- 113comments
- 166comments
- 26comments
- 80comments
- 450comments
- 108comments
- 77comments
- 2comments
- 285comments
- 2comments
- 342comments
- 20comments
- 40comments
- 83comments
- 19comments
- 94comments
- 32comments
- 6comments
- 1comments
- 4comments
- 108comments
- 270comments
- 81comments
- 89comments
- 4comments
- 73comments
- 1comments
- 14comments
- 83comments
- 102comments
Huh, it looks like suing a state-sponsored malware manufacturer doesn't prevent them from continuing to hijack your devices. Live and learn, I suppose.
This is based on Apple notifying the employees based on prior behavior of NSO.
Suing is hardly the same as having the suit decided, grow up.
Okay. Let's assume they do have the suit decided, and they rule in Apple's favor. What next?
NSO is a corporation with US bank accounts and business deals; the courts take its money.
“ NSO says its intrusion system cannot work on phones with U.S. numbers beginning with the country code +1.”
Seems like they just need to add a similar patch for apple ids for emails ending in “state.gov”. Not sure why this is such a big deal.
Come on, think about it. Doesn't work for phone numbers starting with +1? So, anyone who buys the right sim card is immune? A team of professional hackers can't find the if-else in the attack binary that enforces that to disable it? They're selling software to cybersecurity teams on the assumption that they can't crack it?
My understanding is that it's not _just_ a tool, but a whole infrastructure around it that the clients use. So presumably, before deploying to a target, it would need to go through NSO infrastructure, so they could vet there.
It's probably easier than that. Seems like the kind of thing that would be in a config file (making this up, satire):
[No Spying Allowed - please do not change]
# Really, really, don't change this setting. We are not responsible if you do.
+1 # USA
+3542 # NSO Group
No, I think they are telling journalists that their hands are clean, and it totally isn't their fault, not in a million years, that their customer changed their software.
which is pretty absurd since there's only a vague relationship in the modern SS7/PSTN between a phone's DID and where it might be physically located. In five minutes of work I could have a New Zealand number ring on my desk phone anywhere in the world.
So it doesn’t work on US phone numbers or doesn’t work on +1 country code?
-confused Canadian because we share the +1 country code with USA under NANPA
Canadians go 'yay', finally some benefit of the big brother.
PS: I don't buy the explanation btw
As someone who doesn’t have a +1 number I find it hard to take this comment seriously. But could it be possible that some state department employees work outside the US?
Presumably those phones had Ugandan numbers.
Wait, what about that one time NSO's malware was used to hack Jeff Bezos? Pretty sure he'd have used a +1 ... number.
Time to go back to rotary phones
As discussed 2 days ago here on HN
https://news.ycombinator.com/item?id=29401454
Just get calyxOS or any other privacy + security FOSS mobile operating system.
Is there a timetable when Apple plans to stop using memory-unsafe languages to avoid memory-bugs? If not, how can the amount of zero-days stop with constant development?
biggest issue here isn't memory safety but the dumpster fire of imessage format that calls out to privileged parts of the system
Which is exploitable primarily it by memory safety exploits.
Will it make attacks impossible? Probably not totally. But it might raise the cost of the attack by an order of magnitude or more and certain classes of vulnerabilities might disappear completely.
I'm suspicious of any messaging system that has ties into rich media / embedded-in-chat content. I even wish I could disable URL previews, gifs, and inline images in Signal.
I didn't know it was possible to disable URL previews in iMessage[1] until I read this comment. Does toggling this setting only prevent the preview from displaying or does it prevent the fetch altogether? I wish there were a way to white list the URL previews for certain contacts rather than turning it off all or nothing.
[1]https://discussions.apple.com/thread/7677834
It can be your "trusted" contacts that infect you though.
"Jeff Bezos was hacked by a file sent from the WhatsApp account of the crown prince of Saudi Arabia, Mohammed bin Salman"
https://en.wikipedia.org/wiki/Jeff_Bezos_phone_hacking
I didn't see a way to disable URL previews in that thread. The given "solution" is wrong -- it just disables message previews in the lock screen.
It's an extremely common attack vector. PDFs, media message, etc. Would it be viable to create a dedicated processor specifically for parsing these things?
And Apple's terrible software and QA processes, like lack of CI or fuzzing, which is why Google Project Zero is discovering flaws for them.
You do know that memory-safe languages are developed using memory-unsafe languages, and eventually execute the binary code on the actual CPU?
I think it comes from that rewrite everything in Rust camp.
A memory safe language can be written in itself.
Most memory-safe languages I've used self-host their compiler and standard library (i.e. they're written in the language itself).
Well, yes, but there is also (usually) a bootstrapping phase before a language is self-hosting, and if you're sufficiently paranoid the 'Trusting Trust' meta-vulnerability comes into play and isn't easily dismissed.
no question that imessage, email parsers, etc that do third party untrusted network type interactions SHOULD be memory safe. But of course they are not, and apple in particular LARDS these formats down with a million features.
Looking at the answers, seems like a NO.
So the point is to stop terrorism and to do that they've immediately ruled that all Americans aren't terrorists. That doesn't seem like a good metric of determining if someone is a terrorist, and makes me doubt their other controls are any better.
NSO has repeatedly shown that their statements are pretty much worthless. It's just damage control. I wouldn't put any stock in the "we avoid +1 numbers" to even be real.
Seriously, they're pretty much the Mark Zuckerberg of their industry.
That is not fair to Mark Zuckerberg.
They're pretty much the General Butt Naked of their industry.
I‘d rather compare Zuckerberg to the Sackler family who knew how addictive and harmful their painkiller Oxycotin was, yet ignoring all evicence, making billions of dollars. Zuckerberg knows how bad Facebook and Instagram is, how harmful to individuals and society alike, yet ignoring that and making billions.
Edit: Replaced „social media“ with „Facebook and Instagram“
Why did you feel the need for the edit? I would agree with the blanket use of social media. Twitter is no better. Do we know enough about the inner working of TikTok to know they aren't doing similar?
That part I believed. Setting up their software to not target the US seems like the kind of move they'd make. Claiming it's so they don't target innocent people is bullshit.
So I just have to buy a US phone to evade detection from NSO? And why didn't that logic work for US State Dept phones?
I'm honestly of the opinion there is nothing that NSO can say that isn't outright lying. This isn't a normal company in anyway.
I remember reading that some Russian (private sector) computer viruses did not attack computers whose language and locale were set to Russia. It's never about ethics. It's always about making as much money as possible without pissing off powerful people and entities.
Yep, Krebs on Security wrote "Try This One Weird Trick Russian Hackers Hate" -- https://krebsonsecurity.com/2021/05/try-this-one-weird-trick...
Crudely, we would say "don't shit where you eat". I've heard from the early (as in, 80's) hacking days some of the people in the US would never hit targets in their own state, as there wasn't good federal-level enforcement nor inter-state collaboration. Of course that would backfire today because you're immediately commiting crimes across state lines...
I had this with a Chinese app. Works well on a Chinese language phone, downloads an extra package if not.
They had Ugandan numbers, as they lived in Uganda.
Phone hardware is not tied to any particular number.
So you just need a SIM with a US number and use that for all your evasion needs.
Yeah, this.
They started off with the arrogance of a liar who thought they were immune from consequences. Now they're looking more like the kid who is actually in trouble only now realizing nobody trusts them to identify the sky color, let alone defend themselves.
Anything and anyone coming out of that shop is tainted.
* A US Phone will route your call via NSA servers[1], so yeah thats OK from the US governments side
* Publicly at least, NSO acknowledges there are state level agreements, the latest one with France, to block entire country codes from Pegasus (in return, France has stopped all legal action against NSO)
* According to Israeli Channel 12 reporting on this tonight, the official NSO response also includes the statement that the accused numbers in the report were not +1 numbers. Their so called "customers" were targeting US government employees using African area codes. NSO claim they have completely disconnected said customers from the system
[1] https://en.wikipedia.org/wiki/Room_641A
These were Foreign Service officers stationed in Uganda, so their phones had local Ugandan phone numbers. Some of them were working out of DC but - given the nature of the State Department (which is like America's foreign affairs department) - probably traveled very frequently and so maintained a Ugandan phone number as well, to save on roaming fees when making calls in Uganda (saving money for the taxpayer) and also so Ugandan officials can contact them easily.
This is not unlike Apple hardware engineers who travel frequently to China and have a Chinese number in addition to their main US number, so people in the factory can communicate with them easily.
This is NSO's claim. Presumably because they want to make it difficult for anyone to sue them in a US court. It's plausible but I don't necessarily believe them either.
I want this company bankrupted out of existence, personally. Apple's lawsuit against them may well result in that outcome.
Reminds me of how some ransomware looks for if your default keyboard language is Russian. If so then it exits, doing nothing.
OK, so the best way to protect privacy is to get US-based phone number and install Russian keyboard as a default.
And it should have a list of sites blocked by Chinese regime downloaded as discovered by Lithuania [0], for even grater privacy.
0: https://news.ycombinator.com/item?id=28616683
The alleged point is to sell software that stops terrorism. Pissing off America is a good way to stop being able to sell your software.
These people are in for a world of hurt, the State Department tells the CIA what to do.
Your broader point is correct, but no, it doesn't. The CIA is an independent agency [1]. It reports to the DNI [2].
[1] https://en.wikipedia.org/wiki/Independent_agencies_of_the_Un...
[2] https://en.wikipedia.org/wiki/Director_of_National_Intellige...
Yes, but who dictates where and how they can play overseas?
The Director and Deputy Director of the CIA.
I'll simply disagree.
Heh, that showdown sounds like it would make for a hell of a book decades later.
NSO has a deal with US Telecom to grow its market share throughout the world and hence the +1 statement. /s
Maybe NSA wants every important call goes through USA network (and hence a deal with NSO) - makes the job easier for three letter agencies.
Funny enough this reminds me of the ransomware that doesn't work if a cyrillic keyboard is installed. https://krebsonsecurity.com/2021/05/try-this-one-weird-trick...
Someone else linked that one, it's hilarious and unsurprising really. Lots of people purposefully avoid certain OSes (mostly linux distros) as well out of respect NOT because of population/userbase of the OS. Lots of discussion on worm/trojan development forums over the years.
If you are a Russian hacker, you probably don't want to piss off a Russian mobster who has the capability to take you out, and the contacts within Russian intelligence to identify you.
"We promise we don't work on numbers with +1" :wink: :wink:
As an obvious statement: I think this should be interpreted similarly to some ransomware not infecting devices with RU keyboards: it's just about avoiding difficult regulatory environments.
The analogy, of course, goes further. Though unlike most ransomware companies, NSO has British and American VC funding.
Most people don't know that the first bit of an area code is the evil bit. https://en.wikipedia.org/wiki/Evil_bit
I'm waiting for the day that the US declares a foreign corporation as an "enemy combatant", as they have done with foreign citizen wahabbist jihadis and US citizens such as Anwar Al-Awlaki.
Given the extent and depth of US-Israeli cooperation and ties, the precedeing theoretical is probably going to remain in the realm of theoretical.
Didn't they get pretty close with Huawei when the previous president issued an executive order in response to state spying fears that:
* banned the sale of any of their phones or networking products in the US
* banned US companies selling product to Huawei
* cut funding to wireless carriers using Huawei equipment
...and then pressured allied countries to do the same?
The investigation into Huawei was going on for many years prior to 2016. It's not exactly an initiative of the previous president.
I sat in briefings about Huawei and ZTE in 2007. Regretfully can't say more.
Are you personally upset about the clear intelligence failures and extrfiltration of protected information?
I've grown up watching this unfold and I'm shocked that the power groups seem to be so ineffectual at times that it's laughable(but that may be by design...)
It's an absolute shitshow from top to bottom. The people who know what they're doing in intelligence/counter-intelligence agency infosec/netsec (and within major DoS and DoD contractors) have been fully aware and ringing the alarm bells for years. The technologically unsophisticated politicians have been mostly ignoring it.
how much of the ignorance is willful?
You'll know when the stock trades are released.
No, given that jihadists were kidnapped, tortured and murdered - all of this illegally.
NSO's PE investors are big-time American and British funds.
Just sayin'.
According to Wikipedia, NSO is owned by by its two founders Omri Lavie and Shalev Hulio and Novalpina Capital. According to Sky News Novalpina Capital is getting liquidated and their stake in NSO will be sold to a third party: https://news.sky.com/story/pegasus-spyware-owner-novalpina-t...
Right. I can’t tell if you’re agreeing with me or not. :)
Prior to Novalpina, it was Francisco Partners.
Point being, NSO has received huge amounts of money from the kind of people who, well, YCombinator founders seek out.
Yes, but it is not Francisco Partners now so it appears there is no "big-time American fund" involved and the British one appears to want to get rid of its stake.
From the side-lines this thread looks like:
- md: X and Y are deeply involved in this company
- yiu: No they are not. X cleanly destroyed all the papers and officially ask we don’t talk about them. Y is a bit late but will finish cuting ties in a minute now.
This implication is about who would care if NSO gets shut down. For that, current investors are what is relevant. If someone already divested they don’t care and wouldn’t pull strings to keep the company around.
Agreed. I find many of the responses unconvincing. They are in many ways exactly what you'd expect. Sure that doesn't prove anything directly, but on these matters having direct and public proof is the exception not the rule.
That's pretty much what they did with NSO, which is getting the Huawei treatment:
https://www.theregister.com/2021/11/03/us_sanctions_spyware/
reportedly, this has created havoc on NSO, since for instance none of the cloud providers can sell services to them to host their zero-days, among other logistics headaches. Their recently hired CEO resigned.
What's the consequence for destabilizing governments worldwide? Logistics headaches? Got it.
The NSO guys are in it purely for the money. IIRC there was a deal on the cards for some investors to buy the company that fell apart because of the sanctions, so the NSO founders can no longer cash out.
