{"id":45598,"date":"2021-10-24T12:25:39","date_gmt":"2021-10-24T19:25:39","guid":{"rendered":"https:\/\/www.politicsplus.org\/blog\/?p=45598"},"modified":"2021-10-24T12:25:39","modified_gmt":"2021-10-24T19:25:39","slug":"everyday-erinyes-289","status":"publish","type":"post","link":"https:\/\/www.politicsplus.org\/blog\/2021\/10\/24\/everyday-erinyes-289\/","title":{"rendered":"Everyday Erinyes #289"},"content":{"rendered":"<p>Experts in autocracies have pointed out that it is, unfortunately, easy to slip into normalizing the tyrant, hence it is important to hang on to outrage. These incidents which seem to call for the efforts of the Greek Furies (Erinyes) to come and deal with them will, I hope, help with that. As a reminder, though no one really knows how many there were supposed to be, the three names we have are <span style=\"color: #800000;\"><strong>Alecto<\/strong><\/span>, <strong><span style=\"color: #800000;\">Megaera<\/span><\/strong>, and <strong><span style=\"color: #800000;\">Tisiphone<\/span><\/strong>. These roughly translate as &#8220;unceasing,&#8221; &#8220;grudging,&#8221; and &#8220;vengeful destruction.&#8221;<\/p>\n<p>We&#8217;ve talked a great deal here about technology used by governments to spy on its citizens. This article is a bit of an update on some of the latest technology. &#8220;Pegasus&#8221; &#8211; it sounds so benign, doesn&#8217;t it? Images of unicorns and My Little Ponies come to mind. And I won&#8217;t even go so far as to say &#8220;This is the dark side,&#8221; because this technology can definitely be used for good. (Don&#8217;t you just wish it were being used right this moment to track Bannon? And a few choice others?) But it wll never be used effectively for good as long as it is being used by people who think they can tell a &#8220;bad guy&#8221; by looking at someone.<br \/>\n================================================================<\/p>\n<h1 class=\"legacy\">What is Pegasus? A cybersecurity expert explains how the spyware invades phones and what it does when it gets\u00a0in<\/h1>\n<figure><img decoding=\"async\" src=\"https:\/\/images.theconversation.com\/files\/415046\/original\/file-20210806-90251-104b4rt.jpg?ixlib=rb-1.1.0&amp;rect=8%2C0%2C5455%2C3645&amp;q=45&amp;auto=format&amp;w=754&amp;fit=clip\" \/><figcaption>A woman holds a phone in front of the office of NSO Group, which makes a tool that can see and hear everything a phone is used for.<br \/>\n<span class=\"attribution\"><a class=\"source\" href=\"https:\/\/www.gettyimages.com\/detail\/news-photo\/an-israeli-woman-uses-her-iphone-in-front-of-the-building-news-photo\/596871396\">Jack Guez\/AFP via Getty Images<\/a><\/span><\/figcaption><\/figure>\n<p><a href=\"https:\/\/theconversation.com\/profiles\/bhanukiran-gurijala-1255497\">Bhanukiran Gurijala<\/a>, <em><a href=\"https:\/\/theconversation.com\/institutions\/west-virginia-university-1375\">West Virginia University<\/a><\/em><\/p>\n<p>End-to-end encryption is technology that scrambles messages on your phone and unscrambles them only on the recipients\u2019 phones, which means anyone who intercepts the messages in between can\u2019t read them. Dropbox, Facebook, Google, Microsoft, Twitter and Yahoo are among the companies whose apps and services <a href=\"https:\/\/www.eff.org\/encrypt-the-web-report\">use end-to-end encryption<\/a>.<\/p>\n<p>This kind of encryption is good for protecting your privacy, but <a href=\"https:\/\/www.washingtonpost.com\/politics\/2021\/03\/04\/cybersecurity-202-fbi-renews-attack-encryption-ahead-another-possible-attack-capitol\/\">governments don\u2019t like it<\/a> because it makes it difficult for them to spy on people, whether tracking criminals and terrorists or, as some governments have been known to do, snooping on dissidents, protesters and journalists. Enter an Israeli technology firm, <a href=\"https:\/\/www.nsogroup.com\/\">NSO Group<\/a>.