the pilots were waving at them
| before they carried out the attack
| lovelyviking wrote:
| can you provide the source?
| markus_zhang wrote:
| By saying "shadow government" I mean groups within the US
| government that has connection to say NOS.
|
| Again I don't have concrete proofs so I could be 100% wrong.
| But reading world history especially cold war history makes
| me be sceptical to certain things.
| BoardsOfCanada wrote:
| Hilarious that anyone thought you were talking about an
| Israeli shadow government.
| Eelongate wrote:
| > _Then there 's the time they stole nuclear material from us
| https://en.wikipedia.org/wiki/The_Apollo_Affair_
|
| On a related note, JFK was trying to shut down Israel's
| nuclear weapons program in the months before his murder.
|
| https://www.jewishvirtuallibrary.org/kennedy-letter-to-
| ben-g...
| duped wrote:
| I'm sure he was conducting a lot of international policy
| initiatives in the months before his assassination
| pphysch wrote:
| Yeah, like (secret) detente with Fidel Castro [1].
|
| [1] -
| https://nsarchive2.gwu.edu/NSAEBB/NSAEBB103/index.htm
| stjohnswarts wrote:
| Anyone who doesn't think the USA and Israel don't spy on each
| other 24/7 is living in a dream world. Israel is an ally but
| I don't think that they are our friends.
| dqpb wrote:
| > 3) have almost zero regulation;
|
| What would shadow government regulation look like?
| markus_zhang wrote:
| It's difficult, you have to break down those brotherhoods who
| will fight to death to be "independent". And then you have to
| find a way to prevent them from spawning again. I don't have
| any idea how to do it properly.
| cwkoss wrote:
| I'd expect if we lived in the sort of society that would
| execute the head of the NSA for treason or something
| similar when the Snowden revelations came out, it would
| have societally beneficial chilling effect on intelligence
| organization brazenness.
|
| Unfortunately, it seems intelligence is mostly immune from
| liability, and lack of consequences lets the rot fester.
| markus_zhang wrote:
| Once the system is setup who is in control is going to be
| irrelevant. I believe the best approach is to educate the
| citizens so that 1) They follow scientific methods; 2)
| They are more resistant to advertisement/propaganda; 3)
| They are keen to corruption and willing to protest.
| catlikesshrimp wrote:
| "1) They follow scientific methods. 2) They are more
| resistant to advertisement/propaganda; 3) They are keen
| to corruption and willing to protest."
|
| You are asking way too much of people. "Normal" people
| can't fulfill any of those 3 requests. Not that they
| don't want to (most don't), or that they aren't taught to
| (this is conflicting through life)
|
| They can't. #1 and #2 sound like something an autist
| would tend to do.
| linschn wrote:
| Maybe stop funding them, for a start?
|
| Congressional oversight used to be a thing.
|
| Snowden showed the NSA lied to congress. No heads rolled.
| throaway46546 wrote:
| Imagine all the dirt the NSA has on congress.
| ruined wrote:
| remember when the cia interfered with the congressional
| investigation of their torture program, by getting the
| FBI to investigate senators for viewing the documents
| that the CIA provided them, and spying on the senate
| investigation activities, and then nothing happened
|
| https://www.cnn.com/2014/03/18/politics/cia-senate-
| dispute-f...
|
| https://www.reuters.com/article/us-cia-senate-
| idUSKBN0KN2Q82...
| cwkoss wrote:
| Imagine how much society would improve if all the dirt
| got aired.
|
| Hiding this information is trading the wellbeing of the
| country for the NSA's own internal goals and power.
| gunfighthacksaw wrote:
| Dangerously based and you're-about-to-commit-suicide-
| with-two-gunshots-to-the-head pilled
| mcbutterbunz wrote:
| > Imagine how much society would improve if all the dirt
| got aired.
|
| Depends on the dirt. Some of it might be private and
| personal stuff, such as infidelity. That type of stuff,
| while blackmailable, doesn't really benefit the public
| much.
| Eelongate wrote:
| The public's elected representatives being easily
| blackmailable is obviously of great concern to the
| public, I don't know why you're downplaying this.
