What are the current trends associated with commercial spyware?ÌęÌę
Used for both military and civil purposes, , often referred to as â,â is software that works through non-consensual infection of a userâs device to monitor their activity and collect data, all while remaining undetected. Government actors commonly use this software to facilitate on individuals to âfight terrorism,â but in reality, it is being infamously used against dissenting civilians and politicians, posing a threat to the safety of these individuals. One notorious spyware product used by governments is the âPegasus Spyware,â developed and sold by the Israeli NSO Group Technologies (NSO) company. Founded in 2009 NSO is an acronym of its founders began as a technology start-up headed by Shalev and Omri, two entrepreneurial high school friends. Niv, a former Mossad operative (a member of Israel's National Intelligence Agency), was later brought on to market the group's technology within the military intelligence community. NSO only sells its surveillance software to government law-enforcement and intelligence agencies globally and its exports are governed by the Israeli Ministry of Defence.Ìę
NSO introduced Pegasus to the in 2011 and the Mexican authorities were one of the few governments to publicly announce its purchase in 2012, whereas European investigators were secretly using Pegasus in the prevention of terrorist schemes and organized crime. Surreptitiously, with NSO, such as Saudi Arabia, United Arab Emirates and Morocco. The spyware technology has become increasingly powerful as governments are using this software under the guise of state security permitting them to spy on individuals without warrant thus, that usually protect individuals living in democracies. NSO and its spyware have consistently been criticized for facilitating human rights violations. Most recently, they made headlines for allegedly undermining the security of technology companies and the safety of their infrastructure, according to multiple lawsuits launched against NSO by companies including WhatsApp (owned by Meta) and Apple.ÌęÌę
Little is publicly known about how spyware firms operate, mainly because most deal exclusively with governments within secretive public-private transactions. The ongoing lawsuits by these companies against NSO will further expose the opaque and problematic business models of such surveillance technology firms. The business model at hand refers to NSOâs strategies for profitability, including how the firm develops its products, the services it provides, and its trade plans.ÌęÌę
Ìę
How does it work?Ìę
Originally, NSO was able to carry out a of the targeted person by transmitting malicious spyware code through a WhatsApp call; the targeted person did not even have to answer the call. After WhatsApp fixed the vulnerabilities which allowed this exploit in 2019, NSO developed a âzero-clickâ technique called â,â where the Pegasus hacking software can turn a device into a 24-hour surveillance device. The governments and law-enforcement agencies that deploy such spyware have access to the victimâs personal data and can control the camera and microphone to gather any information on the targeted person. argues that its spyware services are created to âhelp government agencies prevent and investigate terrorism and crimeâŠ[aiming]âŠto save thousands of livesâ. However, this technology not only undermines internationally recognized human rights, including , but it also poses a threat to the voice of journalists and human rights activists that represent civiliansâ opinions against governmental interests. It doesnât end there; NSOâs product development also depends on its encroachment onto the property of other technology companies to weaken the pillars of their security and undermine the safety of their products and services.ÌęÌę
What does the business model look like?ÌęÌę
recognizes that the business model of surveillance-technology firms ârelies on the ongoing discovery and exploitation of vulnerabilities in widely used third-party digital operating systems.â This business model is aimed at assaulting usersâ right to privacy when monetizing data about civilians. Surveillance-technology firms like NSO grow and profit by continuously undermining the products of other technology manufacturers such as iOS, Windows, and commonly used messaging services. These attacks not only create less secure products for the users of technology companies but also generate costs for these technology manufacturers when they have to improve their infrastructure or remedy reputational damage, reassure investors, etc... In other words, the operation of NSO surveillance products rests on compromising other companiesâ efficacy and public standing. The ongoing and lawsuits are examples of how companies are attempting to fight back against the harms caused by spyware firms and help ensure the safety of their users and products. These lawsuits provide insight into the strategies used by NSO, revealing their vectors of attack and how they profit from the targeted surveillance of political oppositions.Ìę
