Review: Pegasus by L. Richard and S. Rigaud

Pegasus by Laurent Richard and Sandrine Rigaud 2023

This book is an exposé written by two senior journalists at the long-form news entity Forbidden Stories in Paris, France. Thanks to some serious hacking talent, this outfit was apprised—in about 2021—of a list of fifty thousand telephone numbers from all over the world. The list contained telephone numbers and dates of attempted cyber intrusion attacks for purposes of surveillance.

The outfit that created the software and other parts of the architecture to do this work was an Israeli company called NSO, the initials of the three founders. The software was Pegasus. NSO sold their software to governments who were supposed to use it to help apprehend criminals and terrorists—we’ve all heard that before, right—but besides those uses, most of these governments (almost all autocratic), including Israel, used it to monitor political opposition figures, journalists, and others who just happened not to favor the regime in power. The Moroccan government, for example, was keeping a close eye on virtually the entire French executive, including the president.

Surveillance software had been around before Pegasus, but most of it focused on computers. NSO was the first (roughly 2012) to recognize that everything important was shifting to the smartphone. Like other hacks, surveillance by Pegasus would begin with a user clicking on a link that then downloads software, triggering the rest of the infection chain. This process should be familiar to anyone today. However, NSO added another twist in 2017, known as “zero-click intrusion.” That meant the phone only had to be on to be invaded. The user doesn’t need to click on anything.  

Once onboard the phone, Pegasus could acquire “root authority” and essentially operate every app on the phone. After offloading the phone’s logs, images, emails, texts, and recordings onto client servers, Pegasus deleted itself to avoid detection. Once zero-click intrusion became available, the Pegasus user could re-access the phone and download its latest data at any time they wished. 

Users would not know of the intrusion. The software could also deliver other malware, such as ransomware attacks, or monitor conversations in real-time, among other things. For example, your government might want to imprison you, but you haven’t committed any crime. They could use Pegasus to put some child porn on your phone in a folder they create. They arrest you, confiscate your phone, and voila, discover the criminal evidence.

The book gives few details, but it says enough to understand that zero-click attacks are not trivial. Some app on your phone (we all have dozens) must have an exploitable weakness. It was the job of the NSO programmers to find these exploits and update their customer software when phone manufacturers found and closed any particular loophole. 

The target apps with the greatest potential for attack are those that receive data from the telephone network and then perform an action without requiring user intervention. Every app that notifies you of something (such as texts, emails, or alerts of all kinds, including weather applications) can be an infection vector, but they are not alone. How many apps do we run that do not need access to your microphone, camera, or contact list, yet they default—on installation—to having such access.

To make a successful attack, the attacker must have your phone number. What kind of phone you have (every OS has different vulnerabilities) also makes a difference, but Pegasus could look for all of them. Client updates to Pegasus likely contained an extensive library of the various hacks needed for any given vulnerable app on every kind of phone. If, starting with your phone number, one attack fails, Pegasus tries again. Eventually, it finds an app on that target’s phone that lets it in. 

All of this revelation about the capabilities of Pegasus are scattered throughout the story which focuses on the the people who figured out how to detect prior infection (Pegasus deletes itself when finished culling your data, but as it happens, it leaves a few illegitimate process names in the phone’s logs), the process of proving prior infections on hundreds of phones in the original list of fifty thousand (mostly journalists and a few political opponents of various regimes), the journalists themselves (a multi-continental collaboration that miraculously maintained its secrecy until their stories were simultaneously released), and the NSO company.

So what happened when all of this got out? As one might easily predict, very little. The NSO company was destroyed, but the talent that created the technology merely scattered to other places—some paid obscene salaries—and duplicated the tech for their new employers. There are now numerous Pegasus clones worldwide.

Supposedly, the Israeli government did not permit Pegasus sales to Russia, China, North Korea, or Iran (they allowed sales to Saudi Arabia). However, China has undoubtedly had this ability (developed in China [see NOTE]) for years now (see We Have Been Harmonized by Kai Strittmatter, 2019), and there is no reason to believe that, in 2025, the other three do not also possess it. In the U.S., the NSA surely has this ability. They are building (or is it operational?) the world’s largest data center for a reason after all.

NOTE: Unique among nations of the world, China, and likely also North Korea, have no need for zero-click technology based on vulnerabilities. The Chinese and North Korean States have the power to mandate that all phones sold in their respective countries come with a built-in, non-removable app that allows the government to access the phone at any time.  

