WhatsApp forces Pegasus spyware maker to share its secret code
WhatsApp’s legal fight against NSO Group over Pegasus spyware is prompting questions about how far U.S. courts can reach into foreign companies and whether powerful states will quietly protect offensive cyber tools they also benefit from. Commenters examine sanctions, extraterritorial jurisdiction, and intelligence agency oversight, contrasting official blacklisting of NSO with the broader “commercial surveillance vendor” ecosystem used by governments worldwide. The thread also highlights tensions within cybersecurity work itself, where offensive research is often more lucrative and celebrated than defensive engineering, potentially undermining overall security.
Lawsuit, Discovery, and National-Security Angle
- NSO initially tried to block all discovery citing US and Israeli restrictions; commenters note US courts generally won’t care about foreign legal limits.
- Some speculate US intelligence agencies may rely on partners’ use of Pegasus rather than direct use, complicating any “national security” argument in court.
- Others expect any genuine national-security issue would appear as sealed filings, not a “mysteriously vanished” case.
- Several people question why NSO would hand over real source code rather than obfuscated material; others stress that courts can impose serious legal and financial consequences for non-compliance or fraud.
Jurisdiction, Extraterritoriality, and the Power of the Dollar
- A major thread explains US jurisdiction over foreign firms via:
- Doing business that harms parties in the US.
- Use of the US financial system and dollar clearing.
- Commenters emphasize that even foreign banks must comply or risk being cut off from US markets, which is economically crippling.
- Some describe this as “extraterritoriality” and give European corporate examples; others see it simply as the practical reach of a dominant financial system.
- There is debate over whether jurisdiction stems from the use of USD specifically or from broader political and banking dependencies.
Sanctions, Israel, and Geopolitics
- Multiple comments note NSO has been blacklisted/sanctioned, but appears still active.
- Some argue politics explains why Israel and NSO aren’t more heavily punished, citing Israel’s role as a security and arms “cut-out” for Western interests.
- Others suggest Western states may benefit indirectly from having a friendly vendor selling offensive tools, even to abusive regimes.
Cybersecurity Work and Incentives
- One subthread criticizes the incentive structure: offensive research and bug bounties get money and prestige, while defensive engineering is under-rewarded and hard to measure.
- Others counter that much of the field is defensive and that many well-known figures work on defense, though teams like Project Zero blur lines (offensive methods for defensive goals).
Messaging Apps and Exploits
- Several comments stress that once Pegasus gains device-level (root) access, app-level security (Signal, WhatsApp) offers little protection; spyware can read data, screenshots, etc.
- Some argue Apple and Google could “disable Pegasus” by closing known vulnerabilities; others note specific Pegasus-related bugs have been patched but new ones can appear.
Language Digression (“Could Care Less”)
- A large side debate erupts over the correctness of “could care less” vs. “couldn’t care less,” touching on idioms, descriptivist vs prescriptivist views of grammar, and how meaning is determined by usage.