Skip to content

Comment on ICE Has a $2M Contract for Spyware That Can Hack Phones Without a Clickparent

Comments

Yup, but here is the rub: you and me can't buy the real stuff. You have to be a professional law breaker, which means you are in organized crime (don't forget the white collar guys), or you are working for Intelligence, in whatever capacity, in whatever oversight. The problem is that for offensive surveillance organizations the line between crime and work gets blurred quickly. That is why I am not too enthusiastic that our Dutch intelligence agency will receive offensive capabilities as well. Information is power, and you will soon end up with an organization that feels limited by oversight, but that also can easily accumulate means to evade such oversight. Bonus points if people from those kinds of organizations find their way in legislative branches or overseeing powers.

This has been a process of decades. Also surveillance, cybercrime and business do connect. If you look at the history of capital flows in the US, you will see a massive shift of capital from military has been redirected to the surveillance industry. If you would cut out surveillance from the USA economy, things would look quite different. The stock market is heavily skewed towards companies with this business model. As food for thought, think about what the GDP looks like without Apple, Google, Anthropic, OpenAI etc. To give an example of just one facet, Meta alone makes billions on crime each year [1] and will fight toot and nail anyone who dares to threaten their business model of addiction and privacy violation. To continue down this path against the interests of the public, these companies feel confident enough to try their hands at dangerous games [2], of which history teaches us that will always end in tears, because zero-sum is in the end a hunger game.

[1] https://www.reuters.com/investigations/meta-is-earning-fortu...

[2] https://abc45.com/news/nation-world/big-tech-ceos-attend-tru...

That is why I am not too enthusiastic that our Dutch intelligence agency will receive offensive capabilities as well

AIVD[0] has had world renowned offensive cyber capabilities for a long time now. They punch _way_ above their weight class, equalling and maybe surpassing the capabilities of countries like Russia, although Russia throws more people at it so they end up with a broader overall impact. It's actually really, really impressive what they've accomplished. You should be proud of it. For example of some of their good work: https://www.zdnet.com/article/dutch-spies-tipped-off-nsa-tha...

"When hackers operating next to Moscow’s Red Square launched an attack against the Democratic Party in 2015, someone was watching. And that someone, according to new reports, was the Dutch General Intelligence and Security Service (AIVD).

Netherlands newspaper de Volkskrant and the public broadcaster NOS reported on Thursday evening that AIVD hackers had penetrated the Russian operation back in the summer of 2014."

More here: https://www.washingtonpost.com/news/worldviews/wp/2018/01/26...

[0] https://english.aivd.nl/

  > It's actually really, really impressive what they've accomplished. You should be proud of it. 
No doubts about that, they are world class. But they are seeking to reduce oversight, and they succeed at that politically. The last government, a (far) right wing coalition of highly ineffective parties and personalities, with Schoof as so-called `neutral` prime minister had laid the ground work. Schoof had been director-general of the NCTV, in his roles he was connected to intelligence services. Unsurprisingly, in the short lifetime of his cabinet he managed to reduce oversight.

This is a moral hazard. Nations should implement a very clear rule: when you have served in the intelligence service community, you cannot partake in politics. The intel branch should be firewalled off from the democratic branches.

A good overview from a big dutch tech site: https://tweakers.net/reviews/15236/aivd-en-mivd-lijken-hun-z...

a lot of these companies sell to people with money. its just that ordinary folks cant afford million dollar contracts.

there are varying degrees ofc. not everyone is NSO group or such ex intelligence folks. many sell licenses to red teams and security service providers (and law enforcement in some cases).

private intelligence companies use such tooling to gather information on individuals for business and private customers too.

a lot of toolkits also allow to just add your own exploits via scripting etc. so you can get exploits in 1 place and tooling in another etc.

there are laws, but those are not everywhere, and its unclear whos dealin to who in a lot of cases

  > private intelligence companies use such tooling to gather information on individuals for business and private customers too.
Yes, that is a very scary. These weapons are being used against journalists and politicians threatening personal business interests.
AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.