2/ I'd say the joint statement on commercial #spyware is unprecedented.
A few years ago spyware like #Pegasus was was treated as a human rights issue.
But the dizzying speed of proliferation made big problems for governments, forcing them to prepare positions & action.
3/ The statement's commitment guardrails for accountable domestic #spyware use is important.
But devil will be in the implementations. Civil society will be watching.
(Note: issue wasn't covered in White House Spyware Executive Order on Monday, so nice to see USA commit here)
4/ Export control commitments on #Spyware. Again, important.
Worth noting, several signatories have a complex history on surveillance tech export...
So transparency about license granting & denials will be essential for accountability & to ensure commitment has teeth.
5/ Tracking & information sharing. Maybe public shaming? Norms? Again, important.
The mercenary #spyware industry has hidden from researchers & victims.
Let's hope it's harder for them to hide from governments.
6/ Commercial #spyware proliferation is now a global problem. Whether it's sold to autocrats, or to more 'democratic' governments in the EU... that wind up abusing it
But a key driver? Investment firms in the US & elsewhere. Good to see the joint statement speak to this.
8/ Spyware proliferation went too far & did too much harm.
Result? Governments are waking up & have started taking action.
But this is also a reminder of all the progress still needed on many fronts, like domestic accountability, oversight & transparency from every signatory.
9/ It remains puzzling to me as I read the joint statement on #Spyware that some EU countries are notably missing (where is #Germany?).
It also puts into stark relief that the EU Parliament's efforts on Spyware have a long way to go.
I hope there is some pressure to catch up!
โข โข โข
Missing some Tweet in this thread? You can try to
force a refresh
NEW: @WhatsApp caught & fixed a sophisticated zero click attack...
Now they've published an advisory about it.
Say attackers combined the exploit with an @Apple vulnerability to hack a specific group of targets (i.e. this wasn't pointed at everybody)
Quick thoughts 1/
Wait, you say, haven't I heard of @WhatsApp zero-click exploits before?
You have.
A big user base makes a platform big target for exploit development.
Think about it from the attacker's perspective: an exploit against a popular messenger gives you potential access to a lot of devices.
You probably want maximum mileage from that painstakingly developed, weaponized, and tested exploit code you created/ purchased (or got bundled into your Pegasus subscription).
3/ The regular tempo of large platforms catching sophisticated exploits is a good sign.
They're paying attention & devoting resources to this growing category of highly targeted, sophisticated attacks.
But it's also a reminder of the magnitude of the threat out there...
WHOA: megapublisher @axelspringer is asking a German court to ban an ad-blocker.
Their claim that should make everyone nervous:
The HTML/ CSS code of websites are protected computer programs.
And influencing they are displayed (e.g by removing ads) violates copyright.
1/
2/ Preventing ad-blocking would be a huge blow to German cybersecurity and privacy.
There are critical security & privacy reasons to influence how a websites code gets displayed.
Like stripping out dangerous code & malvertising.
Or blocking unwanted trackers.
This is why most governments do it on their systems.
3/Defining HTML/CSS as a protected computer program will quickly lead to absurdities touching every corner of the internet.
Just think of the potential infringements:
-Screen readers for the blind
-'Dark mode' bowser extensions
-Displaying snippets of code in a university class
-Inspecting & modifying code in your own browser
-Website translators
3/ What still gives me chills is how many cases surfaced of people killed by cartels... or their family members... getting targeted with Pegasus spyware.
The #PegasusProject found even more potential cases in Mexico.