Security

Hackers Hide Web Skimmer Behind a Website's Favicon (zdnet.com) 18

In one of the most complex and innovative hacking campaigns detected to date, a hacker group created a fake icons hosting website in order to disguise malicious code meant to steal payment card data from hacked websites. From a report: The operation is what security researchers refer to these days as a web skimming, e-skimming, or a Magecart attack. Hackers breach websites and then hide malicious code on its pages, code that records and steals payment card details as they're entered in checkout forms. Web skimming attacks have been going on for almost four years, and as security firms are getting better at detecting them, attackers are also getting craftier. In a report published today, US-based cybersecurity firm Malwarebytes said it detected one such group taking its operations to a whole new level of sophistication with a new trick.
Security

An Adult Cam Site Exposed 10.88 Billion Records (wired.com) 73

CAM4, a popular adult platform that advertises "free live sex cams," misconfigured an ElasticSearch production database so that it was easy to find and view heaps of personally identifiable information, as well as corporate details like fraud and spam detection logs. According to Wired, the database exposed 7 terabytes of names, sexual orientations, payment logs, and email and chat transcripts -- 10.88 billions records in all. From the report: First of all, very important distinction here: There's no evidence that CAM4 was hacked, or that the database was accessed by malicious actors. That doesn't mean it wasn't, but this is not an Ashley Madison-style meltdown. It's the difference between leaving the bank vault door wide open (bad) and robbers actually stealing the money (much worse). [...] The list of data that CAM4 leaked is alarmingly comprehensive. The production logs Safety Detectives found date back to March 16 of this year; in addition to the categories of information mentioned above, they also included country of origin, sign-up dates, device information, language preferences, user names, hashed passwords, and email correspondence between users and the company.

Out of the 10.88 billion records the researchers found, 11 million contained email addresses, while another 26,392,701 had password hashes for both CAM4 users and website systems. A few hundred of the entries included full names, credit card types, and payment amounts. Who's Affected? It's hard to say exactly, but the Safety Detectives analysis suggests that roughly 6.6 million US users of CAM4 were part of the leak, along with 5.4 million in Brazil, 4.9 million in Italy, and 4.2 million in France. It's unclear to what extent the leak impacted both performers and customers.
The report says CAM4's parent company, Granity Entertainment, took the server offline within a half hour of being contacted by the researchers.
Security

Apple's Copyright Lawsuit Has Created a 'Chilling Effect' on Security Research (vice.com) 76

Last year, Apple accused a cybersecurity startup based in Florida of infringing its copyright by developing and selling software that allows customers to create virtual iPhone replicas. Critics have called the Apple's lawsuit against the company, called Corellium, "dangerous" as it may shape how security researchers and software makers can tinker with Apple's products and code. From a report: The lawsuit, however, has already produced a tangible outcome: very few people, especially current and former customers and users, want to talk about Corellium, which sells the eponymous software that virtualizes iPhones and Android devices. During the lawsuit's proceedings, Apple has sought information from companies that have used the tool, which emulates iOS on a computer, allowing researchers to probe potential iPhone vulnerabilities in a forgiving and easy-to-use environment.

"Apple has created a chilling effect," a security researcher familiar with Corellium's product, who asked to remain anonymous because he wasn't allowed to talk to the press, told Motherboard. "I don't know if they intended it but when they name individuals at companies that have spoken in favor [of Corellium], I definitely believe retribution is possible," the researcher added, referring to Apple's subpoena to the spanish finance giant Santander Bank, which named an employee who had Tweeted about Corellium. Several other cybersecurity researchers expressed fear of retribution from Apple for using Corellium.

Firefox

Firefox 76 Arrives With Password Management and Zoom Improvements (venturebeat.com) 75

Mozilla today launched Firefox 76 for Windows, Mac, and Linux. Firefox 76 includes new Firefox Lockwise password functionality, Zoom improvements, and a handful of developer features. From a report: Lockwise, the password management service formerly known as Firefox Lockbox, is getting smarter. The Firefox feature already lets you generate, manage, and protect all those passwords for streaming services, grocery deliveries, and anything else that helps during the pandemic. If you share your device with family or roommates, Lockwise in Firefox 76 can now protect your saved passwords. When you try to view or copy a password from your "Logins and Passwords" page, you will be prompted for your device's account password.

