[HN Gopher] U.S. State Department phones hacked with Israeli com...
       ___________________________________________________________________
        
       U.S. State Department phones hacked with Israeli company spyware
        
       Author : amadeuspagel
       Score  : 680 points
       Date   : 2021-12-03 17:05 UTC (5 hours ago)
        
 (HTM) web link (www.reuters.com)
 (TXT) w3m dump (www.reuters.com)
        
       | jimnotgym wrote:
       | TlDr. Weapons designed to use against baddies can also be used
       | against goodies
        
       | maltalex wrote:
       | I don't understand the focus on NSO in these stories. If U.S
       | State Department personnel in Uganda were shot from an M-16,
       | would the headline mention "an American arms manufacturer"? No,
       | because it's ridiculous.
       | 
       | For better or worse, NSO's product is a weapon. How is it any
       | different from an M-16? Where is the outrage towards the people
       | who used this weapon against the State Department?
        
         | user-the-name wrote:
         | > No, because it's ridiculous.
         | 
         | Is it really.
        
           | dang wrote:
           | Could you please stop posting unsubstantive and/or flamebait
           | comments to HN? You've been doing it a lot, unfortunately,
           | and we ban that sort of account.
           | 
           | https://news.ycombinator.com/newsguidelines.html
        
         | sangnoir wrote:
         | NSO doesn't "sell" cyberweapons - they lease them and provide
         | logistical support (including running the cloud
         | infrastructure). This confers a lot more knowledge on where and
         | how the weapons are used, and adds a lot more culpability.
         | 
         | The situation is less "M-16 and rounds sold once-off", and more
         | of a turnkey armed drone (or surveillance drone, if you're
         | charitable) service provided to governments, where the
         | missiles, fuel, and airbases are provided by a private party on
         | an ongoing basis. It's more of a tailored service, than a sale
         | of goods.
        
         | bell-cot wrote:
         | In National Security contexts, the "get angry at the weapon
         | seller" response is very strongly correlated with how advanced
         | (in technology, power, and scarcity) the weapon is perceived to
         | be.
         | 
         | For an "average soldier" weapon, such as an M-16 - $Company
         | isn't likely to catch much grief - unless they're selling a
         | considerable quantity of them, or to an extremely notorious
         | buyer. Similar for a cyberweapon - but an "everyday" one, which
         | wouldn't be a big surprise for a C-list ransomware group to
         | use.
         | 
         | Vs. NSO's stuff seems to be the sort of top-tech goodies which
         | A-list nation states use to maintain & enjoy their A-list
         | status. Whether any actual harm results from this incident...
         | publicly letting a bunch of "the wrong sorts" into that
         | exclusive clubhouse is getting NSO into really deep do-do with
         | "the regulars".
        
         | tschwimmer wrote:
         | Perhaps you are unaware of the nature of global arms control
         | and how much work goes in to prevent scenarios exactly like
         | this.
         | 
         | Small arms proliferation is much harder to control, but yes
         | there has been extensive reporting on Operation Fast and
         | Furious where US gun sellers were allowed to sell to Mexican
         | cartels under ATF supervision. [0] Those guns were used against
         | both US and Mexican citizens, including fatally against 1 US
         | Border Patrol Agent in 2010.
         | 
         | Looking farther back, during the Falklands war in the early 80s
         | there was much controversy over the Exocet anti-ship missile,
         | which was manufactured and sold by France. When these missiles
         | were successfully used against British warships near the
         | Falklands, Britian successfully lobbied for France to stop
         | selling them to the Argentinians.[1]
         | 
         | So yes, it's actually very common to put the responsibility of
         | how their products are used on arms manufacturers. It's a good
         | thing and it keeps the world safer.
         | 
         | [0]https://en.wikipedia.org/wiki/ATF_gunwalking_scandal
         | [1]https://www.bbc.com/news/magazine-17256975
        
         | walrus01 wrote:
         | It's my understanding that NSO runs centralized command and
         | control servers that their "clients" are granted access to, for
         | both the on-device payload installation and also data
         | exfiltration.
         | 
         | They do not give the software to their clients to go use
         | somewhere in the world fully independently (self hosted payload
         | dropper, C&C, etc)
         | 
         | They're a direct participant in the network traffic. Unlike a
         | dumb purely offline piece of hardware like a M4 rifle or
         | similar.
        
           | montblanc wrote:
           | So selling an F-15 to the Saudis (like the U.S is doing in
           | droves) is more morally justifable because what exactly..?
           | After the plane is sold the Saudis are independent with it?
           | (they aren't really btw. I'm sure there's maintenance and
           | buying parts etc).
        
             | walrus01 wrote:
             | I am also not in favor of selling advanced weaponry to the
             | saudis or pretty much any non-democratic regime. The US has
             | a very poor historical track record of supporting strongmen
             | that do brutal things. Pinochet. Suharto. MBS. I could
             | write a very long list.
        
             | phatfish wrote:
             | None one else was talking about F-15s or drones in this
             | thread. The only mention was of weapons that even civilians
             | can buy is some countries and do not come with a support
             | contract attached.
             | 
             | IMO the US selling F-15s or drones to the Saudis is very
             | similar. The US shouldn't be supporting the Saudis
             | murdering civilians with F-15s, and Israel should not be
             | supporting hacking tools that enable other governments (or
             | private organizations) to murder people they dont like.
        
             | [deleted]
        
           | montblanc wrote:
           | I find it very unlikely they knew about state department
           | phones. Why bring up M4 rifles all the time? That's not how
           | the U.S or any other arms seller makes money at all. The big
           | money comes from planes, drones, etc. 350 billion worth over
           | 10 years just to Saudi Arabia alone https://en.wikipedia.org/
           | wiki/2017_United_States%E2%80%93Sau....
        
         | Sporktacular wrote:
         | Speak plainly. Are you suggesting this is a company being
         | unfairly singled out just because it's Israeli?
        
           | montblanc wrote:
           | It being Israeli is definitely a big part of why this story
           | is so huge. Why do you think it's making huge headlines then
           | - what's your theory? The fact that 8 American diplomats got
           | their phones hacked?
        
         | jimbob45 wrote:
         | I'm in agreement with you. I don't see any indication that the
         | Israelis specifically made this weapon to target US interests,
         | nor do I see any indication that the Israelis are
         | discriminating between the US and any other nation, nor do I
         | see anything that leads me to believe that we aren't
         | potentially using this ourselves against other nations.
         | 
         | Fuck NSO, for sure. But I'm just not sure Israel should be held
         | accountable for the actions of a private corporation with no
         | apparent political motivations, just as in your M-16 example.
        
           | tomjakubowski wrote:
           | The Israeli state regulates the export of NSO Group's
           | software. So yeah, they do have some responsibility here.
           | 
           | https://www.haaretz.com/israel-news/tech-news/israel-will-
           | re...
        
             | jimbob45 wrote:
             | If it's specifically, then I'd agree with you. If it's just
             | broadly (such as how the US unilaterally doesn't trade with
             | countries currently in the midst of war), then I'm not so
             | sure.
        
         | dmix wrote:
         | It's more like a PMC ala Wagner than selling an M-16. They
         | essentially run the technical side of operations and provide
         | the talent.
        
           | brendoelfrendo wrote:
           | Ah, I like this analogy. NSO's role isn't so much selling a
           | weapon as it is selling "cyberwarfare as a service."
        
         | montblanc wrote:
         | > I don't understand the focus on NSO in these stories
         | 
         | What's to understand ? It's an Israeli company. Enough said. If
         | it was an American or German company no one would have cared.
         | Why the obsession with Israel? It's a complicated phenomena. I
         | think it has to do with the role Jews played in Christianity
         | (Jesus' death etc) and the holocaust but that's just my 2
         | cents.
        
           | Tronno wrote:
           | Israel is ostensibly a Western ally, yet they sell weapons
           | that are used to attack Western nations and their citizens.
           | Can you see why some people might consider that a problem?
           | 
           | Your accusations of anti-semitism are unwelcome and without
           | merit.
        
             | mola wrote:
             | Uganda is not a US enemy. NSO is a disgusting money grab
             | and a threat for democracies. But, they never sold to any
             | nation which is a US enemy. Uganda is not a US enemy.
             | Israeli government, which grants the export licenses is not
             | that dumb.
             | 
             | Allies spy on eachother all the time. that's a given any
             | sovreign state knows and takes into account.
        
             | ryneandal wrote:
             | There are also numerous instances of their intelligence
             | forces spying on us, an ally.
             | 
             | - https://apnews.com/article/israel-jonathan-pollard-
             | espionage... -
             | https://www.politico.com/story/2019/09/12/israel-white-
             | house...
        
               | xxpor wrote:
               | Everyone spies on everyone, no one is actually shocked by
               | that. The US does it too (see the interception of Angela
               | Merkel's phone calls...)
               | 
               | The key is you don't get caught doing it, because it
               | removes plausible deniability.
        
             | montblanc wrote:
             | You are being a demagogue here. It's 8 phones that were
             | hacked, by someone in Uganda - a friendly country to the
             | U.S, with NSO probably not knowing and Israel as a state
             | definitely not knowing. Was any of the 8 Americans harmed
             | physically btw?
             | 
             | I don't care if it's unwelcome to you...I call it as I see
             | it and you're not doing a great job convincing me
             | otherwise.
        
           | gowld wrote:
           | Is there another popular spyware company being used by rogue
           | states to perform terrorist attacks?
        
             | montblanc wrote:
             | What is your definition of rogue states? The U.S sells
             | weapons to the Saudis in hundreds of billions https://en.wi
             | kipedia.org/wiki/2017_United_States%E2%80%93Sau....
             | 
             | So I should believe the U.S thinks it's OK to sell F-15
             | planes but not OK to sell software? I'm gonna assume yes,
             | there are probably other players in cyber warfare who sell
             | to these countries, probably also the U.S.
        
               | JumpCrisscross wrote:
               | > _the U.S thinks it 's OK to sell F-15 planes but not OK
               | to sell software?_
               | 
               | The U.S. thinks it's okay to sell F-15s that don't attack
               | Americans and not okay to sell software that attacks
               | Americans. As a, granted, American, I'm not seeing the
               | incoherence.
        
