Skip to content

Comment on Government Spyware Targets Mexican Journalists and Their Familiesparent

Comments

Having up to date Android and iOS zero days plus the rootkit / RAT software is not something you can get open source or find easily commercially.

There's a reason this company is charging hundreds of thousands of dollars to target only 10s of phones...

I wouldn't downplay the gatekeeper aspect of these companies and the technical investment it takes for non technical governments to do this stuff.

But generally I agree that attempting to control it via the tools is a bad idea or merely putting the blame on the tools is missing the bigger picture. Plus limiting zero day sales will only harm legitimate security research and encourage unrealistic pen testing.

Mexico's government is the primary issue here. They have a serious human rights abuse issue at various layers of government.

But that said if we're going to try to protect these people from abusive government tactics, since it happens in secrecy and their 'self-regulation' totally fails to stop abuse (even in the US), then there is some value on pushing back against these more sophisticated companies that sell the high end tools that are harder to detect. Since it is a niche market at the moment and a niche expensive skillset... Unlike guns in the US that will be everywhere regardless of gun control, since it's the biggest gun exporter and gun ownership rate in the world, we can hold these companies to a higher degree of responsibility.

Eventually though it will have to come down to holding the governments responsible and pushing back by protecting our software.

The fact NSO has publicly said they will continue to sell to Mexico despite the clear evidence here that they are not following their stated policy of only targeting cartels, criminals, and terrorists... Then clearly they are shady as hell and their stated policy is bullshit.

NSO is hardly without fault here. Unlike the AK47 analogy used in this article which are sold once and then the manufacturer loses control of how its used, this exploitation software needs to be updated with new zero days, new RAT software for new iOS/Android versions, and support/training staff. NSO has chosen to continue offering these services so they are just as much liable as far as I'm concerned.

Having up to date Android and iOS zero days plus the rootkit / RAT software is not something you can get open source or find easily commercially.

You might be right about not being able to find 0days that target the latest versions of iOS or Android so easily, but there are dark web markets stuffed with 0days that target specific versions, or a range of versions. Not sure about pricing, but they're typically cheaper than the exploits that target the latest and greatest.

It's by pure chance that the owner of a device is using an out-dated O.S on their phone. Others may argue it's not by chance, but by design, and that some phones can't upgrade properly and remain locked to a specific version..You know, because governments sometimes demand that phones are deliberately left unpatched so they can do interception or do ex-filtration on them?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.