As for destabilizing governments, they are doing the opposite, they are helping authoritarian governments worldwide crack down on journalists and dissidents, or murder them in the case of Saudi Arabia and Jamal Khashoggi. Reportedly, after the Khashoggi murder, NSO yanked the Saudi account but was forced to reinstate it by Netanyahu who was pursuing diplomatic relations with them.
The episode of Darknet Diaries on NSO was very informative.
https://darknetdiaries.com/episode/100/
I knew about Israeli security consultancies putting out stringrays and phone cracking tools, but I did not know about NSO. He has a good interview with one of the lead devs.
correction the interview isn't a lead dev of NSO but from a third party who investigate malware attacks on reporters etc
Good point. Although i think the preceding comment was using "destabilizing governments" as a catch-all for non-democratic and morally dubious activity.
It’s particularly interesting to watch as the company is based in a country that is a very close ally.
Ignorant question: is Israel literally an ally of the US? I know they are not in NATO or 5 Eyes, and I don't think they have some other close agreement, like US and Japan.
Israel is a client state of the USA. They are America's enforcers in the Middle East.
That's factually wrong. Israel is it's own full state.
The relations are green hearts, and the U.S. is guaranteeing independence.
Israel wouldn't last a year without the unequivocal support of the West.
They have had consecutive Memorandi of Understanding that promise security collaboration and funding. The current one is a 20 year treaty that promises $38B in spending and expires in 2036.
Memoranda, AFAICT?
Lol, yeah, that's how to pluralize that correcty.
Despite not being in 5 eyes, Israel does get special treatment in the form of raw intelligence data from the US.
https://www.theguardian.com/world/2013/sep/11/nsa-americans-...
Just declare them a terrorist organization.
This isn't War on Terror-adjacent - it's a local repressive government catching embassy workers in a dragnet while spying on the opposition. The full security-state treatment will not be in effect. Still bad, though!
I thought the exploited holes were patched by iOS at some point. How are these phones still getting hacked?
People are notoriously bad at keeping their devices up to date, with some even intentionally disabling updates. This can be prevented by the IT department having MDM profiles with strict update enforcement in place, but I don’t have much hope that the IT department of any given US government office is particularly capable or competent.
The article doesn't say if they were personal or work provided phones. Many people living/working overseas have work and personal phones. Also, almost all of those with personal phones get a local SIM, so they'd get a local non-US (not +1) phone number. I used to be an IT admin with DOS overseas. Updates were enforced, and phones were disabled if they were not upgraded to the most recent version. Starting in about 2019, mobile device security went into overdrive and is very serious now. Additionally, the MDM profiles are quite limiting, so this pushed most people to get personal phones. A huge pain for records retention.
Because there is a never-ending supply of vulnerabilities in our smartphones.
A system this complex can never be secure no matter what google/apple PR dep claims.
Exploits are now a multi-billion dollar market. And iPhones can be obtained worldwide. You just need one person with questionable morals, good hardware hacking skills and a need for some hefty payout.
There's a lot of buyers, Five Eyes, China, Russia and naturally companies like NSO.
There's always another zero day
In past exploits were used for jailbreaking. Now they can be sold for 6 figures. The incentive to report vulnerabilities or even use them casually for jailbreaking has gone way down. I think the only way would be for Apple to offer 6 figure pay outs for the exploits. Maybe they could get a tax write off.
This is being publicized only now.
The issues were patched in September, the exploit was being used as of February, and it took some time for someone to notice that an @state.gov Apple ID was among the compromised phones.
Seems like not-the-smartest move for Israel to mess with one of the few powerful entities that desires its continued existence
and the one entity that give it wagons of usd.
This is just another incident in a long list that goes back decades of Israel getting carte blanche to do whatever they want to the US with little to no repercussion. The most famous probably being USS Liberty (https://en.wikipedia.org/wiki/USS_Liberty_incident)
Why would Israel be allowed to do whatever they want?
https://en.wikipedia.org/wiki/American_Israel_Public_Affairs...
Really? Have you actually read the Wikipedia page you're referring to?
50 years ago during a full scale war with all surrounding countries, Israel accidentally (as determined by US investigation) hit a "spy-ship" near Egypt (one if the countries participating in the war).
Israel subsequenly paid around 70 million $ in compensation for the families.
Everyone knows already nothing will happen, they will get slap on the wrist as usual and show goes on.
Or the smartest move. They probably own more politicians than the NRA, the pharma ind, and and the aerospace ind combined.
Why would they cancel accounts without knowledge of wrongdoing?
Because the US government is one of the few groups that can put real pressure on them and they're in full panic mode
And simultaneusly:
- not have any indication their tools were used
- canceled the relevant accounts
Which "relevant" accounts if NSO's tools weren't used?
I think it's pretty clear by now that they have 100% visibility into the entire exploitation chain for all of their customers. Their "official statements" mean nothing.
Well since they do the exploitation on behalf of customers, yes?
NSO is very popular with governments that don't have robust domestic intelligence because all you have to do is type a phone number into a web form and in anywhere from an hour to a week you get a point and click GUI for accessing the contents of the phone.
You have a source for this? I genuinely want to know if they make it that simple
Publicly? No.
Should all come out in the Apple lawsuit though.
Edit: Rereading the NSO statement they said they blocked exploitation of numbers starting with +1. Take that to mean whatever you'd like.
You should listen to darknet diaries podcast about NSO group activities
I understand that, but they have repeatedly denied that this is the case, which is simply absurd.
My thought was that the customer runs the server provided by NSO. I though the web form is running off of a webserver in a building owned by the customer.
I used to work for an ISV in the finance industry. Most of our customers ran our stuff on their own servers in their own data centres, but we had direct logon to the application user account to manage the application config, do software upgrades, investigate issues, etc. A few of our customers preferred to support the software entirely themselves, we had no access and ran training courses for their support teams. I wouldn't be surprised if NSO offer a similar range of options depending on the client's budget and technical capabilities.
... Is this real? There's no way to resist this?
Presumably the full accusation is "Entity ABC used NSO tools for XYZ". So the reaction was to cancel ABC's account while NSO investigates whether ABC actually did use the tools for XYZ, or whether ABC was only using them for other (approved) purposes.
Regardless, NSO rules over international law.
No, it means that NSO takes customer complaints seriously, especially a customer as important as the US. They operate under Israeli legal jurisdiction, and probably have an existing relationship with US firms, public and private, and I don't think the Israelis would hesitate to take whatever action the US wanted, because it benefits them to "play nice" and be cooperative. It kinda sucks for them in this case because chances are this is evidence of in-fighting between US agencies, and NSO tools are in the middle.
FWIW "international law" is its own thing and doesn't work like normal law; in truth every nation by default "rules over international law". When was the last time you saw an "international law" trial or saw a nation punished?
Mid-to-late 1990s, den Haag, Serbia?
Shrödinger's moderation. NSO has this magical zero-knowledge technology that:
- When questioned about a specific malevolent client misusing their data, they cannot be held accountable because the client is running the ops and NSO has no access.
- When asked how they ensure that clients in general don't go rogue and misuse (i.e. human rights & international law abuse) their service, they assure you they monitor them and turn off their access.
This is in Uganda.
NSO sells only to governments and law enforcement agencies.
Therefore, the relevant client would be the Ugandan government.
Aside from that obvious contradiction - this also indicates that the tools they deploy are either NSO hosted or use a licensing system to run.
There was a recent Darknet Diaries episode that reported evidence that at least some of the NSO tools are hosted services.
I can't imagine something like this not being in the cloud. The potential for a customer to give their local NSA/8200 the tool to figure out the 0days used is too large
Pegasus is only as good as its 0days are secret
Heck, forget about bothering to extract 0-days; if you have access to the binary, straight-up warez techniques would be applied to nerf any restrictions (licensing or otherwise) on the operation of the software, as well as any monitoring functionality that can "phone home".
Couldn’t you hack your own phone and somehow log traffic to get the exploit used?
Yes you could. You could even use a fake phone which is wired to log everything. A lot of malware attempts to avoid VMs and stimulated environments but the actual 0 day would be before that point.
If a state sponsored party really wants to find these zero days I'm sure they can. I would imagine that this is more like what happened with EternalBlue: it's something they know but don't report because it's useful to them too.
Remember that this group's tools have been used to murder journalists, which they are unapologetic about.
Dead journalists can't close them down, but the US government can.
I think that remains to be seen.
Oh man, for purely comical purposes I would love to see NSO actually believe that.
In principle, America could drop Hellfire R9X sword missiles through the cars of every NSO employee. In practice, would American politicians have the nerve to go to war with NSO, when NSO probably infected all their phones years ago? How much dirt do they have on American politicians?
So you think because NSO breached a few state department phones that they have the deep dirt on every sitting congress member?
You think the iceberg is coincidentally only as deep as what we've presently heard? That we didn't have the full story yesterday, but today we definitely do?
Well I hope you're right, but I don't think you are.
Not all but do you really believe that the NSO group wont have some blackmail material on at least some US politicians?
The next step isn't to blow them up, the next step is to sue them.
I just assume the IDF and Shin Bet would like to be the only ones who blow up civilians in Israel, but I can't think of a single reason why the Israeli government would oppose an extradition request if they were presented with evidence of cyber-whatever.
Because they want to foster such companies, and not deter people from founding them by showing them that they will be extradited to the US?
If an American company would get caught doing the similar, would US allow extradition request of those people to some other country?
Except the really obvious detail that most normal countries won’t extradite their citizens? Israel loosened up their laws on this a bit after the Sheinbein affair, but extraditing resident-citizens remains a rather unlikely prospect.
Really, all you need is a subtle suggestion to the Israeli government that the hundred billions or so dollars they receive from the US every year might be impacted by continued NSO bad publicity.
More like ~$4B (out of a total foreign aid of ~$50B annually).
https://usafacts.org/articles/how-much-military-aid-does-the...
that number is way off, and the money they "receive", is specifically for use with US defence contracts and deals.. Its like Disneyland giving you Disneydollars.. You can only spend them at Disneyland.. It is a way for the US military-industrial complex to stay afloat.. And it is a drop in the bucket for Israeli Defence spending, and would make little difference if they took it out.
Only if you can find their remains
I don't think the US really cares all that much if Saudi Arabia cracks down on dissidents. It's only bad if Russia or China does it.
It seems to me their entire repeated justification is to pass the buck to foreign governments that buy their product. It's like the 4th time I've seen this company pop up in my newsfeed in the last 6 months, every time a similar story. I wonder when enough is enough for whoever holds authority over them
Sounds like NSO Group is about to be served a subpoena.
Presumably they wouldn't want to be associated with people who do this sort of thing. (Not neccesarily for ethical reasons, its probably just bad for business)
I mean, they could also be lying, but its also pretty standard business practise to not work with people who bring your reputation into disrepute. For example, consider how hard it was for parler to get hosting.
How do they know that their tools are not used, but know which accounts hacked the phones?
Also in other stories they have claimed they do not track who does what.
Because who else is going to be plugging Ugandan phone numbers into NSO software other than the Ugandan government?
I’m not saying that they don’t have that knowledge, and I really don’t mean to offend or be rude, but if the US government asks something of you, you tend to comply wether it’s reasonable or not.
I think it’s naive to think of ourselves as living in a just world. Post 9/11 the CIA abducted European citizens with the knowledge of our governments. In more recent years, here in Denmark we had a rather huge scandal when it was revealed that changing governments had allowed American intelligence services direct access to the backbone of our national internet. The list goes on.
Its of course unfortunate, but the world we live in is basically a huge turd of authoritarian bullshit where the users and customers have no actual enforceable rights.
I mean, even on a much smaller and much more harmless scale, just consider how many times you’ve read about someone losing their Google account here on HN.
The US military entered a foreign nation without their knowledge or authorization, abducted a resident, took the resident out to sea, placed a bag over their heads, put concrete shoes on that resident, and then dumped them overboard with no witnesses other than the "Seal Team" carrying out the order.
No trial. No witnesses. Only abduction, seclusion, and murder.
That's not justice. Those are Mafia Tactics. ___
Does this remind anyone of anything? A Mr. Al. A Mr. Al Capone perhaps? That's right. One of the world's most infamous gangsters, mobsters, crimelords, did this very thing to individuals that Capone didn't want talking to the press, the government, or anyone else that would listen.
This is mob-boss behavior, and the US Government does this now.
Oh, how about the unlawful imprisonment of 100s of detainees at Guantanamo Bay in Cuba?
Secret courts, whose authority is far-reaching with no citizen oversight whatsoever.
Yeah the US Federal Government, since 9-11, is a bunch of mobsters with guns. There is no difference in the way our Federal Government acts now, and how 1920s and 1930s mobsters act.
Any human being that doesn't recognize the similarity is deluding themselves into believing so.
How did you learn about this incident which had no witnesses?
GP's obvious hyperbole and distortions are obvious.
That said, this is among the weaker rebuttals which could be offered. (See my own response in thread.)
This was in response to acts of war and unprovoked attacks against the United States mainland with both military and civillian targets by an individual who had made a specific declaration of war against the U.S.: https://scholar.dickinson.edu/faculty_publications/277/
Comparing that speific case to failure to follow proper criminal procedure and rule of law is disengenuous to the extreme. There are many criticisms which can be made of the US response to (and other actions after) the 9/11 attacks. The assassination of the leader of the irregular forces aligned against the US is not one such. Numerous other instances would have made for a vastly stronger argument.
The fact is that there is no clear dividing line between acts of war and criminal acts --- recognised among other ways in the phrase "war crimes" itself (which might be applied both by, and against, the United States).
The situation in Guantanamo is far more valid.
The case of drone warfare and strikes another instance.
It's worth noting that the US is hardly alone in these tactics, and that irregular and extrajudicial killings are in fact a major element of the considerations in the case of Al Qaeda, at least some of the Guantanamo detainees, and drone strikes.