<\/p>\n<p>The company\u2019s flagship product is Pegasus, <a href=\"https:\/\/techterms.com\/definition\/spyware\">spyware<\/a> that can stealthily enter a smartphone and gain access to everything on it, including its camera and microphone. Pegasus is designed to infiltrate devices running Android, Blackberry, iOS and Symbian <a href=\"https:\/\/techterms.com\/definition\/operating_system\">operating systems<\/a> and turn them into surveillance devices. The company says it sells Pegasus <a href=\"https:\/\/www.nsogroup.com\/about-us\/\">only to governments<\/a> and only for the purposes of tracking criminals and terrorists.<\/p>\n<h2>How it works<\/h2>\n<p><a href=\"https:\/\/economictimes.indiatimes.com\/tech\/trendspotting\/what-is-pegasus-spyware-and-how-it-works\/articleshow\/84607533.cms\">Earlier version of Pegasus<\/a> were installed on smartphones through <a href=\"https:\/\/nvd.nist.gov\/vuln\">vulnerabilities<\/a> in commonly used apps or by <a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/definition\/spear-phishing\">spear-phishing<\/a>, which involves tricking a targeted user into clicking a link or opening a document that secretly installs the software. It can also be installed over a wireless <a href=\"https:\/\/www.pcmag.com\/encyclopedia\/term\/transceiver\">transceiver<\/a> located near a target, or manually if an agent can steal the target\u2019s phone.<\/p>\n<figure class=\"align-right zoomable\"><a href=\"https:\/\/images.theconversation.com\/files\/415050\/original\/file-20210806-19-17pnxr8.jpg?ixlib=rb-1.1.0&amp;q=45&amp;auto=format&amp;w=1000&amp;fit=clip\"><img decoding=\"async\" src=\"https:\/\/images.theconversation.com\/files\/415050\/original\/file-20210806-19-17pnxr8.jpg?ixlib=rb-1.1.0&amp;q=45&amp;auto=format&amp;w=237&amp;fit=clip\" sizes=\"(min-width: 1466px) 754px, (max-width: 599px) 100vw, (min-width: 600px) 600px, 237px\" srcset=\"https:\/\/images.theconversation.com\/files\/415050\/original\/file-20210806-19-17pnxr8.jpg?ixlib=rb-1.1.0&amp;q=45&amp;auto=format&amp;w=600&amp;h=400&amp;fit=crop&amp;dpr=1 600w, https:\/\/images.theconversation.com\/files\/415050\/original\/file-20210806-19-17pnxr8.jpg?ixlib=rb-1.1.0&amp;q=30&amp;auto=format&amp;w=600&amp;h=400&amp;fit=crop&amp;dpr=2 1200w, https:\/\/images.theconversation.com\/files\/415050\/original\/file-20210806-19-17pnxr8.jpg?ixlib=rb-1.1.0&amp;q=15&amp;auto=format&amp;w=600&amp;h=400&amp;fit=crop&amp;dpr=3 1800w, https:\/\/images.theconversation.com\/files\/415050\/original\/file-20210806-19-17pnxr8.jpg?ixlib=rb-1.1.0&amp;q=45&amp;auto=format&amp;w=754&amp;h=502&amp;fit=crop&amp;dpr=1 754w, https:\/\/images.theconversation.com\/files\/415050\/original\/file-20210806-19-17pnxr8.jpg?ixlib=rb-1.1.0&amp;q=30&amp;auto=format&amp;w=754&amp;h=502&amp;fit=crop&amp;dpr=2 1508w, https:\/\/images.theconversation.com\/files\/415050\/original\/file-20210806-19-17pnxr8.jpg?ixlib=rb-1.1.0&amp;q=15&amp;auto=format&amp;w=754&amp;h=502&amp;fit=crop&amp;dpr=3 2262w\" alt=\"Close-up of an icon on a smartphone screen\" \/><\/a><figcaption><span class=\"caption\">Pegasus can infiltrate a smartphone via the widely used messaging app WhatsApp without the phone\u2019s user noticing.<\/span><br \/>\n<span class=\"attribution\"><a class=\"source\" href=\"https:\/\/flickr.com\/photos\/140988606@N08\/25076398627\/\">Christoph Scholz\/Flickr<\/a>, <a class=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\">CC BY-SA<\/a><\/span><\/figcaption><\/figure>\n<p>Since 2019, Pegasus users have been able to install the software on smartphones with a <a href=\"https:\/\/economictimes.indiatimes.com\/tech\/trendspotting\/what-is-pegasus-spyware-and-how-it-works\/articleshow\/84607533.cms\">missed call on WhatsApp<\/a>, and can even delete the record of the missed call, making it impossible for the the phone\u2019s owner to know anything is amiss. Another way is by simply sending a message to a user\u2019s phone that produces no notification.