Citizen Lab Profile Banner
Citizen Lab Profile
Citizen Lab

@citizenlab

121,741
Followers
1,451
Following
310
Media
12,696
Statuses

Research & development at the intersection of cyberspace, global security & human rights. Munk School of Global Affairs & Public Policy, University of Toronto

Toronto
Joined April 2009
Don't wanna be here? Send us removal request.
Pinned Tweet
@citizenlab
Citizen Lab
22 days
🚨 WE URGE ALL USERS TO UPDATE THEIR KEYBOARD APPS IMMEDIATELY 🚨 🆕 New @citizenlab report finds vulnerabilities in the security of cloud-based #pinyin #keyboard apps from vendors Baidu, Honor, iFlytek, OPPO, Samsung, Tencent, Vivo, and Xiaomi that could be exploited to reveal
46
741
1K
@citizenlab
Citizen Lab
5 years
WhatsApp has just pushed out updates to close a vulnerability. We believe an attacker tried (and was blocked by WhatsApp) to exploit it as recently as yesterday to target a human rights lawyer. Now is a great time to update your WhatsApp software
@FinancialTimes
Financial Times
5 years
WhatsApp has announced that it discovered attackers were able to install surveillance software on to both iPhones and Android phones by ringing up targets using the app’s call function. The app is used by 1.5bn people worldwide.
28
948
727
28
798
718
@citizenlab
Citizen Lab
2 years
The Citizen Lab, in collaboration with Catalan civil society groups, has identified at least 65 individuals targeted or infected with mercenary spyware.
8
321
421
@citizenlab
Citizen Lab
1 year
🚨NEW REPORT: NSO Group’s #Pegasus #Spyware returns in 2022 with a trio of iOS 15 and iOS 16 zero-click exploit chains. The report finds NSO group clients deployed exploits against civil society members including two human right defenders in #Mexico
5
239
339
@citizenlab
Citizen Lab
6 years
NEW REPORT: Bad Traffic: Deep Packet Inspection Devices Used to Deploy Government Spyware in Turkey and Redirect Egyptian Users to Affiliate Ads? packetlogic-devices-deploy-government-spyware-turkey-syria
Tweet media one
8
335
318
@citizenlab
Citizen Lab
5 years
We have identified over 100 cases of abusive targeting in at least 20 countries that took place after Novalpina Capital acquired NSO Group and began an ongoing public relations campaign to promote the narrative that the new ownership would curb abuses.
8
239
315
@citizenlab
Citizen Lab
4 years
Have you heard about us on @joerogan thx to @Snowden ? Check out Security Planner! Gives hints on how to make your online experience more secure: . Also see our friends @EFF 's surveillance self-defence guide
8
113
302
@citizenlab
Citizen Lab
6 years
“Leaked documents have long indicated that a number of governments are targeting their opponents by surreptitiously injecting spyware into their Internet connections. For the first time ever, we have the proof.” - @billmarczak
2
286
305
@citizenlab
Citizen Lab
3 years
While analyzing the phone of a Saudi activist infected with NSO Group’s Pegasus spyware, we found a zero-day zero-click exploit against iMessage. The exploit, called FORCEDENTRY, targets Apple’s image rendering library & was effective against Apple iOS, MacOS & WatchOS devices.
108
145
286
@citizenlab
Citizen Lab
4 years
While ostensibly sold to thwart terrorism, commercial spyware is habitually abused and used to target journalists. “What we have found is that companies either are unwilling or unable to control how their government clients use it.”- @RonDeibert
7
176
280
@citizenlab
Citizen Lab
3 years
The deployment of NSO Group’s Pegasus spyware is, unfortunately, not new. Since 2016, the Citizen Lab + others have documented the abuse of this government-exclusive technology. To help keep track of these developing issues, we've created a living thread for all of our reports🧵
1
149
275
@citizenlab
Citizen Lab
3 years
Today, September 13th, Apple is releasing an update that patches CVE-2021-30860. We urge everyone to immediately update all Apple devices.
6
148
250
@citizenlab
Citizen Lab
3 years
In the two years since heightened calls for democracy in Hong Kong began, thousands of images have been censored on Chinese social media. From calls for international support to memes, no image of the movement is off limits.
18
219
245
@citizenlab
Citizen Lab
3 years
Recently, NSO Group extended an invitation to meet and discuss our concerns about their ongoing spyware abuse in more detail. We do not believe this invitation is made in good faith and have declined. Here’s why:
4
102
241
@citizenlab
Citizen Lab
8 years
Thanks from our team to @Apple for their commitment to working with us and @Lookout and quickly patching the Trident vulnerabilities
0
95
214
@citizenlab
Citizen Lab
4 years
This report examines encryption in the popular Zoom app. We find that Zoom has “rolled their own” encryption scheme, which has significant weaknesses & we identify potential areas of concern in Zoom’s infrastructure, including the transmission of encryption keys through China.
