Menu
Pegasus Spyware: Meta Won. You Still Get Tracked

Pegasus Spyware: Meta Won. You Still Get Tracked

David Bombal

249,908 views Save 42 min (8 min read) 8 months ago

Video Summary

A recent court ruling prohibits the NSO Group's Pegasus spyware from intercepting WhatsApp messages, a decision stemming from a lawsuit filed by Meta. This ruling, while specific to Meta's products, highlights ongoing concerns about sophisticated surveillance tools used by governments and other entities to spy on individuals, including journalists and activists. The discussion also delves into the broader landscape of cybersecurity, questioning the inherent security of consumer devices like iPhones and Android phones, and exploring the persistent vulnerabilities in software development and digital infrastructure that make widespread hacking a reality. The conversation stresses the importance of user vigilance in the face of these systemic flaws, emphasizing that security is not an inherent feature but a constant, individual responsibility.

A key insight reveals that despite Apple's claims of robust security, off-the-shelf malware is demonstrably present on iPhones, contradicting public perception and highlighting a significant gap between marketing and reality.

Short Highlights

  • A court ruling has issued a permanent injunction against NSO Group's Pegasus spyware accessing WhatsApp and other Meta products, though this doesn't prevent targeting of other apps.
  • Off-the-shelf malware is actively found on Apple iPhones, contradicting claims that they are unhackable, with approximately $5 million in bug bounties offered for hacking iPhones with specific security modes enabled.
  • The discussion highlights that all software is considered a service in the US, which prevents consumers from suing developers for data loss due to hacks, unlike with physical products.
  • Government intelligence agencies like the NSA and CIA operate with significant autonomy, often above the law, and can develop or acquire sophisticated surveillance tools.
  • A significant portion of hacks involve social engineering, followed by technical execution, and the pervasive nature of malware extends to smart home devices and industrial control systems (SCADA).

Key Details

The Mr. Robot Analogy and Wi-Fi Vulnerabilities [00:00]

  • The opening scene from "Mr. Robot" illustrates how easily a phone can be hacked if connected to the same Wi-Fi network with a weak password (e.g., "12345678").
  • This scenario serves as an immediate demonstration that off-the-shelf malware can be used against Apple products, debunking a common misconception.

"So the brother asks them, "What's your password on your Wi-Fi?" Oh, okay. Here's my password. You know, 1 2 3 4 5 6 7 8. Okay, go ahead and connect."

Pegasus Spyware Ruling and its Limitations [03:02]

  • A court ruling on October 19th prohibited NSO Group's Pegasus spyware from intercepting messages on WhatsApp.
  • The lawsuit was brought by Meta (Facebook), not the government, framing the issue as an infringement on corporate property rather than a criminal act.
  • The ruling is a permanent injunction specifically against NSO accessing Meta's products, including WhatsApp, Facebook, and Instagram.
  • However, this ruling is narrow and does not prevent Pegasus from targeting any other app or communication on a phone.
  • Pegasus has been used to spy on journalists, lawyers, diplomats, human rights activists, and political dissidents, but its reach has been observed on regular individuals' phones as well.
  • The spyware can also be used to track location, which has implications for governments tracking individuals for deportation or other purposes.

"It doesn't say anything about anybody else's product, but it also kind of reflects badly upon the NSO, you know, that they really are producing a product that is infringing upon somebody's corporate property, WhatsApp, okay, and people's privacy."

Cynicism on Data Privacy: Meta's Spying Habits [08:14]

  • The host expresses cynicism, questioning why Meta (Facebook) would complain about being spied on when they themselves constantly monitor users and sell their data.
  • The core business model of many tech companies is identified as selling user information, leading to the adage: "if a service is free, you're not the customer, you're the product."

"Our territory, right? You guys can't spy. there's Facebook is spying on us and they're selling our data."

Software as a Service vs. Product Liability in the US [09:48]

  • In the United States, all software is legally considered a service, not a product.
  • This distinction prevents consumers from suing software developers for defects or damages, unlike car manufacturers who are subject to product liability laws.
  • If software were treated as a product, users could sue developers for data loss or breaches, similar to how one can sue a car manufacturer for a defective vehicle.
  • This loophole, allegedly created by lobbyists, allows for the release of flawed software without significant legal repercussions for the developers.