<\/p>\n<p>This means the latest version of this spyware does not require the smartphone user to do anything. All that is required for a successful spyware attack and installation is having a particular vulnerable app or operating system installed on the device. This is known as a <a href=\"https:\/\/www.news18.com\/news\/tech\/explained-what-are-zero-click-hacks-and-why-are-they-such-a-menace-3988664.html\">zero-click exploit<\/a>.<\/p>\n<p>Once installed, Pegasus can theoretically <a href=\"https:\/\/www.documentcloud.org\/documents\/4599753-NSO-Pegasus.html\">harvest any data<\/a> from the device and transmit it back to the attacker. It can steal photos and videos, recordings, location records, communications, web searches, passwords, call logs and social media posts. It also has the capability to activate cameras and microphones for real-time surveillance without the permission or knowledge of the user.<\/p>\n<h2>Who has been using Pegasus and why<\/h2>\n<p>NSO Group says it builds Pegasus solely for governments to use in counterterrorism and law enforcement work. The company markets it as a targeted spying tool to track criminals and terrorists and not for mass surveillance. The company does not disclose its clients.<\/p>\n<p>The <a href=\"https:\/\/www.ynetnews.com\/articles\/0,7340,L-5444330,00.html\">earliest reported use<\/a> of Pegasus was by the Mexican government in 2011 to track notorious drug baron Joaqu\u00edn \u201cEl Chapo\u201d Guzm\u00e1n. The tool was also reportedly used to <a href=\"https:\/\/www.washingtonpost.com\/investigations\/interactive\/2021\/jamal-khashoggi-wife-fiancee-cellphone-hack\/\">track people<\/a> close to murdered Saudi journalist Jamal Khashoggi.<\/p>\n<p>It is unclear who or what types of people are being targeted and why. However, <a href=\"https:\/\/www.bbc.com\/news\/technology-57881364\">much of the recent reporting<\/a> about Pegasus centers around a list of 50,000 phone numbers. The list has been attributed to NSO Group, but the list\u2019s origins are unclear. A statement from Amnesty International in Israel stated that <a href=\"https:\/\/twitter.com\/KimZetter\/status\/1418212758185648146\">the list contains phone numbers<\/a> that were marked as \u201cof interest\u201d to NSO\u2019s various clients, though it\u2019s not known if any of the phones associated with numbers have actually been tracked.<\/p>\n<p>A media consortium, <a href=\"https:\/\/forbiddenstories.org\/case\/the-pegasus-project\/\">the Pegasus Project<\/a>, analyzed the phone numbers on the list and identified over 1,000 people in over 50 countries. The findings included people who appear to fall outside of the NSO Group\u2019s restriction to investigations of criminal and terrorist activity. These include politicians, government workers, journalists, human rights activists, business executives and Arab royal family members.<\/p>\n<h2>Other ways your phone can be tracked<\/h2>\n<p>Pegasus is breathtaking in its stealth and its seeming ability to take complete control of someone\u2019s phone, but it\u2019s not the only way people can be spied on through their phones. Some of the ways phones <a href=\"https:\/\/ssd.eff.org\/en\/playlist\/privacy-breakdown-mobile-phones\">can aid surveillance and undermine privacy<\/a> include location tracking, eavesdropping, <a href=\"https:\/\/techterms.com\/definition\/malware\">malware<\/a> and collecting data from sensors.