{"id":46252,"date":"2024-12-23T16:35:18","date_gmt":"2024-12-23T21:35:18","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=46252"},"modified":"2025-05-13T14:27:39","modified_gmt":"2025-05-13T18:27:39","slug":"whatsapp-v-nso-group","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2024\/12\/23\/whatsapp-v-nso-group\/","title":{"rendered":"WhatsApp v. NSO Group"},"content":{"rendered":"<p><a href=\"https:\/\/www.reuters.com\/technology\/cybersecurity\/us-judge-finds-israels-nso-group-liable-hacking-whatsapp-lawsuit-2024-12-21\/\">Reuters<\/a> (via <a href=\"https:\/\/news.ycombinator.com\/item?id=42476828\">Hacker News<\/a>, <a href=\"https:\/\/www.courtlistener.com\/docket\/16395340\/facebook-inc-v-nso-group-technologies-limited\/\">Court Listener<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.reuters.com\/technology\/cybersecurity\/us-judge-finds-israels-nso-group-liable-hacking-whatsapp-lawsuit-2024-12-21\/\"><p>U.S. judge ruled on Friday in favor of Meta Platforms&rsquo;, WhatsApp in a lawsuit accusing Israel&rsquo;s NSO Group of exploiting a bug in the messaging app to install spy software allowing unauthorized surveillance.<\/p><p>[&#8230;]<\/p><p>WhatsApp in 2019 sued NSO seeking an injunction and damages, accusing it of accessing WhatsApp servers without permission six months earlier to install the Pegasus software on victims&rsquo; mobile devices. The lawsuit alleged the intrusion allowed the surveillance of 1,400 people, including journalists, human rights activists and dissidents.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/news.ycombinator.com\/item?id=42481704\">kdbg<\/a>:<\/p>\n<blockquote cite=\"https:\/\/news.ycombinator.com\/item?id=42481704\"><p>I&rsquo;m not a lawyer so maybe I&rsquo;m misunderstanding something but the plaintiff is Whatsapp, not the journalists. This isn&rsquo;t really about holding NSO Group accountable for hacking journalists at all\nThe fact journalists were compromised seems only incidental, the ruling is about weather or not NGO Group &ldquo;exceeded authorization&rdquo; on WhatsApp by sending the Pegasus installation vector through WhatsApp to the victims and not weather they were unauthorized in accessing the victims.<\/p><p>[&#8230;]<\/p><p>Adding a little more detail that comes from the prior dockets and isn&rsquo;t in the judgement directly but basically NSO Group scripted up a fake Whatsapp client that could send messages that the original application wouldn&rsquo;t be able to send. They use this fake client to send some messages that the original application wouldn&rsquo;t be able to send which provide information about the target users&rsquo; device. In that the fake client is doing something the real client cannot do (and fake clients are prohibited by the terms) they exceeded authorization.<\/p><p>Think about that for a moment and what that can mean. I doubt I&rsquo;m the only person here who has ever made an alternative client for something before.<\/p><p>Whatapp (that I recall) does not claim that the fake client abused any vulnerabilities to get information just that it was a fake client and that was sufficient.<\/p><\/blockquote>\n\n<p>I guess the vulnerabilities they exploited were in the operating systems, not in WhatsApp, but Apple withdrew its suit against NSO Group.<\/p>\n\n<p>See also: <a href=\"https:\/\/pxlnv.com\/linklog\/judge-rules-against-nso-group\/\">Nick Heer<\/a>.<\/p>\n\n<p>In other news about old lawsuits, I just received my small settlement checks from <a href=\"https:\/\/www.macrumors.com\/2023\/12\/15\/apple-settles-family-sharing-lawsuit\/\">Peters v. Apple<\/a> and <a href=\"https:\/\/mjtsai.com\/blog\/2019\/07\/25\/equifax-breach-settlement\/\">Equifax<\/a>.<\/p>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2024\/09\/18\/apple-drops-lawsuit-against-nso-group\/\">Apple Drops Lawsuit Against NSO Group<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/11\/24\/apple-sues-nso-group\/\">Apple Sues NSO Group<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/08\/04\/scanning-your-iphone-for-pegasus\/\">Scanning Your iPhone for Pegasus<\/a><\/li>\n<\/ul>\n\n<p id=\"whatsapp-v-nso-group-update-2025-01-09\">Update (2025-01-09): <a href=\"https:\/\/www.techdirt.com\/2024\/12\/23\/federal-judge-says-nso-group-violated-cfaa-holds-it-liable-for-malware-delivered-via-whatsapps-servers\/\">Tim Cushing<\/a> (<a href=\"https:\/\/yro.slashdot.org\/story\/24\/12\/23\/1538200\/whatsapp-scores-historic-victory-against-nso-group-in-long-running-spyware-hacking-case\">Slashdot<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.techdirt.com\/2024\/12\/23\/federal-judge-says-nso-group-violated-cfaa-holds-it-liable-for-malware-delivered-via-whatsapps-servers\/\">\n<p>The win here is limited. And while it does seem to expand the definition of unauthorized access that has so often been a problem in CFAA cases, it only does so because NSO refused to make the source code available to WhatsApp, which means the court has to assume Whatsapp&rsquo;s allegations are true because NSO is unwilling to prove them false.<\/p>\n<\/blockquote>\n\n<p id=\"whatsapp-v-nso-group-update-2025-05-13\">Update (<a href=\"#whatsapp-v-nso-group-update-2025-05-13\">2025-05-13<\/a>): <a href=\"https:\/\/arstechnica.com\/security\/2025\/05\/jury-orders-nso-to-pay-167-million-for-hacking-whatsapp-users\/\">Dan Goodin<\/a> (via <a href=\"https:\/\/www.schneier.com\/blog\/archives\/2025\/05\/court-rules-against-nso-group.html\">Bruce Schneier<\/a>):<\/p>\n<blockquote cite=\"https:\/\/arstechnica.com\/security\/2025\/05\/jury-orders-nso-to-pay-167-million-for-hacking-whatsapp-users\/\">\n<p>A jury has awarded WhatsApp $167 million in punitive damages in a case the company brought against Israel-based NSO Group for exploiting a software vulnerability that hijacked the phones of thousands of users.<\/p>\n<\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Reuters (via Hacker News, Court Listener): U.S. judge ruled on Friday in favor of Meta Platforms&rsquo;, WhatsApp in a lawsuit accusing Israel&rsquo;s NSO Group of exploiting a bug in the messaging app to install spy software allowing unauthorized surveillance.[&#8230;]WhatsApp in 2019 sued NSO seeking an injunction and damages, accusing it of accessing WhatsApp servers without [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2024-12-23T21:35:21Z","apple_news_api_id":"7adeabca-2c83-47ac-943e-de44fb9a80dc","apple_news_api_modified_at":"2025-05-13T18:27:42Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAQ==","apple_news_api_share_url":"https:\/\/apple.news\/Aet6ryiyDR6yUPt5E-5qA3A","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[31,1837,41,209,2657,355,48,1363],"class_list":["post-46252","post","type-post","status-publish","format-standard","hentry","category-technology","tag-ios","tag-ios-14","tag-lawsuit","tag-legal","tag-nso-group","tag-privacy","tag-security","tag-whatsapp"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/46252","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=46252"}],"version-history":[{"count":3,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/46252\/revisions"}],"predecessor-version":[{"id":47711,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/46252\/revisions\/47711"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=46252"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=46252"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=46252"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}