-
WhatsApp v NSOÌęÌę
In their 2019 lawsuit against NSO, WhatsApp sought an injunction before the U.S. Ninth Circuit Court to block NSOâs access to Metaâs platforms and servers and sought to recover damages from NSO for allegedly targeting around 1,400 users of its messaging services. WhatsAppâs claims against NSO included and of its Meta servers and products, breach of contract, and wrongful trespass on Metaâs property. WhatsApp alleged that NSO violated its user agreement terms when it relied its Spyware operation on vulnerabilities found in WhatsAppâs security infrastructure. In their lawsuit, WhatsApp also claimed that NSO committed wrongful trespass when it transmitted harmful software through WhatsAppâs platform to gain unauthorized access to user information.ÌęÌę
An was prepared by international non-governmental and non-profit organizations, like Amnesty International and Access Now, who have been closely monitoring NSOâs operations and fighting for the protection of digital human rights. These organizations filed the brief to draw the courtâs attention to the international law and human rights concerns that weigh against NSOâs defence in this lawsuit. The brief highlighted NSOâs lack of consideration for (UNGPs). These non-state watchdog organizations criticized NSO for prioritizing profits from governments over the detrimental effects on human rights and the stability of other third-party technology companies in its cost-benefit analysis. According to the firm displayed a lack of regard for business policies and processes that ensure human rights obligations, a lack of active engagement in performing human rights due diligence, and a failure to implement remedies when its business dealings or relationships contributed to adverse impacts.Ìę
-
Apple v NSOÌęÌę
In November of 2021, Apple filed a lawsuit against NSO to hold it accountable for the surveillance and targeting of Apple users by seeking damages and a permanent injunction to ban NSO from using any Apple software services or devices. This complaint revealed new ways through which the NSO could infect victimsâ devices, developed by NSO as a response to the improvements made to WhatsAppâs security infrastructure. Apple characterizes these cyberattacks as a threat to Appleâs self-professed reputation of making ââ and a threat to the safety of its products as well as the customerâs trust in the company.ÌęÌę
NSO has been aiming to dismiss the lawsuits entirely by , claiming that the lower courts have failed to recognize the firm as a âforeign government agentâ entitled to foreign sovereign immunity from lawsuits in the U.S. This argument is , according to pundits. However, if the court were to accept NSOâs claims that it is a â,â the precedent would enable further concealment of NSOâs business dealings, foreign governmentsâ abusive applications of NSOâs spyware technology, and the firmâs technological toolkit.ÌęÌę
Ìę
What are the revelations from the lawsuits?Ìę
These lawsuits will give exclusive access into the opaque business model of spyware surveillance companies, giving the public a better understanding of their operations and corporate governance. Consequently, the findings from these cases could be used to investigate and potentially ban different surveillance companies with similar business models according to a standardized set of criteria. Although the US has , the US department of commerce should extend the decision to a wider range of spyware firms with similar business models. Accordingly, US bans on similar spyware firms could lead to these businesses struggling to operate without access to the American market.ÌęÌę
Governmental restrictions on the sale and use of spyware in the U.S. could spark a chain reaction, leading more countries or transnational bodies to implement bans. The U.S. would not be the first country to call for greater restrictions on the commercial trade of cyber-surveillance technologies. On April 13th, 2022, Costa Rica became the first country to call for a global moratorium on spyware technology. This is These moratoriums could apply to the sale, transfer and use of such technology and be critical of firms that invest in or adopt a business model similar to NSOâs.Ìę
The lawsuits against NSO are shedding a light on the how spyware firms operate, highlighting their reliance on an intrusive and unethical basis of conducting operations. These findings will provide actors with the legitimate grounds to call for the ban on surveillance corporations with similar business models, to diminish the scale of their business processes, and protect the welfare of both civilians and companies.Ìę
Ìę