John Scott-Railton Profile picture
Mar 27, 2023 19 tweets 12 min read Read on X
BREAKING: Biden White House issues executive order on commercial spyware.

Also confirms over 50+ USG personnel suspected targeted w/#Pegasus

Huge deal, let me break the new #SpywareEO down. 1/ ImageImage
2/ Investment fuels spyware proliferation. A lot of that is predicated on the juicy dream of the USG as the ultimate customer.

The new #SpywareEO says to mercenary spyware vendors & backers: decision time.

Either stop contributing to proliferation right now, or lose our number.
3/ Biden's #SpywareEO's closes door for vendors if their spyware has:

❌Been used against USG
❌Has counterintelligence / foreign intel risks

-or-
❌ Abused for repression
❌Used on 🇺🇸Americans
❌Sold to govs that systematically do political repression. ImageImage
4/ For each component of the #SpywareEO I'm going to relate it to something concrete.

Let's call it the #Pegasus factor: would provision result in blocking USG from purchasing spyware from NSO for operational use?

Link to the full EO: whitehouse.gov/briefing-room/…
5/ First #SpywareEO component: national security, counterintelligence

Clearly derived from recent experiences with NSO.

#Pegasus factor? Yes, the EO would likely block NSO as a vendor. Image
6/Second #SpywareEO trigger: abuses.

Reflects the broad spectrum #spyware harms happen.

But *also* and critically, situations where vendors should expect that their product, once sold, will inevitably be abused.

#Pegasus factor: Ouch. NSO again would get dinged. Image
7/ I initially expected #SpywareEO to look like a allow/deny aka "blacklist" of spyware sellers..

But the EO's conduct based definitions = constant shell game of vendors corporate identities is blunted.

Even applies to companies that haven't been formed yet.

Probably better.
8/ Lots of spyware companies absolutely know what they are doing.

What's especially interesting is the term "remove" to describe risks.

Not the milquetoast & unverifiable "mitigate."

#SpywareEO is saying: cancel the contracts & more.

And you may still be toast. Do it now. Image
9/ Reports in the past that USG entities may have occasionally facilitated spyware purchases / acquisition by other governments.

If the #SpywareEO abuse/natsec/counterintelligence triggers are met... that door now closes. Image
10/ How does the USG know if #spyware vendors hit the #SpywareEO's triggers?

The EO contains a robust set of reporting requirements around misuses from the Intel community & procurement reporting.

Seems intended to prevent vendors from slipping through the cracks. ImageImageImageImage
11/ Use of the "operational use" term is interesting.

And creates carve outs for things like testing & analysis.

Analogy: USG can buy an anti-tank missile from a shady entity to test it against armor, but can't reward the vendor by equipping the whole military with them. Image
12/ Takeaway: The #SpywareEO is the first comprehensive action by any government on #spyware.

It was clearly drafted to pump the breaks on proliferation & is written with a good understanding the slippery nature of the industry.

It closes many loopholes.
13/ Whenever the USG regulates there's always temptation to speculate about protectionism for American companies.

But reading the #SpywareEO...these provisions hit US-based spyware companies just as hard if they meet the triggers / contribute to proliferation.

Good.
14/ Every government wants to not tie their hands too tightly, so there is a waiver provision.

But what's interesting is how restricted this is. This is a very high bar.

The #SpywareEO is not designed to be easily circumvented by someone in a corner of the USG bureaucracy. Image
15/ I've spent over a decade researching commercial spyware.

The #spywareEO is one of the most consequential actions to blunt proliferation that I've seen a government take.

So, where do we go from here?
16/ While the #SpywareEO addresses federal procurement, it doesn't hit state & local agencies.

And we know these are targets for sales by NSO Group & others.

This is going to be a really important area in coming years.

By: @josephfcox
vice.com/en/article/m7v…
17/ Second, while USG is a big & juicy prize, European governments are another core vendor target.

And #Germany is an example of a country on the wrong side of history on this.

Hopefully the #spywareEO provides a better model for how to not reward the worst of the worst. Image
18/ I expect the #SpywareEO to immediately chill investor comfort with reckless spyware vendors...

Some prospectuses are probably hitting the shredder right now.

But also need to see other direct disincentives for US-based investors that fuel harmful spyware proliferation.
19/ Remarkable to see @POTUS and the White House leaning this hard into the issue.

This is what global leadership looks like.

It also would not have happened without tremendous work from civil society and many brave #spyware victims coming forward year. after. year.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with John Scott-Railton

John Scott-Railton Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @jsrailton

May 6
BREAKING: jury awards massive $167 million in punitive damages against spyware company NSO Group.

Precedent-setting win against the notorious #Pegasus spyware maker.

Congratulations to @WhatsApp on sticking this case through since 2019. Some thoughts 1/
2/ After years of every trick & delay tactic it only took a California jury one days deliberation to the heart of the matter:

NSO makes millions hacking mostly-🇺🇸American tech companies... so that dictators can hack dissidents.

Their conduct deserved to be punished.
3/ NSO Group emerges from the trial severely damaged.

The verdict ($167,256,000 punitive, $440K+ compensatory) is big enough to make your eyes water.

The case is ALSO a huge blow to NSO's secrecy, with their business splashed all over a courtroom.

This will scare customers...
Read 14 tweets
May 1
Friends don't let friends get their eyeballs scanned to buy a coffee.

Sam Altman's Orwellian "Tools for Humanity" says this dystopia machine could help distinguish between #AI agents & humans... or verify at Point of Sale..or..?

