NSO Group 'will no longer be responding to inquiries' about misuse of its software
- Reference: 1626926986
- News link: https://www.theregister.co.uk/2021/07/22/nso_group_denies_everything_stops_answering_questions/
- Source link:
The company on Wednesday published a [2]missive titled "Enough is Enough" that opens as follows:
In light of the recent planned and well-orchestrated media campaign lead by Forbidden Stories and pushed by special interest groups, and due to the complete disregard of the facts, NSO is announcing it will no longer be responding to media inquiries on this matter and it will not play along with the vicious and slanderous campaign.
The document goes on to state that the list of alleged targets "is not a list of targets or potential targets of Pegasus" and that "The numbers in the list are not related to NSO group".
"Any claim that a name in the list is necessarily related to a Pegasus target or Pegasus potential target is erroneous and false," the statement adds.
Amnesty International and Forbidden Stories, plus the 17 media outlets privy to the documents allegedly detailing the leak, stand by their analysis and reporting. Indeed, the media outlets continue to report the contents of the list, recently revealing that French President Emmanuel Macron and a number of cabinet members were included in the list of those whose phones were touched by Pegasus.
[3]
Macron has said France will investigate the software.
[4]India IT minister denies illegal use of NSO Pegasus spyware
[5]Amnesty International and French media protection org claim massive misuse of NSO spyware
[6]Microsoft, Google, Citizen Lab blow lid off zero-day bug-exploiting spyware sold to governments
[7]Israeli spyware maker NSO channels Hollywood spy thrillers in appeal for legal immunity in WhatsApp battle
Mexican President Andrés Manuel has also ordered investigations, and called for the release of WikiLeaks boss Julian Assange for first alerting the world to the sort of pervasive surveillance Pegasus enables – with or without misuse.
In Hungary, the opposition is calling for investigations into suggestions that they've been targeted by the government. And in India, some are calling for investigations into how NSO was used as a catspaw to discredit the nation's government.
[8]
The NSO Group's post states it "will thoroughly investigate any credible proof of misuse of its technologies, as we always had, and will shut down the system where necessary".
There is no evidence it's shut down Pegasus – just its PR department. ®
Get our [9]Tech Resources
[1] https://www.theregister.com/2021/07/19/mass_misuse_of_nso_pegasus_spyware_alleged/
[2] https://www.nsogroup.com/Newses/enough-is-enough/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YPlBu7079uimzX6dTwPkwQAAAIk&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2021/07/20/ashwini_vaishnaw_bnso_pegasus_denial/
[5] https://www.theregister.com/2021/07/19/mass_misuse_of_nso_pegasus_spyware_alleged/
[6] https://www.theregister.com/2021/07/16/microsoft_candiru_malware/
[7] https://www.theregister.com/2020/11/17/israeli_hacking_group_goes_hollywood/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YPlBu7079uimzX6dTwPkwQAAAIk&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://whitepapers.theregister.com/
Re: There is no evidence it's shut down Pegasus – just its PR department.
the personnel in the PR department have more integrity and the spokespersons are not able to lie with a straight face
ROTFL
PR people ===> see icon
This is a strawman.
The whole issue is not just misuse of software. When you give someone a copy of your software, you have no control where it ends up. But this is not the issue at all here.
According to Amnesty, NSO operated the servers. NSO had lists of phone numbers for target people. NSO is not just a software manufacturer in this game. NSO is actively participating in the attacks, including the unlawful ones. They cannot just say: «Someone took our software and did an unlawful attack without our knowledge.» NSO was basically performing the unlawful attack themselves.
Re: This is a strawman.
Another interesting question: How about terms of service? They used Amazon servers, fake Apple IDs, etc. It would be funny if Apple could sue them to never touch any iPhone again.
Re: This is a strawman.
It would be nothing short of a miracle if a US based company could make that stick internationally.
Re: This is a strawman.
They cannot catch them, but it would be punishment enough if NSO associates had an international warrant on them, not being able to travel anywhere without fear of arrest.
Re: This is a strawman.
I've got the feeling that it's rather the critics of NSO to find themselves on search lists than their employees. Which still beats finding yourself on a rendes-vouz with a bone saw.
The fundamental problem
Underlying all the immediately apparent problems is the basic one that commercial interests are deeply involved in the provision and use of surveillance technologies. Profits demand wide use, and that incentive can easily result in further blunting of already questionable ethics.
The same mechanism is effectively universal in antisocial media, where offensive or illegal posts are left in place until a threshold of embarrassment to the service is crossed, because, regardless of protestations, they attract hits.
NSA swats cheeky NSO?
Word is that NSO got cheeky, stealing customers/victims from traditional spy services. So Amnesty (CIA controlled) leaked NSO capers to keep NSA king of the hill. The Israelis must kow-tow to the master, not compete.
imperva.com fake certificate?
Can someone shed some light on this?