               | montblanc wrote:
               | Attacks Americans? Come on now, don't go overboard sir.
        
               | JumpCrisscross wrote:
               | > _Attacks Americans?_
               | 
               | I was delineating why the U.S. is fine with selling
               | weapons to _e.g._ Saudi Arabia but would not be happy
               | about those same weapons being sold by Russia to Iran.
               | You seemed confused on that point. There isn 't a grand
               | philosophy. It's international relations. It's anarchy.
               | The U.S. government promotes American and allied
               | interests.
               | 
               | Separately, yes, if you're hacking the State Department,
               | you're attacking the U.S. This is consistent with how
               | cyberterrorism is treated by DNI since at least 2014.
        
               | montblanc wrote:
               | This wasn't done by NSO knowingly. I have no reason not
               | to believe them on that, they have a financial and
               | strategic interest not to piss America off that bad. Also
               | - Uganda is not Iran, it's a friendly country.
               | Unfortunately someone there decided to use it against
               | American diplomats which is unfortunate.
        
               | KMag wrote:
               | > This wasn't done by NSO knowingly.
               | 
               | In the past month or so, there was a front page story on
               | HN about NSO and a journalist, detailing evidence that
               | NSO-controlled servers served up the exploit to the
               | journalist's phone. This suggests that the NSO group has
               | less of an arms-length relationship with their clients
               | than they let on. It seems that at least for some
               | clients, they're running some variant on exploits-as-a-
               | service.
        
               | montblanc wrote:
               | That still doesn't mean they knew about this. How would
               | they even know it were American phones? Its very possible
               | it were some IPhone with a Ugandan sim card. How do you
               | know who's using it - do the Ugandans tell you? It's a
               | very real possibility NSO servers simply show some
               | Ugandan number. I have no more knowledge on this than
               | anyone here but I don't find it realistic NSO would take
               | this chance.
        
               | JumpCrisscross wrote:
               | > _doesn 't mean they knew about this_
               | 
               | Mitigating but not exonerating. (Also, unknown and
               | possibly unknowable.) NSO are still selling cyberweapons
               | hitting the United States. If they didn't give a shit
               | about keeping an eye on their kit, that's a negligent gap
               | in oversight by Jerusalem.
               | 
               | It's a good thing we have a talking-not-shooting
               | relationship with Israel. The U.S. would be within its
               | rights to launch a proportional counterattack were that
               | not the case. If Israel doesn't deal with this properly,
               | there's a decent chance we'll see calls for criminal
               | penalties and targeted sanctions.
        
             | boomboomsubban wrote:
             | DarkMatter seems to have done basically the same as NSO,
             | except with an even more explicit US connection.
        
               | bauruine wrote:
               | > DarkMatter is under investigation by the F.B.I. for
               | crimes including digital espionage services, involvement
               | in the Jamal Khashoggi assassination, and incarceration
               | of foreign dissidents.[28] The F.B.I. is also
               | investigating current and former American employees of
               | DarkMatter for possible cybercrimes.
               | 
               | Doesn't look like they only target Israeli companies.
        
           | loeg wrote:
           | The US provides substantial financial, military, and
           | political aid to Israel, that it does not provide to Germany.
        
             | montblanc wrote:
             | The U.S basically protects the whole of Europe by
             | subsidizing NATO. It's probably in the trillions. Sorry but
             | Trump had a point there. What it gives Israel is peanuts
             | compared to that. Without U.S support to Europe who knows
             | what happens, maybe the Russians and Chinese start looking
             | at Europe as easy prey to pick on. Also the obsession with
             | Israel isn't a uniquely American thing, it's the same in
             | France and Canada and Germany and basically any Western
             | country.
        
               | mullingitover wrote:
               | The attacks on NATO are such a weird thing. US support of
               | NATO isn't a charity operation, there are strategic and
               | economic benefits to the US from NATO participation that
               | greatly exceed the expenses.
               | 
               | If the argument is that the United States shouldn't be a
               | global power, that it should dismantle the US military
               | and be a demure, multilateral player in the international
               | space, sure, attack NATO. However, attacking NATO while
               | saying the US should be a _stronger_ international player
               | is contradictory.
        
               | montblanc wrote:
               | I'm not attacking NATO. I'm saying the U.S is subsidizing
               | Europe's defense in the trillions (if we count since WW2
               | end). It could be beneficial to the U.S, or not. I'm only
               | saying U.S aid to Israel is not unique and is peanuts
               | compared to the NATO subsidy. People here like saying
               | they are super focused on Israel because of the 3 billion
               | annual subsidy the U.S gives to Israel. I call bullshit
               | on that.
        
               | mullingitover wrote:
               | The NATO relationship effectively turns Europe into
               | vassal states - we don't have German or French bases on
               | US soil, only the US gets that out of NATO. So it's a
               | 'subsidy' only in the sense that the US is protecting its
               | property.
               | 
               | People get angry about the Israel aid not because of the
               | volume of funding, but because of the human
               | rights/colonialism problems that the US subsidizes. I
               | personally feel that way, but at the same time I
               | understand the realpolitik deal with Israel - I believe
               | the purpose of keeping Israel there is to prevent some
               | version of the Ottoman Empire from re-forming.
        
               | whimsicalism wrote:
               | Only if you count general American military spending as
               | supporting Germany more than Israel?
               | 
               | Otherwise, US absolutely provides far more military
               | spending to Israel than to Germany, it's not really
               | comparable.
        
               | montblanc wrote:
               | > Only if you count general American military spending
               | 
               | Of course I do. Europe has no real army. France kinda has
               | an army and the U.K got out. If America didn't provide a
               | military umbrella Europe would need to actually build a
               | real army (Europe's contributions to NATO are pitiful).
               | How much would it cost the Europeans to do that? Going
               | back since WW2 that's easily in the trillions.
        
               | whimsicalism wrote:
               | Given that the US actively engages in military operations
               | in defense of Israel, I would say that it not reasonable
               | to attribute a larger share of the spending to Germany
               | rather than Israel?
        
               | montblanc wrote:
               | What military operations would those be?
        
               | xxpor wrote:
               | Stuxnet and the intervention in Syria just off the top of
               | my head.
        
               | montblanc wrote:
               | The intervention in Syria? That's a military operation
               | done by the U.S for Israel? How did you come up with
               | that? If there's no Israel tomorrow the entire region is
               | still messed up with possibly tens of millions of new
               | refugees flooding Europe. It's not all about Israel.
        
               | FDSGSG wrote:
               | As opposed to the absolutely massive US military presence
               | in Germany?
        
               | trasz wrote:
               | There is no military danger Europe would need protecting
               | from. The only thing US is subsidising is itself: all
               | those trillions go directly back to US and benefit US,
               | not Europe.
        
             | FDSGSG wrote:
             | There are currently around 35000 American service members
             | deployed to Germany.
        
               | trasz wrote:
               | That's Germany providing its land, for free, to the US.
               | Those forces are not protecting Germany from any existing
               | military danger, they are just projecting US power and
               | protecting its interests.
        
             | fortran77 wrote:
             | The US rebuilt Germany and continues to support them to
             | this day militarily.
        
         | snowwrestler wrote:
         | U.S. weapons manufacturers receive a lot of criticism too, both
         | domestically in the U.S. and internationally.
         | 
         | The comments here focus on NSO because the story is about what
         | NSO did. This is computer tech kind of community so you're
         | going to see more computer weapon stories here than stories
         | about improper use of rifles.
        
           | montblanc wrote:
           | The U.S sells super sophisticated weapons such as attack
           | drones, F-15s or nuclear submarines. The tech behind these
           | things is probably super interesting and there's a lot of
           | software involved. If you look at the comments here, around
           | 90% of them don't care about the tech at all but focus on
           | bashing Israel. This isn't a tech story.
        
             | chucksmash wrote:
             | It would certainly be a news story if someone used a U.S.
             | built submarine to attack the U.S. State Department.
        
               | montblanc wrote:
               | You do realize it was Ugandans who actually ordered the
               | hack yes?
        
               | hxkandbe wrote:
               | Uganda used a US submarine to hack the US State
               | Department?
        
               | hxkandbe wrote:
               | Is this a joke?
        
         | fnordfnordfnord wrote:
         | Unlike a firearm which has no intelligence or software, NSO
         | retains significant control over their product.
        
           | montblanc wrote:
           | U.S drones and F-15s don't have software?
        
         | sva_ wrote:
         | > For better or worse, NSO's product is a weapon. How is it any
         | different from an M-16? Where is the outrage towards the people
         | who used this weapon against the State Department?
         | 
         | It is highly unlikely that NSO group actually gives out their
         | exploits, based on what we know about previous exploitations
         | that have become known. It's more like they offer an interface
         | to execute their exploits on a given target. The fact that they
         | can block entities from using their service, after having had
         | access to it (like they supposedly did in this case), very
         | strongly supports this hypothesis. Hence they're offering a
         | service, to use weapons for (or rather, in the name of) some
         | (government) entity that pays them money to do so.
         | 
         | Imagine bombing-as-a-service, as an instance. That's much more
         | like it, and your argument doesn't hold in that case.
        
         | JumpCrisscross wrote:
         | > _don 't understand the focus on NSO in these stories. If U.S
         | State Department personnel in Uganda were shot from an M-16,
         | would the headline mention "an American arms manufacturer"? No,
         | because it's ridiculous._
         | 
         | No, because it isn't novel, it's not wide reaching, it's not at
         | arm's length and it cannot be stopped.
         | 
         | Stuxnet, a novel American-Israeli cyber weapon, purpose built
         | to hit Iran, was _absolutely_ billed as such. And it was
         | received differently, by Iran, than would be _e.g._ an
         | American-made gun fired by Iraqis at Iranian surrogates.
         | 
         | NSO is making and selling cyberweapons. They're doing it now.
         | These weapons are hitting the U.S. government and its allies to
         | an unknown extent. And they can be turned off, right now, if
         | Jerusalem orders it.
         | 
         | U.S. persons being shot in Uganda by Kalashnikovs are none of
         | these things. It's not novel. Nobody wonders if the Ugandans
         | are going to show up, guns blazing, in Arlington. And Moscow
         | can't remotely disable the guns.
        
