News: 1637759530

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Apple's Pegasus lawsuit a 'declaration of war' against offensive software developers, says Kaspersky director

(2021/11/24)


Kaspersky's APAC director of Global Research and Analysis, Vitaly Kamlyuk, has called Apple's lawsuit against Pegasus maker NSO a "declaration of war against software developers."

On Tuesday, Apple filed [1]suit against the cyber firm and its parent company for surveillance and targeting of US Apple users. Apple wants to prevent NSO Group from using any Apple software, services or devices in the future, and would like some damages to boot.

[2]Pegasus spyware is repeatedly used by authoritarian regimes to infiltrate phones of journalists, dissidents, and academics, and Apple's [3]argument is that the software "weaponizes powerful state-sponsored spyware against those who seek to make the world a better place."

[4]Apple sues 'amoral 21st century mercenaries' NSO for infecting iPhones with Pegasus spyware

[5]Shotgun targeting of malware attacks will be the defining infosec theme of 2022, reckons Sophos

[6]Reward! Uncle Sam promises $10m for info about DarkSide ransomware gang chiefs

[7]SolarWinds attacker on the move: Russia's Nobelium crew has trebled attacks targeting MSPs, cloud resellers, says Microsoft

Kamlyuk made the comments while speaking at [8]Kaspersky's webcast , Reinforcing Cybersecurity Strategy: The Way Forward , on Wednesday.

He later clarified directly to The Register that he was referring to offensive software developers. Kamluck told El Reg :

In my opinion, Apple wants offensive researchers out of the field, because they are harmful to the reputation of the company. The US govt cares more about controlled use and non-proliferation of offensive technology but seems to support the same side. WhatsApp previously, now Apple and the US govt. This seems to become a trend to put offensive research in order.

It's not just Apple looking to put Pegasus and NSO in its place. The malware company has already been sued by Facebook for exploiting WhatsApp to infiltrate its victims. Furthermore, a US appeals court [9]ruled earlier this month that the Israel-based firm cannot hide behind its government clients when it comes to litigation.

If Apple wins, it says it plans to donate the money to non-profits that investigate spyware like Citizen Lab and Amnesty Tech. Apple plans to kick in an extra $10m to assist efforts in the field. ®

[10]

Get our [11]Tech Resources



[1] https://www.theregister.com/2021/11/23/apple_nso_group/

[2] https://www.theregister.com/2021/07/16/microsoft_candiru_malware/

[3] https://www.apple.com/newsroom/2021/11/apple-sues-nso-group-to-curb-the-abuse-of-state-sponsored-spyware/

[4] https://www.theregister.com/2021/11/23/apple_nso_group/

[5] https://www.theregister.com/2021/11/09/sophos_infosec_predictions_2022_linux_targeting/

[6] https://www.theregister.com/2021/11/05/us_darkside_ransomware_10m_bounty/

[7] https://www.theregister.com/2021/10/25/nobelium_russia_svr_msp_warning_microsoft/

[8] https://event.on24.com/wcc/r/3451869/4F99A49599F89CB5E4499D0187CA4EF7

[9] https://www.theregister.com/2021/11/09/nso_foreign_immunity_whatsapp_decision/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/legal&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YZ5vvXaGNgs3qXQu2gLsuAAAAFQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[11] https://whitepapers.theregister.com/



Offensive Researchers

Anonymous Coward

While I have no doubt Apple want to stop any research they don't control NSO are not just offensive researchers. They crossed a line selling the malware to various ever so slightly dodgy groups and organisations. As such Apple have a legitimate reason to sue here.

Re: Offensive Researchers

Pascal Monett

Indeed. Vitaly missed a golden opportunity to shut his mouth.

The NSO is not your garden variety of software developer. Conflating NSO state-approved malware writers with "software developers" in general is just muddying the waters.

Shame on you, Vitaly.

Re: Offensive Researchers

Yet Another Anonymous coward

And of course Apple/Google/Facebook/etc won't use any NSO decision to prosecute people who find vulnerabilities in the future - because they are all such nice friendly companies.

Backdoor smashed in

elsergiovolador

In my opinion it sounds like Apple has created ability for services to spy on its customers and now are upset that private company is also using these features?

Surely instead of "declaring a war" they should just patch the holes?

Re: Backdoor smashed in

Def

Surely instead of "declaring a war" they should just patch the holes?

They did. [1]Here , [2]here , and [3]here .

[1] https://www.theregister.com/2016/09/02/macos_safari_security_update/

[2] https://www.theregister.com/2021/09/24/apple_zero_day/

[3] https://www.theregister.com/2021/10/12/apple_ios_15_0_2_zero_day_patched/

Re: Backdoor smashed in

elsergiovolador

Well, given the lawsuit, you can't really trust these patches don't ship new set of holes for services to use.