[...] Firefox 76 adds support for Audio Worklets, which run custom JavaScript audio processing code for applications like VR and gaming on the web. Unlike their predecessor, ScriptProcessorNode, worklets run off the main thread in a similar way to web workers. Mozilla also notes Audio Worklets are "being adopted by some of your favorite software programs." The company specifically called out Zoom, which has become a phenomenon of its own during the pandemic. In short, you now join Zoom calls in Firefox without having to download or install the Zoom client.

Microsoft

How Microsoft Fought the 'ILOVEYOU' Virus 20 Years Ago (fastcompany.com) 74

The inside story of 'ILOVEYOU' and two other viruses from two decades ago. Steven Sinofsky, who worked at Microsoft from 1989-2012 and oversaw the Office (1998-2006) and Windows (2006-2012) teams, writes (shared by reader harrymcc): One morning during the first week of May of the new millennium, I received a call at my apartment while I was getting ready for work. I heard a female reporter tell me her name, and then basically listened to her hyperventilating and proclaiming her love for me repeatedly: "I love you. I love you." That's what I heard, anyway. The call. A reporter. Early morning. It was all weird. In reality, LOVE broke out all over the internet. Over the span of a weekend, inboxes around the world of Outlook and Exchange email users were inundated with dozens of copies of email messages with the subject line, "ILOVEYOU."

I learned from the reporter that the LOVE email incident was deemed so serious that the PR lead gave her my home number and simultaneously sent me a briefing via email. In the era of dial-up, I could not read the email and talk on the phone because I only had one analog phone line at home. I had no idea what was going on, so I agreed to return the call after I dialed up and downloaded my email. That's when I realized the magnitude of the issue.

Portables (Apple)

Apple's T2 Security Chip Has Created a Nightmare for MacBook Refurbishers (vice.com) 213

As predicted, the proprietary locking system Apple rolled out with its 2018 MacBook Pros is hurting independent repair stores, refurbishers, and electronics recyclers. A combination of secure software locks, diagnostic requirements, and Apple's new T2 security chip are making it hard to breathe new life into old MacBook Pros that have been recycled but could be easily repaired and used for years were it not for these locks. From a report: It's a problem that highlights Apple's combative attitude towards the secondhand market and the need for national right to repair legislation. "The irony is that I'd like to do the responsible thing and wipe user data from these machines, but Apple won't let me," John Bumstead, a MacBook refurbisher and owner of the RDKL INC repair store, said in a tweet with an attached picture of two "bricked" MacBook Pros. "Literally the only option is to destroy these beautiful $3,000 MacBooks and recover the $12/ea they are worth as scrap."

As Motherboard has reported previously, without official Apple diagnostic software, newer MacBooks cannot be repaired or reset. "By default you can't get to recovery mode and wipe the machine without a user password, and you can't boot to an external drive and wipe that way because it's prohibited by default," Bumstead told Motherboard in an email. "Because T2 machines have no removable hard drive, and the drive is simply chips on the board, this default setting means that a recycler (or anyone) can't wipe or reinstall a T2 machine that has default settings unless they have the user password."

Businesses

Cisco Spotlights New IT Roles You May Have Never Heard of (networkworld.com) 79

coondoggie writes: A glimpse into what that future means for IT networking professionals can be found in Cisco's 2020 Global Networking Trends Report. It was completed before COVID-19 changed the way company's do business, but the predicted impacts have been hastened by the pandemic's impact. From the networking study, Cisco put forward a number of new or developing roles it expects to see in the future, including:

Business translator: The business translator works to better turn the needs of business into service-level, security and compliance requirements that can be applied and monitored across the network. The translator also works to use network and network data for business value and innovation, and their knowledge of networking and application APIs will help them glue the business to the IT landscape.
Network guardian: A network guardian works to bridge network and security architectures. They build the distributed intelligence of the network into security architecture and the SecOps process. This is where networking and security meet, and the guardian is at the center of it all, pulling in and pushing out vast amounts of data, distilling it and then taking action to identify faults or adapt to shutdown attackers.
Network commander: Intent-based networking builds on controller-based automation and orchestration processes. The network commander takes charge of these processes and practices that ensure the health and continuous operation of the network controller and underlying network.
Network orchestrator: This position translates business needs into network policy. It focuses on policy translation and automation, and policy alignment across network and IT domains.
Network detective: A network detective uses and tunes network assurance tools that employadvanced analytics and AI to ensure that the network delivers on business intent. They work with IT service-management processes and SecOps teams to identify network anomalies and close potential security holes. Like the network guardian, they use data proactively to identify faults and attacks.

