This brand new non-fiction book combines the true story of a recent masterpiece of complex investigative journalism with revelations that are disturbing and important for all who value privacy, individual rights and democratic norms.
The authors are two noted French journalists, Laurent Richard and Sandrine Rigaud. They are both leaders in a French non-profit journalism organization called Forbidden Stories, which seeks to continue the investigative work of assassinated reporters from many dangerous authoritarian countries around the world. To accomplish this mission, they make use of the skills of a team of their own organization's staff, who work in collaboration with top reporters and technical experts from major news media companies and human rights groups from many nations.
The target of the special investigation described in this book was an Israeli company called NSO. NSO was a high-tech security company that developed and sold surveillance tools to governments. Among their most valuable tools was a secret product known as Pegasus, a combination of spy software and hosted I.T. services which allowed their customers to hack into smartphones, and to use the compromised phones and their data in a variety of nefarious ways.
Pegasus enabled not only access to all the existing content (email, text, video, audio) on any phone it compromised, but also the ability to plant data on it (such as child porn, or other fake evidence used to besmirch the phone owner’s reputation, and justify arrest and prosecution). It also allowed the cracker to activate the microphone and cameras on the phone remotely, to serve as an unintended bugging device against the phone's owner, as well as being able to use the phone's GPS information to track the phone's owner's location. And it enabled the cracker to interact with the phone in other ways too, to control it, and download a vast array of personal private information from it on demand.
The product was quietly sold to select governmental agencies in allied countries with the permission of the Israeli government. In the beginning, it was marketed and defended by NSO as a tool for democratic governments, primarily in the west, to defend themselves and their populations from terrorists and criminals, in response to the many new apps and tools for data encryption on Apple and Android phones. The ability to hack into suspects' phones appealed to worried law enforcement agencies and officials in many countries, who feared that new phone encryption apps would prevent them from being able to monitor and investigate lawbreakers effectively.
However, this positive spin on the purpose and uses of NSO's tools took a dark turn when Forbidden Stories obtained a list of over 10,000 phone numbers from a secret source (probably within the NSO company), from nations around the world, which had been hacked using Pegasus.
It quickly became obvious from the journalists' initial review of the phone numbers on the list that NSO must also be selling the product to repressive regimes and unsavory leaders in many places, to allow those dangerous customers to surveil, monitor and track individuals who were considered a threat to them or to their regime(s). Pegasus suddenly looked to be a terrifyingly powerful new weapon for authoritarian dictatorships hunting dissidents, and seeking to silence or punish political opponents and inquisitive reporters.
Once Forbidden Stories realized the threat posed by the existence and sale of this tool, to them as journalists as well as to anyone who might fear the sort of all-knowing governmental surveillance and targeting made possible by Pegasus, they set to work on trying to find out more about it. To do that, they had to slowly and carefully build a wide network of respected journalists and media outlets in many countries, who would contribute to a large group investigative journalism project, but under very strict security restrictions.
One of the greatest risks to the project, and to the journalists working on it, was that each of their own smartphones might become a potential source of leaks that could blow the story wide open, before they were able to complete the deep and wide research needed to document it. Indeed, just by tracing the owners of many of the phone numbers on the list, the journalists working on the project quickly discovered that some of their own phones had already been hacked by Pegasus customers from repressive regimes.
The reporters, computer experts and Forbidden Stories project organizers thus had to find ways to do their work, coordinate all their efforts and handle communications among participants on different continents, over a period of many months, without relying on the most common tools of their trade, the ones we all take for granted now – their phones and the internet. This made their achievements all the more difficult, and their success that much more astonishing.
This is a truly disturbing, but impressive and thoroughly researched story on how a voluntary network of idealistic journalists around the globe pieced together the truth about a set of repressive surveillance tools, aimed directly at our smartphones, that could destroy the ability of anyone to trust in their own personal safety or security from malevolent governments and criminals anywhere in the world. Having managed to uncover and document the story in astonishing detail, they then made it public, with a highly synchronized barrage of stories from many reporters in different places, with each report addressing the local instances and effects of the Pegasus spyware and operations in their many respective countries.
The fact that Forbidden Stories' investigation, and its revelations, ultimately drove NSO out of its very lucrative phone spyware business is encouraging, but only somewhat. Unfortunately, as the authors point out, we still have to recognize how relatively easy it is to create spyware systems like Pegasus, tools that can use all the wonderful technological capabilities of our smartphones against us. The authors suggest we need to try to prepare for the next time in advance, by passing laws to try to limit or prevent development of these kinds of Orwellian surveillance technologies in the future.
This is an exciting real-world thriller of investigative journalism, combined with a vital cautionary tale about the threats to freedom and privacy posed by our ubiquitous smartphone technology. It includes a powerful and enlightening introduction by Rachel Maddow. Highly recommended.