The real world is messy.
That said, I'd disagree with your conclusion on lack of difference, moralising, invective, and hyperbole notwithstanding.
Since when do individuals wage "war" on nation-states?
(And no, if the only counter-examples you can come up with are 18th-century pirate chiefs and tiny Carribbean islands you've failed. We're talking 21st-century USA here.)
Which "specific" case? The GP mentioned hundreds of Gitmo prisoners, several of which have later been shown to be completely innocent victims of mistaken identity.
If anything is "disengenuous to the extreme" here it seems to be your defense of the USA's recent practices.
What I wrote was "acts of war" and "specific declaration of war" by the individual in quesiton, with a link to the citation. If you have any issue with established historical fact, that's your own concern.
Decapitating a specific cult of personality has been an effective method of eliminating it. Which also proved successful in the case of AQ.
(Yes, there are new emergent threats and groups, including several previously associated with AQ. I also said that the real world is messy.)
The specific case I was discussing, and I really hope I'm not so vague in my dotage that this wasn't crystal clear, was the 2 May 2011 attack on Osama bin Laden's compound resulting in his death.
What I defended was a specific instance, while acknowledging concerns and issues in other areas. Both you and imbchillyb are displaying a lack of such naunce. The US is vast and contains multitudes, some defensible, some not. It cares little for what I have to say.
Refreshing your memory: https://forum.iwethey.org/forum/post/8257/
obLRPD: Powered by sporks.
Nope, certainly not crystal clear: You were replying to a post that mentioned, among other things, the Guantanamo internment camp, and airily said "this" case. I saw no specification there of which case, exactly, that was supposed to be.
Yes, the USA may be vast and contain multitudes, but even you talk about "the US": In the end there is only one of it, and when the USA as a nation-state does stuff then it's the USA, singular, as a nation-state that gets discussed and criticized. Just like here. I hope I'll never get so fuzzy in my dotage that I'll let sich disingenuous attempts at obfuscation slip by.
Hm... Pseudo-helpful hint/ reminder; feels like about 50/50 past and current posters. I'd already concluded neither extreme of Box or Ash, for rather obvious linguistic reasons. Been considering alumni like RM, DRL, KMS et al, but this feels more like currents such as RC, SK, or SA. Or perhaps AG; I notice that his recipe -- besides the formal declaration being severely watered down -- was pretty much what the US (singular, as a nation-state) went with.
I don't have your email; you have mine.
I've told you specifically what I was referring to, and you are continuing to dispute what I was telling you. The same vagueness applies to imchillyb's comment, yet you seem to find no fault with that.
Concisely: AQ runs Afghanistan, now.
So, it was difficult to finish your comment.
My understanding is that it's the Taliban, and a cursory check of credible references supports this. That's a group formally alligned with AQ, but distinct from it, again, via credible references.
Other active entities include the Islamic State (ISIL / Daesh), and various organisations largely funded / supported and/or organised around Iranian, Syrian, and Palastinian interests.
Please note that this is not an area of personal expertise.
Still, the Mossad is one of the agencies who can keep pace with the CIA when they put their mind to it. Nonetheless, if you're not directly an agent, no sense putting yourself in the middle of a spy war.
The victims will be pleased to learn that they're all terrorists and criminals, as NSO keeps asserting that their spyware is only used against those.
I wonder if we would be hearing about this if NSO had paid its 30% to Apple in the first place.
I don't understand the focus on NSO in these stories. If U.S State Department personnel in Uganda were shot from an M-16, would the headline mention "an American arms manufacturer"? No, because it's ridiculous.
For better or worse, NSO's product is a weapon. How is it any different from an M-16? Where is the outrage towards the people who used this weapon against the State Department?
It's my understanding that NSO runs centralized command and control servers that their "clients" are granted access to, for both the on-device payload installation and also data exfiltration.
They do not give the software to their clients to go use somewhere in the world fully independently (self hosted payload dropper, C&C, etc)
They're a direct participant in the network traffic. Unlike a dumb purely offline piece of hardware like a M4 rifle or similar.
I find it very unlikely they knew about state department phones. Why bring up M4 rifles all the time? That's not how the U.S or any other arms seller makes money at all. The big money comes from planes, drones, etc. 350 billion worth over 10 years just to Saudi Arabia alone https://en.wikipedia.org/wiki/2017_United_States%E2%80%93Sau....
No, because it isn't novel, it's not wide reaching, it's not at arm's length and it cannot be stopped.
Stuxnet, a novel American-Israeli cyber weapon, purpose built to hit Iran, was absolutely billed as such. And it was received differently, by Iran, than would be e.g. an American-made gun fired by Iraqis at Iranian surrogates.
NSO is making and selling cyberweapons. They're doing it now. These weapons are hitting the U.S. government and its allies to an unknown extent. And they can be turned off, right now, if Jerusalem orders it.
U.S. persons being shot in Uganda by Kalashnikovs are none of these things. It's not novel. Nobody wonders if the Ugandans are going to show up, guns blazing, in Arlington. And Moscow can't remotely disable the guns.
U.S. weapons manufacturers receive a lot of criticism too, both domestically in the U.S. and internationally.
The comments here focus on NSO because the story is about what NSO did. This is computer tech kind of community so you’re going to see more computer weapon stories here than stories about improper use of rifles.
The U.S sells super sophisticated weapons such as attack drones, F-15s or nuclear submarines. The tech behind these things is probably super interesting and there's a lot of software involved. If you look at the comments here, around 90% of them don't care about the tech at all but focus on bashing Israel. This isn't a tech story.
It would certainly be a news story if someone used a U.S. built submarine to attack the U.S. State Department.
You do realize it was Ugandans who actually ordered the hack yes?
And Israel also sells super sophisticated weapons like AWACS radars and surface-to-air missiles.
But there are clear understandings that e.g. nothing goes to China, and no fancy radars go even to untrustworthy places like Myanmar. NSO is still in a gray zone.
An Israeli company selling hacking services to every dictatorship and or corporation willing to pay? I hope you can see why that's bad.
And yes I'm acutely aware that the CIA literally ran torture training camps in the 1970s but two wrong don't make something right.
Unlike an M-16, hacks can be conducted remotely, they can be used to plant evidence, conduct blackmail, and lots of other things where most people would never know a hack was involved.
Also, there's outrage towards NSO because Israel is supposedly an American ally. Israel needs American support, and yet Israel freely allows Israeli corporations to sell services American enemies. And this isn't an isolated company--there are other Israeli hacking companies that target Americans, such as Black Cube.
Uganda is not an American enemy.
This isn't being sold to an American enemy - in fact, the US sells and donates (!) weapons to the same government. The US doesn't care much about Israel (a Major Non-NATO Ally) or Turkey (a NATO member) selling artillery pieces and APCs to Uganda.
It's all about the specific class of weapon. There are general understandings about who can get sold what weapon without the US getting mad. No radars or surface-to-air missiles for China or Russia or for random tiny dictatorships; but it's totally okay to sell them to India or Latin America. Dumber things like artillery pieces can go anywhere, even places under US sanctions like Myanmar, without crossing any lines. But this isn't written in treaties; it's all implicit understandings and learned patterns of retaliation.
For this new class of weapon, both sides are still feeling out the rules. The US is laying down precedents that put NSO's products much closer to the rules for radars and missiles, while Israel is pushing the limits to see how far the US can live with.
In National Security contexts, the "get angry at the weapon seller" response is very strongly correlated with how advanced (in technology, power, and scarcity) the weapon is perceived to be.
For an "average soldier" weapon, such as an M-16 - $Company isn't likely to catch much grief - unless they're selling a considerable quantity of them, or to an extremely notorious buyer. Similar for a cyberweapon - but an "everyday" one, which wouldn't be a big surprise for a C-list ransomware group to use.
Vs. NSO's stuff seems to be the sort of top-tech goodies which A-list nation states use to maintain & enjoy their A-list status. Whether any actual harm results from this incident... publicly letting a bunch of "the wrong sorts" into that exclusive clubhouse is getting NSO into really deep do-do with "the regulars".
Yup. If decently up to date surface-to-air missiles were fired at State Department helicopters in X country, the US would be very very angry at whoever let those get sold so loosely.
Nope, that’s a bad analogy. A manufacturer that produces and sells thousands if not millions of items won’t be deemed as complicit as one building a nuke that somehow lands in your enemies’ lap.
That’s pretty obvious and it’s disingenuous that you’re trying to steer the conversation in that direction
Speak plainly. Are you suggesting this is a company being unfairly singled out just because it's Israeli?
It being Israeli is definitely a big part of why this story is so huge. Why do you think it's making huge headlines then - what's your theory? The fact that 8 American diplomats got their phones hacked?
Because they are amoral pieces of shit who'll sell to dictatorships and use state export regulations as a fig leaf. Because they fight back, lobbying in an attempt at regulatory capture. Because of how many innocent people's phones their software has provably ended up on. Because it's so closely connected with state funded and trained hackers from Unit 8200. Because they lie, simultaneously denying involvement, yet, disabling the relevant accounts. Just a theory.
Follow the industry long enough and you'll know how Hacking Team (Italy), Finfisher (Germany), Gamma International (UK), smaller and larger firms have rightfully attracted their fair share of condemnation. Journalists pile on when a story gains momentum, this round was started by the published list of targets and Citizen Lab. We can't call this anti-semitism yet.
Defending it just because it's Israeli would be as unjustifiable as attacking it just because it's Israeli.
I'm in agreement with you. I don't see any indication that the Israelis specifically made this weapon to target US interests, nor do I see any indication that the Israelis are discriminating between the US and any other nation, nor do I see anything that leads me to believe that we aren't potentially using this ourselves against other nations.
Fuck NSO, for sure. But I'm just not sure Israel should be held accountable for the actions of a private corporation with no apparent political motivations, just as in your M-16 example.
The Israeli state regulates the export of NSO Group's software. So yeah, they do have some responsibility here.
https://www.haaretz.com/israel-news/tech-news/israel-will-re...
If it's specifically, then I'd agree with you. If it's just broadly (such as how the US unilaterally doesn't trade with countries currently in the midst of war), then I'm not so sure.
Unlike a firearm which has no intelligence or software, NSO retains significant control over their product.
U.S drones and F-15s don't have software?
OP said M-16 not F-15.
NSO doesn't "sell" cyberweapons - they lease them and provide logistical support (including running the cloud infrastructure). This confers a lot more knowledge on where and how the weapons are used, and adds a lot more culpability.
The situation is less "M-16 and rounds sold once-off", and more of a turnkey armed drone (or surveillance drone, if you're charitable) service provided to governments, where the missiles, fuel, and airbases are provided by a private party on an ongoing basis. It's more of a tailored service, than a sale of goods.
It's more like a PMC ala Wagner than selling an M-16. They essentially run the technical side of operations and provide the talent.
Ah, I like this analogy. NSO's role isn't so much selling a weapon as it is selling "cyberwarfare as a service."
Weapon merchants get flack all the time for selling their wares to... we'll call them "rivals," but it could be any state or organization not in the US's sphere of influence.
NSO gets particular flack because they're inextricable from the weapon they sell. If an M-16 is used to shoot someone, provenance is probably harder to prove; weapons change hands all the time, or are smuggled to ne're-do-wells via the black market. But everyone using Pegasus, as far as we know, is an NSO client; NSO made the choice to provide that software, including NSO support and NSO services.
It is highly unlikely that NSO group actually gives out their exploits, based on what we know about previous exploitations that have become known. It's more like they offer an interface to execute their exploits on a given target. The fact that they can block entities from using their service, after having had access to it (like they supposedly did in this case), very strongly supports this hypothesis. Hence they're offering a service, to use weapons for (or rather, in the name of) some (government) entity that pays them money to do so.
Imagine bombing-as-a-service, as an instance. That's much more like it, and your argument doesn't hold in that case.
Hacking as a service is a good way to put it
Perhaps you are unaware of the nature of global arms control and how much work goes in to prevent scenarios exactly like this.
Small arms proliferation is much harder to control, but yes there has been extensive reporting on Operation Fast and Furious where US gun sellers were allowed to sell to Mexican cartels under ATF supervision. [0] Those guns were used against both US and Mexican citizens, including fatally against 1 US Border Patrol Agent in 2010.
Looking farther back, during the Falklands war in the early 80s there was much controversy over the Exocet anti-ship missile, which was manufactured and sold by France. When these missiles were successfully used against British warships near the Falklands, Britian successfully lobbied for France to stop selling them to the Argentinians.[1]
So yes, it's actually very common to put the responsibility of how their products are used on arms manufacturers. It's a good thing and it keeps the world safer.
[0]https://en.wikipedia.org/wiki/ATF_gunwalking_scandal [1]https://www.bbc.com/news/magazine-17256975
Isn't the actual problem that a private company is using security holes that presumably Apple opened for three letter agencies to use?
The Israel government gets a pass for anything they do. Whether it is lying about nukes or what they've done to Palestine. NSO is a feather in their cap.
Why are you conflating Israel (a state) and NSO (a fully private company, owned by American private equity at some point)?
The Israeli Ministry of Defense licenses the export of Pegasus to foreign governments, but not to private entities.
https://en.wikipedia.org/wiki/NSO_Group#Pegasus
These export controls for weapons exist in much of the western world. Once granted a license, Israel has no legal say in how the product is used by the end user.
It’s all very routine and standard, not sure why people need basic explanations of what government export regulation is when the discussion is on Israel.
It goes much deeper than that. For a while now Israel has been using NSO as an incentive for foreign relations with authoritarian regimes.
https://www.theguardian.com/world/2021/jul/20/pegasus-projec...
https://foreignpolicy.com/podcasts/foreign-policy-playlist/h...
https://www.nytimes.com/2021/11/08/world/middleeast/nso-isra...
https://www.haaretz.com/israel-news/tech-news/.premium.HIGHL...
https://www.irishtimes.com/news/world/middle-east/how-israel...
https://www.ft.com/content/24f22b28-56d1-4d66-8f76-c9020b1b5...
https://www.jpost.com/jpost-tech/what-does-the-nso-hacking-s...