<\/p>\n<figure class=\"align-center zoomable\"><a href=\"https:\/\/images.theconversation.com\/files\/415049\/original\/file-20210806-90685-1xfv372.jpg?ixlib=rb-1.1.0&amp;q=45&amp;auto=format&amp;w=1000&amp;fit=clip\"><img decoding=\"async\" src=\"https:\/\/images.theconversation.com\/files\/415049\/original\/file-20210806-90685-1xfv372.jpg?ixlib=rb-1.1.0&amp;q=45&amp;auto=format&amp;w=754&amp;fit=clip\" sizes=\"(min-width: 1466px) 754px, (max-width: 599px) 100vw, (min-width: 600px) 600px, 237px\" srcset=\"https:\/\/images.theconversation.com\/files\/415049\/original\/file-20210806-90685-1xfv372.jpg?ixlib=rb-1.1.0&amp;q=45&amp;auto=format&amp;w=600&amp;h=384&amp;fit=crop&amp;dpr=1 600w, https:\/\/images.theconversation.com\/files\/415049\/original\/file-20210806-90685-1xfv372.jpg?ixlib=rb-1.1.0&amp;q=30&amp;auto=format&amp;w=600&amp;h=384&amp;fit=crop&amp;dpr=2 1200w, https:\/\/images.theconversation.com\/files\/415049\/original\/file-20210806-90685-1xfv372.jpg?ixlib=rb-1.1.0&amp;q=15&amp;auto=format&amp;w=600&amp;h=384&amp;fit=crop&amp;dpr=3 1800w, https:\/\/images.theconversation.com\/files\/415049\/original\/file-20210806-90685-1xfv372.jpg?ixlib=rb-1.1.0&amp;q=45&amp;auto=format&amp;w=754&amp;h=482&amp;fit=crop&amp;dpr=1 754w, https:\/\/images.theconversation.com\/files\/415049\/original\/file-20210806-90685-1xfv372.jpg?ixlib=rb-1.1.0&amp;q=30&amp;auto=format&amp;w=754&amp;h=482&amp;fit=crop&amp;dpr=2 1508w, https:\/\/images.theconversation.com\/files\/415049\/original\/file-20210806-90685-1xfv372.jpg?ixlib=rb-1.1.0&amp;q=15&amp;auto=format&amp;w=754&amp;h=482&amp;fit=crop&amp;dpr=3 2262w\" alt=\"An electronic device with handles on either side of a front panel containing buttons and lights and a graphic representation of a stingray\" \/><\/a><figcaption><span class=\"caption\">Law enforcement agencies use cell site simulators like this StingRay to intercept calls from phones in the vicinity of the device.<\/span><br \/>\n<span class=\"attribution\"><a class=\"source\" href=\"https:\/\/newsroom.ap.org\/detail\/WashingtonSuspectedPhoneSpying\/4e99d5e5bd054437abaf4ae4981894a0\/photo\">U.S. Patent and Trademark Office via AP<\/a><\/span><\/figcaption><\/figure>\n<p>Governments and phone companies can track a phone\u2019s location by tracking cell signals from cell tower transceivers and <a href=\"https:\/\/www.eff.org\/pages\/cell-site-simulatorsimsi-catchers\">cell transceiver simulators<\/a> like the <a href=\"https:\/\/www.engadget.com\/2015-04-08-erie-county-police-stingray-spy.html\">StingRay<\/a> device. Wi-Fi and Bluetooth signals can also be <a href=\"https:\/\/arstechnica.com\/tech-policy\/2020\/08\/beware-of-find-my-phone-wi-fi-and-bluetooth-nsa-tells-mobile-users\/\">used to track phones<\/a>. In some cases, apps and web browsers can determine a phone\u2019s location.<\/p>\n<p>Eavesdropping on communications is harder to accomplish than tracking, but it is possible in situations in which encryption is weak or lacking. Some types of malware can compromise privacy by accessing data.<\/p>\n<p>The National Security Agency has sought agreements with technology companies under which the companies would give the agency special access into their products via <a href=\"https:\/\/techterms.com\/definition\/backdoor\">backdoors<\/a>, and has <a href=\"https:\/\/www.reuters.com\/article\/us-usa-security-congress-insight\/spy-agency-ducks-questions-about-back-doors-in-tech-products-idUSKBN27D1CS\">reportedly built backdoors on its own<\/a>. The companies say that backdoors <a href=\"https:\/\/www.zdnet.com\/article\/coalition-of-tech-giants-hit-by-nsa-spying-slams-encryption-backdoors\/\">defeat the purpose of end-to-end encryption<\/a>.<\/p>\n<p>The good news is, depending on who you are, you\u2019re unlikely to be targeted by a government wielding Pegasus. The bad news is, that fact alone does not guarantee your privacy.<\/p>\n<p>[<em>Understand new developments in science, health and technology, each week.