"But that doesn't apply to software because in the United States software is a service. It's not a product."

Government Surveillance Autonomy and NSA Contractors [12:28]

  • Government agencies, referred to as "three-letter agencies" (NSA, CIA, ICE), are often perceived as operating above the law.
  • While NSO Group's products are banned in the US, these agencies can contract with other companies or develop similar tools internally.
  • The NSA utilizes contractors, including highly talented individuals, to develop and acquire surveillance capabilities, exemplified by the Eternal Blue malware that was leaked after being developed by an NSA contractor.
  • The US has 17 intelligence agencies, each capable of independent development or acquisition of surveillance tools.
  • There is a legitimate, legal career path for individuals to produce malware specifically for government use.

"No, it it certainly does not because the three-letter agencies are always above the law law. They make the law. Whatever they decide is legal is legal, right?"

Apple's Memory Integrity Enforcement and Real-World Hacking [19:59]

  • Apple's introduction of "Memory Integrity Enforcement" in newer iPhones is aimed at making attacks more difficult and expensive.
  • This feature is compared to Address Space Randomization (ASLR) and Data Execution Protection, which have been used for years to enhance operating system security.
  • Despite these measures, the video asserts that iPhones are not unhackable, and off-the-shelf malware is a significant problem, contradicting Apple's marketing.
  • The speaker shares firsthand experience seeing a large number of infected Apple phones, indicating that the perception of iPhones being immune to consumer-level malware is false.
  • While Apple is credited with taking cybersecurity more seriously than some competitors (like Google), the claim of being "unhackable" is labeled as marketing fluff.

"We have been going through these homes and we've been going through these phones and we've been going through these computers and they're full of malware. They're full of their routers are full of malware."

iPhone vs. Android: A Comparative Security Analysis [32:19]

  • Among major manufacturers, Apple is considered to take security more seriously than others, although no system is truly unhackable.
  • Hackers typically target the easiest vulnerabilities, making more secure systems like those from GrapheneOS or iOS harder to breach.
  • Android phones are generally easier to hack, especially older, unupdated models, which are prevalent due to Android's dominant global market share (around 82%).
  • The ease of hacking increases when an attacker gains access to a local network, allowing them to move laterally to other connected devices.

"Well, of the the the major manufacturers, I would have to say that Apple does takes security more serious than the others."

Satellite Communication Vulnerabilities and Clear Text Messaging [37:56]

  • Government agencies and cybercriminals can attack phone systems, potentially intercepting all calls and texts.
  • A new study confirming the interception of satellite phone calls highlights that this is not new information and has been demonstrated in hacking classes.
  • Many satellite services still transmit messages in clear text, making them highly vulnerable to interception, even if encryption is sometimes employed.
  • Low Earth Orbit (LEO) satellite systems like Starlink are becoming more prevalent, offering global connectivity but also introducing new potential attack vectors.
  • The communication infrastructure, built largely without security in mind since the 1970s, is inherently flawed and requires rebuilding with security as a foundational element.

"And many of the services are still sending messages in clear text. All right? So, even if they they encrypt it, you know, there's still a possibility of decryting it."

The Unending Battle: Vigilance in a Flawed Digital World [46:52]

  • Despite the pervasive threats, there is hope, but it relies heavily on individual vigilance.
  • The digital world in 2025 is likened to a jungle with constant threats, requiring users to be constantly aware and skeptical.
  • Users must take responsibility for their own safety, as software, telecom, and banking companies are unlikely to prioritize individual security over their own interests.
  • The core message is to be skeptical of everything encountered online until the digital infrastructure is fundamentally rebuilt with security as a primary design principle, rather than an afterthought.

"You have to take responsibility for your safety because your software company's not going to do it. Okay? Your telecom company's not going to do it. Your bank's not going to do it. You have to do it."

Other People Also See