           | [deleted]
        
         | octopoc wrote:
         | Unlike an M-16, hacks can be conducted remotely, they can be
         | used to plant evidence, conduct blackmail, and lots of other
         | things where most people would never know a hack was involved.
         | 
         | Also, there's outrage towards NSO because Israel is supposedly
         | an American ally. Israel needs American support, and yet Israel
         | freely allows Israeli corporations to sell services American
         | enemies. And this isn't an isolated company--there are other
         | Israeli hacking companies that target Americans, such as Black
         | Cube.
        
           | montblanc wrote:
           | Uganda is not an American enemy.
        
         | brendoelfrendo wrote:
         | Weapon merchants get flack all the time for selling their wares
         | to... we'll call them "rivals," but it could be any state or
         | organization not in the US's sphere of influence.
         | 
         | NSO gets particular flack because they're inextricable from the
         | weapon they sell. If an M-16 is used to shoot someone,
         | provenance is probably harder to prove; weapons change hands
         | all the time, or are smuggled to ne're-do-wells via the black
         | market. But everyone using Pegasus, as far as we know, is an
         | NSO client; NSO made the choice to provide that software,
         | including NSO support and NSO services.
        
         | eecc wrote:
         | Nope, that's a bad analogy. A manufacturer that produces and
         | sells thousands if not millions of items won't be deemed as
         | complicit as one building a nuke that somehow lands in your
         | enemies' lap.
         | 
         | That's pretty obvious and it's disingenuous that you're trying
         | to steer the conversation in that direction
        
       | boomboomsubban wrote:
       | >In a public response, NSO has said its technology helps stop
       | terrorism and that they've installed controls to curb spying
       | against innocent targets. For example, NSO says its intrusion
       | system cannot work on phones with U.S. numbers beginning with the
       | country code +1.
       | 
       | So the point is to stop terrorism and to do that they've
       | immediately ruled that all Americans aren't terrorists. That
       | doesn't seem like a good metric of determining if someone is a
       | terrorist, and makes me doubt their other controls are any
       | better.
        
         | JumpCrisscross wrote:
         | > _the point is to stop terrorism and to do that they 've
         | immediately ruled that all Americans aren't terrorists_
         | 
         | The alleged point is to sell software that stops terrorism.
         | Pissing off America is a good way to stop being able to sell
         | your software.
        
         | discreditable wrote:
         | Funny enough this reminds me of the ransomware that doesn't
         | work if a cyrillic keyboard is installed.
         | https://krebsonsecurity.com/2021/05/try-this-one-weird-trick...
        
           | fmajid wrote:
           | If you are a Russian hacker, you probably don't want to piss
           | off a Russian mobster who has the capability to take you out,
           | and the contacts within Russian intelligence to identify you.
        
           | fibbberMEN wrote:
           | Someone else linked that one, it's hilarious and unsurprising
           | really. Lots of people purposefully avoid certain OSes
           | (mostly linux distros) as well out of respect NOT because of
           | population/userbase of the OS. Lots of discussion on
           | worm/trojan development forums over the years.
        
         | snarf21 wrote:
         | "We promise we don't work on numbers with +1" :wink: :wink:
        
         | comrh wrote:
         | NSO has repeatedly shown that their statements are pretty much
         | worthless. It's just damage control. I wouldn't put any stock
         | in the "we avoid +1 numbers" to even be real.
        
           | boomboomsubban wrote:
           | > I wouldn't put any stock in the "we avoid +1 numbers" to
           | even be real.
           | 
           | That part I believed. Setting up their software to not target
           | the US seems like the kind of move they'd make. Claiming it's
           | so they don't target innocent people is bullshit.
        
           | bogwog wrote:
           | Seriously, they're pretty much the Mark Zuckerberg of their
           | industry.
        
             | submeta wrote:
             | I'd rather compare Zuckerberg to the Sackler family who
             | knew how addictive and harmful their painkiller Oxycotin
             | was, yet ignoring all evicence, making billions of dollars.
             | Zuckerberg knows how bad Facebook and Instagram is, how
             | harmful to individuals and society alike, yet ignoring that
             | and making billions.
             | 
             | Edit: Replaced ,,social media" with ,,Facebook and
             | Instagram"
        
               | dylan604 wrote:
               | Why did you feel the need for the edit? I would agree
               | with the blanket use of social media. Twitter is no
               | better. Do we know enough about the inner working of
               | TikTok to know they aren't doing similar?
        
             | indymike wrote:
             | That is not fair to Mark Zuckerberg.
        
               | rory wrote:
               | They're pretty much the General Butt Naked of their
               | industry.
        
         | [deleted]
        
         | notsureaboutpg wrote:
         | America (who are effectively the world police) have decided to
         | have pretty poor metrics to determine who is a terrorist, so
         | they set the precedent for this kind of stuff.
         | 
         | Random government officials in Iran cannot be considered
         | terrorists because of a an embassy hostage situation from 50
         | years ago during a revolution in the country. If they can, then
         | so can nearly every Chinese government official, every current
         | Russian government official who was high up in the USSR, every
         | current official in Iraq and Afghanistan, half the political
         | leadership of Lebanon, Vietnam, etc.
        
         | md_ wrote:
         | As an obvious statement: I think this should be interpreted
         | similarly to some ransomware not infecting devices with RU
         | keyboards: it's just about avoiding difficult regulatory
         | environments.
         | 
         | The analogy, of course, goes further. Though unlike most
         | ransomware companies, NSO has British and American VC funding.
        
         | shireboy wrote:
         | Most people don't know that the first bit of an area code is
         | the evil bit. https://en.wikipedia.org/wiki/Evil_bit
        
         | s_dev wrote:
         | So I just have to buy a US phone to evade detection from NSO?
         | And why didn't that logic work for US State Dept phones?
         | 
         | I'm honestly of the opinion there is nothing that NSO can say
         | that isn't outright lying. This isn't a normal company in
         | anyway.
        
           | shmatt wrote:
           | * A US Phone will route your call via NSA servers[1], so yeah
           | thats OK from the US governments side
           | 
           | * Publicly at least, NSO acknowledges there are state level
           | agreements, the latest one with France, to block entire
           | country codes from Pegasus (in return, France has stopped all
           | legal action against NSO)
           | 
           | * According to Israeli Channel 12 reporting on this tonight,
           | the official NSO response also includes the statement that
           | the accused numbers in the report were not +1 numbers. Their
           | so called "customers" were targeting US government employees
           | using African area codes. NSO claim they have completely
           | disconnected said customers from the system
           | 
           | [1] https://en.wikipedia.org/wiki/Room_641A
        
           | dkjaudyeqooe wrote:
           | Phone hardware is not tied to any particular number.
           | 
           | So you just need a SIM with a US number and use that for all
           | your evasion needs.
        
           | _jal wrote:
           | Yeah, this.
           | 
           | They started off with the arrogance of a liar who thought
           | they were immune from consequences. Now they're looking more
           | like the kid who is actually in trouble only now realizing
           | nobody trusts them to identify the sky color, let alone
           | defend themselves.
           | 
           | Anything and anyone coming out of that shop is tainted.
        
           | smnrchrds wrote:
           | I remember reading that some Russian (private sector)
           | computer viruses did not attack computers whose language and
           | locale were set to Russia. It's never about ethics. It's
           | always about making as much money as possible without pissing
           | off powerful people and entities.
        
             | madars wrote:
             | Yep, Krebs on Security wrote "Try This One Weird Trick
             | Russian Hackers Hate" --
             | https://krebsonsecurity.com/2021/05/try-this-one-weird-
             | trick...
        
             | prox wrote:
             | I had this with a Chinese app. Works well on a Chinese
             | language phone, downloads an extra package if not.
        
             | patrickyeon wrote:
             | Crudely, we would say "don't shit where you eat". I've
             | heard from the early (as in, 80's) hacking days some of the
             | people in the US would never hit targets in their own
             | state, as there wasn't good federal-level enforcement nor
             | inter-state collaboration. Of course that would backfire
             | today because you're immediately commiting crimes across
             | state lines...
        
           | diebeforei485 wrote:
           | > And why didn't that logic work for US State Dept phones?
           | 
           | These were Foreign Service officers stationed in Uganda, so
           | their phones had local Ugandan phone numbers. Some of them
           | were working out of DC but - given the nature of the State
           | Department (which is like America's foreign affairs
           | department) - probably traveled very frequently and so
           | maintained a Ugandan phone number as well, to save on roaming
           | fees when making calls in Uganda (saving money for the
           | taxpayer) and also so Ugandan officials can contact them
           | easily.
           | 
           | This is not unlike Apple hardware engineers who travel
           | frequently to China and have a Chinese number in addition to
           | their main US number, so people in the factory can
           | communicate with them easily.
           | 
           | > So I just have to buy a US phone [number] to evade
           | detection from NSO?
           | 
           | This is NSO's claim. Presumably because they want to make it
           | difficult for anyone to sue them in a US court. It's
           | plausible but I don't necessarily believe them either.
           | 
           | I want this company bankrupted out of existence, personally.
           | Apple's lawsuit against them may well result in that outcome.
        
           | boomboomsubban wrote:
           | >And why didn't that logic work for US State Dept phones
           | 
           | They had Ugandan numbers, as they lived in Uganda.
        
         | Apofis wrote:
         | These people are in for a world of hurt, the State Department
         | tells the CIA what to do.
        
           | [deleted]
        
           | JumpCrisscross wrote:
           | > _State Department tells the CIA what to do_
           | 
           | Your broader point is correct, but no, it doesn't. The CIA is
           | an independent agency [1]. It reports to the DNI [2].
           | 
           | [1] https://en.wikipedia.org/wiki/Independent_agencies_of_the
           | _Un...
           | 
           | [2] https://en.wikipedia.org/wiki/Director_of_National_Intell
           | ige...
        
             | Apofis wrote:
             | Yes, but who dictates where and how they can play overseas?
        
               | JumpCrisscross wrote:
               | > _who dictates where and how they can play overseas?_
               | 
               | The Director and Deputy Director of the CIA.
        