| OminousWeapons wrote:
| Everyone has dirty laundry they would prefer not be
| aired, and if they don't then their friends, family, or
| partners do. I don't think we want to live in a world
| where absolute moral purity (as determined by the most
| vocal, biased critics of a given person) is required to
| hold public office.
| krapp wrote:
| >I don't think we want to live in a world where absolute
| moral purity (as determined by the most vocal, biased
| critics of a given person) is required to hold public
| office.
|
| Don't worry, you live in a world where a man with a well
| documented decades-long laundry list of scandals and
| faux-pas can brag on tape about how he can get away with
| molesting young women because of how rich he is and still
| get elected President.
|
| I'm actually wondering what you _could_ effectively
| blackmail an American politician with, given how little
| Americans seem to care about the morality of their
| leaders. Maybe just the eponymous "dead girl or live
| boy," but then you have the Kennedys...
| catlikesshrimp wrote:
| Don't believe representatives are elected because of
| their integrity and their willingness to serve.
|
| They represent groups of interest. And being
| blackmailable is, in my opinion, a handy leash to keep
| them in check, for those groups which propose the
| candidates
|
| The public is not concerned with corruption until they
| feel affected by it.
| literallyaduck wrote:
| Why would heads roll?
|
| Congress has blocked inquiries into their split loyalty as
| far as them having multiple citizenship in other countries.
| If you were McDonald's board of directors would you allow
| someone to be on both the McDonald's board and Wendy's?
|
| Congress isn't personally harmed by a surveillance state
| unless you consider they may all be being blackmailed but
| that is another conversation. In fact mass surveillance
| widens the barrier to new entries into politics as they can
| use whatever dirty they find and give it to federally
| funded media mouthpieces.
|
| This week we saw articles of sexual crimes against children
| being swept under the rug to "protect our country" do we
| really think that congress would actively pursuit this line
| of inquiry?
| BoardsOfCanada wrote:
| Context:
| https://www.wsws.org/en/articles/2014/03/07/spyi-m07.html
| jjeaff wrote:
| I can believe there are shadow organizations that lack
| oversight. In fact, it seems likely.
|
| But that these shadow organizations are maintaining power
| by surveiling and blackmailing congress people is a whole
| other ballgame and seems highly unlikely to me.
|
| For one, it's likely that not every Congressperson has some
| deep dark secret that makes them blackmail-able. And
| pissing off the only group of people that could cut your
| funding and expose your shadow organization as well as
| bring oversight is not the group that you want to be
| pissing off.
|
| I think game theory would indicate that your only chance of
| maintaining a shadow organization in the US gov for any
| length of time is going to be secrecy and maybe some
| heavily funded lobbying.
| arthur_sav wrote:
| > But that these shadow organizations are maintaining
| power by surveiling and blackmailing congress people is a
| whole other ballgame and seems highly unlikely to me.
|
| Why is it so hard to believe that a few powerful
| indivisuals at the top, with common interests and
| agendas, are banded together?
|
| There's no official organization but a few indivisuals
| that streer things their way because they can.
| autoexec wrote:
| > For one, it's likely that not every Congressperson has
| some deep dark secret that makes them blackmail-able.
|
| I'd be more than willing to bet that they do. "If you
| give me six lines written by the hand of the most honest
| of men, I will find something in them which will hang
| him." and that only covers "honest" men who wouldn't have
| illegal coordination with PACs, bribes with lobbyists,
| personal communications filled with racism, or evidence
| of sexual activities that might upset their base. When "6
| lines" becomes a record of everything you've ever done
| online, all of your communications, your GPS coordinates
| and the data of anyone around you it's going to get
| easier to find a noose around your neck.
|
| Even if there managed to exist a single person in
| congress who wasn't screwing over the American people
| somehow for personal gain, or didn't have some skeleton
| in their closet they didn't want exposed to
| voters/campaign contributors when a group is capable of
| compromising your system and inserting whatever offensive
| material they want to use against you it's incentive
| enough to back off.
| willcipriano wrote:
| You only need the capture the party leadership, they can
| keep everyone else in line via fundraising initiatives.