Security

Hackers Breach LineageOS Servers Via Unpatched Vulnerability (zdnet.com) 9

An anonymous reader writes: Hackers have gained access to the core infrastructure of LineageOS, a mobile operating system based on Android, used for smartphones, tablets, and set-top boxes. The intrusion took place on Saturday night at around 8 pm (US Pacific coast), and was detected before the attackers could do any harm, the LineageOS team said in a statement published less than three hours after the incident. The LineageOS team said the operating system's source code was unaffected, and so were any operating system builds, which had been already paused since April 30, because of an unrelated issue. Signing keys, used to authenticate official OS distributions, were also unaffected, as these hosts were stored separately from the LineageOS main infrastructure. LineageOS developers said the hack took place after the attacker used an unpatched vulnerability to breach its Salt installation.
Microsoft

Microsoft Confirms Windows 10X is Coming To Laptops Amid Big Jump in Windows Usage (theverge.com) 94

Microsoft is confirming today that it's planning to refocus Windows 10X on single-screen devices. "The world is a very different place than it was last October when we shared our vision for a new category of dual-screen Windows devices," explains Panos Panay, Microsoft's Windows and devices chief. From a report: "With Windows 10X, we designed for flexibility, and that flexibility has enabled us to pivot our focus toward single-screen Windows 10X devices that leverage the power of the cloud to help our customers work, learn and play in new ways." Microsoft isn't saying exactly when single-screen devices like laptops will support Windows 10X, nor when dual-screen devices will launch with the OS. However, Windows 10X will launch on single-screen devices first. "We will continue to look for the right moment, in conjunction with our OEM partners, to bring dual-screen devices to market," says Panay. Microsoft is reprioritizing Windows 10X for laptops and single-screen devices because of the coronavirus pandemic. The software maker has seen a 75 percent year-over-year increase in the time spent in Windows 10. More people are turning to using their laptops or PCs instead of a smartphone or tablet during the lockdowns we've seen worldwide to work or study.
IT

Academics Turn PC Power Units Into Speakers To Leak Secrets From Air-Gapped Systems (zdnet.com) 102

Academics from an Israeli university have published new research last week showing how an attacker could turn a computer's power supply unit into a rudimentary speaker that can secretly transmit data from an infected host using audio waves. From a report: The technique, named POWER-SUPPLaY, is the work of Mordechai Guri, the head of R&D at the Ben-Gurion University of the Negev, in Israel. Over the last half-decade, Guri has been pioneering research into new covert data exfiltration channels. The techniques Guri has been developing can be used for stealing data through unconventional means. Guri has been developing these techniques specifically for extracting data from air-gapped systems -- computers isolated on local networks with no internet access. Such computers are often used on government or corporate networks to store sensitive data, such as classified files or intellectual property. Air-gapped systems are protected by several layers of defenses, on top of the "air gap," and you need novel data transmission techniques to go around these defenses. For example, some air-gapped systems don't have speakers, because it's been proven in the past that speakers could be abused to leak information from a secure system using inaudible sound waves.
Open Source

What Keeps Developers Happy? Contributing to Open Source (techrepublic.com) 64

This week long-time open source advocate Matt Asay warned employers that the best way to keep their developers happy was to let them contribute to open source projects: SlashData recently surveyed over 16,000 developers to see what makes them tick... what they care about. The data is collected in SlashData's State of the Developer Nation, though let me give you the tl;dr: 59% of developers contribute to open source software today. Why do they contribute? The top two reasons are: To improve coding skills and because they believe in open source.

Want to keep those developers happy and employed with you? Let them contribute...

[Y]our employees want to contribute both code and knowledge — they want to be part of something. Talking to Bert Hubert, founder of PowerDNS, a supplier of open source DNS software, services, and support, he stressed that an open source project must be "a fun place where people feel that they are learning things, that they're contributing things, that they're being valued." Perhaps not surprisingly, these are the same elements developers expect from their employers. By making open source a valued part of workplace expectations, employers tick both boxes.

Is it an absolute requirement that you encourage your developers to contribute to open source projects? No. But many of your best developers will chafe at keeping their talents locked up behind the firewall, and other developers simply won't apply if you have a reputation for being an open source scrooge.

The article was written by Matt Asay, a former COO of Canonical now working at AWS. (Right before becoming Canonical's COO, Matt answered questions from Slashdot readers).

