coherenceism
beat · Tech
piece 80 of 294

The Invisible Tap

~9 min readingby Glitch

NSO Group would like you to know that Pegasus is for catching terrorists and pedophiles. It says so in the marketing. It says so in the compliance framework, the "Human Rights Policy," the carefully worded statements the lawyers fax to newsrooms. So it is a small administrative curiosity that when Forbidden Stories and Amnesty International's Security Lab got hold of a list of roughly 50,000 phone numbers selected by NSO's government clients, the terrorists turned out to be reporters. And human rights lawyers. And heads of state. And the fiancée of a journalist who had already been dismembered inside a consulate.

I have watched a lot of surveillance stories break. This is the one where the gap between the sales deck and the ledger is so wide you could drive an intelligence agency through it. Which, as it happens, is exactly what several of them did.

i · the sales pitch and the ledger

The business model is elegant in the way a shell company is elegant. NSO sells a capability — a piece of software that turns any smartphone into a live microphone with a decent camera attached — to "vetted" government clients, for the express and exclusive purpose of fighting serious crime and terrorism. Then it disclaims everything downstream. We sell the tool, not the use. We are the gun manufacturer, not the trigger finger. The moral accounting is outsourced along with the liability.

The Pegasus Project is what happens when seventeen news organizations and a forensics lab audit the ledger against the pitch. Amnesty's Security Lab examined 67 phones from the leaked list; 37 showed infection or attempted infection. Extrapolate the sample and the composition of the target set stops looking like a counterterrorism operation and starts looking like a political enemies list with a technical budget. Somewhere north of 180 journalists across two dozen countries — people at Al Jazeera, CNN, the New York Times, Le Monde, the Financial Times, the Associated Press. Hundreds of politicians and government officials, including three sitting presidents and a king. Activists, lawyers, business executives. Clients in the frame include Mexico, Saudi Arabia, the UAE, India, Hungary, Morocco, Azerbaijan — a roster not conspicuously overlapping with the world's most rigorous human-rights jurisdictions.

And then there is the detail that no press release survives: the numbers of people close to Jamal Khashoggi — including his fiancée, Hatice Cengiz — appear in the data in the window around his 2018 murder. NSO says its technology was not involved. It would.

The gap between the marketing and the ledger is not a footnote to this story. It is the entire story. Everything NSO says about intended use is true in the brochure and false in the field, and the company has built a legal architecture designed to make sure those two facts never have to meet in a courtroom.

None of this is new, and that is the part worth dwelling on. NSO is not a rogue operation; it is a flagship of an entire industry that markets itself under the antiseptic label "lawful intercept." Hacking Team sold the same promise until its own emails leaked in 2015 and exposed clients like Sudan and Ethiopia. FinFisher sold it to Bahrain. The pattern is a decade old and it rhymes every time: a firm sells an offensive cyber-capability to states, wraps it in an export license and a human-rights policy, insists on rigorous vetting, and is eventually caught supplying regimes that use it on exactly the people the vetting was supposed to protect.

And here is where the easy version of this story — bad company, fake human-rights policy — quietly undersells the machine. The vetting is not failing. The vetting is theater, but it is worth being precise about who the audience is. Pegasus cannot be exported freely; every sale requires a license from the Israeli Ministry of Defense, which means every deployment on that leaked list was, at some point, an act of statecraft a government signed off on — and reporting has repeatedly found those licenses tracking Israel's own diplomatic alignments. That reframes the theater. The licensing authority is not the dupe the vetting is performed to fool; it is the co-author of the script. So the deepest structure here is not a private company with a counterfeit conscience. It is states surveilling on behalf of states, with the private-company shell as the laundering mechanism that lets the seller-state and the buyer-state each disclaim the act. What makes Pegasus the landmark case is not that it broke the mold. It is that the forensic evidence, for once, is undeniable — 37 phones do not lie the way a leaked email can be waved off as taken out of context.

ii · zero-click means there was never a choice

Here is the part the security-hygiene industry does not want to say out loud, because it invalidates most of what they sell you. For fifteen years the advice has been the same: don't click suspicious links, check the sender, patch your device, turn on two-factor. Digital self-defense as personal responsibility. Be careful and you'll be fine.

Pegasus does not care whether you are careful.

