this post was submitted on 03 Mar 2024
42 points (100.0% liked)

Cybersecurity

5507 readers
312 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities [email protected] [email protected] [email protected] [email protected] [email protected] [email protected] [email protected]

Notable mention to [email protected]

founded 1 year ago
MODERATORS
top 3 comments
sorted by: hot top controversial new old
[–] [email protected] 7 points 7 months ago (1 children)

On what grounds does Meta deserve the source code here? Unless Pegasus is considered a "derivative work," the most Meta should be able to demand is money.

[–] [email protected] 1 points 7 months ago (1 children)

They need to know how they were hacked so they can fix the vulnerability. NSO broke the law when they hacked whatsapp, it seems reasonable that they're forced to share details to prevent others from using the same method.

I'm wondering on what grounds is NSO allowed to keep the names of their co-conspirators (AKA clients) secret?

[–] [email protected] 1 points 7 months ago

I think it's reasonable to require them to share details, but source code is a copyright issue and shouldn't be given up. I'm guessing the source has a lot more than just the one attack.

But yeah, I'm also surprised they're not obligated to reveal the names of anyone involved in planning or ordering the attack. Surely that could be subpoenad.