Because Jerusalem has the power to stop, or at the very least regulate, NSO.
Please don't virtue signal, or state flame wars, or use this to posture some kind of agenda.
I’m not seeing any virtue signaling.
These political flame comments don't belong on HN.
Please do not take HN threads further into generic flamewar hell. It's not what this site is for, and it destroys what it is for.
We detached this subthread from https://news.ycombinator.com/item?id=29432721.
Why not flag the article itself? There's nothing technical to be discussed here. If the article was talking about the technology, that's one thing, but its talking about state-sponsored espionage. Flagging my post is a bit like closing the barn door after the horses have left the building.
HN isn't just for technical discussion. That ought to be clear both from the site guidelines (https://news.ycombinator.com/newsguidelines.html) and the front page every day. HN has had articles about this kind of thing pretty much since the beginning and there are often interesting details and twists to discuss. Moreover, the ongoing NSO/Pegasus story is one that a lot of the community has been following with genuine interest. So I think it's ok (I admit I didn't read the article though!)
Most importantly: no matter what the topic is, it doesn't make it ok for commenters to break the guidelines. Just the opposite, in fact—that's why we have this one:
"Comments should get more thoughtful and substantive, not less, as a topic gets more divisive."
Your comment obviously broke that, as well as several others, which is why I replied as I did.
Slapping down the NSO doesn't fix the problem. We should be glad we even know that their software exists, imagine if it was completely hidden from the public? The problem is that Apple needs to fix this. Security is an arms race, and the more visibility we have into where it is weak, the better for everyone. To paraphrase the motorcycle repair episode of Winter Steele, "You are stronger now for having been fixed." IMHO.
I don't think most Apple customers know or care so despite being ostensibly "privacy focused" Apple doesn't have much of an incentive to take action.
Apple has demonstrated complacency on security issues. Stiffing security researchers on bug bounties is just one symptom, but so is the fact the market price for iOS exploits has cratered compared to Android ones.
Great commentary. The US is hopefully looking into why these employees are using iPhones + local SIM. And if that has been approved in the past, maybe re-think that
Are you implying there is a way to use an iPhone with a prophylactic defense against Pegasus? I was unaware one existed...
Imagine that sinking feeling in the NSO offices. Uncle Sam's coming...
You sure about that?
Yes.
"A State Department spokesperson declined to comment on the intrusions, instead pointing to the Commerce Department's recent decision to place the Israeli company on an entity list, making it harder for U.S. companies to do business with them.
NSO Group and another spyware firm were "added to the Entity List based on a determination that they developed and supplied spyware to foreign governments that used this tool to maliciously target government officials, journalists, businesspeople, activists, academics, and embassy workers," the Commerce Department said in an announcement last month."
uh oh. That's a paddlin'
As an American, it's becoming harder for me to muster sympathy for an entity that actively discovers and exploits technological flaws to use against their adversaries while simultaneously purposefully not alerting the manufacturers in order to correct the flaws so they can continue to exploit them and then those flaws are subsequently discovered by others and used against them. Poor you.
It is worth distinguishing between the State Department and the NSA. The US government is hardly monolithic, even if we restrict our discussion to just the executive branch:
https://www.washingtonpost.com/news/the-switch/wp/2013/10/05...
While I find it interesting that focus in comments appears to be on Israel, NSO and the complicated ( or not really that complicated if you look at it from a different angle ) relationship between them and US. I did not see a mention a broader discussion of, you know, hoarding zero days, exploits and whether using those can be worse than conventional weaponry.
The reason I find it interesting is because it is clear that US government supports Israel ( and NSO ) practically unconditionally ( recent vote on Iron Dome being a more amusing example of bipartisanship ).
Why is Reuters, an old guard by any account, concerned? Or are they simply following what sells and government is really at odds with its people when it comes to policy in ME.
Meta-concerns about "the media" are not relevant to every story that is ever published.
They shouldn't have anything to worry about, unless they have something to hide
Arguably, this is the real use case Pegasus was designed for. A government (Uganda) that does not have a large and mature civil service that would support a G7 level technical domestic intelligence agency went to market for the tools of one (NSO), so they can keep tabs on foreign intelligence agents (state department staff) in their country. I am not a fan of NSO at all, but this case sounds like they're providing sovereignty or statecraft as a service to a government that prefers to buy instead of build their security capability.
When the game is defined as a competition for how to break its rules in the most unexpected ways and with the fewest consequences, Uganda appears to have joined in with aplomb. To me it's the first time an NSO story doesn't seem like a scandal.
The "oh, but everyone is doing it!" argument. I don't for a second believe that other countries install spyware on foreign diplomats and other peoples phones. What NSO and the Israeli government is doing is rotten to the core and unless you have evidence of the contrary you cannot assert that other actors are doing the same thing.
I know you're joking but for anyone that's not in on the joke:
https://www.bbc.com/news/world-europe-24690055
Wow! You found one instance of the US spying on a friendly government. That totally justifies NSO leasing spyware to authoritarian third world regimes! Carry on folks, nothing to see here.
It doesn't justify it, but if we're going to take a stance against spyware, we have to take a stance against all spyware. That includes the home-rolled stuff that the NSA pushes out to Apple and Google.
No, we don’t.
What makes that kind of hypocrisy okay?
It seems if Israel is receiving money from the US government and Israel controls the usage of NSO group weapons that are being targeted at the American government then there are problems yea?
Politics is not about fairness or the truth, it all about getting people to buy the ideas your selling.
Dude, the "state department" is blaming Israel because they're just embarassed your guys got owned by Uganda.
Totally agree. There is a difference still between totalitarian countries against its own people with no theoretical way out even, vs USA that still have some way out.
Wait, you were actually being serious? How about this one: https://www.theguardian.com/world/us-embassy-cables-document... / https://en.wikipedia.org/wiki/Spying_on_United_Nations_leade...
Please state which of these examples involve spyware or cut the snark.
Do you think they asked UN dignitaries nicely for their passwords?
Kind of? It seems like the main use case isn't a country that needs the tools of state-on-state spying; it's a country that needs the tools of Chinese-style domestic surveillance of the political opposition. In most cases where US persons have been targeted with NSO software, it's as part of operations against domestic dissidents, including in this case, where most of the usage was against Ugandan protesters.
If you are a state, NSO is what you get when you don't have Stingrays, PRISM, and a pipeline into domestic enforcement for paralell construction. Imo, in this specific case, it's equivalent.
This is a typical "shadow government" symptom. You have forces working within the government that 1) have their own agendas; 2) have connection to international communities, usually military-intelligence ones; 3) have almost zero regulation; 4) even many high ranking government officials don't know about them because they are brotherhood-like closed circles.
This reminds me of Operation Gladio or Propaganda Due but domestic. Same playbook, different players.
What would shadow government regulation look like?
Maybe stop funding them, for a start?
Congressional oversight used to be a thing.
Snowden showed the NSA lied to congress. No heads rolled.
Imagine all the dirt the NSA has on congress.
Imagine how much society would improve if all the dirt got aired.
Hiding this information is trading the wellbeing of the country for the NSA's own internal goals and power.
Depends on the dirt. Some of it might be private and personal stuff, such as infidelity. That type of stuff, while blackmailable, doesn't really benefit the public much.
The public's elected representatives being easily blackmailable is obviously of great concern to the public, I don't know why you're downplaying this.
Everyone has dirty laundry they would prefer not be aired, and if they don't then their friends, family, or partners do. I don't think we want to live in a world where absolute moral purity (as determined by the most vocal, biased critics of a given person) is required to hold public office.
Don't believe representatives are elected because of their integrity and their willingness to serve.
They represent groups of interest. And being blackmailable is, in my opinion, a handy leash to keep them in check, for those groups which propose the candidates
The public is not concerned with corruption until they feel affected by it.
Sure it does. There is no longer leverage of whoever is holding that blackmail, who may easily have interests opposite the public.
The problem is that the existence of the secret and its power over the subject, not the actual content of it.
Making it public benefits the public just because it’s no longer a secret.
Dangerously based and you’re-about-to-commit-suicide-with-two-gunshots-to-the-head pilled
remember when the cia interfered with the congressional investigation of their torture program, by getting the FBI to investigate senators for viewing the documents that the CIA provided them, and spying on the senate investigation activities, and then nothing happened
https://www.cnn.com/2014/03/18/politics/cia-senate-dispute-f...
https://www.reuters.com/article/us-cia-senate-idUSKBN0KN2Q82...
I do remember that one. I can't believe they got away with it with zero consequences.
Yes, I remember! But I just got up to 2011 on my todo list and am playing through Borderlands 2. I'll follow up on 2014 matters which will hopefully take less than 3 more years.
I can believe there are shadow organizations that lack oversight. In fact, it seems likely.
But that these shadow organizations are maintaining power by surveiling and blackmailing congress people is a whole other ballgame and seems highly unlikely to me.
For one, it's likely that not every Congressperson has some deep dark secret that makes them blackmail-able. And pissing off the only group of people that could cut your funding and expose your shadow organization as well as bring oversight is not the group that you want to be pissing off.
I think game theory would indicate that your only chance of maintaining a shadow organization in the US gov for any length of time is going to be secrecy and maybe some heavily funded lobbying.
I'd be more than willing to bet that they do. "If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him." and that only covers "honest" men who wouldn't have illegal coordination with PACs, bribes with lobbyists, personal communications filled with racism, or evidence of sexual activities that might upset their base. When "6 lines" becomes a record of everything you've ever done online, all of your communications, your GPS coordinates and the data of anyone around you it's going to get easier to find a noose around your neck.
Even if there managed to exist a single person in congress who wasn't screwing over the American people somehow for personal gain, or didn't have some skeleton in their closet they didn't want exposed to voters/campaign contributors when a group is capable of compromising your system and inserting whatever offensive material they want to use against you it's incentive enough to back off.
You only need the capture the party leadership, they can keep everyone else in line via fundraising initiatives.
Why is it so hard to believe that a few powerful indivisuals at the top, with common interests and agendas, are banded together?
There's no official organization but a few indivisuals that streer things their way because they can.
I think there are enough hornery (and incidentally patriotic) congresspeople that they'd be okay exposing the CIA for blackmail even at the expense of exposing the secret.
The funny thing is that the worst of it is already exposed, and no-one seems to care. money-in-politics, the most serious problem of our time, is a "meh" issue to most folks, even though money poisons discourse on literally every other issues! And we know the precise mechanism and how to stop it (a law overturning Citizens United), and yet we do nothing.
Politics is a funny business. I have spent alot of time dealing with political people ranging from staffers to actual officials.
Many are very well meaning public servants, others careerists, some are… insane on various scales. Politics is a business with uncertain outcomes where “friends” are important and personal stakes are high.
From a blackmail perspective, you have people like the bartender turned member of congress who got their GED to run who are obvious puppets with a wheelbarrow of odious behavior behind them. But even the most boring congressman has a legal escrow account with irregularities, a kid with emotional problems that caused trouble, a campaign finance violation, etc.
I don’t think there is a shadow cabal, but some executive branch entities wield tremendous power.
AOC is an obvious puppet?
Not quite. Different educational dynamic. Polarizing figure for sure, but whomped an old school political machine candidate.
I'd like to visit the Museum of Counterproductivity in the area of your brain that downgraded Bobert from business owner to bartender.
There’s no dishonor in bartending. Failed business owner turned agent provocateur on the other hand…
how would you cut the budget of the CIA for example, an organization that doesn't really answer to anyone but itself ? an organization that can self fund when it wants. Eisenhower, a general called out the so called military industrial complex in a way that befits a prophet
it's likely that not every Congressperson has some deep dark secret that makes them blackmail-able
You don't need to control every congresscritter directly, just to control them by proxy is enough. The nomination committees have a lot of power on who stays and who goes, for example, and so do subcommittee chairs.
There's a long history of illegal domestic surveillance since at least the 1940s - why would it have stopped?
Secret blackmail files worked for J. Edgar Hoover[0].
[0] https://www.thedailybeast.com/fbi-director-hoovers-dirty-fil...
Well, if blackmail won't do the trick, there is always extortion…
Why would heads roll?
Congress has blocked inquiries into their split loyalty as far as them having multiple citizenship in other countries. If you were McDonald's board of directors would you allow someone to be on both the McDonald's board and Wendy's?
Congress isn't personally harmed by a surveillance state unless you consider they may all be being blackmailed but that is another conversation. In fact mass surveillance widens the barrier to new entries into politics as they can use whatever dirty they find and give it to federally funded media mouthpieces.
This week we saw articles of sexual crimes against children being swept under the rug to "protect our country" do we really think that congress would actively pursuit this line of inquiry?
Context: https://www.wsws.org/en/articles/2014/03/07/spyi-m07.html
Isn't it pretty common to sit on the boards of multiple companeis?
I'm all for sorting the problem out, but isn't the reality a little more complex given other countries? Doesn't cutting your intelligence / signals budgets give your "enemies" an advantage? By "enemies" I'm referring predominantly to foreign nation states.
I tried, they sent men with guns to my house when I stopped paying taxes
More light and transparency = less shadows
Enforce our laws would be a good start.
It's difficult, you have to break down those brotherhoods who will fight to death to be "independent". And then you have to find a way to prevent them from spawning again. I don't have any idea how to do it properly.
I'd expect if we lived in the sort of society that would execute the head of the NSA for treason or something similar when the Snowden revelations came out, it would have societally beneficial chilling effect on intelligence organization brazenness.
Unfortunately, it seems intelligence is mostly immune from liability, and lack of consequences lets the rot fester.