           | the_only_law wrote:
           | Heh, that showdown sounds like it would make for a hell of a
           | book decades later.
        
         | TriNetra wrote:
         | NSO has a deal with US Telecom to grow its market share
         | throughout the world and hence the +1 statement. /s
         | 
         | Maybe NSA wants every important call goes through USA network
         | (and hence a deal with NSO) - makes the job easier for three
         | letter agencies.
        
         | SamuelAdams wrote:
         | Reminds me of how some ransomware looks for if your default
         | keyboard language is Russian. If so then it exits, doing
         | nothing.
        
           | tut-urut-utut wrote:
           | OK, so the best way to protect privacy is to get US-based
           | phone number and install Russian keyboard as a default.
        
             | TriNetra wrote:
             | And it should have a list of sites blocked by Chinese
             | regime downloaded as discovered by Lithuania [0], for even
             | grater privacy.
             | 
             | 0: https://news.ycombinator.com/item?id=28616683
        
       | turings wrote:
       | I would not be surprised if it's an Israeli company behind using
       | NSO to steal it.
       | 
       | There's Lusha too and it's stealing info in plain sight. It's
       | basically stealing information and completely violating any GDPR
       | or Californian law. Here is a good spiel of the whole thing tying
       | their _founder_ to all the apps that steal information:
       | https://wwws.nightwatchcybersecurity.com/2020/02/20/another-...
       | 
       | And they just raised $200M to continue spying. The investors
       | probably have no clue https://techcrunch.com/2021/11/10/lusha-a-
       | crowdsourced-data-...
       | 
       | If we don't penalize crap like this, you encourage. And then it
       | booms somewhere else.
        
         | entom wrote:
         | Holy shit! How's Simple Apps stuff not shutdown by GDPR? Either
         | Simpler App is lying (thus GDPR kicks in) or Lusha. This is
         | insane
        
       | jiveturkey wrote:
       | uh oh. That's a paddlin'
        
       | kyahsworld wrote:
       | I have credit card data information + MSR HID + but i dont know
       | how to read or do the code metric etc in order to retrieve track
       | 1 or 2
        
       | walrus01 wrote:
       | I'm waiting for the day that the US declares a foreign
       | corporation as an "enemy combatant", as they have done with
       | foreign citizen wahabbist jihadis and US citizens such as Anwar
       | Al-Awlaki.
       | 
       | Given the extent and depth of US-Israeli cooperation and ties,
       | the precedeing theoretical is probably going to remain in the
       | realm of theoretical.
        
         | fmajid wrote:
         | That's pretty much what they did with NSO, which is getting the
         | Huawei treatment:
         | 
         | https://www.theregister.com/2021/11/03/us_sanctions_spyware/
         | 
         | reportedly, this has created havoc on NSO, since for instance
         | none of the cloud providers can sell services to them to host
         | their zero-days, among other logistics headaches. Their
         | recently hired CEO resigned.
        
           | BrianOnHN wrote:
           | What's the consequence for destabilizing governments
           | worldwide? Logistics headaches? Got it.
        
             | fmajid wrote:
             | The NSO guys are in it purely for the money. IIRC there was
             | a deal on the cards for some investors to buy the company
             | that fell apart because of the sanctions, so the NSO
             | founders can no longer cash out.
             | 
             | As for destabilizing governments, they are doing the
             | opposite, they are helping authoritarian governments
             | worldwide crack down on journalists and dissidents, or
             | murder them in the case of Saudi Arabia and Jamal
             | Khashoggi. Reportedly, after the Khashoggi murder, NSO
             | yanked the Saudi account but was forced to reinstate it by
             | Netanyahu who was pursuing diplomatic relations with them.
        
         | lostlogin wrote:
         | > I'm waiting for the day that the US declares a foreign
         | corporation as an "enemy combatant"
         | 
         | It's particularly interesting to watch as the company is based
         | in a country that is a very close ally.
        
           | galimaufry wrote:
           | Ignorant question: is Israel literally an ally of the US? I
           | know they are not in NATO or 5 Eyes, and I don't _think_ they
           | have some other close agreement, like US and Japan.
        
             | DaveExeter wrote:
             | Israel is a client state of the USA. They are America's
             | enforcers in the Middle East.
        
               | vorpalhex wrote:
               | That's factually wrong. Israel is it's own full state.
        
               | shrimp_emoji wrote:
               | The relations are green hearts, and the U.S. is
               | guaranteeing independence.
        
         | notsureaboutpg wrote:
         | They basically declared the embargoed Iranian corporations as
         | enemy combatants a while ago, if that's what you mean.
        
         | md_ wrote:
         | NSO's PE investors are big-time American and British funds.
         | 
         | Just sayin'.
        
           | bjourne wrote:
           | According to Wikipedia, NSO is owned by by its two founders
           | Omri Lavie and Shalev Hulio and Novalpina Capital. According
           | to Sky News Novalpina Capital is getting liquidated and their
           | stake in NSO will be sold to a third party:
           | https://news.sky.com/story/pegasus-spyware-owner-
           | novalpina-t...
        
             | md_ wrote:
             | Right. I can't tell if you're agreeing with me or not. :)
             | 
             | Prior to Novalpina, it was Francisco Partners.
             | 
             | Point being, NSO has received huge amounts of money from
             | the kind of people who, well, YCombinator founders seek
             | out.
        
         | drusepth wrote:
         | Didn't they get pretty close with Huawei when the previous
         | president issued an executive order in response to state spying
         | fears that:
         | 
         | * banned the sale of any of their phones or networking products
         | in the US
         | 
         | * banned US companies selling product to Huawei
         | 
         | * cut funding to wireless carriers using Huawei equipment
         | 
         | ...and then pressured allied countries to do the same?
        
           | goodpoint wrote:
           | > Didn't they get pretty close with Huawei
           | 
           | No, given that jihadists were kidnapped, tortured and
           | murdered - all of this illegally.
        
           | walrus01 wrote:
           | The investigation into Huawei was going on for many years
           | prior to 2016. It's not exactly an initiative of the previous
           | president.
           | 
           | I sat in briefings about Huawei and ZTE in 2007. Regretfully
           | can't say more.
        
             | deathhand wrote:
             | Are you personally upset about the clear intelligence
             | failures and extrfiltration of protected information?
             | 
             | I've grown up watching this unfold and I'm shocked that the
             | power groups seem to be so ineffectual at times that it's
             | laughable(but that may be by design...)
        
               | walrus01 wrote:
               | It's an absolute shitshow from top to bottom. The people
               | who know what they're doing in intelligence/counter-
               | intelligence agency infosec/netsec (and within major DoS
               | and DoD contractors) have been fully aware and ringing
               | the alarm bells for years. The technologically
               | unsophisticated politicians have been mostly ignoring it.
        
               | adamrezich wrote:
               | how much of the ignorance is willful?
        
         | afterburner wrote:
         | Just declare them a terrorist organization.
        
       | starik36 wrote:
       | I thought the exploited holes were patched by iOS at some point.
       | How are these phones still getting hacked?
        
         | 14 wrote:
         | In past exploits were used for jailbreaking. Now they can be
         | sold for 6 figures. The incentive to report vulnerabilities or
         | even use them casually for jailbreaking has gone way down. I
         | think the only way would be for Apple to offer 6 figure pay
         | outs for the exploits. Maybe they could get a tax write off.
        
         | odiroot wrote:
         | Exploits are now a multi-billion dollar market. And iPhones can
         | be obtained worldwide. You just need one person with
         | questionable morals, good hardware hacking skills and a need
         | for some hefty payout.
         | 
         | There's a lot of buyers, Five Eyes, China, Russia and naturally
         | companies like NSO.
        
         | kitsunesoba wrote:
         | People are notoriously bad at keeping their devices up to date,
         | with some even intentionally disabling updates. This can be
         | prevented by the IT department having MDM profiles with strict
         | update enforcement in place, but I don't have much hope that
         | the IT department of any given US government office is
         | particularly capable or competent.
        
           | brynx97 wrote:
           | The article doesn't say if they were personal or work
           | provided phones. Many people living/working overseas have
           | work and personal phones. Also, almost all of those with
           | personal phones get a local SIM, so they'd get a local non-US
           | (not +1) phone number. I used to be an IT admin with DOS
           | overseas. Updates were enforced, and phones were disabled if
           | they were not upgraded to the most recent version. Starting
           | in about 2019, mobile device security went into overdrive and
           | is very serious now. Additionally, the MDM profiles are quite
           | limiting, so this pushed most people to get personal phones.
           | A huge pain for records retention.
        
         | zibzab wrote:
         | Because there is a never-ending supply of vulnerabilities in
         | our smartphones.
         | 
         | A system this complex can never be secure no matter what
         | google/apple PR dep claims.
        
         | ryneandal wrote:
         | There's always another zero day
        
       | mjamil wrote:
       | Is anyone working on a microkernel design for privacy-sensitive
       | devices (like phones) that would prevent outright this class of
       | kernel-level arbitrary code execution exploits? We're stuck with
       | iOS and Android for the foreseeable future, but is there hope
       | that we'll get this right some day?
       | 
       | Actually, would a microkernel design even be sufficient? Given
       | that hackers exploit deserialization, memory safety, and variable
       | type confusion issues, there's still plenty of avenues for data
       | corruption and data leakage.
        
         | fulafel wrote:
         | I'm not convinced microkernels are the answwr but we do have
         | QubesOS.
        
         | eightails wrote:
         | Though currently Android-based, grapheneos is planning to move
         | towards a microkernel + virtualisation model eventually. I'd
         | imagine this is several years away at least, though.
         | 
         | https://grapheneos.org/faq#roadmap
         | 
         | There's also sel4, a security focused version of the l4
         | microkernel which is apparently one of the only formally
         | verified kernels.
         | 
         | https://sel4.systems/About/
        
         | junon wrote:
         | Yep, a number of people are, myself included. OSDev channels
         | have a few people who talk about it. The Fuchsia folks are
         | around, too, and are quite friendly people. They probably have
         | the most hopeful chance of a widespread release, though
         | admittedly I worry about the affiliation with Google getting in
         | the way of pro-consumerism. Just my opinion though.
        