The survey he cites also found that out of 17,000 developers they talked to, just 3% said they were paid to contribute to open source.

The other 97% contributed for free.
Google

Google's reCAPTCHA Is Being Used To Hide Phishing Pages (infosecurity-magazine.com) 20

An anonymous reader quotes Infosecurity magazine: New research from Barracuda Networks has revealed that cyber-criminals are increasingly using official reCAPTCHA walls to disguise malicious content from email security systems and trick unsuspecting users... [S]ophisticated scammers are beginning to use the Google-owned service to prevent automated URL analysis systems from accessing the actual content of phishing pages, and to make phishing sites more believable in the eyes of the victim, Barracuda Networks warned.

In fact, the security solutions provider observed a single phishing campaign that sent out 128,000 emails to a variety of organizations and employees using reCAPTCHA walls to conceal fake Microsoft log-in pages. This campaign used the lure of a voicemail receipt to fool users into solving the reCAPTCHA wall before being redirected to the malicious page, with any log-in info entered then sent straight to the scammers.

Security

20 Years Later, Creator of World's First Major Computer Virus Located in Manila (bbc.com) 100

"The man behind the world's first major computer virus outbreak has admitted his guilt, 20 years after his software infected millions of machines worldwide," reports the BBC: Filipino Onel de Guzman, now 44, says he unleashed the Love Bug computer worm to steal passwords so he could access the internet without paying. He claims he never intended it to spread globally.

And he says he regrets the damage his code caused. "I didn't expect it would get to the US and Europe. I was surprised," he said in an interview for Crime Dot Com, a forthcoming book on cyber-crime.

The Love Bug pandemic began on 4 May, 2000. Victims received an email attachment entitled LOVE-LETTER-FOR-YOU. It contained malicious code that would overwrite files, steal passwords, and automatically send copies of itself to all contacts in the victim's Microsoft Outlook address book. Within 24 hours, it was causing major problems across the globe, reportedly infecting 45 million machines...

He claims he initially sent the virus only to Philippine victims, with whom he communicated in chat rooms, because he only wanted to steal internet access passwords that worked in his local area. However, in spring 2000 he tweaked the code, adding an auto-spreading feature that would send copies of the virus to victims' Outlook contacts using a flaw in Microsoft's Windows 95 operating system.

"It's not really a virus," wrote CmdrTaco back on May 4, 2000. "It's a trojan that proclaims its love for the recipient and requests that you open its attachment. On a first date even! It then loves you so much that it sends copies of itself to everyone in your address book and starts destroying files on your drive...

"Pine/Elm/Mutt users as always laugh maniacally as the trojan shuffles countless wasted packets over saturated backbones filling overworked SMTP servers everywhere. Sysadmins are seen weeping in the alleys."
Microsoft

Beware of Emails Impersonating 'Microsoft Teams' Notifications (forbes.com) 23

Researchers at the email security company Abnormal Security have discovered "a multi-prong Microsoft Teams impersonation attack" involving "convincingly-crafted emails impersonating the automated notification emails from Microsoft Teams," reports Forbes: The aim, simply to steal employee Microsoft Office 365 login credentials. To date, the researchers report that as many as 50,000 users have been subject to this attack as of May 1.

This is far from your average phishing scam, however, and comes at precisely the right time to fool already stressed and somewhat disoriented workers. Instead of the far more commonly used "sort of look-alike" alerts and notifications employed by less careful cybercriminals, this new campaign is very professional in approach. "The landing pages that host both attacks look identical to the real webpages, and the imagery used is copied from actual notifications and emails from this provider," the researchers said. The attackers are also using newly-registered domains that are designed to fool recipients into thinking the notifications are from an official source...

As far as the credential-stealing payload is concerned, this is delivered in an equally meticulous way. With multiple URL redirects employed by the attackers, concealing the real hosting URLs, and so aiming to bypass email protection systems, the cybercriminals will eventually drive the user to the cloned Microsoft Office 365 login page.

Businesses

How Kickstarter's New Union Negotiated Terms For Pandemic-Related Layoffs (kickstarterunited.org) 55

"The COVID crisis has led to a 35% drop in live projects" says Kickstarter communications officer David Gallagher -- who points out that fees on those projects are the company's sole source of income. This led Kickstarter's CEO to announce "sweeping layoffs of up to 45 percent of employees," the union of Kickstarter employees tells Gizmodo. (Though Gallagher says the final numbers will first include some voluntary buyouts, followed by a re-assessment to "better understand the scale of any layoffs that may be required.")

