: New: Book Report: Chasing Shadows

It's a history of The Citizen Lab, a team of academics and hackers at U. of Toronto who investigate when bad guys hack the phones of journalists, activists, and the like. It's also a history of the rise of hack-for-hire mercenary groups.

I'd read about about a lot of this in individual articles over the years. But this book put it all together and pointed out some long-term trends.

When the Lab started out, they didn't think they'd be tangling with hack-for-hire groups. They thought they'd be detecting when governments blocked off access to parts of the internet. I guess that's back when China's Great Firewall was in the news. If China was blocking net access to some some sites, maybe other countries would do the same?

Maybe there was some of that going on. But when Lab folks actually went and talked to journalists, activisits, etc—net access wasn't their urgent tech problem. Activists' phones were acting funny; their friends were getting arrested. Activists wanted to know: were they being surveilled by their phones?

The Lab thought they were going to look for network interference, so they applied those techniques. They looked at how an activist's phone used the network. Weeeird, the phone was sending a lot of data to someplace on the net at strange times; turns out, it was sending the activist's theoretically-private data to someplace bad. The Lab knew networks, so they again applied that knowledge: they queried DNS servers and checked timing data to figure out where else in the world activists' phones were sending data to someplace bad. If you're looking at a Guatemalan reporter's phone that's been hacked to surveil them, you kinda expect other Guatemalans' phones to be hacked. And some were. But strangely, they saw that phones in other countries were also sending data to the same someplace-bad.

They published reports on what they found. They talked to reporters, helped to spread the word. They got kind of famous. They attracted some new recruits, and thus got more knowledge about phone hacking, not just internet-networking smarts.

They were up against mercenary hack-for-hire groups; the archetype of these is NSO Group. These groups figured out how to hack for several countries each. Kinda like how SalesForce provides customer databases for many companies; or Google provides spreadsheets for many companies; these hacker groups set up systems to hack phones and store stolen data in such a way that several countries could use them.

NSO group claimed they only sold their services to governments with good human rights records. But that turned out to be a lie; they did secret deals with dictators; they abetted murder, harassment, theft, etc. (While I was reading the book, some articles were coming out figuring out how the deals were done thanks to records newly made public.) It took years of Citizen Lab, Access Now,+Amnesty International finding NSO Group software spying on various activists, associates of activists, etc to drive home that these weren't one-off mistakes, but business as usual.

Tags: book brutal truth capabilities

lahosken@gmail.com

Tags