         | kevingadd wrote:
         | User-space ACE would still be enough to do something like this.
         | All sorts of user-space apps have the relevant permissions and
         | are not secured against attacks to the necessary extent to stop
         | a state level actor.
        
         | bri3d wrote:
         | Many of the kernel issues exploited in iOS are caused
         | indirectly by its microkernel architecture, namely, the use of
         | "ports" for kernel to kernel and kernel to user land IPC. For
         | example: https://bugs.chromium.org/p/project-
         | zero/issues/detail?id=21... .
         | 
         | Microkernel vs monolithic kernel has little to do with this,
         | IMO. The main issues are asynchronous complexity and memory
         | safety.
         | 
         | Also, a lot of your most sensitive data lives in userland. If
         | someone gets access to the iMessage sandbox and the message
         | database files, that's your most sensitive and privileged data
         | gone, no kernel touched.
        
           | stefan_ wrote:
           | And the userland is the worst possible combination of
           | technology imaginable for this purpose - a memory unsafe
           | language with a ton of magic dynamic features. You get the
           | horrible serialization issues from Java & Ruby with the same
           | old heap, stack and integer overflows we've come to love in C
           | and mix in some of the runtime control flow from C++.
        
         | CameronNemo wrote:
         | The Intel ME runs a microkernel but it is still exploitable
         | (even if you "clean" it).
         | 
         | SEL4 and Fuchsia seem to have a security focus, but whether
         | that results in real world difficult to exploit devices is
         | unclear.
        
         | fsflover wrote:
         | Perhaps something like this:
         | https://www.crowdsupply.com/sutajio-kosagi/precursor.
         | 
         | Or, just use Linux on the smartphone and harden it with a
         | smartcard (Librem 5).
        
         | Raqbit wrote:
         | Google is, with Fuchsia: https://fuchsia.dev
        
         | apayan wrote:
         | I'm not aware of any microkernels for phones (I'm not sure that
         | would help either), but Android has been sandboxing more and
         | more processing [1] and started using some Rust at the system
         | level [2] ever since the stagefright bug [3].
         | 
         | 1: https://android-developers.googleblog.com/2019/05/queue-
         | hard...
         | 
         | 2: https://security.googleblog.com/2021/04/rust-in-android-
         | plat...
         | 
         | 3: https://en.wikipedia.org/wiki/Stagefright_(bug)
        
       | vinniejames wrote:
       | They shouldn't have anything to worry about, unless they have
       | something to hide
        
       | FredPret wrote:
       | Seems like not-the-smartest move for Israel to mess with one of
       | the few powerful entities that desires its continued existence
        
         | ElDji wrote:
         | and the one entity that give it wagons of usd.
        
         | fnordfnordfnord wrote:
         | Or the smartest move. They probably own more politicians than
         | the NRA, the pharma ind, and and the aerospace ind combined.
        
         | JohnWhigham wrote:
         | This is just another incident in a long list that goes back
         | decades of Israel getting carte blanche to do whatever they
         | want to the US with little to no repercussion. The most famous
         | probably being USS Liberty
         | (https://en.wikipedia.org/wiki/USS_Liberty_incident)
        
           | l33tbro wrote:
           | Why would Israel be allowed to do whatever they want?
        
             | theknocker wrote:
             | Exactly, genius.
        
             | kevingadd wrote:
             | https://en.wikipedia.org/wiki/American_Israel_Public_Affair
             | s...
        
         | [deleted]
        
         | dr-detroit wrote:
         | There is 0 popular support for Israel and their "religion of
         | peace". Biden got in soooo much trouble for saying he would
         | divest during the election.
        
         | Dma54rhs wrote:
         | Everyone knows already nothing will happen, they will get slap
         | on the wrist as usual and show goes on.
        
       | varispeed wrote:
       | Isn't the actual problem that a private company is using security
       | holes that presumably Apple opened for three letter agencies to
       | use?
        
       | redman25 wrote:
       | > NSO Group said in a statement on Thursday that it did not have
       | any indication their tools were used but canceled the relevant
       | accounts and would investigate based on the Reuters inquiry.
       | 
       | Why would they cancel accounts without knowledge of wrongdoing?
        
         | becuz99h wrote:
         | They canceled them because "How about this weather, Janet?
         | 
         | That's right, Bob! It'll be a cold one this week. Sportsball is
         | next."
         | 
         | What weasel words?
        
         | q1w2 wrote:
         | Aside from that obvious contradiction - this also indicates
         | that the tools they deploy are either NSO hosted or use a
         | licensing system to run.
         | 
         | There was a recent Darknet Diaries episode that reported
         | evidence that at least _some_ of the NSO tools are hosted
         | services.
        
           | shmatt wrote:
           | I can't imagine something like this not being in the cloud.
           | The potential for a customer to give their local NSA/8200 the
           | tool to figure out the 0days used is too large
           | 
           | Pegasus is only as good as its 0days are secret
        
             | [deleted]
        
         | gameswithgo wrote:
         | Remember that this group's tools have been used to murder
         | journalists, which they are unapologetic about.
        
           | turminal wrote:
           | Dead journalists can't close them down, but the US government
           | can.
        
             | Eelongate wrote:
             | I think that remains to be seen.
        
               | JumpCrisscross wrote:
               | > _that remains to be seen_
               | 
               | Oh man, for purely comical purposes I would _love_ to see
               | NSO actually believe that.
        
               | Eelongate wrote:
               | In principle, America could drop Hellfire R9X sword
               | missiles through the cars of every NSO employee. In
               | practice, would American politicians have the nerve to go
               | to war with NSO, when NSO probably infected all their
               | phones years ago? How much dirt do they have on American
               | politicians?
        
               | vorpalhex wrote:
               | So you think because NSO breached a few state department
               | phones that they have the deep dirt on every sitting
               | congress member?
        
               | [deleted]
        
               | Eelongate wrote:
               | You think the iceberg is coincidentally only as deep as
               | what we've presently heard? That we didn't have the full
               | story yesterday, but today we definitely do?
               | 
               | Well I hope you're right, but I don't think you are.
        
               | vorpalhex wrote:
               | Well how do you know the NSO hasn't replaced the sitting
               | US President with a very convincing android?
               | 
               | I mean, they are a very skilled set of engineers. You
               | seem to grant them being able to hold onto very powerful
               | secrets and use them for active blackmail. You even
               | believe they've been operating actively against the US
               | government for several years.
               | 
               | If they can do all that, then replacing the sitting US
               | president with a very convincing android isn't much
               | harder! It is just as likely as the situation you
               | propose.
        
               | Eelongate wrote:
               | NSO is skilled at hacking androids, not making them. You
               | know that; you are arguing in bad faith.
        
               | catlikesshrimp wrote:
               | I can believe that a foreign hacking group, who can
               | zeroclick the most widely used personal device to obey a
               | remote control center, who sells this service to
               | totalitarian regimes and to corrupt governments, has
               | exfiltrated as much data as they can. They are careful
               | enough to cover their tracks as part of the service.
               | 
               | What I cannot believe is you dismiss concern over ongoing
               | security risks, however exagerated, by suggesting a head
               | of state might have been replaced by an android. Please
               | don't troll.
        
         | intunderflow wrote:
         | Because the US government is one of the few groups that can put
         | real pressure on them and they're in full panic mode
        
         | fabianhjr wrote:
         | And simultaneusly:
         | 
         | - not have any indication their tools were used
         | 
         | - canceled the relevant accounts
         | 
         | Which "relevant" accounts if NSO's tools weren't used?
        
           | seoaeu wrote:
           | Presumably the full accusation is "Entity ABC used NSO tools
           | _for XYZ_ ". So the reaction was to cancel ABC's account
           | while NSO investigates whether ABC actually did use the tools
           | for XYZ, or whether ABC was only using them for other
           | (approved) purposes.
        
             | BrianOnHN wrote:
             | Regardless, NSO rules over international law.
        
           | klabb3 wrote:
           | Shrodinger's moderation. NSO has this magical zero-knowledge
           | technology that:
           | 
           | - When questioned about _a specific malevolent client_
           | misusing their data, they cannot be held accountable because
           | the client is running the ops and NSO has no access.
           | 
           | - When asked how they ensure that _clients in general_ don 't
           | go rogue and misuse (i.e. human rights & international law
           | abuse) their service, they assure you they monitor them and
           | turn off their access.
        
           | Cyph0n wrote:
           | I think it's pretty clear by now that they have 100%
           | visibility into the entire exploitation chain for all of
           | their customers. Their "official statements" mean nothing.
        
       | christophilus wrote:
       | Well, that wasn't predictable at all.
       | 
       | In all seriousness, I hope this finally prompts our agencies to
       | push for stronger security and better encryption rather than
       | fighting it as they have for so long.
        
       | SavantIdiot wrote:
       | The Israel government gets a pass for anything they do. Whether
       | it is lying about nukes or what they've done to Palestine. NSO is
       | a feather in their cap.
        
         | jjclint wrote:
         | Sounds like you and some other "clever" souls have an axe to
         | grind with Israel.
        
           | boomskats wrote:
           | > "clever"
           | 
           | This is offensive. They outlined how they disagree with the
           | Israeli _government_ pretty clearly in their comment.
        
         | voz_ wrote:
         | Please don't virtue signal, or state flame wars, or use this to
         | posture some kind of agenda.
        
           | birdyrooster wrote:
           | Please don't mistake yourself for dang
        
           | devmunchies wrote:
           | I'm not seeing any virtue signaling.
        
         | q1w2 wrote:
         | These political flame comments don't belong on HN.
        
         | dang wrote:
         | Please do not take HN threads further into generic flamewar
         | hell. It's not what this site is for, and it destroys what it
         | is for.
         | 
         | We detached this subthread from
         | https://news.ycombinator.com/item?id=29432721.
        
         | flyinglizard wrote:
         | Why are you conflating Israel (a state) and NSO (a fully
         | private company, owned by American private equity at some
         | point)?
        
