back to article Super spyware maker NSO must pay Meta $168M in WhatsApp court battle

A California jury has awarded Meta more than $167 million in damages from Israeli surveillanceware slinger NSO Group, after the latter exploited a flaw in WhatsApp to allow its government customers to spy on supposedly secure communications. In May 2019 engineers at WhatsApp discovered a zero-click, zero-day vulnerability in …

  1. elDog

    "... and numerous security operations that have saved many lives ..." Ask Khashoggi's relatives, ...

    Pegasus has probably been used for many such operations. They can cloak their terms in statements that it should only be used by benevolent "state actors" but everyone knows, everyone knows that the darkest forces on earth will also be using it.

    This is why state-mandated back-doors into privacy functions will be ultimately used for ill purposes. Whether by the states or by the rest of the criminals.

  2. Anonymous Coward
    Anonymous Coward

    A pox on all their houses

    Who in their right mind would have anything to do with these showers?

    1. Anonymous Coward
      Anonymous Coward

      Re: A pox on all their houses

      I guarantee the only reason you think your country of residence hasn't used them is because they've either not been caught yet or have their own exploits to use and don't need NSO

  3. Anonymous Coward
    Anonymous Coward

    What is really interesting.........

    .....is that when NSO/Pegasus is installed on an end point.........

    .....it DOES NOT MATTER if the user uses Signal or Telegram or WhatsApp.............

    .....everything that user does on that end point is available (in plain) to the scumbag who installed NSO/Pegasus!!!!

    (1) Ask Angela Merkel!!!

    (2) ....or Peter Hegseth

    (3) ....or Mike Waltz

    (4) ....or maybe Joe Biden

    ......or maybe YOU!!

    Paranoid?..........No, not me!

    1. Mr Dogshit

      Re: What is really interesting.........

      Well DUH

      If you walk around all day carrying a small and powerful computer running a complex operating system which by definition will contain bugs and you're of interest to someone somewhere, then you're gonna get fucked over.

      See the book "Pegasus: The Story of the World's Most Dangerous Spyware" by Laurent Richard and Sandrine Rigaud

  4. Grindslow_knoll

    I think it's well understood that E2E only secures the protocol, not the endpoints, as noted above.

    The interesting thing here is that a company that survives by harvesting personal data they persuade people to hand over for free, then sues a spyware company.

    I think Tery Pratchett would be hard pressed to come up with a cheeky plotline like this.

    If the zero day was in Signal, it would be fixed, and that'd be that.

    But I imagine Meta is making the point that only they have the right to hover personal data from the E2E mirage, and if anyone else wants in (C-Analytica), they need to sign on the dotted line with a hefty cheque.

    That is the crossed line, and the rest is PR.

    1. Anonymous Coward
      Anonymous Coward

      it's in the article

      "WhatsApp's engineers patched the flaw within days. "

      The zero day was patched in days, NSO didn't and don't have just the one undisclosed vulnerability, they literally spend tens of millions every year buying, finding and developing ways to exploit them and, as you yourself say, nothing is safe if they compromise an endpoint.

      Which they have done and continue to do in multiple ways.

  5. lostinspace

    How exactly is NSO any different to any illegal hacking organisation that sells malware?

    Why do NSO get some sort of legitimacy rather than being locked up in prison?

    1. Anonymous Coward
      Anonymous Coward

      They're state backed.

      1. Anonymous Coward
        Anonymous Coward

        State backed by Israel. If they were state backed by any other nation then the US would have no problem with pursuing criminal penalties.

        1. Furious Reg reader John

          Ah, the Jews control the US theme surfaces.

          1. Anonymous Coward
            Anonymous Coward

            Regardless of any antisemitic root to their comment, NSO is state backed by Israel and Israel gets an easy ride because of a tragic history which the current Israeli government seems intent on inflicting on Palestine

            1. Furious Reg reader John

              Ah, the Jews are Nazis theme emerges.

  6. alain williams Silver badge

    What about compensation to those attacked ?

    Q: So Meta gets $168M but what will be paid to those who's 'phones were infected and suffered real damage ?

    A: Nothing.

    As usual real justice does not happen.

  7. PCScreenOnly

    Can we sue meta for their unsolicited data hovering

    Just asking

  8. mark l 2 Silver badge

    Well now its been established they can be sued in the US and NSO admit their spyware is being installed on both iOS and Android devices, I would say its time that both Apple and Google should be contacting their lawyer as well. I'm not usually one to propose suing but in this case I say lets bring on the fines until the scumbags run out of money.

    And if you work for NSO I hope that you don't own any electronic devices as no doubt the people you sell the spyware to will be spying on you with your own software.

  9. Anonymous Coward
    Anonymous Coward

    I am a iPHONE user who is SUPER GEEKY on my old iPHONE-8 I had 2000 apps from the APP store.

    the iPHONE-8 worked perfectly until I upgraded it to the latest iOS version then it BROKE. I believe NSO spyware uses APPs from the APPLE APP store to install PEGASUS spyware on the iPHONE

    so everyone who has 100s of APPs is attacked by NSO spyware. I hope ALL of the TECH companys sue this company out of buisiness so people can use thier iPHONE without the NSO spyware bothering them.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like