But Kickstarter is also the first major tech company to unionize. So what happened next? An anonymous reader shares this report from the two-months-old Kickstarter United (KSRU) union: The bargaining unit was faced with the prospect of involuntary layoffs with two to three weeks of severance per year of employment in the midst of a global pandemic... After two weeks of bargaining, we negotiated a severance package that we are incredibly proud of, which has been unanimously ratified by KSRU.

The package prioritizes extended severance payments and health insurance coverage, and we were inspired to see dozens of our highest-paid colleagues volunteer to take layoffs in order to save jobs and increase payouts for lower-paid bargaining unit members. We also negotiated additional terms that are previously unheard-of in tech severance agreements, fulfilling another of our longstanding goals: moving our industry forward and demonstrating the necessity of organizing in tech.

The terms we won for our 86-member bargaining unit include:

- Four months of severance pay for all laid-off employees, both voluntary and involuntary.

- Continuing healthcare coverage increased by salary: four months for our higher-paid colleagues, and six months for those who make less than the bargaining unit's median salary.

- Recall rights for a full year, so that if an eliminated position becomes open again in the future, qualified laid-off workers will have priority consideration in filling it.

- A release from the non-compete and a modification of the non-solicitation clauses included in our original hiring agreements — an allowance unprecedented in tech that will enable our members to pursue new avenues of employment unfettered...

This experience has shown us how crucial it is for tech workers to unite, to leverage our collective strength, and to focus on lifting each other up and protecting one another. Kickstarter United is committed to standing alongside workers everywhere, helping to bring our collective visions for a fairer, more just world to life.

IT

Are Job Interviews Broken? (nytimes.com) 187

"Job interviews are broken," according to a recent New York Times piece by an organizational psychologist at Wharton who argues that his profession has "over a century of evidence on why job interviews fail and how to fix them..." The first mistake is asking the wrong kinds of questions. Some questions are just too easy to fake. What's your greatest weakness? Even Michael Scott, the inept manager in the TV show "The Office," aced that one: "I work too hard. I care too much...." Brainteasers turn out to be useless for predicting job performance, but useful for identifying sadistic managers, who seem to enjoy stumping people.

We're better off asking behavioral questions. Tell me about a time when... Past behavior can help us anticipate future behavior. But sometimes they're easy to game, especially for candidates with more experience... The second error is focusing on the wrong criteria. At banks and law firms, managers often favor people who went to the same school or share their love of lacrosse... A third problem: Job interviews favor the candidates who are the best talkers...

My favorite antidote to faking is to focus less on what candidates say, and more on what they do. Invite them to showcase their skills by collecting a work sample -- a real piece of work that they produced... Credentials are overrated, and motivation is underrated. It doesn't matter how much experience people have if they lack the drive to think creatively, work collaboratively and keep on learning.

The article's subheading argues "Instead of focusing on credentials, let's give candidates the chance to showcase their will and skill to learn." Any Slashdot readers want to share their own experiences?

And are job interviews broken?
Encryption

Documents Reveal FBI Head Defended Encryption for WhatsApp Before Becoming Fierce Critic (theguardian.com) 34

Christopher Wray, the FBI director who has been one of the fiercest critics of encryption under the Trump administration, previously worked as a lawyer for WhatsApp, where he defended the practice, according to new court filings. From a report: The documents, which were released late on Wednesday night as part of an unrelated matter, show Wray worked for WhatsApp in 2015 while he was an attorney for the Washington law firm of King & Spalding. While there are sparse details about the precise nature of the work, the filings indicate that Wray strongly defended the need for end-to-end encryption in his previous representation of WhatsApp, the popular messaging application owned by Facebook. Wray's earlier work -- which has not previously been public -- contradicts his current position on encryption, which protects users' communications and other data from being read by outsiders. The Trump administration and major technology companies like Facebook have been at odds over the need to offer customers encryption services, with the White House and law enforcement officials arguing the technology represents a security risk by protecting the communication of terrorists and criminals.
Firefox

New Firefox Service Will Generate Unique Email Aliases To Enter In Online Forms (zdnet.com) 70