           | [deleted]
        
           | ignoramous wrote:
           | _The Israeli Ministry of Defense licenses the export of
           | Pegasus to foreign governments, but not to private entities._
           | 
           | https://en.wikipedia.org/wiki/NSO_Group#Pegasus
        
             | flyinglizard wrote:
             | These export controls for weapons exist in much of the
             | western world. Once granted a license, Israel has no legal
             | say in how the product is used by the end user.
             | 
             | It's all very routine and standard, not sure why people
             | need basic explanations of what government export
             | regulation is when the discussion is on Israel.
        
               | [deleted]
        
               | thekid314 wrote:
               | It goes much deeper than that. For a while now Israel has
               | been using NSO as an incentive for foreign relations with
               | authoritarian regimes.
               | 
               | https://www.theguardian.com/world/2021/jul/20/pegasus-
               | projec...
               | 
               | https://foreignpolicy.com/podcasts/foreign-policy-
               | playlist/h...
               | 
               | https://www.nytimes.com/2021/11/08/world/middleeast/nso-
               | isra...
               | 
               | https://www.haaretz.com/israel-news/tech-
               | news/.premium.HIGHL...
               | 
               | https://www.irishtimes.com/news/world/middle-east/how-
               | israel...
               | 
               | https://www.ft.com/content/24f22b28-56d1-4d66-8f76-c9020b
               | 1b5...
               | 
               | https://www.jpost.com/jpost-tech/what-does-the-nso-
               | hacking-s...
        
           | [deleted]
        
           | JumpCrisscross wrote:
           | > _Why are you conflating Israel (a state) and NSO (a fully
           | private company, owned by American private equity at some
           | point)?_
           | 
           | Because Jerusalem has the power to stop, or at the very least
           | regulate, NSO.
        
       | classified wrote:
       | The victims will be pleased to learn that they're all terrorists
       | and criminals, as NSO keeps asserting that their spyware is only
       | used against those.
        
       | Iwan-Zotow wrote:
       | "Hello, dog!" Said tail
        
       | SavantIdiot wrote:
       | Slapping down the NSO doesn't fix the problem. We should be glad
       | we even know that their software exists, imagine if it was
       | completely hidden from the public? The problem is that Apple
       | needs to fix this. Security is an arms race, and the more
       | visibility we have into where it is weak, the better for
       | everyone. To paraphrase the motorcycle repair episode of Winter
       | Steele, "You are stronger now for having been fixed." IMHO.
        
         | shmatt wrote:
         | Great commentary. The US is hopefully looking into why these
         | employees are using iPhones + local SIM. And if that has been
         | approved in the past, maybe re-think that
        
         | elliekelly wrote:
         | I don't think most Apple customers know or care so despite
         | being ostensibly "privacy focused" Apple doesn't have much of
         | an incentive to take action.
        
           | fmajid wrote:
           | Apple has demonstrated complacency on security issues.
           | Stiffing security researchers on bug bounties is just one
           | symptom, but so is the fact the market price for iOS exploits
           | has cratered compared to Android ones.
        
       | motohagiography wrote:
       | Arguably, this is the real use case Pegasus was designed for. A
       | government (Uganda) that does not have a large and mature civil
       | service that would support a G7 level technical domestic
       | intelligence agency went to market for the tools of one (NSO), so
       | they can keep tabs on foreign intelligence agents (state
       | department staff) in their country. I am not a fan of NSO at all,
       | but this case sounds like they're providing sovereignty or
       | statecraft as a service to a government that prefers to buy
       | instead of build their security capability.
       | 
       | When the game is defined as a competition for how to break its
       | rules in the most unexpected ways and with the fewest
       | consequences, Uganda appears to have joined in with aplomb. To me
       | it's the first time an NSO story doesn't seem like a scandal.
        
         | bjourne wrote:
         | The "oh, but everyone is doing it!" argument. I don't for a
         | second believe that other countries install spyware on foreign
         | diplomats and other peoples phones. What NSO and the Israeli
         | government is doing is rotten to the core and unless you have
         | evidence of the contrary you cannot assert that other actors
         | are doing the same thing.
        
           | jimbob45 wrote:
           | I know you're joking but for anyone that's not in on the
           | joke:
           | 
           | https://www.bbc.com/news/world-europe-24690055
        
             | bjourne wrote:
             | Wow! You found one instance of the US spying on a friendly
             | government. That totally justifies NSO leasing spyware to
             | authoritarian third world regimes! Carry on folks, nothing
             | to see here.
        
               | smoldesu wrote:
               | It doesn't justify it, but if we're going to take a
               | stance against spyware, we have to take a stance against
               | _all_ spyware. That includes the home-rolled stuff that
               | the NSA pushes out to Apple and Google.
        
               | triactual wrote:
               | No, we don't.
        
               | smoldesu wrote:
               | What makes that kind of hypocrisy okay?
        
               | Thorncorona wrote:
               | It seems if Israel is receiving money from the US
               | government and Israel controls the usage of NSO group
               | weapons that are being targeted at the American
               | government then there are problems yea?
        
               | smoldesu wrote:
               | It's a catch-22. Telling other countries not to spy on us
               | while we happily spy on others is a double standard.
        
       | aunty_helen wrote:
       | Imagine that sinking feeling in the NSO offices. Uncle Sam's
       | coming...
        
         | sixothree wrote:
         | You sure about that?
        
       | newbamboo wrote:
       | " NSO says its intrusion system cannot work on phones with U.S.
       | numbers beginning with the country code +1."
       | 
       | Seems like they just need to add a similar patch for apple ids
       | for emails ending in "state.gov". Not sure why this is such a big
       | deal.
        
         | [deleted]
        
         | walrus01 wrote:
         | which is pretty absurd since there's only a vague relationship
         | in the modern SS7/PSTN between a phone's DID and where it might
         | be physically located. In five minutes of work I could have a
         | New Zealand number ring on my desk phone anywhere in the world.
        
         | Scoundreller wrote:
         | So it doesn't work on US phone numbers or doesn't work on +1
         | country code?
         | 
         | -confused Canadian because we share the +1 country code with
         | USA under NANPA
        
         | fmajid wrote:
         | Presumably those phones had Ugandan numbers.
        
         | kshacker wrote:
         | Canadians go 'yay', finally some benefit of the big brother.
         | 
         | PS: I don't buy the explanation btw
        
         | asplake wrote:
         | As someone who doesn't have a +1 number I find it hard to take
         | this comment seriously. But could it be possible that some
         | state department employees work outside the US?
        
         | whatshisface wrote:
         | Come on, think about it. Doesn't work for phone numbers
         | starting with +1? So, anyone who buys the right sim card is
         | immune? A team of professional hackers can't find the if-else
         | in the attack binary that enforces that to disable it? They're
         | selling software to cybersecurity teams on the assumption that
         | they can't crack it?
        
           | indymike wrote:
           | > A team of professional hackers can't find the if-else in
           | the attack binary that enforces that to disable it?
           | 
           | It's probably easier than that. Seems like the kind of thing
           | that would be in a config file (making this up, satire):
           | 
           | [No Spying Allowed - please do not change]
           | 
           | # Really, really, don't change this setting. We are not
           | responsible if you do.
           | 
           | +1 # USA
           | 
           | +3542 # NSO Group
           | 
           | > They're selling software to cybersecurity teams on the
           | assumption that they can't crack it?
           | 
           | No, I think they are telling journalists that their hands are
           | clean, and it totally isn't their fault, not in a million
           | years, that their customer changed their software.
        
           | RealityVoid wrote:
           | My understanding is that it's not _just_ a tool, but a whole
           | infrastructure around it that the clients use. So presumably,
           | before deploying to a target, it would need to go through NSO
           | infrastructure, so they could vet there.
        
       | illusivesaint wrote:
       | Wow, Israeli's spying on their main sponsor?? Espionage is part
       | of the political territory but hopefully this sets precedent to a
       | change of optics. (Which probably not since Russia does it boldly
       | for fun at this point).
        
       | afterburner wrote:
       | This was entirely predictable.
        
       | cblconfederate wrote:
       | Time to go back to rotary phones
        
         | yodon wrote:
         | As discussed 2 days ago here on HN
         | 
         | https://news.ycombinator.com/item?id=29401454
        
         | fabianhjr wrote:
         | Just get calyxOS or any other privacy + security FOSS mobile
         | operating system.
        
       | tdhz77 wrote:
       | NSA backdoors the peg spyware and Apple believes State Department
       | has been hacked when in reality the information return has been
       | manipulated. State Actors believe the information they received
       | is legit, when it's actually what the US wants them to see. This
       | is common knowledge that CIA had hands into the development of
       | Pegasus. The media hasn't been able to keep up yet.
        
       | cronix wrote:
       | As an American, it's becoming harder for me to muster sympathy
       | for an entity that actively discovers and exploits technological
       | flaws to use against their adversaries while simultaneously
       | purposefully not alerting the manufacturers in order to correct
       | the flaws so they can continue to exploit them and then those
       | flaws are subsequently discovered by others and used against
       | them. Poor you.
        
       | literallyaduck wrote:
       | Let's cancel their foreign aid, 3 Billion and change, and put a
       | trade embargo until they pay back all their foreign aid.
        
         | [deleted]
        
       | markus_zhang wrote:
       | This is a typical "shadow government" symptom. You have forces
       | working within the government that 1) have their own agendas; 2)
       | have connection to international communities, usually military-
       | intelligence ones; 3) have almost zero regulation; 4) even many
       | high ranking government officials don't know about them because
       | they are brotherhood-like closed circles.
       | 
       | This reminds me of Operation Gladio or Propaganda Due but
       | domestic. Same playbook, different players.
        
