[HN Gopher] Civil society in Latvia, Lithuania, and Poland targe...
___________________________________________________________________
Civil society in Latvia, Lithuania, and Poland targeted with
Pegasus spyware
Author : rntn
Score : 134 points
Date : 2024-05-31 14:47 UTC (8 hours ago)
(HTM) web link (www.accessnow.org)
(TXT) w3m dump (www.accessnow.org)
| betaby wrote:
| "Polish media reports say Poland purchased Pegasus in 2017, using
| money from the so-called Justice Fund, which is meant to help the
| victims of crimes and to rehabilitate criminals." from the older
| 'scandals'.
|
| https://www.euractiv.com/section/politics/short_news/polish-...
|
| At that moment it's safe to assume that all EU govs use Pegasus
| against the public in general.
| eigenket wrote:
| I don't think it's reasonable to assume all EU governments (or
| even all Polish governments) will act the same as PiS do/did.
| betaby wrote:
| I think it is in fact reasonable. Private persons are
| unlikely to have means/connections to acquire Pegasus while
| victims are all around EU, see another link below.
|
| https://www.dw.com/en/spain-court-reopens-investigation-
| in-p...
| eigenket wrote:
| There are not many examples of the government hacking
| opposition politicians an en leaking damaging material to
| friendly "news" agencies for political gain
|
| https://notesfrompoland.com/2023/12/18/polish-state-tv-
| order...
|
| Law and justice are a particularly extreme example.
| peterfirefly wrote:
| Didn't Merkel have the Bundesamt fur Verfassungsschutz
| spy on her political opposition?
| eigenket wrote:
| I haven't seen anything about that, but if she did then
| thats disapointing
| Etherlord87 wrote:
| AFAIK all uses of Pegasus were conducted after an agreement
| (a warrant) was issued from Polish courts - which were in
| opposition to the PiS government. If I'm right about this,
| doesn't it mean this particular affair unnecessarily
| demonizes PiS?
|
| Either way, I think it's very reasonable to *do* assume the
| worst of governments - as in we should strive to design the
| system to be able to withstand as much malice from people in
| power as possible.
| d_theorist wrote:
| What is meant by "civil society" in this article?
| swifthesitation wrote:
| civilians
| nonameiguess wrote:
| It would appear the targets are all journalists. I think
| they're using this phrasing to denote that they're civilians.
| lupusreal wrote:
| "Civil society" implies the existence of uncivil people; it's
| good guys vs bad guys, not civilian vs military. If Ukraine
| targeted civilian organizations in Russia, the headline
| wouldn't call it an attack on "civil society" (but Russian
| media might.)
| samatman wrote:
| > _" Civil society" implies the existence of uncivil
| people_
|
| It does not. You are conflating:
|
| civil 2b: adequate in courtesy and politeness : MANNERLY
|
| with
|
| civil 4: of, relating to, or involving the general public,
| their activities, needs, or ways, or civic affairs as
| distinguished from special (such as military or religious)
| affairs
|
| https://www.merriam-webster.com/dictionary/civil
|
| You can see that 'uncivil' does not include in its meanings
| an antonym of civil 4:
|
| https://www.merriam-webster.com/dictionary/uncivil
| lupusreal wrote:
| You're being naive. Propaganda often employs double
| meanings, subtext and implications. This kind of language
| would not be used if the actors were reversed.
| aaronblohowiak wrote:
| Civil society as a term for "not government" goes
| waaaayyyyyy back.. I think you are mistaking a cloud for
| a ufo here..
| lupusreal wrote:
| As a term for "not government", it would not be used to
| refer to civilians of a hostile nation.
| mopsi wrote:
| Major public organizations and interest groups (such as the
| EFF, ACLU or AARP) that are independent from the state:
| Civil society can be understood as the "third sector" of
| society, distinct from government and business, and including
| the family and the private sphere. By other authors, civil
| society is used in the sense of 1) the aggregate of non-
| governmental organizations and institutions that advance the
| interests and will of citizens or 2) individuals and
| organizations in a society which are independent of the
| government.
|
| https://en.wikipedia.org/wiki/Civil_society
| praptak wrote:
| I believe Wikipedia has a good overview, in particular "the
| aggregate of non-governmental organizations and institutions
| that advance the interests and will of citizens" is probably
| the definition that best matches the one used in the article.
|
| https://en.wikipedia.org/wiki/Civil_society
| eli_gottlieb wrote:
| NGOs.
| bragr wrote:
| This kind of spying seems necessary and appropriate to me,
| provided it is done under the appropriate legal framework. The
| security concern with Russia and Belarus are self evident now,
| and the security concerns around hosting a large dissident
| population must be enormous. You don't want extremists within the
| dissident movements (it'd bad if the Putin assassination was
| planned on your soil), nor penetration of the dissident movement
| by foreign intelligence (it'd be a bad if the opposition leader
| got novichoked on your soil). I'm not sure how else to address
| these kinds of problems in society except with some kind of well
| regulated security apparatus (making the big assumption that it
| is well regulated here).
