Tag: foreign surveillance

Apple sues NSO Group over “Pegasus” spyware

30. November 2021

On November 25th, Apple announced in a press release that it has filed a lawsuit against NSO Group Technologies Ltd. (NSO Group) to hold them accountable for their spy software “Pegasus”.

NSO Group is a technology company that supplies surveillance software for governments and government agencies. Applications like Pegasus exploit vulnerabilities in software to infect the target’s devices with Trojans. Pegasus is a spyware that can be secretly installed on cell phones (and other devices) running most iOS and Android versions. Pegasus is not a single exploit, but a series of exploits that exploit many vulnerabilities in the system. Some of the exploits used by Pegasus are zero-click, which means that they can be executed without any interaction from the victim. It is reorted to be able to read text messages, track calls, collect passwords, track location, access the microphone and camera of the targeted device, extract contacts, photos, web browsing history, settings and collect information from apps.

NSO Group is accused of selling its software to authoritarian governments, which use it to monitor journalists and the opposition. Accusations that the company regularly denies. According to an investigation done by a global consortium of journalists of 17 media oganizations, Pegasus has been used to monitor female journalists, human rights activists, lawyers and high-ranking politicians. There are even reports suggesting it is even used by Mexican drug cartels to target and intimidate Mexican journalists. Among the more famous confirmed Pegasus victims are Amazon founder Jeff Bezos and murdered Saudi Arabian journalist Jamal Kashoggi.

Apple wants to prevent “further abuse and harm” to Apple users. The lawsuit also demands unspecified compensation for spying on users.

In the press release Apple states:

NSO Group and its clients devote the immense resources and capabilities of nation-states to conduct highly targeted cyberattacks, allowing them to access the microphone, camera, and other sensitive data on Apple and Android devices. To deliver FORCEDENTRY to Apple devices, attackers created Apple IDs to send malicious data to a victim’s device — allowing NSO Group or its clients to deliver and install Pegasus spyware without a victim’s knowledge. Though misused to deliver FORCEDENTRY, Apple servers were not hacked or compromised in the attacks.

Ivan Krstić, head of Apple Security Engineering and Architecture is quoted:

In a free society, it is unacceptable to weaponize powerful state-sponsored spyware against those who seek to make the world a better place

Apple has announced the lawsuit contains new information about the so-called ForcedEntry exploit for a now-closed vulnerability that NSO Group used to “break into a victim’s Apple device and install the latest version of NSO Group’s Pegasus spyware program,” according to Apple’s press release. The vulnerability was originally discovered by Citizen Lab, a research group at the University of Toronto. Apple says it will support organizations like Citizen Lab and Amnesty Tech in their work, and will donate $10 million and any compensation from the lawsuit to organizations involved in researching and protecting against cyber surveillance. The company will also support Citizen Lab with free technology and technical assistance.

Apple is the second major company to sue NSO Group after WhatsApp Inc. and its parent company Meta Platforms, Inc.(then Facebook, Inc.) filed a complaint against NSO Group in 2019. The allogation of that lawsuit is that NSO Group unlawfully exploited WhatsApp’s systems to monitor users.

In early November 2021, the US Department of Commerce placed NSO Group on its “Entity List”. The justification for this step states that Pegasus was used to monitor government officials, journalists, business people, activists, academics and embassy staff. On the “Entity List,” the U.S. government lists companies, individuals or governments whose activities are contrary to the national security or foreign policy interests of the United States. Trade with these companies is subject to strict restrictions and in some cases is only possible with an exemption from the Department.

Germany’s Constitutional Court curbs Federal Intelligence Service’s competence

16. June 2020

In a court ruling from May 19th 2020 with regards to the German Federal Intelligence Service (BND) and their manner of operation, the German Constitutional Court has proclaimed that the BND is bound by fundamental rights in cases of surveillance of foreigners, even outside of Germany’ federal territory.

 Background

The case, which was brought to the court in the manner of a constitutional complaint by a collective of foreign journalists, found its origin initially through the disclosures made by Edward Snowden back in 2013, where some of the BND’s practices in relation to strategic foreign surveillance came to light. In 2016, German legislators passed a new law with the purpose to regulate surveillance done by the BND. However, that new law mainly restricted surveillance of German citizens, as well as foreigner living in Germany. It has been criticized that the new law did nothing to restrict and regulate the BND’s actions abroad by not having to abide by any legal provisions. The constitutional complaint brought to the German Constitutional Court deals with strategic surveillance from foreign reporters and journalists with regards to their highly confidential data necessary to perform their work through the BND, which risks to be exchanged with their own country’s intelligence agencies and in the process put them at risk of federal measures taken against them.

The key points

Territorial Scope. One of the biggest points of the court ruling has been the definition of the territorial scope of the fundamental rights at risk in this case. Since the complainants are journalists from outside the German territory, the Constitutional Court had to specify if the constitutional rights that would shield them from surveillance by the BND would find application in the matter. In this instance, the court has ruled that the fundamental rights are not limited to the German territory, but rather apply wherever the German state authority is acting. This is derived from Art. 1 III of the German Constitution (GG), which binds the German state authority to conformity with the Constitution. In such, as the fundamental rights from Art. 10 I, Art. 5 I GG are not simply applicable to Germans, the Constitutional Court has extended the range of application to foreigners in foreign countries, and given them international importance.

Current legislation is unconstitutional. In effect, the Constitutional Court has further analysed the new intelligence law from 2016, and ruled it unconstitutional in the current state. The main reason is that, due to the fact that the legislators assumed that the fundamental rights did not apply, they did not conform with the requirements set out in the Constitution for such law. In such, the new law violates the privacy of telecommunications and its requirements from Art. 10 I GG, and in addition does not meet the key requirements deriving from other fundamental rights, such as Art. 19 I GG. However, the Constitutional Court has stated that the law can be amended to follow fundamental rights and comply with the constitution. The court declared several points which are necessary to implement in the amended law, some of which we will present further below.

Independent oversight. The Constitutional Court stated that in order to ensure conformity with the Constitution and regulate the BND in a way that would ensure the protection of fundamental rights of the people under surveillance, it would be necessary to establish a new, independent oversight regime that would act to judge and regulate strategic surveillance. Its main purposes would be the legal oversight of the BND and protection of the surveillance subjects, as well as the control of the surveillance process, from the analysing of data to the transfer of information between agencies, etc.

Legislative suggestions. In the ruling of the case, the Constitutional Court also made a few suggestions in regards to potential statutory regulation in order to regulate the BND and its area of action better than it was in the past. Part of those suggestions were the necessity of defining the purpose of surveillance measures with precision and clarity, in order to ensure transparency, as well as the necessity for the legislator to set out essential framework for the analysis of the collected data, like a cease in analysis as soon as it becomes clear that the surveillance has touched the core of private life. The court also suggested that special requirements have to apply to the protection of professional groups with communications of increased confidentiality, and that the surveillance in these cases must be tied to qualified thresholds. The court also mentioned the storage and deletion of surveillance data, stating that the traffic data obtained should not be stored for longer than six months, while a systematic deletion policy needs to be established. In the terms of the transfer of information to other (foreign) intelligence agencies, the Constitutional Court made it clear that such transfers will need an official statutory basis in order to be lawful.

The court has given the German government until the end of 2021 to amend the law and make statutory changes to comply with the ruling and the decision of the international scope of the fundamental rights. While this may seem like a big set back for the BND, it is a chance to show that intelligence agencies can work on a high constitutional standard while also being successful in their purpose.