Re: patching holes

Snake

But the fundamental elephant in the room, which people never want to seem to accept, is that humans are fallible. There will never be perfect, uncrackable computers without vulnerabilities. Ever. From hardware to software there will always be something soft, and if all else fails they'll just social engineer the wetware to get what they want.

Patch holes? Absolutely! But then another hole will be found, the patching will never end. The issue is state-sponsored hacking - we have it bad enough without the governments that are supposed to be working for their people hacking those very people's computers for selfish 'benefit'.

I am not

LordHighFixer

Entirely sure I care. I mean there are low tech ways to organize against your government. I believe that if you are going to do that, no matter which government we are talking about, using your iphone, or any device with GPS features, is just looking for more trouble than you originally intended. That is what burner phones are for.

And good luck apple getting any money. By all mean take it to trial, I can hardly wait to see the 'discovery' phase..

Re: I am not

big_D

Yes, but in this case, the spyware was used against legitimate journalists, world leaders etc. doing their normal day-to-day business.

They know they won't get any money

DS999

But one of two things are likely to happen. 1) somehow it goes to trial and there is a discovery phase, and some very seedy relationships with the worst regimes in the world are outed 2) NSO Group goes out of business, because everyone that doesn't want to be classed with the thugs in Thailand or the people who bonesawed Khashoggi will refuse to do business with them.

Sure its a shell game as there are other companies like NSO Group and you can't get rid of them all, but at least you can force the ones trying to operate as legitimate companies from doing business with the worst of the worst. There will probably still be criminal organizations selling such services on the darknet, but the authorities will go after those like they always have.

Sure people can say "where do you draw the line, should you do business with the US government since their hands aren't clean either" but I think when you support those murdering people with bonesaws that's a line everyone can agree on.

There is a big difference...

Electronics'R'Us

Between searching for flaws and responsibly disclosing them compared to using them to sell to high bidders for some very nefarious purposes that have possibly led to the death of some people and quite probably others being detained 'for the good order of the state'.

In other cases the threat of not being able to make a living is certainly an issue when the state is getting its hands on literally everything of interest in the phone and its surroundings.

The surveillance of politicians and press by certain governments is quite well documented elsewhere when they use NSO's wares.

Certainly Apple might not want pen testers from outside rooting through their kit (no pun directly intended) but that is not something they can really control.

So overall, I really can't see Vitaly Kamluk's comments as being the case.

Re: There is a big difference...

Yet Another Anonymous coward

>Between searching for flaws and responsibly disclosing them compared to using them to sell to high bidders

Yes one enables people to search for vulnerabilities as a full time job.

If you ban selling exploits then Apple/Google/Facebook can just offer 1c rewards for each exploit, and threaten to sue anybody else.

As a result only criminals have exploits. No exploits are ever made public and so all computers must be secure.

Anonymous Coward

Just offer a life-changing bounty to anyone who provides exploit details that NSO is using. Indemnify them against any legal action re: stealing trade secrets. Get them on a plane and out of the reach of Mossad. Drop flyers all around NSO's HQ announcing the $bignumber bounty. You'll have the code within a week

Anonymous Coward

Doesn't Mossad have a reputation for "extraordinary rendition," though, meaning nowhere is really safe?

out of the reach of Mossad

TheOldGuy

Hmm... Good luck with that.

Apple & C. want the information control - and the power to decide who is under surveillance or not.

LDS

We should start from an axiom - law enforcement agencies require to be able to access communication and data storage for investigations - which could be wholly lawful and to combat nasty crimes. Of course the same technologies can be used to commit nasty crimes - it's not different from guns. And even common people do employ surveillance cameras that can be used to protect people and properties, or to peep.

NSO still made the huge mistake of selling to the wrong government and agencies - and in some cases it can amount to a crime, and I'm not going to say that all governments and law enforcement agencies are wrong - although the more power they get the more accountable they must be.

Still these tools are here to stay - unless we want to see more government pressure to cripple cryptography, provide interception facilities, and require access to data stored by companies. But maybe that's what Apple & C. exactly want? Because that will put THEM in charge of what information can be accessed by law enforcement agencies, under their full control.

For example a spyware could hit - let's imagine for wholly lawful reasons - Tim Cook iPhone. And Apple would have no way to control it. But if law enforcement agencies have to ask Apple to graciously provide access to that, they have the power to decide what is accessed.

Just like banks offer ways to customers who can pay for it to get a far higher degree of "secrecy", I wouldn't be surprised if that happens or will happen in the comm/data storage arena....

xyz123

In my opinion, Apple wants offensive researchers out of the field - said Putin-controlled spokesperson for Russian "anti-virus" company thats been banned from dozens of government systems due to integrated "vulnerabilities".

Modern art is what happens when painters stop looking at girls and persuade
themselves that they have a better idea.
-- John Ciardi