So, from here in Thailand to Shanghai using trace route:
tracert english.sse.com.cn (222.73.229.73) (Shanghai stock exchange on China Telecom, located in Shanghai)
> 30 hops, from TripleT (Thai ISP) it heads to Singapore (e.g. 203.208.172.234 Singtel etc.)
Then to Zayo in the USA zayo.china-telecom.mpr1.lax12.us.zip.zayo.com [64.125.15.95]
Then to 61.152.25.125 (China Telecom in Shanghai) 24 hops 411ms!
Takes more than 30 hops and times out.
So now lets trace the route to 61.162.25.125... that midpoint server located in Shanghai
tracert 61.162.25.125
This time it routes from Thailand to Hong Kong via 203.100.48.185 HongKong
Arrives at 61.152.25.125 in 229ms, a lot faster, 15 hops vs 24 hops.....
OK, so there's an intercept on queries to the Shanghai stock exchange, that reroutes data from Thailand to the USA via Singapore.
If I trace a route to a China Telecom local server I saw in the tracepath on one run, it takes a much shorter path, twice as fast via HongKong.
It strikes me that this is a https connection, and should be secure. So what would be gained by intercepting this unless the certificate is also intercepted?
So lets go look at the certificate... holy fook, it covers like a gazillion domains, was issued to imperva.com Issued by GlobalSign nv-sa in Belgium
Including iplocation ones, and a load of Israeli ones too.
https://www.iplocation.net/ip-lookup
Care to explain GlobalSign?
Re: imperva.com fake certificate?
All your data are belong to US.
So it was, so it is, so it will always be.
I wish...
the NSO chief and/or senior officers had attractive twitter handles.
Nowhere good to run, nowhere smart to hide leaves one naked and exposed to more than just ridicule.
NSO is announcing it will no longer be responding to media inquiries on this matter and it will not play along with the vicious and slanderous campaign.
It has been said before, but it is always well worth repeating, and especially so with particular and peculiar regard to neglectful and disrespectful NSO Group firmware? .....
How very wise. If one doesn't open one's mouth one cannot put one's feet in it. But that in itself reveals all that one would really need to know ...... such as there being no viable defence against outrageous suggestions and/or valid accusations ‽ .
Oooo look, magically fixed!
On that GlobalSign certificate, the one with a bunch of domains listed, seemingly unrelated, that popped up when I went to look at the cert for Shanghai stock exchange. The plot thickens:
Curious the domains listed don't include sse.com.cn or anything like it.
Cert 09:EF:78:B3:0E:BA:08:05:6D:E4:94:22:93:E9:D3:CF:CE:D7:FA:86
Auth Key id 42:6D:57:2D:4F:1F:26:77:74:A6:27:64:F6:80:FA:8F:48:68:FE:7C
https://english.sse.com.cn/
"Forbidden...." no longer gives me an encrypted link let alone to imperva.com
http://english.sse.com.cn/
Fast and responsive now. Now it defaults to this NON-encrypted site now.
Likewise the tracert for 222.73.229.73 now goes via 116.51.17.189 in Singapore and direct to China Telecom..... 24 hops decent speed now.
Q1. How is it that I get a cert for Imperva.com when I clicked to view the firefox cert for the Shanghai stock exchange, yet the domain isn't listed anywhere as an alias in that cert? How would that work? How would it get verified by GlobalSign???
Q2. I see it has magically fixed itself!
Now Shanghai stock exchange website no longer claims to be encrypted! And certainly not with some magical catch all cert! Is this the same for others?
Q3. Is that how the route was forced? Return it as if it was encrypted, wrap the connection in TLS as imperva.com and route it yourselves? But then how did you inject the redirect to encrypted? The router perhaps (Cisco), a firefox exploit? PC exploit? Some sort of packet injection?
Q4. How do I remove built in certificate authorities I don't trust? GlobalSign Belgium gave this cert out, and yet when I go to each site, I find their domain is slightly different and the cert provided by someone else. So I want to remove GlobalSign from the approved certificate authorities on Firefox.
e.g.
123-flowers.co.uk main domain is their www subdomain, www.123-flowers.co.uk and the cert if from Cloudflare not GlobalSign.
kitkat.com.au is KitKat Australia, their domains is the www subdomain, www.kitkat.com.au and the cert is from LetsEncrypt, not Global Sign.
*.iplocation.net still shows as this magic cert.
hays.com.sg, redirects to www.hays.com.sg and the cert is from DigiCert not GlobalSign
So you can see how I'd want to remove Global Sign from the list of trusted certificate authority. How do I do it?
Deny Everything!
"Are you private S. Baldric?"
"NO!"
"... but you are Captain Blackadder's batman"
"NO!"
"Come on Baldric, can't you be a bit more helpful? It's me"
"NO IT ISN'T!"
There is no evidence it's shut down Pegasus – just its PR department.
Maybe, the personnel in the PR department have more integrity and the spokespersons are not able to lie with a straight face.
Or, maybe, their lawyers told them to shut up.