An anonymous reader writes: Browser maker Mozilla is working on a new service called Private Relay that generates unique aliases to hide a user's email address from advertisers and spam operators when filling in online forms. The service entered testing last month and is currently in a closed beta, with a public beta currently scheduled for later this year, ZDNet has learned. Private Relay will be available as a Firefox add-on that lets users generate a unique email address -- an email alias -- with one click. The user can then enter this email address in web forms to send contact requests, subscribe to newsletters, and register new accounts. "We will forward emails from the alias to your real inbox," Mozilla says on the Firefox Private Relay website. "If any alias starts to receive emails you don't want, you can disable it or delete it completely," the browser maker said.
Privacy

Quibi, JetBlue and Others Gave Away Email Addresses, Report Says (variety.com) 13

An anonymous reader quotes a report from The New York Times: Millions of people gave their email addresses to Quibi, JetBlue, Wish and other companies (Warning: source may be paywalled; alternative source) -- and those email addresses got away. They ended up in the hands of advertising and analytics companies like Google, Facebook and Twitter, leaving the people with those email addresses more easily targeted by advertisers and able to be tracked by companies that study shopping behavior, according toa reportpublished on Wednesday. The customers unwittingly exposed their email addresses when signing up for apps or clicking on links in marketing emails, said the researcher Zach Edwards, who runs the digital strategy firm Victory Medium. In the report, he described the giveaway of personal data as part of a "sloppy and dangerous growth hack."

Mr. Edwards, a contributor to a recent studythat examined potential privacy violations by dating services like Grindr and OkCupid, wrote in the new report that one of the "most egregious" leaks involvedQuibi, a short-form video platform based in Los Angeles that is run by the veteran executives Jeffrey Katzenberg and Meg Whitman. Quibi went live on April 6, long after new data privacy regulations went into effect in Europe and California. People who downloaded the Quibi app were asked to submit their email addresses. Then they received a confirmation link. Clicking on the link made their email addresses available to Google, Facebook, Twitter and Snapchat, according to the report. Quibi said in a statement on Wednesday that data security "is of the highest priority" and that "the moment the issue on our webpage was revealed to our security and engineering team, we fixed it immediately."
"Mr. Edwards said customers were probably unaware of leaks at Wish, an e-commerce platform where hundreds of millions of email addresses were most likely exposed starting in 2018," the report adds. "When users clicked on links in marketing emails from the company, their email addresses were shared with Google, Facebook, Pinterest, PayPal and others, he wrote."

Other companies that suffered limited leaks included The Washington Post, JetBlue, and Mailchimp.
Security

WhatsApp: Israeli Firm 'Deeply Involved' In Hacking Our Users (theguardian.com) 9

WhatsApp has alleged in new court filings that an Israeli spyware company used US-based servers and was "deeply involved" in carrying out mobile phone hacks of 1,400 WhatsApp users, including senior government officials, journalists, and human rights activists. The Guardian reports: The new claims about NSO Group allege that the Israeli company bears responsibility in serious human rights violations, including the hacking of more than a dozen Indian journalists and Rwandan dissidents. For years, NSO Group has said that its spyware is purchased by government clients for the purpose of tracking down terrorists and other criminals and that it had no independent knowledge of how those clients -- which in the past have reportedly included Saudi Arabia and Mexico -- use its hacking software.

But a lawsuit filed by WhatsApp against NSO Group last year -- the first of its kind by a major technology company -- is revealing more technical details about how the hacking software, Pegasus, is allegedly deployed against targets. In the court filings last week, WhatsApp said its own investigation into how Pegasus was used against 1,400 users last year showed that servers controlled by NSO Group -- not its government clients -- were an integral part of how the hacks were executed. WhatsApp has said victims of the hack received phone calls using its messaging app, and were infected with Pegasus. Then, it said: "NSO used a network of computers to monitor and update Pegasus after it was implanted on users' devices. These NSO-controlled computers served as the nerve centre through which NSO controlled its customers' operation and use of Pegasus."

NSO has said in legal filings that it has no insight into how government clients use its hacking tools, and therefore does not know who governments are targeting. But one expert, John Scott-Railton of Citizen Lab, who has worked with WhatsApp on the case, said NSO's control of the servers involved in the hack suggests the company would have had logs, including IP addresses, identifying the users who were being targeted.
"Our products are used to stop terrorism, curb violent crime, and save lives. NSO Group does not operate the Pegasus software for its clients," the company said in a statement. "Our past statements about our business, and the extent of our interaction with our government intelligence and law enforcement agency customers, are accurate."

Slashdot Top Deals