When the #PegasusProject dropped last week, it was both an ordinary and exceptional moment. The report - from @Amnesty, @CitizenLab, @FbdnStories, and 80 journalists in 10 countries - documented 50,000 uses of @NSOgroup's Pegasus malware.
The 50,000 targets of NSO's cyberweapon include politicians, activists and journalists. The Israeli arms-dealer - controlled by Novalpina Capital and Francisco Partners - has gone into full spin mode.
2/
NSO insists that the report is wrong, but also that it's fine to spy on people, and also that terrorists will murder us all if they aren't allowed to reap vast fortunes by helping the world's most brutal dictators figure out whom to kidnap, imprison and murder.
3/
As I say, all of this is rather ordinary. The NSO Group's bloody hands, immoral practices and vicious retaliation against critics are well established.
4/
It's been four years since NSO's assurances that it only sold spying tools to democratic states to hunt terrorists were revealed as lies, when Citizenlab revealed that its weapons targeted Mexican anti-sugar activists (and their children).
Then Citizenlab found 45 more countries where NSO's Pegasus weapon had been used, and demonstrated that notorious human-rights abusers got help from NSO to target everyday citizens to neutralize justice struggles.
Outside of human rights and cybersecurity circles, the story drew little attention, but it did prick NSO's notoriously thin skin - the company dispatched (inept) private spooks, late of the Mossad, to entrap Citizenlab's researchers.
As far as we know, the company never managed to infiltrate any of Citizenlab's systems - but their weapons were found on the devices of an Israeli lawyer suing them for their role in human rights abuses.
THAT had SOME consequences. The attack exploited a vulnerability in Whatsapp, owned by Facebook. FB retaliated by suing - and terminating NSO Group employees' Facebook accounts. Judging from NSO's outraged squeals, getting kicked of FB hurt far worse.
Through it all, the NSO Group insisted that its tools were vital anti-terror weapons - not the playthings of rich sociopaths with long enemies lists.
10/
They continued these claims even after Pegasus was linked to the blackmail attempt against Jeff Bezos, in a bid by Saudi royals to end the @WashingtonPost's investigative reporting on the murder and dismemberment of the journalist Jamal Khashoggi.
Despite all this - attacks on the powerful and the powerless, grisly deaths and farce-comedy entrapment attempts - NSO Group plowed on, raking in millions while undermining the security of the devices that billions of us rely on for our own safety.
Until now.
12/
Something about the Pegasus Project shifted the narrative. Maybe it's the ransomware epidemic, shutting down hospitals, energy infrastructure, and governments - or maybe it's the changing tide that has turned on elite profiteers. Whatever it is, people are PISSED.
Finally.
13/
I mean, when @snowden calls for the owners of a cybercrime company to be arrested, people sit up and pay attention. But Snowden's condemnation of NSO and its industry are just for openers.
Snowden describes NSO as part of an "Insecurity Industry" that owes its existence to critical vulnerabilities in digital devices in widespread use. They spend huge sums discovering these vulns - and then, rather than reporting them so they can be fixed, they weaponize them.
15/
As Snowden points out, this is not merely a private sector pathology. Governments - notably the US government, through the NSA's Tailor Access Operations Group - engage in the same conduct.
16/
Indeed, as with all digital surveillance, there's no meaningful difference between private and public spying. Governments rely on tech and telecoms giants for data (which they buy, commandeer, or steal, depending on circumstances).
17/
This, in turn, creates powerful security/public safety advocates for unlimited commercial surveillance, to ensure low-cost, high-reliability access to our private data. Those agencies stand ready to quietly scuttle comprehensive commercial privacy legislation.
18/
This private-public partnership from hell extends into the malware industry: the NSA and CIA can't, on their own, create enough cyber-weapons to satisfy all government agencies' demand, so they rely on (and thus protect) the Insecurity Industry.
19/
But as Snowden points out, none of this would be possible were it not for the vast, looming, grotesque tech-security debt that the IT industry has created for us. Everything we use is insecure, and it's built atop more insecure foundations.
20/
We live in an information society with catastrophic information security. If our society was a house, the walls would all be made of flaking asbestos and the attic would be stuffed with oily rags.
21/
It's hard to overstate just how much risk we face right now, and while the Insecurity Industry didn't create that risk, they're actively trying to increase it - finding every weak spot and widening it as far as possible, rather than shoring it up.
22/
But they're not alone. As Snowden says, both the commercial IT sector ("who want to sell things, not fix things") and free/open source hackers ("who want to fix things, not sell things") are mired in bad security practices that rack up still more technology debts.
23/
It's a cliche: "Security is a team sport." But I like how Snowden puts it: security is a public health matter. "To protect anyone, we must protect everyone."
24/
Step one is "to ban the commercial trade in intrusion software" for the same reason we "do not permit a market in biological infections-as-a-service."
We should punish the cyber-arms dealers - but also use international courts to target the state actors who pay them.
25/
But this fight will be a tough one. The huge sums that governments funnel to cyber arms-dealers allows them to silence their critics - I've been forced to remove some of my own coverage thanks to baseless threats I couldn't afford to fight.
26/
Writing in today's @guardian (who also removed unfavorable coverage of NSO Group following legal threats), Arundhati Roy demolishes the company's claims of clean hands.
After all, NSO charges a 17% "system maintenance fee" that gives them oversight and insight into how their tools are being used by the demagogues and dictators who shower them with money.
"There has to be something treasonous about a foreign corporation servicing and maintaining a spy network that is monitoring a country’s private citizens on behalf of that country’s government." -Roy
29/
The NSO Group claims that the human rights abuses it abets are exceptions that slip through the cracks, but the reality is, it has no business model without state terror - without powerful thugs who demand weapons to help jail, torture and kill their critics.
30/
NSO, more than anyone, should know this. But as Upton Sinclair wrote, "It is difficult to get a man to understand something when his salary depends upon his not understanding it."
eof/
ETA - If you'd like an unrolled version of this thread to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:
I've been writing about the Sackler crime-family for years, as a new generation turned the family's benzo empire into a opioid powerhouse, exceeding the Rockefeller family fortune by pushing Oxycontin and jumpstarting an epidemic that has claimed 800,000 American lives.
1/
The Sacklers are canny: for years, they laundered their reputation through elite philanthropy, using blood money to paint their names on the world's great cultural institutions and spending comparable sums to threaten journalists and critics into silence about their crimes.
2/
But no one can run across a river on the backs of alligators forever - eventually, even the fleetest grifter will lose a leg. The Sacklers eventually came into the crosshairs of district attorneys, federal enforcers, bereaved families and recovering addicts.
3/
@ClimateTechFin@KetanJ0 Tesla is a grift whose profitability depends on mining bitcoin and selling carbon credits to the world's most polluting SUV manufacturers. It's run by a con artist who literally paid the company's founders to call him the founder.
@ClimateTechFin@KetanJ0 It maims workers, busts unions, and tells farcical lies about self-driving cars and spins even more farcical fantasies that cars - not transit - are the future of urban mobility. Musk claims that transit is bad "because you might sit next to a serial killer."
@ClimateTechFin@KetanJ0 Just as Musk has claimed that he can deliver more bandwidth than the universe has available radio frequency spectrum, he's also claimed that he can nullify the laws of geometry that dictate that private vehicles can't be the default means of transport in livable cities