| logicchains wrote:
| >I'm not sure how else to address these kinds of problems in
| society except with some kind of well regulated security
| apparatus (making the big assumption that it is well regulated
| here).
|
| The whole populace being under surveillance is a much worse
| outcome than the chance of some politician being assassinated
| being relatively higher. Mass surveillance to prevent the
| latter seem absolutely in the worst interests of the average
| citizen; spying on people to protect the elites is what every
| nasty dictatorship does.
| trustno2 wrote:
| I think Russian security services work fully legally under
| Russian legal framework.
| duxup wrote:
| I think we can differentiate between the rules, level of
| judicial independence, and different systems too.
|
| It's not all or nothing as far as the words "legal framework"
| goes.
| Muromec wrote:
| No they don't. They are a signatory of ECHR convention (which
| makes is part of national law).
| holmesworcester wrote:
| What about _this_ type of spying? (Also frontpage of HN right
| now, and done with similar tools i.e. Lumma malware-as-a-
| service)? https://news.ycombinator.com/item?id=40534868
|
| The problem is, when the vulns exist due to hand-rolled
| parsing, you don't get to choose who the attacker is.
| eigenket wrote:
| I don't think it's either necessary or appropriate for the
| government to be spying on its political opponents and then
| leaking damaging material to friendly "news" agencies
|
| https://notesfrompoland.com/2023/12/18/polish-state-tv-order...
|
| This was a pretty clear and obvious abuse of the state
| apparatus against political opponents.
| holmesworcester wrote:
| I think a lot of people are mis-seeing these Pegasus attacks as a
| problem of political will ("we need sanctions on NSO/Israel!") or
| memory safety ("rewrite it in Rust!") when there is a deeper
| problem: parser complexity.
|
| Specifically, we're using context-sensitive and Turing-complete
| parsers up and down the software stack, which (at the Turing-
| complete level of complexity, says Godel) _guarantees_ that
| determined attackers can expect to discover an exploitable
| "weird machine."
|
| Folks should watch this panel and other talks by Meredith L.
| Patterson (co-collaborator and wife of the late Len Sassaman) and
| Sergey Bratus (previously at DARPA, now Dartmouth) to get a sense
| of the problem and the solution.
|
| https://youtu.be/8tAxHrntBJs?t=806
|
| These folks are saying that, just as the industry handled over-
| the-wire insecurity with TLS and e2ee (and not rolling our own
| crypto) we can handle device exploitability with well-described
| data and automated parser generation from those descriptions (and
| not rolling our own parsers, which these folks say should be
| verboten for the same reason as rolling one's own crypto: parsing
| is too hard for non-specialists to get right).
|
| Moreover, we don't have to redo the whole stack for it to be
| meaningful: big players can start using this tooling (e.g.
| https://github.com/UpstandingHackers/hammer) for parsers handling
| data from very untrustworthy inputs, such as message payloads
| sent to a phone number.
|
| Apple's Lockdown mode is a step in this direction, though in such
| a crude, "burn the village" way that it makes the phone almost
| unusable. But sacrificing usability shouldn't be necessary with
| current methods. If these folks can make safe parsers for PDF
| (https://www.darpa.mil/program/safe-documents) it should be
| possible for anything.
|
| Another great talk: https://www.youtube.com/watch?v=3kEfedtQVOY
| samatman wrote:
| You've over-egged the pudding here: neither Godel's
| incompleteness theorem, nor Rice's Theorem, _guarantee_ that an
| algorithm in a certain complexity class will have exploitable
| defect. Rice 's Theorem in particular suggests that it's
| unlikely one will be able to statically prove that such an
| algorithm has the properties it's designed to have. That should
| be enough to make anyone nervous.
|
| I hope readers will be able to look past this one sentence in
| your post and take a good hard look at the rest of it, which is
| quite important.
| nextos wrote:
| Rice's Theorem, as all Free Lunch Theorems, is too
| pessimistic.
|
| In real conditions, static analysis and theorem proving can
| verify lots of safety properties. See e.g. Astree & Airbus,
| or F* and Project Everest.
|
| IMHO, the solution is to use static analysis in conjunction
| with DSLs that have restricted semantics to make static
| analysis and hand-written proofs easy.
| samatman wrote:
| It doesn't appear that we're disagreeing.
|
| You're referring to verifying 'lots' of safety properties,
| I referred to verifying that an algorithm does everything
| it's supposed to. These are not the same thing in the
| general case.
|
| My actual _point_ was that generic incompleteness and
| undecidability theorems do not _guarantee_ that any given
| program must be defective.
|
| The thrust of langsec is in fact to parse all inputs at the
| boundaries, using algorithms with known properties, that
| is, ones where it's feasible to prove that they'll halt,
| won't overrun buffers, and so on.
| alephnerd wrote:
| The Godel and computational complexity stuff is a bit out in
| the horizon, but the rest ain't wrong and is something that's
| getting a lot of (indirect) federal funding via the Secure
| Enclave/Trusted Execution Environment related research - and
| Bratus was one of the earlier people in the Trusted Computing
| space.