         | KennyBlanken wrote:
         | Implying that Israeli spying on the US is some fringe "shadow
         | government" sub-group of the Israeli government is strange
         | given a long, long history of high profile Israeli spying
         | incidents against the US.
         | 
         | https://en.wikipedia.org/wiki/Lawrence_Franklin_espionage_sc...
         | 
         | https://en.wikipedia.org/wiki/Jonathan_Pollard
         | 
         | https://en.wikipedia.org/wiki/Ben-Ami_Kadish
         | 
         | https://en.wikipedia.org/wiki/Jack_Parsons_(rocket_engineer)
         | 
         | Then there's the time they stole nuclear material from us
         | https://en.wikipedia.org/wiki/The_Apollo_Affair
         | 
         | Then there's the time they slaughtered several dozen US navy
         | and NSA personnel with repeated attacks on an unarmed vessel
         | because they didn't like that we were watching them:
         | https://en.wikipedia.org/wiki/USS_Liberty_incident
        
           | ginja wrote:
           | The US spies on its European allies all the time, and I'm
           | sure they spy on Israel too, so that's not super surprising.
           | 
           | As for the USS Liberty, some do argue that it was
           | intentional, but both the Israelis and Americans ended up
           | agreeing that it was a mistake. The US is no stranger to such
           | mistakes either, even more egregious ones like when they
           | killed close to 300 civilians aboard a regular passenger
           | flight following an approved route and in contact with ATC
           | (Iran Air 655).
           | 
           | In the end both the US and Israel are amoral states that act
           | only according to their economic and strategic interests and
           | I feel that this unites them. I wish it didn't, though.
        
             | colordrops wrote:
             | They _officially_ decided it was a mistake, as it did
             | neither government any good to officially announce that it
             | was intentional. But the sailors that were on the ship say
             | otherwise.
        
             | stjohnswarts wrote:
             | And the European allies spy on the USA, rinse and repeat.
        
           | Lammy wrote:
           | Why would the tail wag the dog? America benefits so much from
           | all the R&D (in e.g. encryption) that can't happen on US
           | soil. They are not our enemy in any way :)
           | 
           | https://en.wikipedia.org/wiki/Report_to_the_Secretary_on_the.
           | ..
           | 
           | https://www.nybooks.com/articles/2001/09/20/the-truth-
           | about-...
        
           | keewee7 wrote:
           | The USS Liberty incident happened 52 years ago.
           | 
           | >because they didn't like that we were watching them
           | 
           | That is the American conspiracy theorist interpretation of
           | the incident that (understandably) also gained traction among
           | a few of the survivors. The Israelis disagree.
           | 
           | It was most likely a case of mistaken identity. Just like
           | friendly fire incidents. Friendly fire incidents happen all
           | the time, including between US forces in the recent Iraq and
           | Afghanistan conflict.
        
             | darwingr wrote:
             | The Liberty was also very far from where the Americans had
             | told the Israelis where it would be. Finding the ship there
             | was unexpected and calls to confirm its identity were not
             | being answered.
        
             | albatross13 wrote:
             | Oy vey what an antisemtic statement, assuming Israeli
             | forces are incapable of knowing friend from foe.
        
               | jack_riminton wrote:
               | It's not in the least bit anti-semitic and to suggest so
               | is inflammatory
        
               | albatross13 wrote:
               | You suggesting me pointing out antisemitism online being
               | inflammatory is actually deeply antisemtic and a white
               | supremacist dog whistle.
        
             | Minor49er wrote:
             | The survivors said that the pilots were waving at them
             | before they carried out the attack
        
               | lovelyviking wrote:
               | can you provide the source?
        
           | markus_zhang wrote:
           | By saying "shadow government" I mean groups within the US
           | government that has connection to say NOS.
           | 
           | Again I don't have concrete proofs so I could be 100% wrong.
           | But reading world history especially cold war history makes
           | me be sceptical to certain things.
        
             | BoardsOfCanada wrote:
             | Hilarious that anyone thought you were talking about an
             | Israeli shadow government.
        
           | Eelongate wrote:
           | > _Then there 's the time they stole nuclear material from us
           | https://en.wikipedia.org/wiki/The_Apollo_Affair_
           | 
           | On a related note, JFK was trying to shut down Israel's
           | nuclear weapons program in the months before his murder.
           | 
           | https://www.jewishvirtuallibrary.org/kennedy-letter-to-
           | ben-g...
        
             | duped wrote:
             | I'm sure he was conducting a lot of international policy
             | initiatives in the months before his assassination
        
               | pphysch wrote:
               | Yeah, like (secret) detente with Fidel Castro [1].
               | 
               | [1] -
               | https://nsarchive2.gwu.edu/NSAEBB/NSAEBB103/index.htm
        
           | stjohnswarts wrote:
           | Anyone who doesn't think the USA and Israel don't spy on each
           | other 24/7 is living in a dream world. Israel is an ally but
           | I don't think that they are our friends.
        
         | dqpb wrote:
         | > 3) have almost zero regulation;
         | 
         | What would shadow government regulation look like?
        
           | markus_zhang wrote:
           | It's difficult, you have to break down those brotherhoods who
           | will fight to death to be "independent". And then you have to
           | find a way to prevent them from spawning again. I don't have
           | any idea how to do it properly.
        
             | cwkoss wrote:
             | I'd expect if we lived in the sort of society that would
             | execute the head of the NSA for treason or something
             | similar when the Snowden revelations came out, it would
             | have societally beneficial chilling effect on intelligence
             | organization brazenness.
             | 
             | Unfortunately, it seems intelligence is mostly immune from
             | liability, and lack of consequences lets the rot fester.
        
               | markus_zhang wrote:
               | Once the system is setup who is in control is going to be
               | irrelevant. I believe the best approach is to educate the
               | citizens so that 1) They follow scientific methods; 2)
               | They are more resistant to advertisement/propaganda; 3)
               | They are keen to corruption and willing to protest.
        
               | catlikesshrimp wrote:
               | "1) They follow scientific methods. 2) They are more
               | resistant to advertisement/propaganda; 3) They are keen
               | to corruption and willing to protest."
               | 
               | You are asking way too much of people. "Normal" people
               | can't fulfill any of those 3 requests. Not that they
               | don't want to (most don't), or that they aren't taught to
               | (this is conflicting through life)
               | 
               | They can't. #1 and #2 sound like something an autist
               | would tend to do.
        
           | linschn wrote:
           | Maybe stop funding them, for a start?
           | 
           | Congressional oversight used to be a thing.
           | 
           | Snowden showed the NSA lied to congress. No heads rolled.
        
             | throaway46546 wrote:
             | Imagine all the dirt the NSA has on congress.
        
               | ruined wrote:
               | remember when the cia interfered with the congressional
               | investigation of their torture program, by getting the
               | FBI to investigate senators for viewing the documents
               | that the CIA provided them, and spying on the senate
               | investigation activities, and then nothing happened
               | 
               | https://www.cnn.com/2014/03/18/politics/cia-senate-
               | dispute-f...
               | 
               | https://www.reuters.com/article/us-cia-senate-
               | idUSKBN0KN2Q82...
        
               | cwkoss wrote:
               | Imagine how much society would improve if all the dirt
               | got aired.
               | 
               | Hiding this information is trading the wellbeing of the
               | country for the NSA's own internal goals and power.
        
               | gunfighthacksaw wrote:
               | Dangerously based and you're-about-to-commit-suicide-
               | with-two-gunshots-to-the-head pilled
        
               | mcbutterbunz wrote:
               | > Imagine how much society would improve if all the dirt
               | got aired.
               | 
               | Depends on the dirt. Some of it might be private and
               | personal stuff, such as infidelity. That type of stuff,
               | while blackmailable, doesn't really benefit the public
               | much.
        
               | Eelongate wrote:
               | The public's elected representatives being easily
               | blackmailable is obviously of great concern to the
               | public, I don't know why you're downplaying this.
        
               | OminousWeapons wrote:
               | Everyone has dirty laundry they would prefer not be
               | aired, and if they don't then their friends, family, or
               | partners do. I don't think we want to live in a world
               | where absolute moral purity (as determined by the most
               | vocal, biased critics of a given person) is required to
               | hold public office.
        
               | krapp wrote:
               | >I don't think we want to live in a world where absolute
               | moral purity (as determined by the most vocal, biased
               | critics of a given person) is required to hold public
               | office.
               | 
               | Don't worry, you live in a world where a man with a well
               | documented decades-long laundry list of scandals and
               | faux-pas can brag on tape about how he can get away with
               | molesting young women because of how rich he is and still
               | get elected President.
               | 
               | I'm actually wondering what you _could_ effectively
               | blackmail an American politician with, given how little
               | Americans seem to care about the morality of their
               | leaders. Maybe just the eponymous  "dead girl or live
               | boy," but then you have the Kennedys...
        
               | catlikesshrimp wrote:
               | Don't believe representatives are elected because of
               | their integrity and their willingness to serve.
               | 
               | They represent groups of interest. And being
               | blackmailable is, in my opinion, a handy leash to keep
               | them in check, for those groups which propose the
               | candidates
               | 
               | The public is not concerned with corruption until they
               | feel affected by it.
        
             | literallyaduck wrote:
             | Why would heads roll?
             | 
             | Congress has blocked inquiries into their split loyalty as
             | far as them having multiple citizenship in other countries.
             | If you were McDonald's board of directors would you allow
             | someone to be on both the McDonald's board and Wendy's?
             | 
             | Congress isn't personally harmed by a surveillance state
             | unless you consider they may all be being blackmailed but
             | that is another conversation. In fact mass surveillance
             | widens the barrier to new entries into politics as they can
             | use whatever dirty they find and give it to federally
             | funded media mouthpieces.
             | 
             | This week we saw articles of sexual crimes against children
             | being swept under the rug to "protect our country" do we
             | really think that congress would actively pursuit this line
             | of inquiry?
        
               | BoardsOfCanada wrote:
               | Context:
               | https://www.wsws.org/en/articles/2014/03/07/spyi-m07.html
        
             | jjeaff wrote:
             | I can believe there are shadow organizations that lack
             | oversight. In fact, it seems likely.
             | 
             | But that these shadow organizations are maintaining power
             | by surveiling and blackmailing congress people is a whole
             | other ballgame and seems highly unlikely to me.
             | 
             | For one, it's likely that not every Congressperson has some
             | deep dark secret that makes them blackmail-able. And
             | pissing off the only group of people that could cut your
             | funding and expose your shadow organization as well as
             | bring oversight is not the group that you want to be
             | pissing off.
             | 
             | I think game theory would indicate that your only chance of
             | maintaining a shadow organization in the US gov for any
             | length of time is going to be secrecy and maybe some
             | heavily funded lobbying.
        