<\/em> <a href=\"https:\/\/theconversation.com\/us\/newsletters\/science-editors-picks-71\/?utm_source=TCUS&amp;utm_medium=inline-link&amp;utm_campaign=newsletter-text&amp;utm_content=science-understand\">Subscribe to The Conversation\u2019s science newsletter<\/a>.]<!-- Below is The Conversation's page counter tag. Please DO NOT REMOVE. --><img loading=\"lazy\" decoding=\"async\" style=\"border: none !important; box-shadow: none !important; margin: 0 !important; max-height: 1px !important; max-width: 1px !important; min-height: 1px !important; min-width: 1px !important; opacity: 0 !important; outline: none !important; padding: 0 !important; text-shadow: none !important;\" src=\"https:\/\/counter.theconversation.com\/content\/165382\/count.gif?distributor=republish-lightbox-basic\" alt=\"The Conversation\" width=\"1\" height=\"1\" \/><!-- End of code. If you don't see any code above, please get new code from the Advanced tab after you click the republish button. The page counter does not collect any personal data. More info: https:\/\/theconversation.com\/republishing-guidelines --><\/p>\n<p><a href=\"https:\/\/theconversation.com\/profiles\/bhanukiran-gurijala-1255497\">Bhanukiran Gurijala<\/a>, Assistant Professor of Computer Science &amp; Information Systems, <em><a href=\"https:\/\/theconversation.com\/institutions\/west-virginia-university-1375\">West Virginia University<\/a><\/em><\/p>\n<p>This article is republished from <a href=\"https:\/\/theconversation.com\">The Conversation<\/a> under a Creative Commons license. Read the <a href=\"https:\/\/theconversation.com\/what-is-pegasus-a-cybersecurity-expert-explains-how-the-spyware-invades-phones-and-what-it-does-when-it-gets-in-165382\">original article<\/a>.<\/p>\n<p>================================================================<br \/>\n<span style=\"color: #800000;\"><strong>Alecto<\/strong><\/span>, <strong><span style=\"color: #800000;\">Megaera<\/span><\/strong>, and <strong><span style=\"color: #800000;\">Tisiphone<\/span><\/strong>, beside the fact that there is no microchip small enough to go through a needle of the size used to deliver the CoViD vaccine, isn&#8217;t it ironic &#8211; or wouldn&#8217;t it be ironic if irony were still alive &#8211; that anti-vaxxers carry cell phones with them everywhere they go?<\/p>\n<p>The Furies and I will be back.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Experts in autocracies have pointed out that it is, unfortunately, easy to slip into normalizing the tyrant, hence it is important to hang on to outrage. These incidents which seem to call for the efforts of the Greek Furies (Erinyes) to come and deal with them will, I hope, help with that. As a reminder, <a href='https:\/\/www.politicsplus.org\/blog\/2021\/10\/24\/everyday-erinyes-289\/' class='excerpt-more'>[&#8230;]<\/a><\/p>\n","protected":false},"author":8,"featured_media":40592,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[3729,4684,4681,4683,4682],"class_list":["post-45598","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-politics","tag-furies","tag-pegasus","tag-spyware","tag-surveillance","tag-tracking","category-5-id","post-seq-1","post-parity-odd","meta-position-corners","fix"],"_links":{"self":[{"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/posts\/45598","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/comments?post=45598"}],"version-history":[{"count":0,"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/posts\/45598\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/media\/40592"}],"wp:attachment":[{"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/media?parent=45598"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/categories?post=45598"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.politicsplus.org\/blog\/wp-json\/wp\/v2\/tags?post=45598"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}