TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Three ex-US intelligence officers admit hacking for UAE

743 pointsby andrewnicolaldeover 3 years ago

22 comments

badRNGover 3 years ago
There is an incredibly well produced podcast episode on these ex-NSA engineers working for the UAE that came out a couple of years ago. Check out Darknet Diaries Ep47: Project Raven [1].<p>Synopsis is that the UAE hires ex-NSA employees as &quot;penetration testers&quot; and when they enter the country for cybersecurity work, some are pulled aside to be briefed to an opportunity called &quot;Project Raven&quot; to assist Emirati intelligence with targeting, allegedly in the interest of counter-terrorism. The thing is, only Emiratis have &quot;hands on keyboard&quot; while the US engineers sit beside them and guide them, which supposedly dodges any legal concerns. Those who Jack interviewed decided to leave Project Raven when it became clear they were targeting dissidents, human rights activists, and later, Americans. As you might imagine, ex-NSA employees who target US citizens for a foreign government are breaking the law. I do wonder if it&#x27;s these ex-Project Raven engineers that have led prosecutors down the road to where we are now.<p>[1] <a href="https:&#x2F;&#x2F;darknetdiaries.com&#x2F;episode&#x2F;47&#x2F;" rel="nofollow">https:&#x2F;&#x2F;darknetdiaries.com&#x2F;episode&#x2F;47&#x2F;</a>
评论 #28545542 未加载
评论 #28542208 未加载
评论 #28548815 未加载
评论 #28543771 未加载
评论 #28542016 未加载
评论 #28542214 未加载
评论 #28542698 未加载
评论 #28542521 未加载
评论 #28548508 未加载
评论 #28546601 未加载
评论 #28546334 未加载
评论 #28568387 未加载
评论 #28542174 未加载
评论 #28542850 未加载
robbiet480over 3 years ago
More interesting to me is that one of the named persons, Daniel Gericke, is the CIO of ExpressVPN [1] which sold yesterday, the same day that the DoJ came to this prosecution agreement (!), for just under $1 billion. [2]<p>[1]: <a href="https:&#x2F;&#x2F;www.cnet.com&#x2F;tech&#x2F;services-and-software&#x2F;expressvpn-cio-among-three-facing-1-6-million-doj-fine-project-raven&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.cnet.com&#x2F;tech&#x2F;services-and-software&#x2F;expressvpn-c...</a> [2]: <a href="https:&#x2F;&#x2F;www.techradar.com&#x2F;news&#x2F;expressvpn-to-join-kape-in-largest-deal-ever-in-vpn-industry" rel="nofollow">https:&#x2F;&#x2F;www.techradar.com&#x2F;news&#x2F;expressvpn-to-join-kape-in-la...</a>
评论 #28542295 未加载
评论 #28542663 未加载
评论 #28546224 未加载
评论 #28549560 未加载
评论 #28542025 未加载
akulbeover 3 years ago
I&#x27;m confused. Isn&#x27;t this considered <i>treason</i>??<p>They get no jail time? They get to buy their way out?!<p>&gt; “Hackers-for-hire and those who otherwise support such activities in violation of U.S. law should fully expect to be prosecuted for their criminal conduct.”<p>I know they lose their clearances and pay a bunch of money, but this seems like it merits a lot more punishment than that.
评论 #28541793 未加载
评论 #28541885 未加载
评论 #28541705 未加载
评论 #28541789 未加载
评论 #28545386 未加载
评论 #28547402 未加载
评论 #28541873 未加载
评论 #28541900 未加载
评论 #28541798 未加载
评论 #28541806 未加载
评论 #28544804 未加载
shmattover 3 years ago
This is an increasing problem in Israel as well.<p>Soldiers who spent years in the exploit-finding units of 8200 (Israeli NSA) can work for NSO and stay in Israel. But they can also leave the country and work for foreign entities. Sometimes without even knowing who their employer is<p>One famous case was &quot;Dark Matter&quot; a UAE company who set up offices in Cyprus and offered 8200 soldiers 7 figures (in USD) a year salaries to relocate, outside of the Israeli Government oversight - which NSO need to adhere to, and work for them
评论 #28543186 未加载
评论 #28541808 未加载
wwwdonohueover 3 years ago
Funny quote from Lori Stroud:<p>&gt; The bureau’s dedication to justice is commendable... the most significant catalyst to bringing this issue to light was investigative journalism - the timely, technical information reported created the awareness and momentum to ensure justice<p>A lot of moral superiority there when based on how Stroud has talked about her own work with Project Raven [1], she was perfectly happy to help the UAE kidnap, torture, and disappear dissidents (including children), human rights activists, and journalists.<p>[1] <a href="https:&#x2F;&#x2F;www.reuters.com&#x2F;investigates&#x2F;special-report&#x2F;usa-spying-raven&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reuters.com&#x2F;investigates&#x2F;special-report&#x2F;usa-spyi...</a>
评论 #28545866 未加载
academia_hackover 3 years ago