Looks to me like a big biometric data grab 1/ Image
2/ Surely they didn't just start with the idea of invasively harvesting eyeball scans...and then look around for potential justifications.

And then add in some AI hype.

Right? Image
3/ Throwback to Tools for Humanity's previous (but non-portable, guys!) eye-scanning thing: WorldCoin.

Remember that? A global biometric data grab rife with documented exploitation in Africa & Latin America.

Still not clear what real value it delivered to the ppl who gave up their biometrics.Image
Image
Image
Read 4 tweets
Apr 28
Fear is dictatorship glue.

You can't imprison everyone with a dissenting thought.

Or inconvenient factual observation.

But fear teaches self censorship. It's a scalable system of control.

The autocrat's challenge is to keep the fear going. 1/ A detention center’s interrogation rooms — Untersuchungshaftanstalt Hohenschönhausen, Vernehmungstrakt (2004) (© Daniel & Geo Fuchs) Image source: https://hyperallergic.com/151019/mundane-horror-in-abandoned-stasi-spaces/
2/ In the 20th century, keeping fear alive required massive human investment.

Informants... archives...exemplary punishments... information control.

Looked like a linear scale.

A post-cold war school of thought said: once everyone is connected, these systems won't work. Hohenschönhausen investigation prison: monitoring room Daniel & Geo Fuchs  Via https://www.ibtimes.co.uk/stasi-secret-rooms-communist-east-germanys-eerie-interrogation-cells-haunted-prisons-1467734
BStU Zentralarchiv Berlin archives (2004) (© Daniel & Geo Fuchs)  URL: https://hyperallergic.com/151019/mundane-horror-in-abandoned-stasi-spaces/
"There are several images of staged Stasi arrests carried out for training purposes. Dissidents, in some case already serving long prison terms, were sometimes made to re-enact their own arrest for the camera.  " Simon Menner BSTU Source: https://www.bbc.com/news/world-europe-23986385
3/ But tech isn't, by nature, a dictatorship antidote.

It can be an expedient.

Just ask China.

In 20 years the CCP empirically developed technologies & private sector partnerships for scaling fear and self censorship to >1.4 billion ppl.

Log scale. A display shows surveillance technology capable of analyzing body motion for specific actions like fighting, theft or fall during Security China 2018 in Beijing, China, Tuesday, Oct. 23, 2018.  Photo/Ng Han Guan
Surveillance cameras are mounted on a post at Tiananmen Square as snow falls in Beijing, China, on Thursday, Feb. 14, 2019. Qilai Shen  https://www.cnbc.com/2021/01/15/huawei-ai-firms-filed-to-patent-tech-that-could-identify-uighurs-report-says.html
Read 6 tweets
Mar 19
🚨NEW REPORT: first forensic confirmation of #Paragon mercenary spyware infections in #Italy...

Known targets: Activists & journalists.

We also found deployments around the world. Including ...Canada?

And a lot more... Thread on our @citizenlab investigation 1/Image
Image
2/ So #Paragon makes zero-click spyware marketed as better than NSO's Pegasus...

Harder to find...

...And more ethical too!

This caught our attention @citizenlab & we were skeptical.

By @iblametom forbes.com/sites/thomasbr…Image
Image
Image
3/ We got a tip about a single bit of #Paragon infrastructure & my brilliant colleague @billmarczak developed a technique to fingerprint some of the mercenary spyware infrastructure (both victim-facing & customer side) globally.

So much for invisibility.

What we found startled us.

citizenlab.ca/2025/03/a-firs…Image
Image
Image
Image
Read 18 tweets
Feb 6
BREAKING: #Paragon reportedly terminates spyware contract with #Italy.

Right on heels of reported targeting of journalist & activists in Italy.

BIG DEAL: puts Italian government in the hot seat, since they denied knowing about it only hours ago.👇
Image
2/ Read this slowly.

The implication is clear: the Italian government was a #Paragon customer & had their contract terminated...

Even as @GiorgiaMeloni's office was issuing denials.

Likely to make the scandal worse.

Exceptional reporting from The Guardian
theguardian.com/technology/202…Image
Image
3/ Big picture:

#Paragon's carefully constructed image of being a clean mercenary spyware company that wasn't susceptible to abuses has been replaced by a more familiar tale of...

Abuses...

And #Italy is now saddled with an unfolding crisis around spyware abuse.
Read 7 tweets
Feb 1
NEW: @WhatsApp says Israeli mercenary spyware company #Paragon targeted scores of users around world.

The infection happened with no interaction. No link to click or attachment to open.

This is called a "zero-click" attack.

WA says targets included journalists & members of civil society.

They dismantled the attack vector & notified users.

Good.

We at @citizenlab shared some info instrumental to their investigation of the vector.

This is a BIG deal. Here's why 1/Image
Image
Image
Image
2/ For a few years the only source of information about #Paragon... has been Paragon.

They marketed themselves as the anti-NSO.

(NSO makes the notorious #Pegasus spyware)

It's easier to frame yourself as virtuous in the spyware game if nobody can look over your shoulder.

By @iblametom
forbes.com/sites/thomasbr…

By @RonanFarrow
newyorker.com/magazine/2022/…Image
Image
Image
Image
3/ Late last year, partly on the strength of their promised virtue #Paragon seemed closer than ever to landing the industrys juiciest of prices.

Market access into the USA.

This is the goal of a lot of spyware companies & their investors...

At the time, there simply were no pesky reports on Paragon that showed anything might be other than rosy.

Story @criticalvas
wired.com/story/ice-para…Image
Read 12 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(