{"id":19539,"date":"2022-07-07T06:30:07","date_gmt":"2022-07-07T14:30:07","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/07\/07\/news-13272\/"},"modified":"2022-07-07T06:30:07","modified_gmt":"2022-07-07T14:30:07","slug":"news-13272","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/07\/07\/news-13272\/","title":{"rendered":"Apple slaps hard against \u2018mercenary\u2019 surveillance-as-a-service industry"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/idge\/imported\/imageapi\/2022\/07\/06\/19\/apple-lockdown-mode-100929882-large.3x2.jpg?auto=webp&amp;quality=85,70\"\/><\/p>\n<p><strong>Credit to Author: Jonny Evans| Date: Thu, 07 Jul 2022 06:17:00 -0700<\/strong><\/p>\n<p>Apple has struck a big blow against the mercenary <a href=\"https:\/\/www.computerworld.com\/article\/3649208\/second-israeli-firm-accused-of-undermining-iphones-like-nso-group.html\">\u201csurveillance-as-a-service\u201d<\/a> industry, introducing a new, highly secure Lockdown Mode to protect individuals at the greatest risk of targeted attacks. The company is also offering millions of dollars to support research to expose such threats.<\/p>\n<p>Starting in iOS 16, iPadOS 16 and macOS Ventura, and available now in the latest developer-only betas, Lockdown Mode hardens security defenses and limits the functionalities sometimes <a href=\"https:\/\/www.computerworld.com\/article\/3665050\/italian-spyware-firm-is-hacking-into-ios-and-android-devices-google-says.html\">abused by state-sponsored surveillance hackers<\/a>. Apple describes this protection as \u201csharply reducing the attack surface that potentially could be exploited by highly targeted mercenary spyware.\u201d<\/p>\n<p>In recent years, a series of targeted spyware attacks against journalists, activists, and others have been exposed. Names including Pegasus, DevilsTongue, Predator, Hermit, and NSO Group have undermined trust in digital devices and exposed the risk of semi-private entities and <a href=\"https:\/\/www.lawfareblog.com\/effects-digital-transnational-repression-and-responsibility-host-states\" rel=\"nofollow noopener\" target=\"_blank\">the threat they show against civil society<\/a>. Apple has made no secret that it is opposed to such practices, <a href=\"https:\/\/www.computerworld.com\/article\/3641261\/apple-pulls-no-punches-in-lawsuit-against-amoral-nso-group.html\">filing suit<\/a> against the NSO Group in November and promising to oppose such practices where it can.<\/p>\n<p>\u201cApple\u2019s newly released Lockdown Mode will reduce the attack surface, increase costs for spyware firms, and thus make it much harder for repressive governments to hack high-risk users,\u201d said John Scott-Railton, senior researcher at the\u00a0<a href=\"https:\/\/citizenlab.ca\/\" rel=\"nofollow noopener\" target=\"_blank\">Citizen Lab<\/a> at the University of Toronto&#8217;s Munk School of Global Affairs and Public Policy.<\/p>\n<p>\u201cWe congratulate [Apple] for providing protection to human rights defenders, heads of state, lawyers, activists, journalists, and more,\u201d <a href=\"https:\/\/twitter.com\/EFF\/status\/1544741006905487360?s=20&amp;t=XjtvbZzEzwq2oNuBkHIPKw\" rel=\"noopener nofollow\" target=\"_blank\">tweeted<\/a> the EFF, a privacy advocacy group.<\/p>\n<p>At present, Apple says Lockdown Mode provides the following protections:<\/p>\n<p>Ivan Krsti\u0107, Apple\u2019s head of Security Engineering and Architecture, notes that Lockdown Mode can be applied to devices that are already enrolled in an MDM service. \u201cPre-existing MDM enrollment is preserved when you enable Lockdown Mode,\u201d he <a href=\"https:\/\/twitter.com\/radian\/status\/1544759049157152768?s=20&amp;t=fqC4YIwpirKKuAzBqkTQhw\" rel=\"nofollow noopener\" target=\"_blank\">tweeted<\/a>.<\/p>\n<p>The company says it intends to extend the protection provided by Lockdown Mode over time and has invested millions in security research to help identify weaknesses and increase the integrity of this protection.<\/p>\n<p>Turning on Lockdown Mode. (Click image to enlarge it.)<\/p>\n<p>These attacks don\u2019t come cheap, which means most people are unlikely to be targeted in this way. Apple began sending threat notifications to potential victims of Pegasus soon after it was revealed and says the number of people targeted in such campaigns is relatively small.<\/p>\n<p>All the same, the scale is international, and the company has warned people in around 150 nations since November 2021. A <a href=\"https:\/\/www.bbc.co.uk\/news\/technology-62069255\" rel=\"nofollow noopener\" target=\"_blank\">BBC report<\/a> confirms hundreds of targets and tens of thousands of phone numbers leaked as a result of NSO\u2019s Pegasus alone. <a href=\"https:\/\/www.applemust.com\/abusive-nso-group-hits-9-u-s-state-department-employees\/\" rel=\"nofollow noopener\" target=\"_blank\">Victims have included<\/a> journalists, politicians, civil society advocates, activists, and diplomats, so while the numbers are small, the chilling impact of such surveillance is vast.