3
115
199
@citizenlab
Citizen Lab
1 year
NEW REPORT: SWEET QUADREAMS: A first look at #spyware vendor QuaDream’s spy tools, victims and customers. We identified traces of suspected exploit deployed against iOS versions 14.4 and 14.4.2 and possibly other versions as zero-day vulnerability.
7
155
207
@citizenlab
Citizen Lab
9 months
🚨🚨➡️ NEW REPORT OUT > Imagine if someone read everything you type online. Our new report-  “Please do not make it public”, analyzes Tencent's #Sogou Input Method, the most popular input app in #China has serious vulnerabilities in the encryption system.
4
122
195
@citizenlab
Citizen Lab
6 years
Saudi activists: here are some tips on how to inspect your phone for possible NSO/Pegasus spyware.
Tweet media one
Tweet media two
5
143
183
@citizenlab
Citizen Lab
4 years
NEW FELLOWSHIP OPPORTUNITY @citizenlab : "Citizen Lab Fellowship: Surveillance, Digital Security, and Race":
6
178
187
@citizenlab
Citizen Lab
3 months
🚨🆕 REPORT- "PAPERWALL": #Chinese websites posing as local news outlets target global audiences with pro-Beijing content. Over 30 countries, we discover a network of #disinformation and attacks masquerading as local news outlets, in local language.
15
128
181
@citizenlab
Citizen Lab
6 years
Very excited to launch @SecPlanner : advice from the world's leading experts in digital safety. Answer a short survey about your devices and online habits, and we recommend easy and accessible steps you can take to instantly improve your digital security
Tweet media one
4
149
173
@citizenlab
Citizen Lab
2 years
While Pegasus dominates headlines, it's not alone. "What is truly daunting to contemplate...is that NSO Group is but one among many companies in a growing marketplace for this type of surveillance technology." - @RonDeibert
6
83
166
@citizenlab
Citizen Lab
2 years
The Citizen Lab is not conclusively attributing the operations to a specific entity, but strong circumstantial evidence suggests a nexus with Spanish authorities.
9
138
174
@citizenlab
Citizen Lab
5 years
"Now, after months of investigation, we can say who was behind this attack. Today, we have filed a complaint in federal court that explains what happened and attributes the intrusion to an Israeli technology company called NSO Group."
5
144
163
@citizenlab
Citizen Lab
22 days
A network eavesdropper can completely reveal keystrokes for apps we tested. This puts upto a billion people who use these input methods at risk, including people who live in #China and diaspora users across the world, and others. We urge all users of Sogou, Baidu, and iFlytek
4
61
168
@citizenlab
Citizen Lab
4 years
Anatomy of a Zoom call
Tweet media one
4
85
159
@citizenlab
Citizen Lab
2 years
We shared a selection of Pegasus cases with @AmnestyTech , which independently validated our forensic methodology.
4
106
159
@citizenlab
Citizen Lab
5 years
What does social engineering look like? Posing as a @nytimes journalist and repeatedly asking for feedback on news articles related to your work, hoping that you'll click on malicious links.
Tweet media one
1
109
148
@citizenlab
Citizen Lab
7 years
Citizen Lab is excited to launch Secure Accounts: a free resource to help anyone protect their digital presence
Tweet media one
0
138
150
@citizenlab
Citizen Lab
1 year
Ending the year with amazing news. Our Director @RonDeibert has been appointed to this year’s Order of Canada🇨🇦. He says, “it’s no secret that I’ve been critical of our lack of accountability around law enforcement but that doesn’t mean I’m not patriotic”.
8
28
148
@citizenlab
Citizen Lab
2 years
Victims included Members of the European Parliament, Catalan Presidents, legislators, jurists, and members of civil society organisations. Family members were also infected in some cases.
1
143
151
@citizenlab
Citizen Lab
7 years
Full list of Mexican targets of spyware now includes int’l investigators of mass disappearances #gobiernoespia
Tweet media one
4
323
142
@citizenlab
Citizen Lab
8 years
No bug bounty for the three iOS zero days. Apple’s bounty program starts in September.
4
59
117
@citizenlab
Citizen Lab
5 years
If you study #disinformation , you should bookmark the annotated bibliography assembled by @gabriellelim : it gives readers a foundational understanding of the immense amount of work that has been done on digital disinformation and where future research may be heading.
Tweet media one
4
64
127
@citizenlab
Citizen Lab
2 years
NEW: Two journalists & human rights defenders devices hacked w Pegasus spyware 🇲🇽 Read report by @R3Dmx Citizen Lab provided technical validation details
Tweet media one
4
77
117
@citizenlab
Citizen Lab
2 years
NEW: Read statement by director @rondeibert on the fatal flaws found by senior researcher @billmarczak in a defunct CIA covert communications system. We are not publishing the full findings at this time pending responsible disclosure process...
3
66
112
@citizenlab
Citizen Lab
2 years
At least 63 were targeted or infected with Pegasus, and four others with Candiru. At least two were targeted or infected with both.