Book Review: Fear: Trump in the White House by Bob Woodward

I haven’t much additional commentary to add here except perhaps to expand a little on my comparison between Wolff’s “Fire and Fury” and Woodward’s Fear. Wolff’s published much earlier covers a shorter time, about 200 days compared to Woodward’s 760+. As mentioned in my review, Wolff focuses on the ring of people immediately surrounding Trump (of course he brings in the next outer band) while Woodward expands his focus to that next outer band while the characters in the inner most group (other than Bannon) receive somewhat less scrutiny. This approach makes perfect sense given the expanded time frame of Woodward’s book.

Woodward is more sympathetic to all concerned (even Trump) than Wolff. Wolff’s picture is one of conflicting and shifting groups running around like chickens with severed heads while doing their best to increase their political influence and personal wealth. Woodward reveals the same self-interested politics in the inner circle while many of those in the wider circle, and even a few in the inner one, are trying sincerely to keep Trump from destroying the nation at every impetuous turn. Sincerity here has a mixed result as many of these people have incompatible political views concerning what constitutes a rational course in the first place. Both books paint a terrifying picture. Wolff’s is more terrifying, but Woodward’s is more frustrating because he highlights many opportunities (never taken) to bring parties together.

Fear: Trump in the White House by Bob Woodward 2018

My first observation is that this book is not as long as it seems. The first 63% (my Kindle tells me that) is the body of the book followed by a long chapter of acknowledgements, a detailed listing, chapter by chapter, of sources with lots of online links (including many of Trump’s infamous tweets), and a long index. Trump assumed the presidency on Jan 20, 2016. The last date mentioned in the book is March 21 2018 so about 760 days into the present (Sept. 2018) administration.

One cannot help but compare Woodward to Wolff’s “Fire and Fury” (also reviewed). Wolff’s focus is the shifting cabals immediately surrounding the president in his first (roughly 200) days. Woodward hits all the same characters and follows them as well but more through the lens of national and international incidents and issues occurring at the time, some precipitated by Trump himself. The characters are painted almost sympathetically, even Trump, relatively speaking. The unifying issue throughout is how the staff, principal cabinet secretaries, and members of Congress struggled to prevent the ever impetuous Trump from wrecking the economy or starting world war III, while a few were eager to egg him on in support of his most destructive instincts. The influence goes both ways. Trump appears to have supported DACA recipients specifically (though he never liked any of the rest of U.S. immigration policy) but was turned away from even DACA support by congressional hard liners.

There are lots of missing pieces. I suppose it would be impossible to include everything. Sean Spicer is mentioned, as is the hiring of Anthony Scaramucci but there is no word about their departure. Of course many characters do come and go. Like Wolff, Woodward focuses early on Bannon, but he hardly touches (of course they are present in the story) Jarad and Ivanka. Like Wolff, Woodward paints a picture of a man whose comprehension of the world’s complexity rises to the level of an elementary school graduate, a man mercurial and impulsive with uneven check on his actions by the adults in the room, often because they themselves are conflicted over every issue.

Washington Post publisher Phillip Graham seems to be credited with the observation that “Journalism is the ‘first rough draft of history'”. That rough draft is unfolding before us in books like Wolff’s and this one from Bob Woodward. I expect there will be a few more before this presidential term is over. Historians of the future (if there is a future) will not lack for sources. If like me you are a news junkie, this book will be an enjoyable, if frightening and possibly frustrating (so many opportunities lost) ride.

Review: Fire and Fury by Michael Wolff

Another diversion here into pop culture, this time the more strictly political. We live in dangerous times and there is no better symbol of them than this book. I did note in the review a single philosophical issue I had with the book. I will spend my time here in these comments elaborating a bit on it. As usual, the original Amazon review is included in full following these comments.

The matter concerns the accuracy of the portrait Wolff paints of both President Trump and the Whitehouse West Wing organization with particular focus on Steve Bannon, and the duo Bannon began to call Jarvanka, Trump’s daughter Ivanka and her husband Jared. In a way, the story is told from their viewpoint while pulling together observations and comments of other parties both a direct part of the Trump organization (however temporarily) and those on the wider periphery.

According to the story various cabals formed and evaporated over the course of Trump’s pre-inaugural period and in the first 200 days or so of the administration. It seems like the only constant was the antipathy between Bannon (painted as an essentially driven fanatic with the old fashioned instincts of a bomb throwing anarchist), and Jarvanka a pair of rich and spoiled children whose politics were liberal leaning but who hadn’t the slightest idea of how to really accomplish anything (or what could be accomplished) aside from protecting their riches and their relation to Trump. Nobody had the slightest real political experience.