<\/p>\n<p>I believe that such technologies will become cheaper and <a href=\"https:\/\/www.applemust.com\/abusive-nso-group-hits-9-u-s-state-department-employees\/\" rel=\"nofollow noopener\" target=\"_blank\">more available over time<\/a>, so it\u2019s <a href=\"https:\/\/www.computerworld.com\/article\/3643970\/designer-smartphone-hacks-will-trickle-down-in-2022.html\">only a matter of time before they leak into wider use<\/a>. Ultimately the very existence of such attacks \u2014 <a href=\"https:\/\/www.computerworld.com\/article\/3625871\/iphone-spyware-its-a-dirty-job-but-nsos-gonna-do-it.html\">state-sponsored or not<\/a> \u2014 makes the entire world less safe, not safer.<\/p>\n<p>\u201cThere is now undeniable evidence from the research of the Citizen Lab and other organizations that the mercenary surveillance industry is facilitating the spread of authoritarian practices and massive human rights abuses worldwide,\u201d said Citizen Lab Director <a href=\"https:\/\/deibert.citizenlab.ca\/bio\/\" rel=\"nofollow noopener\" target=\"_blank\">Ron Deibert<\/a> in <a href=\"https:\/\/www.apple.com\/newsroom\/2022\/07\/apple-expands-commitment-to-protect-users-from-mercenary-spyware\/\" rel=\"noopener nofollow\" target=\"_blank\">a statement<\/a>. Deibert <a href=\"https:\/\/www.cnet.com\/tech\/mobile\/apple-announces-new-lockdown-mode-for-iphone-to-fight-hacking\/\" rel=\"noopener nofollow\" target=\"_blank\">told CNET<\/a> he thinks Lockdown Mode will deal a &#8220;major blow&#8221; to spyware companies and the governments that use their products.<\/p>\n<p>\u201cWhile the vast majority of users will never be the victims of highly targeted cyberattacks, we will work tirelessly to protect the small number of users who are,\u201d said Apple&#8217;s Krsti\u0107 in <a href=\"https:\/\/www.apple.com\/newsroom\/2022\/07\/apple-expands-commitment-to-protect-users-from-mercenary-spyware\/\" rel=\"noopener nofollow\" target=\"_blank\">a statement<\/a>. \u201cThat includes continuing to design defenses specifically for these users, as well as supporting researchers and organizations around the world doing critically important work in exposing mercenary companies that create these digital attacks.\u201d<\/p>\n<p>There\u2019s little doubt Microsoft and Google will also move to provide similar protection to users. Google and Meta already offer tools to secure the accounts of those who are at an \u201celevated risk of targeted online attacks,\u201d but these tools don\u2019t go nearly as far as Lockdown Mode.<\/p>\n<p>Apple already makes <a href=\"https:\/\/developer.apple.com\/security-bounty\/\" rel=\"nofollow noopener\" target=\"_blank\">vast investments in security<\/a>. For example, the company is working with others in the industry to support password-free authentication, has <a href=\"https:\/\/www.computerworld.com\/article\/3645848\/how-apples-icloud-private-relay-supports-enterprise-vpn.html\">built tools to mask IP addresses<\/a> and <a href=\"https:\/\/www.computerworld.com\/article\/3656803\/apple-has-good-privacy-arguments-but-critics-arent-listening.html\">continues to focus on user privacy<\/a>.<\/p>\n<p>The company will introduce a <a href=\"https:\/\/www.applemust.com\/wwdc-what-is-rapid-security-response-and-how-to-enable-it\/\" rel=\"nofollow noopener\" target=\"_blank\">Rapid Security Response<\/a> feature for its devices this fall, which will make it possible to deploy security fixes outside of full security updates and much more. Apple is even investing in <a href=\"https:\/\/jobs.apple.com\/en-us\/details\/200310662\/security-tools-compiler-engineer?team=SFTWR\" rel=\"nofollow noopener\" target=\"_blank\">improving the security of programming languages<\/a>, further eroding potential attack surfaces.<\/p>\n<p>The company has now announced further investment in the security community:<\/p>\n<p>The fund will make its first grants later this year, focusing initially on initiatives to expose the use of mercenary spyware. In the press release announcing the initiative, Apple tells us these grants will focus on:<\/p>\n<p>The fund\u2019s grant-making strategy will be advised by a global Technical Advisory Committee. Initial members include <a href=\"https:\/\/www.accessnow.org\/profile\/daniel\/\" rel=\"nofollow noopener\" target=\"_blank\">Daniel Bedoya Arroyo<\/a>, digital security service platform analyst at <a href=\"https:\/\/www.accessnow.org\/help\/\" rel=\"nofollow noopener\" target=\"_blank\" data-analytics-exit-link=\"\">Access Now<\/a>; Citizen Lab Director <a href=\"https:\/\/deibert.citizenlab.ca\/bio\/\" rel=\"nofollow noopener\" target=\"_blank\">Ron Deibert<\/a>; <a href=\"https:\/\/www.theengineroom.org\/people\/paola-mosso\/\" rel=\"nofollow noopener\" target=\"_blank\">Paola Mosso<\/a>, co-deputy director of <a href=\"https:\/\/www.theengineroom.org\/\" rel=\"nofollow noopener\" target=\"_blank\" data-analytics-exit-link=\"\">The Engine Room<\/a>; <a href=\"https:\/\/interview-her.com\/speaker\/rasha-abdul-rahim\/\" rel=\"nofollow noopener\" target=\"_blank\">Rasha Abdul Rahim<\/a>, director of <a href=\"https:\/\/www.amnesty.org\/en\/tech\/\" rel=\"nofollow noopener\" target=\"_blank\" data-analytics-exit-link=\"\">Amnesty Tech<\/a> at Amnesty International; and Apple&#8217;s Krsti\u0107.