1
90
120
@citizenlab
Citizen Lab
3 years
تقرير جديد: ثغرة Zero-Click في تطبيق iMessage استخدمت لاختراق هواتف 36 شخص في ⁦ @AlJazeera ⁩ باستخدام برنامج NSO. ونعتقد (بدرجة متوسطة) ان الامارات العربية المتحدة والمملكة العربية السعودية وراءها.
6
50
106
@citizenlab
Citizen Lab
3 years
According to @lotus_ruan and @gabriellelim , fears of Chinese disinformation are often exaggerated by overblown assessments of the effects of China’s propaganda campaigns. In other words: evidence of activity is not the same as evidence of impact.
5
49
111
@citizenlab
Citizen Lab
3 years
The Citizen Lab disclosed the vulnerability and code to Apple, which has assigned the FORCEDENTRY vulnerability CVE-2021-30860 and describes the vulnerability as “processing a maliciously crafted PDF may lead to arbitrary code execution.”
4
33
104
@citizenlab
Citizen Lab
8 months
🚀 EXCITING JOB OPPORTUNITY 📢 We @citizenlab are hiring a Research Assistant. If you are passionate about research and human rights, this could be for you. ⏰ Application deadline: September 30, 2023 👉 Application details: #researchjobs
0
64
110
@citizenlab
Citizen Lab
8 years
Had there been a bounty @citizenlab and @lookout had agreed to donate to charity.
1
35
97
@citizenlab
Citizen Lab
3 years
To highlight this, we've created a history of the protests and a Lennon Wall: an interactive mosaic of these thousands of censored images, showing just how expansive this system of repression is.
3
61
103
@citizenlab
Citizen Lab
3 years
We determined that the mercenary spyware company NSO Group used the vulnerability to remotely exploit and infect the latest Apple devices with the Pegasus spyware. We believe that FORCEDENTRY has been in use since at least February 2021.
2
40
97
@citizenlab
Citizen Lab
2 years
“Even the U.K. was underestimating the threat from Pegasus, and had just been spectacularly burned” - @jsrailton
1
54
104
@citizenlab
Citizen Lab
4 years
Starting Nov. 9th, @RonDeibert will deliver this year's Massey Lectures on @cbcideas . Each of the six episodes will highlight a distinct concept in his new book, from the spread of authoritarian practices to the environmental impacts of social media.
4
41
103
@citizenlab
Citizen Lab
2 years
We identified evidence of HOMAGE, a previously-undisclosed iOS zero-click vulnerability used by NSO Group that was effective against some versions prior to 13.2.
1
72
103
@citizenlab
Citizen Lab
2 years
Spyware is huge threat to global human rights & democracy, like "a wiretap on steroids," @RonDeibert @citizenlab director to testify today before the 🇨🇦 House of Commons on RCMP use of spyware, 3pm ET, urging greater oversight & accountability
3
53
97
@citizenlab
Citizen Lab
9 years
You can find all of our #HackingTeam related reports and posts here:
1
144
93
@citizenlab
Citizen Lab
3 years
JOB POSTING: Interested in the technical, legal, and/or policy aspects of censorship and surveillance? Apply to work with the Citizen Lab as part of the @OpenTechFund Information Controls Fellowship! Deadline: June 30
1
60
96
@citizenlab
Citizen Lab
3 years
Congratulations to @RonDeibert , winner of the 2021 #ShaughnessyCohen Prize for Political Writing!
Tweet media one
5
30
95
@citizenlab
Citizen Lab
5 years
In light of two recent attempts to compromise our work at the Citizen Lab, @RonDeibert discusses the tactics used and how such deceitful attacks on an academic group like the Citizen Lab is an attack on academic freedom everywhere
3
85
95
@citizenlab
Citizen Lab
2 years
Today at 10:00 am EST, @jsrailton will be testifying before the U.S. @HouseIntel Committee. He'll be addressing the increasing harms of mercenary spyware companies and the torrent of human rights abuses they support. Watch live:
5
45
90
@citizenlab
Citizen Lab
5 years
The murder of Jamal Khashoggi is directly linked to spyware meant to target criminals, demonstrating an abuse of power in a market without consequence. And in the absence of any meaningful action, this won't be the last lethal use of such technology.
1
94
85
@citizenlab
Citizen Lab
22 days
🚨 我們強烈建議所有使用者更新手機上的中文拼音輸入法 @citizenlab 公民實驗室在八家廠商的雲端拼音輸入法中發現了一系列嚴重漏洞: @Baidu 百度、榮耀、訊飛、OPPO、三星、騰訊、Vivo
6
28
90
@citizenlab
Citizen Lab
4 years
June 4, 1989: Chinese military carries out a brutal crackdown on demonstrations calling for democratic reform, leading to deaths estimated to be between hundreds & thousands. This remains one of the most censored topics on the Internet in China. #6431truth
Tweet media one
2
36
87
@citizenlab
Citizen Lab
4 years
“I would think very carefully before I used Zoom to communicate classified information, trade secrets, or confidential medical data." - @billmarczak
1
74
84