Paragon Spyware Faces Scrutiny Over Logging, Oversight and Customer Abuse
Paragon customers can enable logging, according to Boyd. However, Paragon cannot—and does not want to—access those logs. Government watchdogs could use them to investigate potential abuse within their own institutions, as an Italian parliamentary committee did last year in the Citizen Lab scandal.
That approach also creates the possibility that officials could conceal or deny misuse if investigators uncover evidence in the logs.
Paragon Calls Limited Access to Spyware Logs a Selling Point
Rather than viewing Paragon’s lack of access to customer logs as an accountability problem, Boyd describes it as a selling point. He says customers would not purchase the company’s products if Paragon could view sensitive targeting information and the logs containing it.
“There’s a balance to be struck between privacy and security and being able to ensure that customers are using them correctly,” Boyd says. “And I think we’ve hit the perfect balance.”
According to Boyd, Paragon seeks to maintain that balance by carefully vetting customers and rejecting countries where spyware is more likely to be abused.
John Scott-Railton, a senior researcher at Citizen Lab who has long tracked the misuse of commercial spyware by governments, called the revelations surprising. He described the absence of logging requirements as “reckless.”
“What Paragon means in some substantive ways is that there is less oversight, less transparency and less contractual protection against wrongdoing than NSO Group,” Scott-Railton says. “It’s refreshing honesty for the CEO to admit that his customers won’t tolerate surveillance. Accountability is bad for business. And it sends a signal to lawmakers and regulators that the spyware industry’s self-regulation cannot be trusted.”
Scott-Railton also finds it ironic that Paragon relies on organizations such as Citizen Lab to expose customer abuses while actively working to hide its spyware from infected devices and prevent its discovery—an approach that can conceal potential exploits.
“We only found a very, very, very small subset of infections,” Scott-Railton says. “These companies are spending millions of dollars hiding from us.”
U.S. Senator Ron Wyden told WIRED that surveillance tools without effective oversight and transparency are “inevitably subject to abuse.”
“It’s easy to claim that a powerful hacking tool isn’t being abused if you don’t bother to find out how your customers are using it,” Wyden says. “The fact that Paragon refuses to audit the use of its tools or even attempt to match the findings of Citizen Lab’s small team of researchers is a major red flag.”
Paragon’s Roots in Israeli Intelligence
Paragon was founded in 2019 by Brigadier General Ehud Schneerson, the former commander of the Israeli Armed Forces Communications Intelligence Group 8200. He co-founded the company with three other 8200 veterans and former Israeli Prime Minister Ehud Barak.
In 2021, the company said it had no customers, but it wanted to develop Graphite and enter the lucrative U.S. market.
Following attacks involving NSO Group’s Pegasus spyware and Candiru’s DevilsTongue malware, the U.S. government began cracking down on foreign spyware companies. DevilsTongue was used against government officials, journalists, dissidents, activists and academics.
U.S. Restrictions on Commercial Spyware
In 2021, the U.S. Department of Commerce added NSO Group and other foreign companies to its Entity List.
The Israeli government also significantly reduced the number of countries to which Israeli companies could sell spyware—from 102 to 37. The restrictions excluded countries including Saudi Arabia, the United Arab Emirates, Morocco and Mexico.
More than a year later, the Biden administration and Congress introduced additional guardrails intended to limit the U.S. government’s ability to purchase foreign commercial spyware when it poses a national security risk or could be misused by a foreign government.
Source: www.wired.com


