{"id":34274,"date":"2021-11-24T15:46:22","date_gmt":"2021-11-24T20:46:22","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=34274"},"modified":"2024-09-16T20:44:19","modified_gmt":"2024-09-17T00:44:19","slug":"apple-sues-nso-group","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2021\/11\/24\/apple-sues-nso-group\/","title":{"rendered":"Apple Sues NSO Group"},"content":{"rendered":"<p><a href=\"https:\/\/www.apple.com\/newsroom\/2021\/11\/apple-sues-nso-group-to-curb-the-abuse-of-state-sponsored-spyware\/\">Apple<\/a> (<a href=\"https:\/\/storage.courtlistener.com\/recap\/gov.uscourts.cand.388382\/gov.uscourts.cand.388382.1.0.pdf\">PDF<\/a>, <a href=\"https:\/\/news.ycombinator.com\/item?id=29320986\">Hacker News<\/a>, <a href=\"https:\/\/www.reddit.com\/r\/apple\/comments\/r0j4ot\/apple_sues_nso_group_to_curb_the_abuse_of\/\">Reddit<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.apple.com\/newsroom\/2021\/11\/apple-sues-nso-group-to-curb-the-abuse-of-state-sponsored-spyware\/\">\n<p>Apple today filed a lawsuit against NSO Group and its parent company to hold it accountable for the surveillance and targeting of Apple users. The complaint provides new information on how NSO Group infected victims&rsquo; devices with its Pegasus spyware. To prevent further abuse and harm to its users, Apple is also seeking a permanent injunction to ban NSO Group from using any Apple software, services, or devices.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/www.nytimes.com\/2021\/11\/23\/technology\/apple-nso-group-lawsuit.html\">Nicole Perlroth<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.nytimes.com\/2021\/11\/23\/technology\/apple-nso-group-lawsuit.html\">\n<p>The lawsuit is the second of its kind &mdash; Facebook sued the NSO Group in 2019 for targeting its WhatsApp users &mdash; and represents another consequential move by a private company to curb invasive spyware by governments and the companies that provide their spy tools.<\/p>\n<p>[&#8230;]<\/p>\n<p>The sample of Pegasus gave Apple a forensic understanding of how Pegasus worked. The company found that NSO&rsquo;s engineers had created more than 100 fake Apple IDs to carry out their attacks. In the process of creating those accounts, NSO&rsquo;s engineers would have had to agree to Apple&rsquo;s iCloud Terms and Conditions, which expressly require that iCloud users&rsquo; engagement with Apple &ldquo;be governed by the laws of the state of California.&rdquo;<\/p>\n<p>The clause helped Apple bring its lawsuit against NSO in the Northern District of California.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/daringfireball.net\/linked\/2021\/11\/23\/apple-newsroom-nso-group-lawsuit\">John Gruber<\/a>:<\/p>\n<blockquote cite=\"https:\/\/daringfireball.net\/linked\/2021\/11\/23\/apple-newsroom-nso-group-lawsuit\">\n<p>Apple repeatedly refers to the &ldquo;FORCEDENTRY&rdquo; exploit by name. This is not PR bullshit&#x2009;&mdash;&#x2009;they&rsquo;re talking about a very specific exploit. Second, they refer to Android as their compatriot, not their competitor. There&rsquo;s a time and place for Apple to brag about iOS being more secure than Android, but this isn&rsquo;t it. The message here: &ldquo;This isn&rsquo;t just about us, NSO Group is after everyone.&rdquo;<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/daringfireball.net\/linked\/2021\/11\/23\/apple-v-nso-complaint\">John Gruber<\/a>:<\/p>\n<blockquote cite=\"https:\/\/daringfireball.net\/linked\/2021\/11\/23\/apple-v-nso-complaint\">\n<p>I genuinely wonder what Apple&rsquo;s goals are with this suit. Is it just to bring NSO Group&rsquo;s activities to light? If this goes to trial, the testimony should really be something to see. How much in damages will Apple seek at trial? Enough to bankrupt NSO Group?<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/sixcolors.com\/link\/2021\/11\/apple-sues-spyware-maker-nso-group\/\">Jason Snell<\/a>:<\/p>\n<blockquote cite=\"https:\/\/sixcolors.com\/link\/2021\/11\/apple-sues-spyware-maker-nso-group\/\">\n<p>Say what you will about Apple&rsquo;s policies regarding bug bounties and other security issues&mdash;the company is capable of spending a nearly infinite amount of money on lawyers who will try to make NSO Group&rsquo;s existence painful for a very long time.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/mxswd\/status\/1463254787902750722\">Maxwell Swadling<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/mxswd\/status\/1463254787902750722\"><p>are you taking any steps to improve platform security processes to prevent what happened over the last 2 years? Such as addressing security disclosures quicker, opening up the security researcher program or catching more issues internally that project zero picks up externally?<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/i0n1c\/status\/1463326306188226561\">Stefan Esser<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/i0n1c\/status\/1463326306188226561\">\n<p>NSO has managed what a lot of legitimate security researchers have been unable to do: make people see the security of iPhones in a more realistic light. Furthermore Apple going after people who discover security problems in their products is just normal Apple tactic anyway.<\/p>\n<\/blockquote>\n<blockquote cite=\"https:\/\/twitter.com\/i0n1c\/status\/1463332306639228930\">\n<p>Never forget that when NSO was first caught and the first time the general public learned about PEGASUS it was Apple who threatened Lookout to not release samples to the public. Nice AppStore app you have there. It would be a shame if something happened to it.<\/p>\n<\/blockquote>\n<blockquote cite=\"https:\/\/twitter.com\/i0n1c\/status\/1463332868269101056\">\n<p>Yeah also never forget that System and Security info which was capable of finding PEGASUS on your iPhone was banned from the Apple App Store because Apple did not want their customers to be able to see if they were infected.