Once the system is setup who is in control is going to be irrelevant. I believe the best approach is to educate the citizens so that 1) They follow scientific methods; 2) They are more resistant to advertisement/propaganda; 3) They are keen to corruption and willing to protest.
"1) They follow scientific methods. 2) They are more resistant to advertisement/propaganda; 3) They are keen to corruption and willing to protest."
You are asking way too much of people. "Normal" people can't fulfill any of those 3 requests. Not that they don't want to (most don't), or that they aren't taught to (this is conflicting through life)
They can't. #1 and #2 sound like something an autist would tend to do.
The types of societies that execute high level civil servants don't actually execute them for the reason given - the reason is an excuse for the masses, the real reason is they fell out of power or were a threat to someone important.
Implying that Israeli spying on the US is some fringe "shadow government" sub-group of the Israeli government is strange given a long, long history of high profile Israeli spying incidents against the US.
https://en.wikipedia.org/wiki/Lawrence_Franklin_espionage_sc...
https://en.wikipedia.org/wiki/Jonathan_Pollard
https://en.wikipedia.org/wiki/Ben-Ami_Kadish
https://en.wikipedia.org/wiki/Jack_Parsons_(rocket_engineer)
Then there's the time they stole nuclear material from us https://en.wikipedia.org/wiki/The_Apollo_Affair
Then there's the time they slaughtered several dozen US navy and NSA personnel with repeated attacks on an unarmed vessel because they didn't like that we were watching them: https://en.wikipedia.org/wiki/USS_Liberty_incident
By saying "shadow government" I mean groups within the US government that has connection to say NOS.
Again I don't have concrete proofs so I could be 100% wrong. But reading world history especially cold war history makes me be sceptical to certain things.
Hilarious that anyone thought you were talking about an Israeli shadow government.
So you are making blind accusations when there is a better explanation, i.e., it was the Israelis.
The USS Liberty incident happened 52 years ago.
That is the American conspiracy theorist interpretation of the incident that (understandably) also gained traction among a few of the survivors. The Israelis disagree.
It was most likely a case of mistaken identity. Just like friendly fire incidents. Friendly fire incidents happen all the time, including between US forces in the recent Iraq and Afghanistan conflict.
The survivors said that the pilots were waving at them before they carried out the attack
can you provide the source?
Have you tried to look and had no luck?
Its the obligation of the person making the claim to provide a source (or other evidence), not the other way around.
The quote "I was actually able to wave to the co-pilot, a fellow on the right-hand side of the plane. He waved back, and actually smiled at me" is attributed to Larry Weaver, a crewmember on the Liberty. It was allegedly originally written in a book called "Assault on the Liberty" by James M. Ennes, but I ordered a copy to confirm
The Liberty was also very far from where the Americans had told the Israelis where it would be. Finding the ship there was unexpected and calls to confirm its identity were not being answered.
https://archive.md/KNYBR/again?url=https://www.haaretz.com/u...
That’s apparently a “story” recounted by a former ambassador?
On a related note, JFK was trying to shut down Israel's nuclear weapons program in the months before his murder.
https://www.jewishvirtuallibrary.org/kennedy-letter-to-ben-g...
I'm sure he was conducting a lot of international policy initiatives in the months before his assassination
Yeah, like (secret) detente with Fidel Castro [1].
[1] - https://nsarchive2.gwu.edu/NSAEBB/NSAEBB103/index.htm
Why would the tail wag the dog? America benefits so much from all the R&D (in e.g. encryption) that can't happen on US soil. They are not our enemy in any way :)
https://en.wikipedia.org/wiki/Report_to_the_Secretary_on_the...
https://www.nybooks.com/articles/2001/09/20/the-truth-about-...
As far as I know there are few (if any) restrictions on encryption R&D (and even publication) in the US.
What is restricted (due to encryption being classed as a 'munition') is the export of robust encryption products to specific countries.
Broadly speaking, circumventing the export controls wouldn't be in the interest of the US Intelligence Community, unless those products have backdoors or vulnerabilities known to the IC.
The US spies on its European allies all the time, and I'm sure they spy on Israel too, so that's not super surprising.
As for the USS Liberty, some do argue that it was intentional, but both the Israelis and Americans ended up agreeing that it was a mistake. The US is no stranger to such mistakes either, even more egregious ones like when they killed close to 300 civilians aboard a regular passenger flight following an approved route and in contact with ATC (Iran Air 655).
In the end both the US and Israel are amoral states that act only according to their economic and strategic interests and I feel that this unites them. I wish it didn't, though.
And the European allies spy on the USA, rinse and repeat.
I don’t think so. If they do, it is either a) not nearly on they same scale, or they b) are way more competent about it and less likely to get caught.
Given the general incompetence of governments in general (Europe is no exception) I doubt it is (b).
Or (c) announcing this now furthers some unknown usa political goal but there would be no political win for publisizing whatever europe does.
If you can't prove that you probably shouldn't make such unqualified statements. There is plenty of proof for the opposite, afaik none whatsoever for the reverse.
Everyone spies on everyone else.
Reminder that France vacuumed up messages on Enrochat after deploying malware globally, and they have clear text messages from users in any arbitrary country and have not disclosed what they will do with it or what they have.
https://www.vice.com/en/article/3aza95/how-police-took-over-...
The specific claim here is that EU countries spy on the US. I do not believe they have that capability, so if you have some proof that would come in handy.
Just to clarify, you're asking for evidence of secret foreign intelligence operations?
Establishing mere capability is pretty trivial: they have diplomats in the United States who can talk to people.
Aside from capability, the relationship between the US and European countries is so biased towards the US that, politically, I just don't think they'd risk it.
The US spies on everyone because they can, and because they have prepared to do basically anything they think might be in their interests; when Germany discovers the US spying on them, what can they really do about it? Whereas if it was the other way, all hell would break loose.
They officially decided it was a mistake, as it did neither government any good to officially announce that it was intentional. But the sailors that were on the ship say otherwise.
How would the sailors on the ship being attacked be able to know anything like that (e.g. know if the Israeli pilots thought they were attacking an Egyptian ship or an American one)?
The sailors would know because they have access to the same information that you do, but a greater incentive to actually do the reading. The Israeli pilots knew it as a US ship, their radio traffic questioning their attack orders - after visually identifying the USS Liberty as a US ship, was recorded and the transcripts widely known about. This happened several times, so unless the Israeli command center had the memory of a goldfish - they intentionally kept sending attack aircraft until they eventually got a pilot to pull the trigger. Why would they do such a thing? Because the US wasn't onboard with the Israeli preemptive strike and they didn't want a signals intelligence boat tipping off the Egyptians. Israel doesn't appear to reciprocate the fond feelings expressed by American politicians - the mere idea of the "Samson Option" is proof enough of that.
To that point, it's worth noting here friendly fire incidents happen all the time in war, as well as attacks against neutral parties. For instance: the US has bombed its own troops probably more times than anyone can count, and it also bombed the Chinese embassy in Belgrade and shot down an Iranian airliner. Why would they do such things? Honestly, it's plausible they they may actually have had the memory of a goldfish, at least occasionally.
While I'm not aware of any formal study on the matter, I do remember them going over the subject at length in a forward observer course: the blame for the majority of airstrike blue on blue falling on the grunt calling for fire. It matched my experience as well - to the point that I'd avoid calling in close air support for anything short of a Custard's last stand scenario. This isn't anything like that, a command center continuously calling in attack aircraft on a target repeatedly identified as non-hostile - being put on and taken off of the situation board... unprecedented. Even if my opinion of the command staff was so low as to grant them a "well, maybe you are just that dangerously incompetent" - the lying makes that even harder to believe (technically impossible claims wrt speed and offshore shelling capability).
The Israeli government had strong incentive to do this, and accounts on the ship were that this was clearly intentional. Why is this so hard for you to believe?
All states act according to their economic and strategic interests right?
Anyone who doesn't think the USA and Israel don't spy on each other 24/7 is living in a dream world. Israel is an ally but I don't think that they are our friends.
Spying between friendly countries happens all the time. It make diplomacy happen much smoother!
Israel even sinked a US navy ship and got away with it.
It gives you an idea how powerful their lobby is.
NSO should be declared a terrorist organization.
I come from a country which US intelligence has many times been caught spying on its officials as recently as 2009[1]. A more recent scheme involved recruiting a convicted criminal with proven antisocial personality disorder[2] to spy on Julian Assanges friends. This has been known about since the 1960s at least among Icelandic communists and other left wing individuals. But until really recently (like 10 years ago) the government has been very sympathetic to this spying.
For some reason I feel like the US government officials probably share the sentiment of their Icelandic colleagues of old. These immoral activists that obviously step out of line, but the only thing that bothers the US officials is that they got caught. But even then it is not such a big deal.
1: https://www.theguardian.com/technology/2013/nov/19/nsa-surve...
2: https://en.wikipedia.org/wiki/Sigurdur_Thordarson
The parent comment doesn't imply that it was the Israeli government that was doing the spying (and neither does the article), only that Israel delivered the tools. Who's to say this wasn't the CIA keeping tabs on the NSA, or the NSA using foreign tools for plausible deniability?
There is nothing supporting the theory or conclusion
What are you trying to suggest? It's just a typical reflexive reactive response to any comment that the government acts in ways other than presented to you by corporate media.
It only takes 3 minutes of google searches or even a daily scan of Hacker News to see endless examples of government corruption and malfeasance. Government employees are only human after all, and there are millions of them. To think this sort of activity ends once you become an agent of the government is absurd.
This weekend I was traveling and I put the stray $20 from my pocket in the bin at the TSA checkpoint. An agent quickly pulled it out and handed it back to me. He then said "a lot of good people work here, but they're still human". It's kind of wild that we endure that level of complacency here in the States.
That's a pretty weird statement, if one of his colleagues would swipe cash that travelers put in the bins then they should fire their ass and move them to the 'not good people' column. Stealing isn't something that defines you as human.
I think pretty much everyone has stolen something before, right?
That says more about you than it does about humans in general.
True, but what I've done should say a lot about humans in general right? I'm told I'm human, after all.
I don't think he has the power to fire his colleagues. I think that's reading too much into it, for a lot of people 20 is a lot and for a lot of people you just don't trust others with stray cash laying around. It doesn't say much about humans, except that a small portion of people are willing to commit crime and that's why we have to protect ourselves
Trying to suggest nothing, I am explicitly saying there is nothing in the article to lead a reasonable person down the shadow government and deep state path It seems vanilla spying or vanilla state backed industrial espionage
5) many high ranking government officials do nothing about this because they're being blackmailed by the spooks.
Tinfoil hat territory? Sure. Plausible and possible? Sure.
I think it is more likely that 5) many high ranking government officials have sympathetic views with said forces and don’t mind the “occasional incident” as long as said forces are working towards their common goal (whatever that goal might be; but it is probably Islamophobia, settler colonialism and exploitative capitalism).
I won't contest that. I recognize that my post was a bit dramatic but it doesn't seem entirely unreasonable knowing what we do know about past behaviors.
So you can be #5 and I'll be #6 :-)
What happened to the “spooks” that hacked the intelligence oversight committee computers? You know, the people who are supposed to watch them?
I know some spooks called the Church of Scientology.
I seriously have no damn clue what those buggers have gotten up to that they’ve bullied the government into leaving them alone.
That’s a great point. They supposedly “beat” the IRS… which is horrifying.
By that standard, we should post every conspiracy theory ever created.
“Shadow government” = “Deep state”?
They're both somewhat vague phrases that are heavily context-dependent and have somewhat different connotations, but yes.
There's nothing wrong with the phrase "deep state". If you're concerned about associations with Trump (which I think you should not be), you can use a former Obama official's favored term, "the blob". Both, and many other similar phrases, are common in the foreign policy literature.
I think the first time I heard the phrase "shadow government" was in connection to Iran-Contra, where it described Oliver North and the small group in charge or those operations, but it's a phrase with many uses. I can't remember when I first heard of the "deep state", but I'd be fairly certain it was before Trump or anyone connected to him started using it.
Regardless of the terminology, the supposed "deep state" is often a fill-in for one's own personal misunderstanding of institutional momentum and basic functions of the government.
"The Government" isn't really a single institution, but a surprisingly loose collection of various institutions that all have some level of momentum guiding the direction they move in. It's critical to note that these institutions may have interests that harshly conflict with one another. Even the intelligence community, insular as it is, cannot be thought of as a monolith, but as various institutions with various priorities, some which conflict with the interests of other government institutions.
When the government does something we dislike politically, or does something we don't understand, it's "the deep state" or "the shadow government" which betrays a deep misunderstanding of what the government is. There's no central, shadowy cabal controlling the affairs of "the government" from behind the scenes, the various institutions that comprise the government maintain momentum and do what is in furtherance of their particular interests.
You’re projecting your own interpretation of “deep state” onto a straw man and then tearing it down.
J. Edgar Hoover was a perfect example of what people are talking about with the deep state. You can claim that’s just “institutional inertia”, but it’s still some unelected official with massive power wielding it in nefarious ways.
Ghost in the Shell: Stand Alone Complex is one of the few pieces of media that gets this right vis-a-vis conspiracy being conflated with the loosely coupled nature of government whose components are sometimes adversarial even in the face of external threat
"Deep state" is used extremely often to mean something non-centralized, and in a sense, aligned with what you describe as "a surprisingly loose collection of various institutions that all have some level of momentum". The reason it's a useful phrase is that much of that momentum was built in completely undemocratic and unaccountable ways, by groups that are illegitimately secretive and deceptive in their activities, and who feel free to use extreme means such as torture and terrorism.
It's a very imprecise term covering bureaucratic norms and blindspots, to unsanctioned domestic and international terrorism, so it's not really useful except as shorthand with ideological bedfellows, so-to-speak, and you're right that it's often used to mean "the government guys I don't like but am too lazy/ill-informed to describe". But OP mentioned Gladio -- I think that's context enough for this thread. Do some reading on the topic (beyond Wikipedia) if you haven't already, and you might get a sense of what this non-centralized deep state can do.
