"We never knew we were using NSO products," says the FBI. https://www.nytimes.com/2023/07/31/us/politics/nso-spy-tool-landmark-fbi.html?smtyp=cur |
Laws governing telecommunications surveillance do not directly address spyware, nor does the regulation of warrants, which police frequently abuse and operate outside of the constraints of what the original warrants may have allowed for, or after the warrant's expiration. |
Police regularly fail to log, or properly log, their activities, and in many regions are not even required to keep records of their activities. |
Networks are full of devices running legacy operating systems that remain vulnerable to 20 year old vulnerabilities due to lack of regulation and old code. All of the edge devices and routers run old code which are vulnerable to AV and EDR evasion techniques once access is established. |
Originally military and intelligence services recommended to government repeatedly to enact security legislation for internet devices/software. Government responded that it would slow development, leaving the industry unregulated for 30 years, even as telcos were repeatedly hacked. |
Even in the 1990's we would repeatedly find foreign governments hacking into telcos, and the telephone companies were very uninterested in responding to the issue. |
Woah look at all these random guest cybersecurity experts blaming governments and hardware. Meanwhile a 2023 security survey said the most commonly used password for 2023 was .... 123456. Sooo yea, there are problems with regulations and technology... but imho the biggest problems like with end users and their desire to use technology without fully understanding it or taking precautions for rectum protectum. |
Vendors could easily provide secure authentication and a more secure default configuration. It's far easier and cheaper to allow you to use 123456 instead. Vehicle manufacturers could also save an enormous amount of money by skipping brakes, seat-belts and other safety features. |
All users of spyware have to do is type in the phone number and click install. NSO handles the installation and extraction of data. It is all about the money and sales. Compliance in the tech industry is already patchy and takes place only after enormous pressure. |