| Spooky23 wrote:
| Politics is a funny business. I have spent alot of time
| dealing with political people ranging from staffers to
| actual officials.
|
| Many are very well meaning public servants, others
| careerists, some are... insane on various scales.
| Politics is a business with uncertain outcomes where
| "friends" are important and personal stakes are high.
|
| From a blackmail perspective, you have people like the
| bartender turned member of congress who got their GED to
| run who are obvious puppets with a wheelbarrow of odious
| behavior behind them. But even the most boring
| congressman has a legal escrow account with
| irregularities, a kid with emotional problems that caused
| trouble, a campaign finance violation, etc.
|
| I don't think there is a shadow cabal, but some executive
| branch entities wield tremendous power.
| btheshoe wrote:
| AOC is an obvious puppet?
| Spooky23 wrote:
| Not quite. Different educational dynamic. Polarizing
| figure for sure, but whomped an old school political
| machine candidate.
| dzonga wrote:
| how would you cut the budget of the CIA for example, an
| organization that doesn't really answer to anyone but
| itself ? an organization that can self fund when it
| wants. Eisenhower, a general called out the so called
| military industrial complex in a way that befits a
| prophet
| thelittleone wrote:
| I'm all for sorting the problem out, but isn't the reality
| a little more complex given other countries? Doesn't
| cutting your intelligence / signals budgets give your
| "enemies" an advantage? By "enemies" I'm referring
| predominantly to foreign nation states.
| pueblito wrote:
| More light and transparency = less shadows
| chillwaves wrote:
| Enforce our laws would be a good start.
| pstuart wrote:
| 5) many high ranking government officials do nothing about this
| because they're being blackmailed by the spooks.
|
| Tinfoil hat territory? Sure. Plausible _and_ possible? Sure.
| zaphirplane wrote:
| There is nothing supporting the theory or conclusion
| colordrops wrote:
| What are you trying to suggest? It's just a typical reflexive
| reactive response to any comment that the government acts in
| ways other than presented to you by corporate media.
|
| It only takes 3 minutes of google searches or even a daily
| scan of Hacker News to see endless examples of government
| corruption and malfeasance. Government employees are only
| human after all, and there are millions of them. To think
| this sort of activity ends once you become an agent of the
| government is absurd.
| WFHRenaissance wrote:
| > Government employees are only human after all
|
| This weekend I was traveling and I put the stray $20 from
| my pocket in the bin at the TSA checkpoint. An agent
| quickly pulled it out and handed it back to me. He then
| said "a lot of good people work here, but they're still
| human". It's kind of wild that we endure that level of
| complacency here in the States.
| xbar wrote:
| I wonder if we would be hearing about this if NSO had paid its
| 30% to Apple in the first place.
| 29athrowaway wrote:
| Sanction them then. The US has sanctioned companies for much
| less.
| bob-a-fet wrote:
| One settler colony hacks another settler colony, the one that had
| co-sponsored its creation along with Britain, the mothership of
| all settler colonies. Honor amongst thieves? No such thing.
| unknown2374 wrote:
| A book came out about a year ago by a fantastic academic about
| the history of settler colonialism by Israel in Palestine [1].
| I'd suggest anyone who wants to learn more about Israel and
| values referenced record of history. The book is very well
| written, referenced (a sixth of the book is references) and
| comes highly regarded.
|
| [1] https://www.amazon.com/Hundred-Years-War-Palestine-
| Resistanc...
| jjclint wrote:
| Your comment has nothing to do with the article. Stop shoving
| your sick agenda down our throats and save your "links" to
| yourself
| dang wrote:
| Whoa - you can't attack another user like that here,
| regardless of how strongly you disagree. We ban accounts
| that post like this.
|
| If you'd please review
| https://news.ycombinator.com/newsguidelines.html and stick
| to the rules when posting here, we'd appreciate it.
| dang wrote:
| Please do not take HN threads into generic flamewar hell. It's
| not what this site is for, and it destroys what it is for.
|
| https://news.ycombinator.com/newsguidelines.html
| ArcCompArthur wrote:
| This post will be flagged shortly.