And I didn't make it clear, but I brought up the North et al "shadow government" as an example far on the small-scale end of the spectrum of meaning of "deep state/shadow government". It _was_ a centralized shadowy cabal doing a now-documented conspiracy. People argue about how much authority they "seized" and how much was delegated by Reagan (and how much capacity he had to delegate much of anything), but regardless, it was not democratic to illegal go around Congress. What I've described as the "deep state" is the more common usage, and it's on the "amorphous, non-centralized, competing institutions, largely free of any democratic accountability" end.
To me, 'deep state' implies an illegal conspiracy against democracy. 'The blob' is a large organization that is hard to change, which describes every such organization. Ask an executive at a Fortune 500 company about blobs. The executive branch has the added complication that the CEO has limited powers and doesn't make the rules, Congress does. At work, you follow the boss's instructions. In the executive branch, you follow the Constitution first, then the laws made by the American people via Congress (accumulated over centuries), then the President's instructions - including instructions of prior presidents that haven't been changed.
Maybe 'deep state' was used before Trump, but the meaning has changed.
This is a very new, post-Trump/QAnon interpretation. The “deep state” has, for at least many decades prior, meant those aspects of government which persist from administration to administration, largely unaffected by those in power. E.g. the CIA keeps doing its thing regardless of whether a Democrat or Republican is in office.
Now in as much as these aspects of government are controlled by unelected officials who are willing to work against the elected representatives (think: J Edgar Hoover), that constitutes a shadow government.
If you can operate without democratic control and do things that would be illegal for anyone else to do, are you an "illegal conspiracy against democracy"? I think every intelligent US president since Eisenhower (which makes sense, as the relevant institutions largely came into being after WW2) has recognized that such a thing exists, with varying degrees of openness (Eisenhower), paranoia (Nixon), and glee (HW Bush).
Yes, basically a state organization that the public has no control over it and is following its own goals, often against the goals of organizations under the control of the public.
It's often taught in political classes and it isn't a conspiracy that there exists a "deep state" or "shadow goverment".
For example, the roman elite troop, the Praetorian Guards, can be classified as a "deep state", as they had their own goals and if they were not meet, then they would just kill the emperor. At the same time, the emporer and the senat had almost no control over the Praetorian Guard.
Pretty much. Not sure why the terminology changed between the Bush years and the Trump administration.
No.
Israel has zero interest in spying on random embassy employees in Uganda who are working with protesters there. This is purely mercenary stuff, and the US is annoyed that a podunk nowhere country got its hands on first-rate tools.
"Hello, dog!" Said tail
NSA backdoors the peg spyware and Apple believes State Department has been hacked when in reality the information return has been manipulated. State Actors believe the information they received is legit, when it’s actually what the US wants them to see. This is common knowledge that CIA had hands into the development of Pegasus. The media hasn’t been able to keep up yet.
Sanction them then. The US has sanctioned companies for much less.
They did.
"A State Department spokesperson declined to comment on the intrusions, instead pointing to the Commerce Department's recent decision to place the Israeli company on an entity list, making it harder for U.S. companies to do business with them.
NSO Group and another spyware firm were "added to the Entity List based on a determination that they developed and supplied spyware to foreign governments that used this tool to maliciously target government officials, journalists, businesspeople, activists, academics, and embassy workers," the Commerce Department said in an announcement last month."
Now it's going to be really funny if later on we find out that that company was funded with Israeli state money that came from the US
Is anyone working on a microkernel design for privacy-sensitive devices (like phones) that would prevent outright this class of kernel-level arbitrary code execution exploits? We're stuck with iOS and Android for the foreseeable future, but is there hope that we'll get this right some day?
Actually, would a microkernel design even be sufficient? Given that hackers exploit deserialization, memory safety, and variable type confusion issues, there's still plenty of avenues for data corruption and data leakage.
Many of the kernel issues exploited in iOS are caused indirectly by its microkernel architecture, namely, the use of "ports" for kernel to kernel and kernel to user land IPC. For example: https://bugs.chromium.org/p/project-zero/issues/detail?id=21... .
Microkernel vs monolithic kernel has little to do with this, IMO. The main issues are asynchronous complexity and memory safety.
Also, a lot of your most sensitive data lives in userland. If someone gets access to the iMessage sandbox and the message database files, that's your most sensitive and privileged data gone, no kernel touched.
And the userland is the worst possible combination of technology imaginable for this purpose - a memory unsafe language with a ton of magic dynamic features. You get the horrible serialization issues from Java & Ruby with the same old heap, stack and integer overflows we've come to love in C and mix in some of the runtime control flow from C++.
Perhaps something like this: https://www.crowdsupply.com/sutajio-kosagi/precursor.
Or, just use Linux on the smartphone and harden it with a smartcard (Librem 5).
Google is, with Fuchsia: https://fuchsia.dev
What are they doing?
The "marketing fluff" is here [0]. From my understanding, the relatively novel things they're doing at the lowest levels are making it a microkernel, and using a capability-based security model [1].
The former decreases the Ring 0 attack surface, and the latter makes it challenging to cause a confused deputy problem -- you know, the ol' classic "whoops this daemon running as root accidentally allowed a browser tab to read /etc/shadow." Or the time honored problem of a single exploit in one process giving access to all files (and in some cases, all processes' memory and resources) controlled by a given user. Capabilities also make it relatively easy to sandbox userspace code, and to reason about what it has access to. Kinda like containers, but as a core concept rather than tacked on a few decades into development.
Now these concepts aren't new, but they haven't been deployed or supported at the scale Fuchsia may end up at. Which obviously makes it a pretty exciting project in terms of real-world impact. That said, I believe there's been some speculation that part of the motivation for Fuchsia is to avoid the mess that is out-of-tree drivers on Android. So on the one hand, the kernel can be updated more easily, but on the other hand there may in practice be a lot more unpatchable binary blobs floating around doing important things.
For a more academic project that has many of the same security concepts there's seL4 [2], which has the additional bonus of doing some insanely clever formal verification of the kernelspace code [3]. They have formal proofs that the compiled machine code actually implements the specified of the security model correctly, which is the first of its kind AFAIK. They actually have a set of interactive tutorials for the platform [4], which are a great way to get a feel for how userspace works on a security-focused kernel.
As a disclaimer, I'm not associated with either project, and I'm sure my explanations will be ripped to shreds. My information comes purely from following the space in my free time.
0: https://fuchsia.dev/fuchsia-src/concepts/principles/secure
1: https://en.wikipedia.org/wiki/Capability-based_security
2: https://sel4.systems/
3: https://sel4.systems/Info/FAQ/proof.pml
4: https://docs.sel4.systems/Tutorials/
User-space ACE would still be enough to do something like this. All sorts of user-space apps have the relevant permissions and are not secured against attacks to the necessary extent to stop a state level actor.
I'm not convinced microkernels are the answwr but we do have QubesOS.
Yep, a number of people are, myself included. OSDev channels have a few people who talk about it. The Fuchsia folks are around, too, and are quite friendly people. They probably have the most hopeful chance of a widespread release, though admittedly I worry about the affiliation with Google getting in the way of pro-consumerism. Just my opinion though.
I wonder if some combination of Fuchsia, Titan, and Tensor would be sufficient to mitigate a baseband processor vulnerability.
Probably not. Processor vulnerabilities have the perpensity to affect most OSes because they're often pretty fundamental flaws in the basic CPU security mechanisms when discovered.
If I wasn't clear, I'm asking about vulnerabilities in the baseband processor (BBP), not the CPU.
The BBP is what makes a smartphone a phone, rather than a small tablet:
https://en.m.wikipedia.org/wiki/Baseband_processor
The thing about the BBP is that it is a second computer running its own proprietary OS (typically an RTOS) to handle the RF modem. The phone's main OS typically has no visibility into that second computer, even as root, but the reverse may not be true.
So I was wondering if any of Google's efforts to increase security can mitigate attacks that might come through this particular channel that lurks, Kuato like, just out of sight.
Apple mitigates baseband processor vulnerabilities by putting it behind what's essentially an IOMMU.
I must be missing something. I don't understand how that's supposed to help.
On other phones the baseband has full control of the AP because it can read and write to all of its physical RAM. With an IOMMU a compromised baseband can only control things inside its small view, rather than completely compromise everything running on your phone.
But doesn't the IOMMU itself become additional attack surface for compromising the kernel? At least, I've seen it suggested that the tradeoff to gain a bit of defense-in-depth isn't necessarily worth it.
Not having an IOMMU=baseband can access all of the AP's memory.
Having an IOMMU=baseband can only access a small section of memory marked for it, ideally.
Obviously, it's worth implementing this: it turns a baseband compromise from "instant game over" to "might be a problem, but the IOMMU needs to have been set up incorrectly or the code that deals with it needs to have a serious vulnerability".
The Intel ME runs a microkernel but it is still exploitable (even if you "clean" it).
SEL4 and Fuchsia seem to have a security focus, but whether that results in real world difficult to exploit devices is unclear.
I'm not aware of any microkernels for phones (I'm not sure that would help either), but Android has been sandboxing more and more processing [1] and started using some Rust at the system level [2] ever since the stagefright bug [3].
1: https://android-developers.googleblog.com/2019/05/queue-hard...
2: https://security.googleblog.com/2021/04/rust-in-android-plat...
3: https://en.wikipedia.org/wiki/Stagefright_(bug)
Though currently Android-based, grapheneos is planning to move towards a microkernel + virtualisation model eventually. I'd imagine this is several years away at least, though.
https://grapheneos.org/faq#roadmap
There's also sel4, a security focused version of the l4 microkernel which is apparently one of the only formally verified kernels.
https://sel4.systems/About/
Here you go. Phone based on a high robustness microkernel.
https://hoyosintegrity.com/products-2/hoyos-phone-2/
I don't know why anyone would even bother to suggest such a thing when there's a second, completely-independent, unobservable computer running on every phone, with ring -1 access. Until we get rid of those, phones will continue to be the IDEAL surveillance tool for state-level actors. It's like the old saying about security: If you have access to the hardware, all bets are off. In our phones, the cell companies already have hardware-level access. It's almost like the government had a hand in developing the cell phone technology stack to make it so easy to use in this capacity... (Seriously, they did, but I don't want to go down the rabbit hole of finding links.)
Well, that wasn't predictable at all.
In all seriousness, I hope this finally prompts our agencies to push for stronger security and better encryption rather than fighting it as they have for so long.
This was entirely predictable.
I have credit card data information + MSR HID + but i dont know how to read or do the code metric etc in order to retrieve track 1 or 2
TlDr. Weapons designed to use against baddies can also be used against goodies
Wow, Israeli's spying on their main sponsor?? Espionage is part of the political territory but hopefully this sets precedent to a change of optics. (Which probably not since Russia does it boldly for fun at this point).
Nobody claimed in the article that this is a case of Israel spying on the US. That would be quite a jump.
But it’s only one or two steps removed = Israeli company, acting with the approval and protection of the Israeli state, enabled and facilitated spying on the US by a third party.
The world is only one or two steps removed. Israel is acting under the approval and protection of the US ==> US was spying on itself /s
There's a big, big difference between acting against your ally, and irresponsibly proliferating technology that's used against them. cf. France's Exocet sales and the Falklands, though much lower impact this time.
I would not be surprised if it's an Israeli company behind using NSO to steal it.
There's Lusha too and it's stealing info in plain sight. It's basically stealing information and completely violating any GDPR or Californian law. Here is a good spiel of the whole thing tying their founder to all the apps that steal information: https://wwws.nightwatchcybersecurity.com/2020/02/20/another-...
And they just raised $200M to continue spying. The investors probably have no clue https://techcrunch.com/2021/11/10/lusha-a-crowdsourced-data-...
If we don't penalize crap like this, you encourage. And then it booms somewhere else.
Holy shit! How's Simple Apps stuff not shutdown by GDPR? Either Simpler App is lying (thus GDPR kicks in) or Lusha. This is insane
why are they just targeting the israeli firm?
If this was a Russian/Iranian/Chinese company, we'd already have a news conference by the US DoS, declaring sanctions, freezing assets, and calling for an international coalition to contain the rogue state that's threatening world peace.
But this is a Israeli company, so it's just another "scandal" that scrolls trough the news feed, it will be forgotten by next week, to be completely memory holed by next year.
Can you explain why that is for us who aren’t well versed in geopolitical issues.
Israel is an ally of the United States.
Many in power even go so far as to refer to Israel as the US's "greatest ally".
https://zeldin.house.gov/media-center/press-releases/standin...
https://www.toomey.senate.gov/about/issues/israel-and-the-mi...
https://www.state.gov/u-s-relations-with-israel/
"Ally" is probably too weak a word for the relationship we have with Israel. Probably no other country has this much influence on our politics. Not even the UK or Canada, who we share close cultural and linguistic bonds with.
Israel is like the Taiwan of the Middle East, meaning it's a useful partner to us in terms of maintaining a separation between the West and some perceived enemy (Muslims in this case, the Chinese in the case of Taiwan). But they also cause us to have more enemies than we otherwise would. In an open letter, Bin Laden specifically called out our support for Israel as one of their justifications behind 9/11.
Spying between allies is a relatively normal thing, but when someone screws up and lets the public see it happen, usually there is at least some mild chiding. Israel doesn't even get that tsk tsk because of how much influence they have.
Also, Israel has a very effective propaganda machine that purposely tries to paint any criticism of Israeli policy as anti-semitism. It's hard for our politicians to openly discuss them without risking their ire, and that of many influential Jewish Americans, and the powerful AIPAC lobby.
Frankly, Israel has us by the balls. Less an ally and more a dominatrix.