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/stroughtonsmith\/status\/1463312845890887685\">Steve Troughton-Smith<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/stroughtonsmith\/status\/1463312845890887685\">\n<p>Observation from Apple&rsquo;s NSO complaint: Apple, curiously, completely omits any mention of App Store or lack of sideloading as a fundamental security measure of iOS. Almost as if they no longer believe they can rely on that point to remain in their favor.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/OrinKerr\/status\/1463278878634348546\">Orin Kerr<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/OrinKerr\/status\/1463278878634348546\">\n<p>According to its CFAA claim filed today, Apple thinks that when your iPhone&rsquo;s operating system is hacked, Apple is hacked-- and it can sue-- because Apple still owns the operating system on your iPhone.<\/p>\n<p>Hmm, seems like a pretty big stretch to me.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/support.apple.com\/en-us\/HT212960\">Apple<\/a>:<\/p>\n<blockquote cite=\"https:\/\/support.apple.com\/en-us\/HT212960\">\n<p>Apple threat notifications are designed to inform and assist users who may have been targeted by state-sponsored attackers. These users are individually targeted because of who they are or what they do. Unlike traditional cybercriminals, state-sponsored attackers apply exceptional resources to target a very small number of specific individuals and their devices, which makes these attacks much harder to detect and prevent. State-sponsored attacks are highly complex, cost millions of dollars to develop, and often have a short shelf life. The vast majority of users will never be targeted by such attacks.<\/p>\n<p>If Apple discovers activity consistent with a state-sponsored attack, we notify the targeted users in two ways[&#8230;]<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/pxlnv.com\/linklog\/apple-sues-nso-group\/\">Nick Heer<\/a>:<\/p>\n<blockquote cite=\"https:\/\/pxlnv.com\/linklog\/apple-sues-nso-group\/\">\n<p>One of the minor privacy flaws of iMessage is that it will automatically tell you whether someone else has enabled it. All you have to do is type an email address or a phone number into the &ldquo;To:&rdquo; field in Messages; if it turns blue, it is an iMessage account and, therefore, associated with an Apple ID and an Apple device. In a vacuum, this is not very meaningful, but it appears that NSO Group was using a similar technique to figure out where to send its spyware.<\/p>\n<p>[&#8230;]<\/p>\n<p>I cannot find any reports of Apple notifying potential victims of state-sponsored attacks, so this appears to be a new policy. Twitter was doing this <a href=\"https:\/\/threatpost.com\/twitter-warns-some-users-of-nation-state-attacks\/115633\/\">in 2015<\/a>, and Google <a href=\"https:\/\/www.computerworld.com\/article\/2504015\/google-warns-gmail-users-of--state-sponsored--hacks.html\">in 2012<\/a>.<\/p>\n<\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/09\/13\/zero-click-imessage-attacks\/\">Zero-click iMessage Attacks<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/09\/24\/ios-vulnerabilities-either-unfixed-or-uncredited\/\">iOS Vulnerabilities Either Unfixed or Uncredited<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/09\/09\/security-researchers-unhappy-with-apples-bug-bounty-program\/\">Security Researchers Unhappy With Apple&rsquo;s Bug Bounty Program<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/08\/04\/scanning-your-iphone-for-pegasus\/\">Scanning Your iPhone for Pegasus<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/07\/23\/through-the-blast-door\/\">Through the Blast Door<\/a><\/li>\n<\/ul>\n\n<p id=\"apple-sues-nso-group-update-2021-12-13\">Update (2021-12-13): <a href=\"https:\/\/daringfireball.net\/linked\/2021\/12\/03\/us-state-dept-iphones-nso-group\">John Gruber<\/a>:<\/p>\n<blockquote cite=\"https:\/\/daringfireball.net\/linked\/2021\/12\/03\/us-state-dept-iphones-nso-group\">\n<p>Fascinating to consider that the U.S. State Department is only aware of this hack because Apple notified the affected employees. That&rsquo;s certainly how this report reads.<\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Apple (PDF, Hacker News, Reddit): Apple today filed a lawsuit against NSO Group and its parent company to hold it accountable for the surveillance and targeting of Apple users. The complaint provides new information on how NSO Group infected victims&rsquo; devices with its Pegasus spyware. To prevent further abuse and harm to its users, Apple [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2021-11-24T20:46:26Z","apple_news_api_id":"615977f2-2977-45e2-9179-9c28cee21e5e","apple_news_api_modified_at":"2024-09-17T00:44:25Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAQ==","apple_news_api_share_url":"https:\/\/apple.news\/AYVl38il3ReKReZwozuIeXg","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[38,31,1837,41,209,2657,48],"class_list":["post-34274","post","type-post","status-publish","format-standard","hentry","category-technology","tag-apple","tag-ios","tag-ios-14","tag-lawsuit","tag-legal","tag-nso-group","tag-security"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/34274","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=34274"}],"version-history":[{"count":2,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/34274\/revisions"}],"predecessor-version":[{"id":34400,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/34274\/revisions\/34400"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=34274"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=34274"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=34274"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}