If you actually read OP&#x27;s link, the charges seem to have nothing to do with the fact that these individuals once worked for the US gov. Instead, the US federal government seems to be asserting that knowledge of offensive security tools and practices in Cybersecurity consultancy is somehow ITAR restricted in the same way that a weapon blueprint would be. That strikes me as absolutely preposterous and I&#x27;m disappointed the defendants settled rather than pushed back on obvious federal overreach into the lives and careers of private persons.
评论 #28541869 未加载
评论 #28544254 未加载
评论 #28543761 未加载
评论 #28542587 未加载
评论 #28542436 未加载
ComodoHackerover 3 years ago
As a non-US person, could someone explain a legal construct of &quot;paying $XXX to resolve criminal charges&quot;? Doesn&#x27;t &quot;criminal&quot; mean there must be some real punishment?
评论 #28543096 未加载
评论 #28546222 未加载
评论 #28542483 未加载
评论 #28542819 未加载
thepasswordisover 3 years ago
Increasingly it seems like our elites look at The US as a resource to be mined, not a home, not a collaborative project.
评论 #28542504 未加载
评论 #28542078 未加载
评论 #28541914 未加载
评论 #28545679 未加载
评论 #28542980 未加载
rank0over 3 years ago
The punishment seems pretty insignificant here. I am surprised the DoJ isn&#x27;t pursuing prison time.
评论 #28542925 未加载
评论 #28544542 未加载
评论 #28553380 未加载
bmcn2020over 3 years ago
Does anyone know whether the spyware mentioned is anyhow related to Project Pegasus[1? It&#x27;s also really interesting that Apple patched Security issues for iOS that was targeted by NSO Group and makes me wonder if that might be the same vulnerabilities exploited by the UAE hacker for higher company [2]. [1] [<a href="https:&#x2F;&#x2F;cybernews.com&#x2F;news&#x2F;expressvpn-cio-daniel-gericke-fined-335-000-for-cyber-espionage" rel="nofollow">https:&#x2F;&#x2F;cybernews.com&#x2F;news&#x2F;expressvpn-cio-daniel-gericke-fin...</a>] [2] <a href="https:&#x2F;&#x2F;www.npr.org&#x2F;2021&#x2F;09&#x2F;14&#x2F;1036869715&#x2F;apple-issues-critical-patch-to-fix-security-hole-exploited-by-spyware-company" rel="nofollow">https:&#x2F;&#x2F;www.npr.org&#x2F;2021&#x2F;09&#x2F;14&#x2F;1036869715&#x2F;apple-issues-criti...</a>
评论 #28548455 未加载
openasocketover 3 years ago
I really don&#x27;t think deferred prosecution is warranted here, this should have been a plea deal. I&#x27;m ambiguous on whether or not these guys should serve jail time, but they deserve a criminal conviction and a criminal record.
errantmindover 3 years ago
One of these officers is CIO of ExpressVPN. Can you really trust a service with these ties, which also just sold to an ad agency? I personally would not.
aerostable_slugover 3 years ago
A reminder that former members of military special operations units admitted assassinating political opponents for UAE. No one was prosecuted.<p><a href="https:&#x2F;&#x2F;sofrep.com&#x2F;news&#x2F;exclusive-interview-with-an-american-mercenary-who-ran-combat-ops-in-yemen&#x2F;" rel="nofollow">https:&#x2F;&#x2F;sofrep.com&#x2F;news&#x2F;exclusive-interview-with-an-american...</a><p><a href="https:&#x2F;&#x2F;spotterup.com&#x2F;episode-44-dale-comstock-former-army-special-forces-cag-operator-merc-and-much-more&#x2F;" rel="nofollow">https:&#x2F;&#x2F;spotterup.com&#x2F;episode-44-dale-comstock-former-army-s...</a>
smashahover 3 years ago
While being federal agents they try to spread democracy with bombs. Once they leave, the pretence is dropped and squash any organic calls for democracy and dissent with hacking.<p>Outraged when these countries are hacking individuals? Then also be outraged when you sell them F35s
Jerry2over 3 years ago
No jail time? I guess when you&#x27;re a member of IC, regular laws don&#x27;t apply to you.
truted2over 3 years ago
&gt; to obtain remote, unauthorized access to any of the tens of millions of smartphones and mobile devices utilizing a U.S. Company Two-provided operating system<p>U.S. Company Two provides a mobile operation system. Hmmm, now who could that be?
评论 #28543953 未加载
stjohnswartsover 3 years ago
There&#x27;s really no reason why they should be able to buy their way out of prison time. It&#x27;s kind of a shame. Justice is supposed to be blind, including to financial assets of the perps.
sneakover 3 years ago
I wish my friends could buy their way out of hacking charges from the DOJ instead of having to get tortured for months and months in US prisons.
aborsyover 3 years ago
How does the security of a Google Pixel phone with Android or GrapheneOS compare with iPhone’s security?<p>The iOS exploits sound scary. Some of them are even zero click.
评论 #28545325 未加载
clarleover 3 years ago
Based on the timeline, is U.S. Company Two Google or Apple?<p>Who had security patches released in September 2016 and August 2017?
5faulkerover 3 years ago
Won&#x27;t be the first time this happens...
kchoudhuover 3 years ago
Good.