The word is "client"; it's just people are used to using it with applying to the other side of a relation with the US, not the US side.
The Taiwan analogy is pretty flawed here.
Is 'separation' a euphemism for 'preventing invasion'? Because threat of that is #1 thing keeping cross-strait relations tense. Mainland China could easily offer Taiwan a better deal than they get by being closely aligned with the US. Their reluctance to do so keeps US influence in the region, and after a while one can't help if it's deliberate.
Also Israel gets a much better deal than Taiwan. The US gives military aid to Israel, where as Taiwan has to petition the US government - their only significant supplier - for the right to even buy weapons. Better hardware too, despite Israels poor track record in passing US military tech to China.
I don't quite follow. Are you saying China purposely gives Taiwan a raw deal just to deliberately spite the US? Why would they do that? I think I'm misunderstanding you.
Yeah, for sure. But our support of both countries (and others like them) pisses other countries off. IMO we have no business being either world police or world arms market, especially in some of the most volatile quagmires in the world. We make our own enemies because of our supposed friends. These places only have strategic value to us so long as we desire to remain the global hegemon, with tentacles everywhere. Let go of that weird military-industrial-hentai complex, and there's no reason for us to artificially prop up these countries. Especially Israel. The IDF can more than take care of themselves. Taiwan is going to fall sooner or later anyway, but why is that our business? We force our enemies to go on eternal arms races against us because we've shown them we're incapable of minding our own business after WW2. It should not be our responsibility to provide world security using our people, our equipment, our money.
I don't quite follow. Are you saying China purposely gives Taiwan a raw deal just to deliberately spite the US? Why would they do that? I think I'm misunderstanding you.
I mean the whole situation is incredibly contrived. The 'sacred chinese territory' narrative feels completely hollow if you consider how long ago they stopped claiming other Qing dynasty possessions like Mongolia. My guess is that it serves a domestic narrative, and that they've backed themselves into a corner by staking their core legitimacy on annexing Taiwan for so long.
So yes, by offering Taiwan a better deal than they get from the US, they could remove a lot of influence from the region. But it never happens.
Yeah, for sure. But our support of both countries (and others like them) pisses other countries off. IMO we have no business being either world police or world arms market, especially in some of the most volatile quagmires in the world. We make our own enemies because of our supposed friends. These places only have strategic value to us so long as we desire to remain the global hegemon, with tentacles everywhere. Let go of that weird military-industrial-hentai complex, and there's no reason for us to artificially prop up these countries. Especially Israel. The IDF can more than take care of themselves. Taiwan is going to fall sooner or later anyway, but why is that our business? We force our enemies to go on eternal arms races against us because we've shown them we're incapable of minding our own business after WW2. It should not be our responsibility to provide world security using our people, our equipment, our money.
The US withdrawing from East Asia would be a global disaster. This wouldn't be a small land skirmish, it would be a massive amphibious invasion in Japans backyard - which knows it's southern territories would be next on the menu. It would also take place in one of the busiest shipping routes in the world, causing a massive disruption of global trade. Not to mention the semi conductor angle, now abandoned US allies pursuing their own nuclear weapons agendas.. etc etc.
You could argue the US should not have been interfering there in the first place. Which is very principled and all, but the USSR was going to be there either way. And now the US is very much the force in that region keeping war from breaking out. Arming South Korea, Taiwan and Japan does not make these places more volatile. It makes them much, much less.
I doubt this is actually as much a cultural issue for the CCP as it was for past emperors. They've long since abandoned that model and instead observed/emulated the successes and failures of the West, including our love of creating enslaved vassal states under the guise of nation-building. Long game, they probably want Taiwan to become another Hong Kong or Tibet. Short term, Taiwan is a useful bargaining chip for them to focus American attention towards, and the mere threat of war there can back the US into our corner while China focuses on domestic infrastructure and continues to leapfrog us across the sectors and years. Never interrupt your enemy while they're making a mistake, etc. China knows they'll win by default while we blindly obsess over our colonies, and if they really need to (unlikely), it's a lot cheaper to sink a carrier group than to build and maintain one.
IMO we're their ultimate target, not Taiwan in and of itself. It's like an abusive, manipulative spouse using a kid as collateral against the other parent (us). Once the other parent is taken care of, they're free to do with the kid as they please.
Sorry, by who? Are you saying South Korea will invade Japan if we pull out...? How?
And why is that our problem to solve?
So, kinda like Covid? Eh, fewer Xboxes and new cars for a few years, global GDP repressed for a bit. The world will survive and move on and adapt.
As for nuclear weapons agendas, the US is still the only one to have used them, and still one of the most imperialist countries in the modern era, and the one who tends to create the biggest enemies out of our misadventures. South Korea and Japan and Taiwan aren't going to nuke each other, even if there's historical animosity there. Maybe the Koreas themselves will break out into war, but that was probably an inevitability anyway, unless the removal of US attention and sanctions allows NK to grow and transform.
So let China take over that role for that region of the globe. Let a resurgent Russia have its piece of the pie. Maybe it's time for US power to wane.
This makes no sense. With US involvement, Taiwan and South Korea become proxy wars with China. Without us, they become regional conflicts affecting a few million people, not WW3.
The comparison is also flawed in that Korea at least makes cheap and good stuff.
Israel should learn that lesson. The way to American hearts is through our phones! Worked for Nokia and Samsung.
I think they lack talent to really do it competitively. Korea has crazy amounts of cheap talent!
Israel is a US ally
Can I ask what your name means? I thought this was a troll account at first glance from the topic matter and your alias but you look like an earnest poster, hence my confusion.
Israel is a third rail in US politics.
One significant faction of the GOP is millenarian evangelical Christians who (a) believe the Israeli state is a necessary precursor to armageddon and (b) have spent the past 2 decades trying to conflate “Muslim” with “terrorist”.
The Democratic party includes as part of its coalition many American Jews who, despite frustration with the human rights abuses of the Israeli government, feel a strong connection with Israel as a symbolic homeland and are worried that criticism of Israel will lead to broader antisemitism.
The US intelligence/defense establishment has strong ties to Israel, the US shares intelligence with Israel, and US firms make a lot of money selling weapons to Israel (a substantial part bought with US tax money). Israel has been the largest recipient of U.S. foreign aid since World War II.
wow, even if you are a proud tinfoil hat wearer you should learn a way to explain your positions in a factual provable way without any attempts to read anyone's minds or guess anyone's motivations
that would be much more effective
this angle seems really out dated. the us alliance with israel is not about religious reasons.
israel is the one democratic state in a region that mostly has our enemies. israel is a military power. we have strategic interests in maintaining the middle east political bloc
imagine if this headline read france instead. we would react similarly
This is simply not true. The base of the US Republican Party is evangelical Christians. This being so, religious reasons are close to the surface. There are surely other interested parties, but Republicans can't get crosswise with any of their conservative Christian constituencies -- evangelicals, Catholics, and Mormons. These constituencies have particular beliefs about Israel and the End Times. Likud and other right wing allies of the evangelicals certainly knows this and don't particularly care, not themselves caring about Christian End Times. I'm sure the leadership of the Republican Party also doesn't care. But they need their foot soldiers, and these soldiers do care.
It is also true that while there are a lot of liberal Jews who criticize Israel, like Noam Chomsky, there is a large block with a lot of sway in Democratic politics that are very leery of criticism of Israel veering into antisemitism.
This is terribly jumbled. Yes, if you’re in a non-Islamic religion that reveres the Old Testament, you probably support Israel’s land claims.
But Catholics, Mormons, and Evangelicals have wildly different views of the end times, and the “Bring in the Armageddon” crowd in particular is an outlier among evangelicals.
Being an outlier still does not stop them from wielding over-proportional political influence compared to other Christian sub-currents, and particularly other religions.
To add data to that degree; In the US such well-organized and rich elite interests are very much the de-facto policy makers [0].
[0] https://www.cambridge.org/core/journals/perspectives-on-poli...
Yes, I shouldn't have mentioned Catholics and Mormons. The official bit of dogma the conservative Catholics care about is abortion. I'm not sure what the Mormons care about. But I don't think dogma is more than rationalization for most of these foot soldiers. They have this in common with conservative Muslims, Hindus, Jews, animists, and atheists. They want the people they approve of to dominate people they disapprove of. The rationale comes after and cleans up the mess. They learn about the approved hierarchy of power from their leaders and community. And in the US the word has come down from the elect that Israel, or right wing Israel, is their ally. Millenarian theology is just window dressing. Netanyahu mocks Obama before the US Congress so he's their man. It didn't begin with Netanyahu, but he knew how to ride the wave. This is why the Right in the US could turn on a dime and start loving Putin: he hated the same people they did. Dogma is just window dressing, a pretty screen over an ugly truth.
Speaking of France and geopolitics, it's worth noting you see similar consistent support for Israel from most of the other major NATO powers. And France's position on Israel is not due to conservative evangelical political influence domestically.
It's not outdated at all, Trump's presidency was a direct throw-back to Dubya times [0] that whole thing with Muslim bans and getting treated like some kind of Messiah by evangelicals [1].
These very same US evangelical currents are also super tight with Israel, because they think Armageddon is gonna happen there and that needs to happen for Christ's return and heaven on earth [2].
These people are a end-world cult, one that has by now had direct influence on at least two US presidents in recent history. One of which they pushed into declaring a literal "crusade" [3] complete with "holy warriors" [4].
In the early 2000s there were a bunch of "scandals" about them infiltrating the US military to further Christianize it [5], even in the 2010s there's been incidents with US government acquired rifle sights featuring secret bibles codes [6].
[0] https://www.theguardian.com/world/2005/oct/07/iraq.usa
[1] https://media-cldnry.s-nbcnews.com/image/upload/newscms/2017...
[2] https://youtu.be/Fo77sTGpngQ
[3] https://www.csmonitor.com/2001/0919/p12s2-woeu.html
[4] http://articles.latimes.com/2003/oct/16/opinion/oe-arkin16
[5] https://harpers.org/archive/2009/05/jesus-killed-mohammed/
[6] https://abcnews.go.com/Blotter/us-military-weapons-inscribed...
The whole point of your comment is wrong. Israel may be considered a democracy, but only for the so-called "chosen people"; This so-called democracy which is based on racial purity and militarism is in fact a form of fascism, and not a democracy in any way. And the main reason for some of the countries in the middle east to become enemies of the US is the blind support of US for the Israel to occupy the land of Palestine and commit war crimes. Occupying other people's land, torturing and killing them, and then claiming to be a democracy is quite laughable claim by Israelis.
right, like was South Africa a democracy during apartheid?
Is America not a democracy because Canadian citizens and Mexican citizens that aren't also American citizens can't vote in elections?
Arguably, yes. Or at least USA are lacking in universal suffrage while they don’t allow long time residents to vote because they lack citizenship.
This is actually a fault in quite a lot of western democracies but USA is actually worse at this the the average democracy. Contrary to most European democracies, foreign citizens are not even allowed to vote in primaries or local elections in the USA.
Off course USA has more problems with how they grant voting rights the just the lack of rights to vote for foreigners, this includes prisoners in many states, but also access to voting and voting registration, as well as disproportionate representation from election outcomes which reflects actual ballot counts poorly. All of this adds to make the USA a rather lacking in democracy.
You bring up some reasonable points.
Argue the case. If you just did, it’s not a convincing one.
First, note I didn’t say long term residents of America. Just Canadian or Mexican citizens in general (be they long term residents of the US or not).
You may say it’s different. Maybe. Then just talk about those that aren’t long term residents.
The point here is equally true of citizens of Armenia, Vietnam, anywhere else (and I would say those that reside in America long term, or not) that aren’t US citizens. If they can’t vote in US elections, how can we consider the US a democracy?
Is democracy a binary? If so, is America one, or not one? At least is it closer to being one, or not being one?
Is democracy a spectrum? If so, where is America on the spectrum? Close to pure perfect democracy, or on the opposite end, close to the complete opposite of that? Or somewhere in the middle? You say its lacking. Where is that on the spectrum? What other countries are near it?
These types of discussion often happen around abstract, nebulous concepts like democracy, justice, good. Generally when they aren’t defined well by any participants.
If your point is the US could be more of a democracy, maybe. But even more so, it could be much less of one.
There is also the matter of "the one democratic state in a region" being BS, or incredibly disingenuous at best. Even if you don't count Lebanon as a democracy (presumably not counted because Israel and Hezbollah hate each other) there is the matter of America's role in toppling other democratic governments in the region, particularly Iran in 1953. Furthermore, America seems to have no trouble cooperating with other monarchies around the world, so the premise of America only being able to cooperate with democracies is nonsense. What's so heinous about Jordan being a constitutional monarchy? Nothing really, it certainly didn't stop America from defending Kuwait (also a constitutional monarchy) when Iraq invaded.
This is what I gather with some research, though I’m no expert and would appreciate more information if anyone has it.
If Tunisia is “in the region” (depends on the region being discussed), then Tunisia is starting to make the claim that Israel is the only strong democracy in the region false. That being said, Tunisia’s situation isn’t doing much to change the claim that Israel is the most democratic country in the region, and was the only one for many decades.
Lebanon is one of the most democratic countries in the region. It has regular elections - though I can’t tell how free and fair they are. It seems they are but there are accusations of bribes and corruption in Lebanon in general so likely that would spill into elections (see https://www.nytimes.com/2021/10/28/magazine/corruption-leban...). Lebanon has relatively diverse political parties, citizens have entrenched rights, general freedom of speech. Anti-government protests seem somewhat allowed (with some accusations of suppression and some violent response).
That being said, it’s not just animosity between Israel and Hezbollah that lead people to considering it less of a democracy or somewhere less than flawed democracy on the spectrum of democracy into something (though that could play a role). It’s presumably also paramilitary organizations like Hezbollah not being subject to civilian rule. Also that not anyone can be president, or prime minister or president of parliament, due to agreements between groups in Lebanon that help with stability.