               | arthur_sav wrote:
               | > But that these shadow organizations are maintaining
               | power by surveiling and blackmailing congress people is a
               | whole other ballgame and seems highly unlikely to me.
               | 
               | Why is it so hard to believe that a few powerful
               | indivisuals at the top, with common interests and
               | agendas, are banded together?
               | 
               | There's no official organization but a few indivisuals
               | that streer things their way because they can.
        
               | autoexec wrote:
               | > For one, it's likely that not every Congressperson has
               | some deep dark secret that makes them blackmail-able.
               | 
               | I'd be more than willing to bet that they do. "If you
               | give me six lines written by the hand of the most honest
               | of men, I will find something in them which will hang
               | him." and that only covers "honest" men who wouldn't have
               | illegal coordination with PACs, bribes with lobbyists,
               | personal communications filled with racism, or evidence
               | of sexual activities that might upset their base. When "6
               | lines" becomes a record of everything you've ever done
               | online, all of your communications, your GPS coordinates
               | and the data of anyone around you it's going to get
               | easier to find a noose around your neck.
               | 
               | Even if there managed to exist a single person in
               | congress who wasn't screwing over the American people
               | somehow for personal gain, or didn't have some skeleton
               | in their closet they didn't want exposed to
               | voters/campaign contributors when a group is capable of
               | compromising your system and inserting whatever offensive
               | material they want to use against you it's incentive
               | enough to back off.
        
               | willcipriano wrote:
               | You only need the capture the party leadership, they can
               | keep everyone else in line via fundraising initiatives.
        
               | Spooky23 wrote:
               | Politics is a funny business. I have spent alot of time
               | dealing with political people ranging from staffers to
               | actual officials.
               | 
               | Many are very well meaning public servants, others
               | careerists, some are... insane on various scales.
               | Politics is a business with uncertain outcomes where
               | "friends" are important and personal stakes are high.
               | 
               | From a blackmail perspective, you have people like the
               | bartender turned member of congress who got their GED to
               | run who are obvious puppets with a wheelbarrow of odious
               | behavior behind them. But even the most boring
               | congressman has a legal escrow account with
               | irregularities, a kid with emotional problems that caused
               | trouble, a campaign finance violation, etc.
               | 
               | I don't think there is a shadow cabal, but some executive
               | branch entities wield tremendous power.
        
               | btheshoe wrote:
               | AOC is an obvious puppet?
        
               | Spooky23 wrote:
               | Not quite. Different educational dynamic. Polarizing
               | figure for sure, but whomped an old school political
               | machine candidate.
        
               | dzonga wrote:
               | how would you cut the budget of the CIA for example, an
               | organization that doesn't really answer to anyone but
               | itself ? an organization that can self fund when it
               | wants. Eisenhower, a general called out the so called
               | military industrial complex in a way that befits a
               | prophet
        
             | thelittleone wrote:
             | I'm all for sorting the problem out, but isn't the reality
             | a little more complex given other countries? Doesn't
             | cutting your intelligence / signals budgets give your
             | "enemies" an advantage? By "enemies" I'm referring
             | predominantly to foreign nation states.
        
           | pueblito wrote:
           | More light and transparency = less shadows
        
           | chillwaves wrote:
           | Enforce our laws would be a good start.
        
         | pstuart wrote:
         | 5) many high ranking government officials do nothing about this
         | because they're being blackmailed by the spooks.
         | 
         | Tinfoil hat territory? Sure. Plausible _and_ possible? Sure.
        
         | zaphirplane wrote:
         | There is nothing supporting the theory or conclusion
        
           | colordrops wrote:
           | What are you trying to suggest? It's just a typical reflexive
           | reactive response to any comment that the government acts in
           | ways other than presented to you by corporate media.
           | 
           | It only takes 3 minutes of google searches or even a daily
           | scan of Hacker News to see endless examples of government
           | corruption and malfeasance. Government employees are only
           | human after all, and there are millions of them. To think
           | this sort of activity ends once you become an agent of the
           | government is absurd.
        
             | WFHRenaissance wrote:
             | > Government employees are only human after all
             | 
             | This weekend I was traveling and I put the stray $20 from
             | my pocket in the bin at the TSA checkpoint. An agent
             | quickly pulled it out and handed it back to me. He then
             | said "a lot of good people work here, but they're still
             | human". It's kind of wild that we endure that level of
             | complacency here in the States.
        
       | xbar wrote:
       | I wonder if we would be hearing about this if NSO had paid its
       | 30% to Apple in the first place.
        
       | 29athrowaway wrote:
       | Sanction them then. The US has sanctioned companies for much
       | less.
        
       | bob-a-fet wrote:
       | One settler colony hacks another settler colony, the one that had
       | co-sponsored its creation along with Britain, the mothership of
       | all settler colonies. Honor amongst thieves? No such thing.
        
         | unknown2374 wrote:
         | A book came out about a year ago by a fantastic academic about
         | the history of settler colonialism by Israel in Palestine [1].
         | I'd suggest anyone who wants to learn more about Israel and
         | values referenced record of history. The book is very well
         | written, referenced (a sixth of the book is references) and
         | comes highly regarded.
         | 
         | [1] https://www.amazon.com/Hundred-Years-War-Palestine-
         | Resistanc...
        
           | jjclint wrote:
           | Your comment has nothing to do with the article. Stop shoving
           | your sick agenda down our throats and save your "links" to
           | yourself
        
             | dang wrote:
             | Whoa - you can't attack another user like that here,
             | regardless of how strongly you disagree. We ban accounts
             | that post like this.
             | 
             | If you'd please review
             | https://news.ycombinator.com/newsguidelines.html and stick
             | to the rules when posting here, we'd appreciate it.
        
         | dang wrote:
         | Please do not take HN threads into generic flamewar hell. It's
         | not what this site is for, and it destroys what it is for.
         | 
         | https://news.ycombinator.com/newsguidelines.html
        
       | ArcCompArthur wrote:
       | This post will be flagged shortly.
        
       | savant_penguin wrote:
       | Now it's going to be really funny if later on we find out that
       | that company was funded with Israeli state money that came from
       | the US
        
       | smoldesu wrote:
       | Huh, it looks like suing a state-sponsored malware manufacturer
       | _doesn 't_ prevent them from continuing to hijack your devices.
       | Live and learn, I suppose.
        
         | BillSaysThis wrote:
         | Suing is hardly the same as having the suit decided, grow up.
        
           | smoldesu wrote:
           | Okay. Let's assume they do have the suit decided, and they
           | rule in Apple's favor. What next?
        
         | nojito wrote:
         | This is based on Apple notifying the employees based on prior
         | behavior of NSO.
        
       | A4ET8a8uTh0 wrote:
       | While I find it interesting that focus in comments appears to be
       | on Israel, NSO and the complicated ( or not really that
       | complicated if you look at it from a different angle )
       | relationship between them and US. I did not see a mention a
       | broader discussion of, you know, hoarding zero days, exploits and
       | whether using those can be worse than conventional weaponry.
       | 
       | The reason I find it interesting is because it is clear that US
       | government supports Israel ( and NSO ) practically
       | unconditionally ( recent vote on Iron Dome being a more amusing
       | example of bipartisanship ).
       | 
       | Why is Reuters, an old guard by any account, concerned? Or are
       | they simply following what sells and government is really at odds
       | with its people when it comes to policy in ME.
        
       | DelightOne wrote:
       | Is there a timetable when Apple plans to stop using memory-unsafe
       | languages to avoid memory-bugs? If not, how can the amount of
       | zero-days stop with constant development?
        
         | whoknowswhat11 wrote:
         | no question that imessage, email parsers, etc that do third
         | party untrusted network type interactions SHOULD be memory
         | safe. But of course they are not, and apple in particular LARDS
         | these formats down with a million features.
        
         | DelightOne wrote:
         | Looking at the answers, seems like a NO.
        
         | DyslexicAtheist wrote:
         | biggest issue here isn't memory safety but the dumpster fire of
         | imessage format that calls out to privileged parts of the
         | system
        
           | fmajid wrote:
           | And Apple's terrible software and QA processes, like lack of
           | CI or fuzzing, which is why Google Project Zero is
           | discovering flaws for them.
        
           | walrus01 wrote:
           | I'm suspicious of any messaging system that has ties into
           | rich media / embedded-in-chat content. I even wish I could
           | disable URL previews, gifs, and inline images in Signal.
        
             | elliekelly wrote:
             | I didn't know it was possible to disable URL previews in
             | iMessage[1] until I read this comment. Does toggling this
             | setting only prevent the preview from displaying or does it
             | prevent the fetch altogether? I wish there were a way to
             | white list the URL previews for certain contacts rather
             | than turning it off all or nothing.
             | 
             | [1]https://discussions.apple.com/thread/7677834
        
               | spear wrote:
               | I didn't see a way to disable URL previews in that
               | thread. The given "solution" is wrong -- it just disables
               | message previews in the lock screen.
        
               | kingcharles wrote:
               | It can be your "trusted" contacts that infect you though.
               | 
               | "Jeff Bezos was hacked by a file sent from the WhatsApp
               | account of the crown prince of Saudi Arabia, Mohammed bin
               | Salman"
               | 
               | https://en.wikipedia.org/wiki/Jeff_Bezos_phone_hacking
        
           | 2OEH8eoCRo0 wrote:
           | It's an extremely common attack vector. PDFs, media message,
           | etc. Would it be viable to create a dedicated processor
           | specifically for parsing these things?
        
           | vlovich123 wrote:
           | Which is exploitable primarily it by memory safety exploits.
           | 
           | Will it make attacks impossible? Probably not totally. But it
           | might raise the cost of the attack by an order of magnitude
           | or more and certain classes of vulnerabilities might
           | disappear completely.
        
         | uniformlyrandom wrote:
         | You do know that memory-safe languages are developed using
         | memory-unsafe languages, and eventually execute the binary code
         | on the actual CPU?
        
           | FpUser wrote:
           | I think it comes from that rewrite everything in Rust camp.
        
           | shrimpx wrote:
           | A memory safe language can be written in itself.
        
           | kevingadd wrote:
           | Most memory-safe languages I've used self-host their compiler
           | and standard library (i.e. they're written in the language
           | itself).
        
       ___________________________________________________________________
       (page generated 2021-12-03 23:00 UTC)