Is the crackdown on US spyware companies just starting? | New Cybersecurity

[ad_1]
Washington, DC – In this increasingly malicious surveillance software industry, the Israeli company NSO Group was created this year as the undisputed poster that lands in the wrong hands of digital spyware.
In july The Pegasus project The collaboration with Amnesty International and a media coalition revealed that the NSO software had been sold to authoritarian governments used to spy on political leaders, journalists, executives and human rights activists, including people close to the dead Saudi journalist Jamal Khashoggi.
It is unclear who directed the attacks. The NSO denied that its software was used by Khashoggi or members of its inner circle and undertook to conduct an investigation into its customers. He also said he would cooperate with any government consultation.
But controversy has surrounded the Pegasus spyware for years.
A month before the Pegasus Project bombs were dropped, the NSO released a “Transparency and Accountability Report” in which it said it had taken “specific steps to mitigate and prevent future misuse of its spyware.”
By November, however, U.S. President Joe Biden had taken action. In an unusual move against an Israeli company, the U.S. Department of Commerce added the NSO to its “entity” list – a blacklist this prevents access to US software and services. The Biden administration accused the NSO of “engaging in activities contrary to the interests of U.S. national security or foreign policy,” according to a statement from the Commerce Department.
The NSO then issued a statement saying it was “disappointed” with the Biden administration’s decision and that its technologies “support the interests and policies of U.S. national security by preventing terrorism and crime.”
But in December, the controversy re-entered the NSO. Reuters reported that at least nine U.S. State Department employees were killed he was hacked Using spyware from the Israeli company, a group of U.S. lawmakers sent a letter to the U.S. Treasury and State Department requesting that the NSO and its top executives be punished under the Global Magnitsky Act.
In the middle of the month, Bloomberg News reported The NSO was considering closing its Pegasus unit, citing people who knew the subject.
And this week, The Washington Post reported A new forensic analysis at CitizenLab in Toronto found that Pegasus software had been used to hack the phone of a member of Jamal Khashoggi’s inner circle a month before he was killed.
While the NSO remains the owner, it is not the only Washington-based surveillance surveillance software company.
In November, the Commerce Department added two other foreign spyware companies to its blacklist, and U.S. lawmakers this month also called on the Biden administration to blacklist U.S. spy companies DarkMatter and European surveillance companies Nexa Technologies and Trovicor.
But as a new year approaches, experts say the Biden administration can do more to address the spread of spyware technology, both through legitimate sales and through black market cyber-weapon vendors.
Effective on a level
Winnona DeSombre is a member of the Atlantic Council’s Cyber Statecraft Initiative and is the lead author of a 20-year report from 224 cyber surveillance companies that sold software at gun fairs, such as France’s Milipol, where hacking tools were offered side by side. -with cannons and tanks on the side.
“It’s much easier to write a piece of code than to create a tank,” he told Al Jazeera. “And it’s much easier to create software that does mass surveillance than to create a ballistic missile program without being caught.”
DeSombre said the November blacklist of NSO and two other spyware companies is effective in part because they make it harder for them to do business.
He also noted that most of the firms in which many of these companies participate are located in Europe, which allows the European Union and the US to limit some of their behavior.
But it says that punishing NSO and other spyware companies and their executives under the Global Magnitsky Act would still scratch the surface.
“Legislators need to look at enforcing responsible limits on similar NSO companies that are still operating in the shadows,” he said.
Other experts say that government action alone is not enough to eradicate the threat posed by spies to human rights.
The Pegasus hack of nine State Department employees’ phones “makes it clear how vulnerable we all are,” said Oona A Hathaway, founder and director of the Global Legal Challenges Center at Yale Law School.
Hathaway told Al Jazeera that governments can do so much to criminalize and punish the malicious use of invasive software. “Ultimately, it will take a collaborative effort between private and public actors to tackle the problem,” he said.
The private sector is making moves to prevent spy abuse. In late November, Apple filed a lawsuit Against the NSO Group and its parent company, “Apple is responsible for the care and goals of its users,” according to a company statement. Apple also told the NSO Group that it is seeking a permanent injunction banning Apple from using any of its software, services or devices “to prevent further abuse and harm to its users”.
Meanwhile, the White House is seeking international partners to help slow the proliferation of cyber surveillance technologies. At the inauguration Summit for Democracy in December, the Biden administration announced an export control and human rights initiative by the US, Australia, Denmark and Norway.
Countries pledged to work together to limit exports of surveillance tools and other technologies that authoritarian governments could use to suppress human rights. Canada, France, the Netherlands and the United Kingdom were in favor of the initiative.
The goal, the White House said, is to “bring together policy makers, technical experts and export control and human rights professionals to ensure that critical and emerging technologies work for and not against democratic societies.”
It was a step towards what DeSombre said was necessary to deal with the threat.
“I think a lot of that has started to happen, but I still haven’t seen anything happen,” he said.
[ad_2]
Source link