|
| > If these folks can make safe parsers for PDF
| (https://www.darpa.mil/program/safe-documents) it should be
| possible for anything
|
| It is, but it's very expensive. That's why a lot of this
| research has been getting billions in funding for 10-15 years
| now in order to build out the underlying ecosystem needed to
| harden the entire stack
| myth_drannon wrote:
| from the article "...there is also no evidence suggesting that
| Russia, Belarus, or Lithuania are Pegasus customers. Latvia
| appears to use Pegasus, but the country is also not known for
| targeting victims outside of its borders. ...., Estonia does
| appear to use Pegasus extensively outside their borders,
| including within multiple European countries. "
|
| It would be very surprising to see Russia using Western tech such
| as Pegasus, you can't just outsource your spy tools to your
| enemies. They most likely have as powerful if not more
| technologies.
|
| This whole NSO spectacle is more about the subversive BDS
| movement than a genuine care about political suppression and
| spying on the citizens.
| lupusreal wrote:
| If they could get their hands on Pegasus tools, their use might
| be ideal for Russia if for no other reason than because it
| would sow uncertainty and confusion.
| myth_drannon wrote:
| It's like using GPS. Russians created Glonass because GPS is
| under US control and can be used to subvert their operations.
| Pegasus is linked to a West allied country and can be used to
| feed them false information.
| krzyk wrote:
| Pegasus is Israeli, I'm not sure it is "western".
|
| Israel is very lenient towards Russia.
| neoromantique wrote:
| Used to be lenient
| Etherlord87 wrote:
| I'm surprised this was the case for so long as Iran is a
| close ally of russia.
| elevaet wrote:
| Israel is very intertwined with the typical conception of
| "the West" via a very cozy relationship with the USA
| including billions in annual funding, and a great proportion
| of its citizens having roots in Europe and the USA.
| mantas wrote:
| At the same time Netanyahu is happy to wear Koloradka. And
| big chunk of Israeli population has Russian/USSR origins.
| elevaet wrote:
| It's certainly a country at the nexus of many dimensions.
|
| What's the significance of wearing Koloradka? It looks
| like something christian priests wear, I don't think I
| understand.
| heavenlyblue wrote:
| > And big chunk of Israeli population has Russian/USSR
| origins.
|
| Most of whom probably still remeber very well the
| moderate Russian racism towards jews.
|
| Also they probably would have stayed in Russia if they
| were happy with their government. Luckily Israel was one
| of the good ways to get out of the country if you had
| jewish roots.
| solarpunk wrote:
| trying to understand the BSD linkage here and I'm coming up
| empty
| rjsw wrote:
| I'm guessing they meant BDS - Boycott, Divestment and
| Sanctions.
| greenish_shores wrote:
| Side note: Just checked are non-Android Linux OSes targeted by
| this spyware. Apparently, there's no public info in favor of
| such. So probably, nope. It looks mostly targeted against Android
| and iOS only.
| servus45678981 wrote:
| Then I am switching to a feature phone Nokia by HMD
| greenish_shores wrote:
| Check out postmarketOS. Can run on a Nokia you're specifying,
| but not only :)
| alephnerd wrote:
| > Just checked are non-Android Linux OSes targeted by this
| spyware
|
| It's safe to assume that any mobile phone OS will inevitably be
| targeted. There are always going to be unpatched and uncaught
| vulnerabilities, and the market for finding these vulns are
| very hot.
|
| The bigger question is why do you think you'd be vulnerable to
| attack by a nation-state? If you are that prominent, you are
| screwed anyhow.
|
| This article by Mickens is fairly accurate [0]
|
| [0] -
| https://scholar.harvard.edu/files/mickens/files/thisworldofo...
| greenish_shores wrote:
| How would you define a "mobile OS" then, to keep the
| alignment of what you said, particularly this part: "There
| are always going to be unpatched and uncaught
| vulnerabilities"?
|
| Everything which can fit into a pocket and has a HTML5
| browser?
|
| FYI, I know about how extremely vulnerable average cellular
| baseband is (and that it would often use unprotected or
| weakly protected DMA). Let's assume the device in question
| doesn't have one of these.
| lupusreal wrote:
| Second time this week in which I've seen "civil society" used in
| a headline on HN. It's such a blunt euphemism they may as well
| write "the good guys".
| mikeyouse wrote:
| It's a bog standard term that has nothing to do with 'good
| guys' or 'bad guys' - civil as in infrastructure not civil as
| in polite...
| hehdhdjehehegwv wrote:
| Let's not forget this technology all comes from IDF spying on
| Palestinians who basically have no legal rights. Injustice breeds
| further injustice.
| g8oz wrote:
| See the book "The Palestine Laboratory" for more on this.
|
| https://www.versobooks.com/en-ca/products/2684-the-palestine...
___________________________________________________________________
(page generated 2024-05-31 23:02 UTC)