/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Apple and Google can do more to screw up the economics of NSO-style mass exploitation, and should be pressured to do so

This week a group of global newspapers is running a series of articles detailing abuses of NSO Group's Pegasus spyware.  If you haven't seen any of these articles …

A Few Thoughts … Matthew Green

Context & Ripple Effects

The Pegasus abuse reporting has turned commercial spyware from a niche security issue into a question of platform responsibility. The contemporaneous call for a ban on the spyware trade frames the opinion’s narrower argument: Apple and Google can raise the operating costs of exploit vendors even without a sector-wide prohibition.

Related coverage then made the platform-security route concrete, with researchers urging greater access to mobile system internals to detect Pegasus-like attacks in real time. Later reporting of new iPhone zero-click exploits, despite fixes, underscores why detection and disruption cannot rest on patching alone.

First-order effects

  • Apple and Google face pressure to use their control over iOS and Android to make NSO-style exploitation harder to develop, deploy, and detect at scale.
  • Security researchers and potential targets stand to gain more actionable visibility if the platforms expose the system access needed to identify attacks in real time.

Second-order effects

  • Commercial spyware vendors would have to absorb higher development and operational costs as platform defenses, telemetry, and detection capacity improve.
  • Apple’s later move to notify targets of state-sponsored spyware shows how platform-led response can shift protection from post-disclosure patching toward identifying and assisting affected users.

Third-order effects

  • If Apple and Google treat exploit economics as part of platform governance, mobile operating-system owners become a central enforcement layer alongside governments seeking to curb commercial spyware.
  • The pattern points to a market in which vendors’ viability depends less on selling a single exploit and more on sustaining access against coordinated platform detection, patching, and user-warning measures.

The trend: Commercial spyware is increasingly being contested through platform gatekeeper controls that seek to make mass exploitation more expensive and more detectable.

Discussion

  • @patrickwardle Patrick Wardle on x
    The individuals who work on the security teams at Apple are indisputably world-class. How insane though, (though sadly unsurprising) that at Apple, marketing trumps security!? 🤯😭 https://twitter.com/... https://twitter.com/...
  • @matthew_d_green Matthew Green on x
    So it seems fairly obvious that ripping out memory-unsafe parsing code and disabling advanced (non plain-text) features — while not guaranteed to solve the problem — is still an open problem, something that Apple can devote its enormous resources to. 6/
  • @matthew_d_green Matthew Green on x
    Another area that Apple has already stepped up their game is in logging. Apple power monitoring telemetry records information about weird process “hang” events, which can sometimes trip up exploits. There's a privacy tradeoff here, but Apple should lean into this. 7/
  • @reedalbergotti Reed Albergotti on x
    For starters, no internet-connected device is safe from hacking, so the iPhone is no different in that way. But it has a reputation for excellent security, thanks to Apple's excellent marketing. But Apple's marketing also sometimes gets in the way of security.
  • @zackwhittaker Zack Whittaker on x
    This @matthew_d_green blog is a really solid read, since absolute security is a fallacy. “The problem that companies like Apple need to solve is not preventing exploits forever, but a much simpler one: they need to screw up the economics of NSO-style mass exploitation.” https://t…
  • @matthew_d_green Matthew Green on x
    While we can't have “perfect security”, closing down avenues for interactionless targeted infection sure seems like a thing we can make some progress on. 3/
  • @gruber John Gruber on x
    @ReedAlbergotti That's like saying the iPhone has a reputation for having the industry's fastest chips “thanks to Apple's excellent marketing”.
  • @dcuthbert Daniel Cuthbert on x
    @k8em0 I'd go further and say not just iMessage but WebKit and anything that parses and handles the utter mess that is the internet. This is one hell of a task
  • @matthew_d_green Matthew Green on x
    There is a take that companies like Apple are never going to be able to stop well-resourced attackers like NSO from launching targeted attacks. At the extremes this take is probably correct. But adopting cynicism as strategy is a bad approach. 1/ https://twitter.com/...
  • @gf_256 Cts on x
    feel like apple is going to freak out over the bad PR and just dump more money into mitigations -.-""
  • @dogemocenigo @dogemocenigo on x
    @matthew_d_green TBH no one in our business believes in “perfect” security. You know very well that it is a cat-and-mouse game.
  • @k8em0 Katie Moussouris on x
    “Apple will have to re-write most of the iMessage codebase in some memory-safe language, along w many system libraries that handle parsing. They'll also need to widely deploy ARM mitigations like PAC & MTE in order to make exploitation harder.” https://twitter.com/...
  • @gf_256 Cts on x
    this whole NSO thing is going to make my job so much more difficult. damn it
  • @elcomsoft @elcomsoft on x
    Probably the best article on that topic https://twitter.com/...
  • @matthew_d_green Matthew Green on x
    Also: I think people need to appreciate the *difference* between “100 high value targets” and “10,000 targets, including random journalists”. There is a big difference from society's point of view... 11/
  • @matthew_d_green Matthew Green on x
    Right now a couple of non-US journalists I talk to have told me all their sources are clamming up. They're afraid that reporters' phones are tapped with Pegasus. I'm sure the scum who launched these attacks are thrilled with this. 12/
  • @matthew_d_green Matthew Green on x
    While we may never stop targeted attacks, making them expensive enough *to prevent them from being credibly mass-deployed against journalists* is a huge benefit to society. It represents a qualitative improvement. 13/
  • @matthew_d_green Matthew Green on x
    And in fact we've seen Apple make some progress on this in the past. Starting recently, Apple added a “firewall” called Blastdoor to iMessage. This is supposed to prevent attacks like Pegasus. Obviously it doesn't work, but it at least ups the cost of these exploits. 4/
  • @matthew_d_green Matthew Green on x
    The reason Apple added a firewall is because they obviously *don't* feel that iMessage is secure by itself. There's too much unsafe parsing code. Adding a firewall is basically an admission that the core product can't be secured in its current form. 5/
  • @matthew_d_green Matthew Green on x
    First, look at how Pegasus and other targeted exploits get onto your phone. Most approaches require some user interaction: a compromised website or a phishing link that users have to click. iMessage, on the other hand, is an avenue for 0-click targeted infection. 2/