a Better Bubble™

Aggregator

Become a Neighborhood Leader with Brightside!

2 years 11 months ago
Neighborhood Leaders Unite! Do your part and encourage others to keep your community clean, green, and thriving! The first step is signing up to become a Neighborhood Leader with Brightside. Next, […]
SLACO USER

UMSL says it could host rec facility at heart of convention center dispute

2 years 11 months ago
The University of Missouri-St. Louis could host on its campus the recreation facility that's at the heart of a dispute over funding for an expansion of the downtown St. Louis convention center. A spokesman for the university said Tuesday that "leadership" in St. Louis County requested that UMSL study "the feasibility of being the site for a proposed Track and Field Complex in north St. Louis County." "In response, UMSL enlisted its Master Plan firm Lamar Johnson Collaborative to review the options,"…
Jacob Kirn

Whistleblower Alleges NSO Offered To 'Drop Off Bags Of Cash' In Exchange To Access To US Cellular Networks

2 years 11 months ago

The endless parade of bad news for Israeli malware merchant NSO Group continues. While it appears someone might be willing to bail out the beleaguered company, it still has to do business as the poster boy for the furtherance of human rights violations around the world. That the Israeli government may have played a significant part in NSO's sales to known human rights violators may ultimately be mitigating, but for now, NSO is stuck playing defense with each passing news cycle.

Late last month, the New York Times revealed some very interesting things about NSO Group. First, it revealed the company was able to undo its built-in ban on searching US phone numbers… provided it was asked to by a US government agency. The FBI took NSO's powerful Pegasus malware for a spin in 2019, but under an assumed name: Phantom. With the permission of NSO and the Israeli government, the malware was able to target US numbers, albeit ones linked to dummy phones purchased by the FBI.

The report noted the FBI liked what it saw, but found the zero-click exploit provided by NSO's bespoke "Phantom" (Pegasus, but able to target US numbers) might pose constitutional problems the agency couldn't surmount. So, it walked away from NSO. But not before running some attack attempts through US servers -- something that was inadvertently exposed by Facebook and WhatsApp in their lawsuit against NSO over the targeting of WhatsApp users. An exhibit declared NSO was using US servers to deliver malware, something that suggested NSO didn't care about its self-imposed restrictions on US targeting. In reality, it was the FBI and NSO running some tests on local applications of zero-click malware that happened to be caught by Facebook techies.

But there's more. Recent reports building on the NYT article contain statements that claim NSO approached service providers with (well, let's just say it) bribes to allow access to targets at a higher level that might mitigate some of the defensive efforts deployed by Facebook, Google, and Apple.

Here's what's been alleged in newer reports, like this one by Craig Timberg of the Washington Post:

The surveillance company NSO Group offered to give representatives of an American mobile-security firm “bags of cash” in exchange for access to global cellular networks, according to a whistleblower who has described the encounter in confidential disclosures to the Justice Department that have been reviewed by The Washington Post.

The mobile-phone security expert Gary Miller alleges that the offer came during a conference call in August 2017 between NSO Group officials and representatives of his employer at the time, Mobileum, a California-based company that provides security services to cellular companies worldwide. The NSO officials specifically were seeking access to what is called the SS7 network, which helps cellular companies route calls and services as their users roam the world, according to Miller.

Mobileum execs were (understandably) unsure how any of this was supposed to work in the unlikely event they were amenable to a foreign entity's requests for elevated access to US cellular networks. Fortunately, the NSO rep made it extremely clear how this was going to work, according to the whistleblower:

In Miller’s account to the Justice Department, when one of Mobileum’s representatives pointed out that security companies do not ordinarily offer services to surveillance companies and asked how such an arrangement would work, NSO co-founder Omri Lavie allegedly said, “We drop bags of cash at your office."

Simple enough. Except -- to quote C. Montgomery Burns -- at the end of the proposed transaction "the money and the very stupid man were still there." Mobileum execs say no such bribery took place -- not because NSO didn't offer it but because the company refused to accept the generous offer of extremely shady "bags of cash" from the Israeli malware maker.