America cooperates daily with non-democracies. Did anyone claim that America can only cooperate with countries that are democracies? I could imagine someone arguing convincingly that all else being equal, America would prefer close ties and cooperation with democracies (for various reasons). In practice, all else is rarely equal. You don't always get to partner with those who you feel have the same values (real or aspirational), or are generally looked on favorably by the world. There is lots of realpolitik in geopolitics.
Wasn’t there another democratic country in the region in the early 50’s? Oh yeah, it was Iran, and then the US took that democratic state and deposed it in a coup.
“We have to stand with the only democratic state in the region” loses a lot of rhetorical force when the US topples other democratic states it doesn’t like.
It absolutely is. Israel, without the protection of the evangelical voting block, is essentially apartheid South Africa.
I know this is what the up-vote button is for. But I do want to add a redundant comment appreciating this explanation. It explains this adequately in three short paragraphs.
The second paragraph is worth expanding from a little. As it can be argued that fear of anti-antisemitism among the left is well warranted. A good example of that is Jeremy Corbin constantly being accused of anti-antisemitism for criticizing the state of Israel for their human rights violation in the last UK general election (a tactic that perhaps worked given the lousy performance of the labour party). Even Bernie Sandars—a jew himself with family ties to holocaust survivors—gets smeared for this reason.
Jeremy Corbin did more than just “criticizing the state of Israel for human rights violations” though. This is a politician who, amongst many other things, called Hamas and Hezbollah “my friends”, so clearly his issue with Israel is not about human rights per se.
A 2 minute web search:
https://www.theguardian.com/news/2019/may/01/jeremy-corbyn-r...
"Before becoming Labour leader he called 1902 book containing antisemitic tropes ‘brilliant’.
Jewish leaders have written to Jeremy Corbyn to express “grave concern” and demand an explanation after it emerged he wrote a glowing foreword for a century-old political tract that includes antisemitic tropes."
https://www.theguardian.com/politics/2018/mar/23/corbyn-crit...
"Labour leader offered support on Facebook in 2012 to artist whose work featured antisemitic tropes"
https://www.thejc.com/news/uk/jeremy-corbyn-blamed-zionist-l...
"By the time Mr Corbyn was writing, Mr Salah's comments were well documented..."
It's possible to criticize Israel while not allowing antisemitic bigotry. It's the smart thing to do for someone trying to advance a political cause.
However, if one does it again and again, even on instances not involving Israel at all, people will start to take notice.
This 2 minute web search is flawed. You don’t disprove a smear by a short web search. If there truly is a smear this smear will be included in the results, so your data is biased and proves nothing.
My short web search found a secondary source[1] which debunks some of the claims you have mentioned here by offering a little more context around them. The Wikipedia page about Jeremy Corbyn has a whole section devoted to this[2] and all the claims are either vague or unsubstantiated.
Now I don’t personally know whether Jeremy Corbyn is an anti-Semite (he might very well be), but there is nothing which he has done which indicates for any amount of certainty that he is. The campaign to smear him as one has most certainly succeeded, and his support for Palestine probably in no small is to blame for this.
1: https://www.spectator.co.uk/article/is-jeremy-corbyn-really-...
2: https://en.wikipedia.org/wiki/Jeremy_Corbyn#Allegations_of_a...
The 'debunking' is just noting that the book in question has over 400 pages. Shouldn't we expect a guy writing a glowing foreword to have actually taken the time to read the book he's praising?
As far as I can tell, there's a lot of consistent smoke. Somehow Corbyn is always involved but never ever notices the bad stuff. There was a good basis to be concerned: Whether Corbyn is an antisemite, cynical or just totally oblivious, is not as material when he's running to such a powerful position. An oblivious PM could do some damage still.
Elections are not a court - we have to decide based on probabilities, and most British voters found Corbyn to be more unworthy than Johnson.
There could be a connection. It could be argued that strong opinions on ME conflict led people to ignore things they did not want to see. From Corbyn supposedly not noticing multiple cases of outright bigotry, to some Labour supporters not noticing a pattern with Corbyn.
This point is kind of moot given that, unlike Corbyn, Johnson is on record actually using racist slurs.
There are many groups, including nation states in the Middle East who would like to destroy Israel and the Jewish people. This is not hyperbole, it’s public policy. And it’s not just words, Israel has been attacked repeatedly by countries intent on its destruction.
There are some people inside the US, and outside it, who feel that allowing that to happen would be unacceptable. The western world does not want another holocaust on their conscience.
But the question is, what makes it more unacceptable than the destruction of other countries, countries who also have enemies, who are not such close allies? "Feel that allowing that to happen would be unacceptable" is the loaded phrase that holds all the content in that description. The US is not giving that much military aid to every country that has such enemies.
Arguably, genocide anywhere should be confronted and prevented (though of course it never is, because the compassion of our species is quite limited).
In the modern era, arguably few have suffered as much as the Jews, in large part due to their historic lack of a homeland and safe haven. That's not to excuse modern Israeli policy, and I find it atrocious that they treat Palestine this way especially because they know what it's like on the other side.
But at the end of the day, most countries that "fall" would just be assimilated into their conquering cultures. The fall of Israel would be another Holocaust. I doubt many of their people would survive at all, given the severe hatred much of the world has for them, especially in that region.
I don't think we should be arming Israel, but that's only because they can take care of themselves. Their military is so far and away above their enemies' that they could easily destroy every single country around them if they so chose. We don't need to stay involved there any longer.
It would be really nice if all cross-border hatred was isolated in one theater where it could easily be dealt with, but that's not the case.
One wonders how long it will be until they move on to taking care of their neighbors.
Yeah. I'd vote for naked MMA mud matches between heads of state.
If the Six-Day War was any indication, they have that option any time they choose to exercise it. But it's doubtful they'd ever be able to hold the peace even if they could win the wars that way. Israel didn't survive by being brash and careless... they're not the United States. One mistake and they'd be wiped from the planet, at least until World War 3.
I'm an evangelical Christian myself, and I think I understand why you characterize us this way, but it's not accurate based on what I know.
Along with those I associate with, I support Jews (and to a lesser extent the modern nation of Israel) only because I serve the God who made the sons of Jacob into a nation in the first place. The modern nation of Israel isn't perfect and my support for being their ally isn't unconditional. It also has nothing to do with end-times (except maybe for the fact that they exist as a nation, which is interesting but mostly inconsequential in terms of religion).
In terms of end-times events, the rise of widespread hatred for my religion is a far more reliable indicator of their proximity...
I grew up evangelical. I have heard multiple pastors in multiple congregations explain that the existence of Israel is divine, that god himself was responsible for it existing after X thousands of years and that everything they did was god’s will.
This was all of course necessary for the rapture. For more look up Hal Lindsey’s “Hinge of history”
Israel/AIPAC on the other hand is mostly composed of atheists, who are more than happy to participate in evangelical delusions to keep the money flowing.
Prior to that, during the Cold War Israel was the US ally surrounded by Soviet client states, so opposing the Godless Commies (whether the important part was "Godless" or "Commies" depended on the audience) was also quite popular.
Look up which 2 countries consistently vote to continue enforcing Cold War era sanctions on Cuba.
It’s not purely geopolitical but I think the top 3 factors for this:
1, the most powerful political organization in the US is AIPAC. More powerful than any other lobbyist and can tip the scales in almost any election.
2, the services provided by Israel to support US-backed dictatorships in the Middle East (eg the NSO group)
3, the military industrial complex loves the Israeli customer because they are dependable, repeating customers (Israel has been bombing the Palestinians and its regional neighbors for decades now)
Could you provide a source for AIPAC being the most powerful political organization in the US? That seems surprising given that they spend a fraction of what other lobbying groups do. How is that measured?
From an nytimes article [0] on this topic and lot of anecdotes on fall outs from taking policy positions against israel (not anti-Semitic)
“ Unlike the National Rifle Association, the Human Rights Campaign and other powerful grass-roots advocacy organizations, Aipac, which is bipartisan, does not endorse or raise money for candidates. But its members do, with the organization’s strong encouragement.”
“Traveling to Israel on a trip financed by Aipac’s education arm is practically a rite of passage for freshman members of Congress.”
https://www.nytimes.com/2019/03/04/us/politics/aipac-congres...
Does this convincingly show AIPAC is "the most powerful political organization in the US"?
More than the Democratic party? More than the Republican party?
More than these groups? https://largest.org/people/lobbying-groups/
I probably would rephrase parent’s comment as “one of the Most powerful political organization”
As a congressman/woman while considering a policy position against Israel AIPAC is probably the most powerful. Any case comparison of strength between corporate funded lobbyists and an organization with singular ideological is pointless.
What's the super charitable reading of "can tip the scales in almost any election"?
The parent commenter talked about political organizations generally. They didn't specify non-corporate funded lobbying.
Also, it's reductive and I would argue misleading to say AIPAC has a "singular ideology" (as opposed to some sort of umbrella of overlapping ideologies, somewhat akin to groups like the Democratic the Republican parties in the US).
Its probably more appropriate to say that they are one of the most powerful lobbyist groups simply because it’s hard to quantify and compare power.
Rule #1: Don't criticize Israel
Rule #2: If anybody criticizes Israel you attack them and call them antisemitic
False. USA doesn't take cyber attacks from Russia and China seriously at all aside from lip service. In all reality USA should be considered in an actual state of war with these countries based on their previous actions.
Were there immediate press conferences or sanctions for the Solarwinds stuff? Honest question. I don’t remember.
The Solarwinds stuff was so obviously the fault of Solarwinds that making a big deal out of it would be an own-goal.
Afaik all attributions to Russia about that came from "unnamed government sources/experts" in media, don't think the US accused Russia of that out in the open and "officially".
Well Israel is a US ally that serves US interests, namely it is by the Suez canal one of the busiest shipping lanes on earth. One could argue that there is a lot of political support for Israel in the US but it really comes down to geopolitical interest.
The others, Russia is a US adversary as it seeks to challenge the US order without Russia in it. Iran is a geopolitical adversary, simply because Saudi Arabia is a US ally - enemy of enemy is friend. China is on that fine line between adversary and competitor but definitely not an ally.
So of course its not a big deal. The US knows Israel needs US support to maintain security along the canal and broader med.
But that whole definition of friends of foe you've given is ridiculous though.
Russia is trying to resist US bullying and european expansionism near its border, Iran revolted against US-selected dictators, and China, the largest country on Earth, doesnt even understand why the US makes any rule in the first place.
I think this inflated US self importance is one of the biggest danger to world stability. This way to see everyone not immediately showing its ass to be sodomized to be an "adversary" is insane.
Israel by your definition very much became an adversary: they wanted to monitor and control US elected officials to guide policies towards its interest. I dont think the "Suez canal" should be more important than the soul of the american democracy, but that, you dont seem to care as much about :D
This explanation is very poor. At their core countries have no feelings, there is no ill will or true adversary. There is a current interest for your people and economy. It is very much in Russia's interest to annex Ukraine, it has nothing to do with US bullying, etc. If Saudi Arabia were not a US ally the Iranian government would find no reason to really look at the US as a foe. Iran and Saudi Arabia have a balance of power to dominate the middle east and Saudi Arabia (with the help of the US) stands in the way of that, and that is why Russia helps Iran to counterbalance that. Historically Iran and Russia do not have alignment in their interests otherwise.
I suspect you see the world this way because you basically 'stand where you sit', but you have to look at it from the point of view of the other side and where people stand where they sit there too. I.e if you were born & raised & were wealthy/vested etc on the other side would your opinion flip. Your opinion should flip, and then of course with both opinions against each other it ends up becoming about having more power, having alliances and playing cards right.
If Sisi blows up Suez, USA is much more better off! =D And if he blows up Tiran, even better — they will have to buy US oil too.
That's more "geopolitical" for ya
Don't think so. Europe (and Nato/USA by extension) would have a very big problem.
They just have to buy stuff from the US then, and not from China.
Interesting. I thought that Europe is depending on the Gulf for its energy, but it turns out that it is Russia. But I guess they don't want to exclusively depend on Russia, so there must be some diversification via the Suez canal.
Interesting what will happen to geopolitics, in the event that Europe turns carbon neutral (if that ever happens)...
https://ec.europa.eu/eurostat/cache/infographs/energy/bloc-2...
"The stability of the EU’s energy supply may be threatened if a high proportion of imports are concentrated among relatively few external partners. In 2019, almost two thirds of the extra-EU's crude oil imports came from Russia (27 %), Iraq (9 %), Nigeria and Saudi Arabia (both 8 %) and Kazakhstan and Norway (both 7 %). A similar analysis shows that almost three quarters of the EU's imports of natural gas came from Russia (41 %), Norway (16 %), Algeria (8 %) and Qatar (5 %), while over three quarters of solid fuel (mostly coal) imports originated from Russia (47 %), the United States (18 %) and Australia (14 %)."
If it served US interests to demonize russia, sure.
However the more likely thing is they would keep it on the phone and feed false intel.
It was always only a matter of time untill this snakes starts eating itself.
News talking heads should be interviewing thousands of experts who can say "I told you so" and asking some tough questions of our joker officials.
What are the metrics of cryptographers by country?
But our greatest ally?
JFK was killed by a magical bullet
NSO should be declared a terrorist organization and enemy combatant.
Man, the man is killing us, man!!
I'm curious what the iPhones being hacked means as they were thought by general public as being very secure.
Would this imply 0-day exploits? Did they use backdoors put in place for US spying agencies?
Zero-days.
"They and other targets notified by Apple in multiple countries were infected through the same graphics processing vulnerability that Apple did not learn about and fix until September, the sources said.
Since at least February, this software flaw allowed some NSO customers to take control of iPhones simply by sending invisible yet tainted iMessage requests to the device, researchers who investigated the espionage campaign said."
"Our greatest ally"