<\/p>\n<p>Ford Foundation Tech and Society Program director Lori McGlinchey said:<\/p>\n<p>\u201cThe global spyware trade targets human rights defenders, journalists, and dissidents; it facilitates violence, reinforces authoritarianism, and supports political repression. The Ford Foundation is proud to support this extraordinary initiative to bolster civil society research and advocacy to resist mercenary spyware. We must build on Apple\u2019s commitment, and we invite companies and donors to join the Dignity and Justice Fund and bring additional resources to this collective fight.\u201d<\/p>\n<p>Following revelations about NSO Group last year, Apple\u00a0<a href=\"https:\/\/support.apple.com\/en-us\/HT212960\" rel=\"nofollow noopener\" target=\"_blank\">published a set of recommendations<\/a>\u00a0to help users mitigate against such risks. These guidelines do not even approach the kind of robust protection you can expect from Lockdown Mode, but it makes sense for anyone to follow such practices:<\/p>\n<p>Furthermore, Amnesty Tech is <a href=\"https:\/\/www.amnesty.org\/en\/petition\/targeted-surveillance-human-rights-defenders\/\" rel=\"nofollow noopener\" target=\"_blank\">gathering signatures<\/a> to demand an end this kind of targeted surveillance of human rights defenders. I\u2019d urge readers to add their signature <a href=\"https:\/\/www.computerworld.com\/article\/3665052\/the-surveillance-as-a-service-industry-needs-to-be-brought-to-heel.html\">to my own<\/a>.<\/p>\n<p><em>Please follow me on\u00a0<a href=\"https:\/\/twitter.com\/jonnyevans_cw\" rel=\"nofollow noopener\" target=\"_blank\">Twitter<\/a>, or join me in the\u00a0<a href=\"https:\/\/mewe.com\/join\/appleholics_bar_and_grill\" rel=\"nofollow noopener\" target=\"_blank\">AppleHolic\u2019s bar &amp; grill<\/a>\u00a0and\u00a0<a href=\"https:\/\/mewe.com\/join\/apple_discussions\" rel=\"nofollow noopener\" target=\"_blank\">Apple Discussions<\/a>\u00a0groups on MeWe.<\/em><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3666688\/apple-slaps-hard-against-mercenary-surveillance-as-a-service-industry.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/idge\/imported\/imageapi\/2022\/07\/06\/19\/apple-lockdown-mode-100929882-large.3x2.jpg?auto=webp&amp;quality=85,70\"\/><\/p>\n<p><strong>Credit to Author: Jonny Evans| Date: Thu, 07 Jul 2022 06:17:00 -0700<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p>Apple has struck a big blow against the mercenary <a href=\"https:\/\/www.computerworld.com\/article\/3649208\/second-israeli-firm-accused-of-undermining-iphones-like-nso-group.html\">\u201csurveillance-as-a-service\u201d<\/a> industry, introducing a new, highly secure Lockdown Mode to protect individuals at the greatest risk of targeted attacks. The company is also offering millions of dollars to support research to expose such threats.<\/p>\n<p>Starting in iOS 16, iPadOS 16 and macOS Ventura, and available now in the latest developer-only betas, Lockdown Mode hardens security defenses and limits the functionalities sometimes <a href=\"https:\/\/www.computerworld.com\/article\/3665050\/italian-spyware-firm-is-hacking-into-ios-and-android-devices-google-says.html\">abused by state-sponsored surveillance hackers<\/a>. Apple describes this protection as \u201csharply reducing the attack surface that potentially could be exploited by highly targeted mercenary spyware.\u201d<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3666688\/apple-slaps-hard-against-mercenary-surveillance-as-a-service-industry.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[2211,10480,10403,10554,5897,714,24580],"class_list":["post-19539","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-apple","tag-ios","tag-macos","tag-mobile","tag-privacy","tag-security","tag-small-and-medium-business"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19539","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19539"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19539\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19539"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19539"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19539"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}