Wolff gives us no reason to believe that in talking to any of these people (both the narrow and wider set of players) he was getting an unvarnished truth uncolored by their desire to use Wolff himself to “get at” any of the opposing cabals. If what he tells us is true, it would have been almost impossible for these players to relate to Wolff with the unbiased truth. Wolff became (or it was hoped he would become) one of the arrows in each cabal’s quiver. It is therefore impossible to tell if the emerging picture is a caricature or faithful photographic image. That question, I believe, will remain unanswered until further journalistic accounts of Trump’s first year (or tenure however long it goes) are written.

But all the same, and this is the scary part, the answer to the question doesn’t much matter here as concerns the relation between the Trump administration and the world (including ourselves in the U.S.). Whether caricature or photograph, the image is that of a very disturbed and dangerous situation, an American administration that not only does not know what it is doing broadly speaking, but whose ostensible leader appears pathologically unfit to serve in this office. Worse, he is surrounded by other pathologies of various kinds all of which overlap with at least two of his; great wealth taken for granted, and an unswerving belief in their judgments about matters with which their lives have prepared them in not the slightest way.

That, my friends, is frightening to me. But it gets even worse. Not only do they not understand the consequences of their actions as concerns the world at large, they do not really care so long as their wealth is preserved. That is only a little unfair because Wolff does paint Jarvanka as caring, they just don’t know what or how to do anything about it so their focus remains, as with the others, on their wealth, power, and even (especially in Bannon’s case as he was not rich) in the appearance of power.

The story continues to take bizarre twists. Today, January 16 2018, results of the President’s medical examination, including investigation of degenerative cognitive decline, were effusively described. The doctor, a military man with rows of campaign ribbons on his breast told us that this 71 year old (and obviously overweight) man was in perfect health physically and mentally. One wants to believe the doctor and perhaps it is so that there is no disease process detectable in the President’s brain. But perfect health is a bit hard to believe and would be of anyone who looked like Donald Trump does today. The doctor attributed it to “good genes”. Based on what Michael Wolff has told us, this could only be a signal that the news conference was a put on, a show. Or am I being paranoid?

Now September 2018 and Bob Woodward has released his book “Fear: Trump in the White House” which I have reviewed. More good journalism.

That’s all I’ll say for now. Happy to discuss in comments.

Fire and Fury Michael Wolff

This must have been a difficult book to write. There is so much story to be told and the principle threads so entangled that it must have been very difficult to tie them together in a coherent story. Wolff mostly succeeds, but not entirely. Then again that is an important part of the very story Wolff is trying to tell, the story itself is about an incoherent presidential administration.

Told in broadly chronological order of the presidential election of 2016 and the roughly first 200 days of the administration up to the middle of August 2017. At the end an epilogue focused on Steve Bannon, who has a claim to being the book’s main character, brings the story up to roughly October 2017, but the pace of news has hardly stopped there. As I write this in January 2018 I can only be sure that much more will happen. Within its chronology, there are frequent steps backwards as Wolff brings in the various characters and their varying alliances coloring-in their relation to the then forward moving part of the story. Of all the characters brought to the fore, at least among the dozen or more who are in direct proximity to the president by living or working in the West Wing, only a single pair (Ivanka and husband Jared Kushner) keep the same relationship relative to one another throughout. Every other person or cabal-like group changes relationships often multiple times as most of the individuals involved come into the story and then go out!

I do have one philosophical matter to bring up. Let’s grant that Wolff reported accurately on everything he was told by everybody. He presents a fair picture of that to which he was a party either first, or at most second (and occasionally third) hand. At the same time that which he is reporting is, he points out, the back stabbing testimony of each cabal out to paint the others in the worst light possible. Even if those to whom he spoke were not outright lying to him, at the least they were telling highly selective truths almost surely leaving much out. Our only hope in this mess is that from the back stabbing of all sides towards one another and the occasional more neutral voice (though nobody was entirely neutral) from the periphery, Wolff has put together if not a true portrait, then at least a portrait true to the Kafka-esque nature of the administration! If that is a horrible thought, it is what makes this an important book.

This is high class journalism first and foremost, but it reads at the same time like an Elmore Leonard novel! As Sean Spicer began to say “you can’t make this shit up!”. Frankly this book would be hysterically funny if it was not so downright dangerous and disturbing.