NSO has its own explanation for these events, which is, basically: "It was a joke, probably."

In a statement through a spokesperson, Lavie said he did not believe he had made the remark. “No business was undertaken with Mobileum,” the statement said. “Mr Lavie has no recollection of using the phrase ‘bags of cash’, and believes he did not do so. However if those words were used they will have been entirely in jest.”

Hahahahahaaaa… here at the home of the zero-click exploit marketed to human rights violators we often joke about bribing tech companies to allow us more access to networks. Oh, our sides ache from the fun we have jesting about subverting networks to compromise targets of evil empires. Ell oh fucking ell.

Mobileum, on the other hand, says it has never done business with NSO and reported this proposed cash drop to the FBI in 2017 but never heard anything back from the agency. Two years later, the FBI was experimenting with NSO malware and trying to gauge the political and constitutional fallout of deploying unregulated malware against US citizens.

Even if NSO is to be believed, there's nothing good awaiting it on the US side of things. The Commerce Department has already blacklisted the company, destroying its ability to purchase US tech for the purpose of compromising it. And the Department of Justice has opened its own investigation into NSO, adding to its list of US-related woes.

NSO could have avoided all of this international attention by being more selective about who it sold to, and stripping customers of their licenses at the first hint of malfeasance. It didn't. And the fact that it may have been pressed into service as a malware-laden extension of the Israeli government's Middle East charm offensive isn't going to save it. NSO has to save itself but it lacks the tools to do so. Whatever it claims in defense of every reported allegation is presumed to be suspect, if not completely false. The reputation it has now is mostly earned. It made millions helping sketchy governments inflict further misery on citizens, dissidents, journalists, and political opponents. The company's honor is no longer presumed if, indeed, it ever was.

Tim Cushing

David Karandish on Selling Answers.com for $950M

2 years 11 months ago
David Karandish is the co-founder and CEO of Capacity, an enterprise artificial intelligence SaaS company focused on helping teams do their best work. To date, the company has raised over $62 million from a Midwest network of private and angel investors. In January 2020, Capacity, announced an additional $27 million in Series C financing, closing […]
Jonathan Allen, EQ Staff

St. Louis Business Diversity Initiative Fellows Experience Accepting Applications

2 years 11 months ago
The Fellows program was founded in 2006. Since then, nearly 1,000 Fellows have completed the program, with 90% remaining in the metro. Through volunteer and civic activities, Fellows hone their skills, expand their relationships, and deepen their connection with the broader St. Louis community.
Jonathan Allen, EQ Staff

HBCU leaders decry waves of bomb threats as federal investigators probe origin

2 years 11 months ago

WASHINGTON — Hours before the Southern Poverty Law Center held a virtual panel Tuesday about recent bomb threats made to dozens of historically Black colleges, yet another bomb threat was reported — this one to Spelman College in Georgia. “This was a racist attack that aims to not only disrupt the start of Black History […]

The post HBCU leaders decry waves of bomb threats as federal investigators probe origin appeared first on Missouri Independent.

Ariana Figueroa

States target ballot drop boxes in fight over voting rights

2 years 11 months ago

Ballot drop boxes are so secure they’ve survived getting hit by an SUV and rolled by a school bus — yet much of the battle over voting rights has centered on the big metal boxes. In the November 2020 general election, nearly 40 states had ballot drop boxes available and more voters used drop boxes than in any […]

The post States target ballot drop boxes in fight over voting rights appeared first on Missouri Independent.

Kira Lerner

Schlafly's Stout and Oyster Festival Makes Its Return Next Month

2 years 11 months ago
Shuck yeah, Schlafly is bringing back their Stout and Oyster Festival in March. Two years have passed since the last Stout and Oyster Fest, and this year the festival will kick off on March 25 and 26 at the Schlafly Tap Room (2100 Locust Street, 314-241-2337).…
Jenna Jones