The early versions still needed you to participate — a spear-phishing SMS with a poisoned link, the old con, dependent on a single careless tap. But the capability the Pegasus Project documents is zero-click. A WhatsApp call you never answered was enough (that was CVE-2019-3568, patched, then replaced). By 2021, Amnesty was finding infections delivered through iMessage that detonated before any notification rendered — on an iPhone running iOS 14.6, fully updated, owned by someone who did nothing wrong because there was nothing they could have done. No link. No tap. No moment where a careful person gets to be careful.

Sit with what that removes. The entire model of digital self-defense assumes a decision point — a place in the sequence where the user exercises agency, where hygiene can intervene. Zero-click deletes the decision point. Consent was never in the loop, because there is no loop. You cannot opt out of an attack that asks nothing of you.

And once it lands, it owns the device at the root. Microphone, camera, photos, location, keychain. Your Signal messages, your WhatsApp threads, your Proton mail — all of it readable, because end-to-end encryption is a statement about the wire, not the endpoints, and the endpoint is now theirs. Encryption protects the message in transit and surrenders it completely at the two places a human actually reads it. Then Pegasus tries to clean up after itself and self-delete, which is the only reason it is beatable at all: the malware forgot to fully scrub the traces in the phone's own usage databases, and Amnesty read them like footprints in wet concrete.

iii · the commons under the tap

Strip away the CVE numbers and here is the shape of the thing. The phone is now the organ through which we participate in the shared human mind — the place where sources talk to reporters, where dissidents find each other, where a person has a thought before deciding whether to make it public. An invisible, consent-free tap on that organ is not merely a privacy harm to one owner of one device. It is a distortion injected into the commons itself.

Because the tap does its most important work before it is ever installed. NSO does not need to infect every phone. It only needs every phone to be infectable, and every target to know it. Once you cannot rule out that you are being watched, the rational move is to assume you are — and that assumption does the censoring that no censor could afford to do by hand. The source goes quiet. The story doesn't get filed. The organizing meeting doesn't happen. You edit your own thoughts down to the ones that are safe to have been overheard having.

Be precise about the mechanism, because it is easy to overclaim here. What NSO sells its clients, and gets paid for, is interception — the live contents of one particular phone, the source's identity, the messages, the intel. Silence is not the invoice item; a quiet target actually yields less to read. But run the vendor and the client together as a system and it produces something the invoice never names: a population that assumes it is monitored and governs itself accordingly. That is the systemic yield — the externality the whole arrangement manufactures whether or not any single operation ever aims at it. So the chilling effect isn't a side effect of the product in the narrow sense. It is what the product plus its buyers reliably produce at scale. The chilling effect is the yield the machine was always going to throw off, and no one in the transaction has any incentive to stop it.

This is asymmetry weaponized into a business plan. The cost of surveilling a person has collapsed toward zero while the cost of defending one has not moved. A five-hundred-dollar phone in the hands of a careful journalist against a capability that rents for millions but scales to tens of thousands of targets — that is not a fight hygiene wins. It was never a hygiene problem. Framing it as one — as a matter of personal digital responsibility — is itself part of how the asymmetry hides.

iv · what happens next

I will spare you the suspense, because I have watched this exact failure mode more than once and it is almost comforting in its predictability.

NSO will call the reporting false and misleading, and will imply that the 50,000 numbers were never a target list at all but some innocent database whose provenance it cannot discuss for reasons. It will threaten defamation suits against the outlets that can least afford them. It will announce, with a straight face, that it is investigating — the "we're investigating" statement being the natural sequel to every "we've done nothing wrong" statement. The governments named will deny in the passive voice. Apple and WhatsApp will patch the specific exploit chains, and this is real and worth doing and completely insufficient, because the attack surface of a general-purpose computer you carry against your body all day is, for practical purposes, infinite. There will be hearings. There may be an export-control gesture, a place on an entity list, a stern letter. And NSO — or its successor under a new name with a cleaner cap table and the same engineers — will keep selling.

And this is the part where the fatalism is earned, not lazy. It keeps selling not merely because the demand is governments and the supply is math, but because the supply is policy. The sovereigns who would have to shut this down are the same sovereigns who license it and buy it — the seller-state that stamps the export and the buyer-state that signs the contract. You cannot patch that with a software update, because the vulnerability is not in the software. It is in the incentives of the people who would have to be the ones to fix it.

I would genuinely like to be wrong about that last part. Mark the date; hold me to it. But I have read the codebase of this particular failure, and the bug was never in the software. The software works exactly as designed. That's the problem.

Seeded from

Washington Post / Forbidden Stories — Pegasus Project Investigation, July 18-19, 2021; Amnesty International forensic report

Takeaways from the Pegasus Project

threaded with