| savant_penguin wrote:
| Now it's going to be really funny if later on we find out that
| that company was funded with Israeli state money that came from
| the US
| smoldesu wrote:
| Huh, it looks like suing a state-sponsored malware manufacturer
| _doesn 't_ prevent them from continuing to hijack your devices.
| Live and learn, I suppose.
| BillSaysThis wrote:
| Suing is hardly the same as having the suit decided, grow up.
| smoldesu wrote:
| Okay. Let's assume they do have the suit decided, and they
| rule in Apple's favor. What next?
| nojito wrote:
| This is based on Apple notifying the employees based on prior
| behavior of NSO.
| A4ET8a8uTh0 wrote:
| While I find it interesting that focus in comments appears to be
| on Israel, NSO and the complicated ( or not really that
| complicated if you look at it from a different angle )
| relationship between them and US. I did not see a mention a
| broader discussion of, you know, hoarding zero days, exploits and
| whether using those can be worse than conventional weaponry.
|
| The reason I find it interesting is because it is clear that US
| government supports Israel ( and NSO ) practically
| unconditionally ( recent vote on Iron Dome being a more amusing
| example of bipartisanship ).
|
| Why is Reuters, an old guard by any account, concerned? Or are
| they simply following what sells and government is really at odds
| with its people when it comes to policy in ME.
| DelightOne wrote:
| Is there a timetable when Apple plans to stop using memory-unsafe
| languages to avoid memory-bugs? If not, how can the amount of
| zero-days stop with constant development?
| whoknowswhat11 wrote:
| no question that imessage, email parsers, etc that do third
| party untrusted network type interactions SHOULD be memory
| safe. But of course they are not, and apple in particular LARDS
| these formats down with a million features.
| DelightOne wrote:
| Looking at the answers, seems like a NO.
| DyslexicAtheist wrote:
| biggest issue here isn't memory safety but the dumpster fire of
| imessage format that calls out to privileged parts of the
| system
| fmajid wrote:
| And Apple's terrible software and QA processes, like lack of
| CI or fuzzing, which is why Google Project Zero is
| discovering flaws for them.
| walrus01 wrote:
| I'm suspicious of any messaging system that has ties into
| rich media / embedded-in-chat content. I even wish I could
| disable URL previews, gifs, and inline images in Signal.
| elliekelly wrote:
| I didn't know it was possible to disable URL previews in
| iMessage[1] until I read this comment. Does toggling this
| setting only prevent the preview from displaying or does it
| prevent the fetch altogether? I wish there were a way to
| white list the URL previews for certain contacts rather
| than turning it off all or nothing.
|
| [1]https://discussions.apple.com/thread/7677834
| spear wrote:
| I didn't see a way to disable URL previews in that
| thread. The given "solution" is wrong -- it just disables
| message previews in the lock screen.
| kingcharles wrote:
| It can be your "trusted" contacts that infect you though.
|
| "Jeff Bezos was hacked by a file sent from the WhatsApp
| account of the crown prince of Saudi Arabia, Mohammed bin
| Salman"
|
| https://en.wikipedia.org/wiki/Jeff_Bezos_phone_hacking
| 2OEH8eoCRo0 wrote:
| It's an extremely common attack vector. PDFs, media message,
| etc. Would it be viable to create a dedicated processor
| specifically for parsing these things?
| vlovich123 wrote:
| Which is exploitable primarily it by memory safety exploits.
|
| Will it make attacks impossible? Probably not totally. But it
| might raise the cost of the attack by an order of magnitude
| or more and certain classes of vulnerabilities might
| disappear completely.
| uniformlyrandom wrote:
| You do know that memory-safe languages are developed using
| memory-unsafe languages, and eventually execute the binary code
| on the actual CPU?
| FpUser wrote:
| I think it comes from that rewrite everything in Rust camp.
| shrimpx wrote:
| A memory safe language can be written in itself.
| kevingadd wrote:
| Most memory-safe languages I've used self-host their compiler
| and standard library (i.e. they're written in the language
| itself).
___________________________________________________________________
(page generated 2021-12-03 23:00 UTC)