Uncle Sam to clip wings of Pegasus-like spyware – sorry, 'intrusion software' – with proposed export controls
- Reference: 1634767746
- News link: https://www.theregister.co.uk/2021/10/20/us_intrusion_software_rules/
- Source link:
The BIS on Wednesday announced an interim final rule that defines when an export license will be required to distribute what is basically commercial spyware, in order to align US policy with the [1]1996 Wassenaar Arrangement , an international arms control regime.
The rule
[2]PDF
– which spans 65 pages – aims to prevent the distribution of surveillance tools, like NSO Group's Pegasus, to countries subject to arms controls, like China and Russia, while allowing legitimate security research and transactions to continue. Made available for public comment over the next 45 days, the rule is scheduled to be finalized in 90 days.[3]
Pegasus allegedly has been used by governments to [4]spy on activists and [5]journalists , among [6]others . The United Nations recently [7]called for a ban on the sale of "life threatening" surveillance technology and specifically criticized the NSO Group, which [8]claimed it "sells its technologies solely to law enforcement and intelligence agencies of vetted governments for the sole purpose of saving lives through preventing crime and terror acts."
[9]
[10]
The Israel-based company, which is awaiting to see whether the US 9th Circuit Court of Appeals will [11]immunize it from [12]WhatsApp's snooping lawsuit , subsequently [13]said it would no longer respond to criticism.
Basically, if you want to sell Pegasus or similar device-penetration software, and you have a presence in the US, you need a license to sell to China, Russia, or the other covered governments. NSO was [14]said to have a marketing and sales arm in the United States, a point the Israeli biz rejects.
[15]Europe clamps down on cybersurveillance exports, pushes human rights focus
[16]United Nations calls for moratorium on sale of surveillance tech like NSO Group's Pegasus
[17]NSO Group's Pegasus malware was used to spy on Dubai princess's lawyers during child custody dispute
[18]So you’ve got a zero-day – do you sell to black, grey or white markets?
The Commerce Department said the US government "opposes the misuse of technology to abuse human rights or conduct other malicious cyber activities, and these new rules will help ensure that US companies are not fueling authoritarian practices."
“The United States is committed to working with our multilateral partners to deter the spread of certain technologies that can be used for malicious activities that threaten cybersecurity and human rights," said US Secretary of Commerce Gina Raimondo, in [19]a statement .
[20]
"The Commerce Department’s interim final rule imposing export controls on certain cybersecurity items is an appropriately tailored approach that protects America’s national security against malicious cyber actors while ensuring legitimate cybersecurity activities.”
Europe [21]took similar steps in November, 2020, with its own export limitations on cybersecurity tools.
The US in 2015 proposed placing export restrictions on cybersecurity tools, but encountered headwinds [22]when the US cybersecurity industry objected , saying the rules were too broad and would [23]interfere with security fixes . The government then went back to negotiate with other Wassenaar participants to come to a more workable definition of how to limit intrusion software.
[24]
Following negotiations in 2016 and 2017, the Wassenaar Agreement negotiators [25]published changes that clarified that limited the definition of intrusion software to malicious contexts, so that it didn't cover all command and control capability and all security research, vulnerability disclosure, incident response, or software updates.
Chris Rohlf, non-resident research fellow at the Georgetown Center for Security and Emerging Technology and a security engineer at Facebook, [26]via Twitter characterized the revised BIS rule as a well-informed attempt to limit the distribution of intrusion software in accordance with the Wassenaar Arrangement.
"It’s hard to capture the nuance necessary to make this successful but this time around it looks to be in a better position," he said. ®
Get our [27]Tech Resources
[1] https://www.armscontrol.org/factsheets/wassenaar
[2] https://public-inspection.federalregister.gov/2021-22774.pdf
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YXDl@2J@Jg0MFVrGqH-rBAAAAEY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2021/09/13/apple_ios_macos_security_fixes/
[5] https://www.theregister.com/2021/07/19/mass_misuse_of_nso_pegasus_spyware_alleged/
[6] https://www.theregister.com/2021/10/07/pegasus_malware_princess_haya/
[7] https://www.theregister.com/2021/08/13/un_wants_surveillance_tech_sales_moratorium/
[8] https://www.nsogroup.com/Newses/following-the-publication-of-the-recent-article-by-forbidden-stories-we-wanted-to-directly-address-the-false-accusations-and-misleading-allegations-presented-there/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YXDl@2J@Jg0MFVrGqH-rBAAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YXDl@2J@Jg0MFVrGqH-rBAAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://www.eff.org/deeplinks/2020/12/eff-ninth-circuit-dont-grant-immunity-notorious-spyware-company
[12] https://www.theregister.com/2020/04/24/nso_group_cant_claim_immunity/
[13] https://www.theregister.com/2021/07/22/nso_group_denies_everything_stops_answering_questions/
[14] https://www.theregister.com/2020/05/01/nso_whatsapp_california/
[15] https://www.theregister.com/2020/11/11/eu_cybersurveillance_laws/
[16] https://www.theregister.com/2021/08/13/un_wants_surveillance_tech_sales_moratorium/
[17] https://www.theregister.com/2021/10/07/pegasus_malware_princess_haya/
[18] https://www.theregister.com/2018/04/15/mature_bug_bounty_market_bsidessf/
[19] https://www.commerce.gov/news/press-releases/2021/10/commerce-tightens-export-controls-items-used-surveillance-private
[20] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YXDl@2J@Jg0MFVrGqH-rBAAAAEY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[21] https://www.theregister.com/2020/11/11/eu_cybersurveillance_laws/
[22] https://www.theregister.com/2015/07/15/infosec_heavyweights_form_coalition_to_oppose_misguided_us_cyber_export_control_rule/
[23] https://www.theregister.com/2015/12/11/overhaul_wassenaar_or_ruin_next_heartbleed_fix_top_policy_boffin_says/
[24] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YXDl@2J@Jg0MFVrGqH-rBAAAAEY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[25] https://www.theregister.com/2017/12/21/infosec_controls_relaxed_a_little_after_latest_wassenaar_meeting/
[26] https://twitter.com/chrisrohlf/status/1450823265157410828?s=20
[27] https://whitepapers.theregister.com/
if you want to sell Pegasus or similar device-penetration software, and you have a presence in the US, you need a license to sell to China, Russia, or the other covered governments
This only restricts Pegasus.
If, for example, China, Russia, Iran or NK happens to "stumble upon" the source code ... all bets are off.
I think this is so "double standard" on the part of the US government -- BIS did not slap an "export control" over EternalBlue, did they?
The rule is pure bullshit. Pegasus has been used by Turkey to spy on journalists on Canada, Turkey and other countries. It has been used by the Mexican government to spy on journalists investigating the murder of students. It has been used by the United Emirates to spy on journalists, dissidents and even US citizens. All of those countries won't be affected by this dummy legislation.
And the countries it's supposed to ban have their own alternatives and won't reach for NSO to spy on whoever they want to spy.
It is good to limit some companies with dangerous capabilities
It is good to limit some companies with dangerous capabilities.
Unfortunately, a software developed "in-house" by officers cannot be regulated the same way, nor its partners can be restricted.