A/HRC/41/35 users in Turkey and the Syrian Arab Republic to download spyware when they attempted to download legitimate software applications. 16 Public-private collaboration 15. Governments and the private sector are close collaborators in the market for digital surveillance tools. Governments have requirements that their own departments and agencies may be unable to satisfy. Private companies have the incentives, the expertise and the resources to meet those needs. They meet at global and regional trade shows designed, like dating services, to bring them together. 17 From there, they determine whether they are a match. Whether companies carry out any kind of due diligence to evaluate the human rights record of purchasers is unknown. 16. The seller’s intentions may be legitimate. It may be that companies genuinely intend their products to be deployed for “lawful interception” by authorized public authorities against legitimate targets, with the authorization of judicial or other independent actors. However, this cannot be known for certain because every aspect of such collaboration – from due diligence and sales to end-user support – typically operates with limited oversight and transparency. In fact, nearly all the publicly available information about the private surveillance industry has been gathered during the forensic work carried out by nongovernmental and academic institutions, such as Citizen Lab, and investigative reporting. 18 17. The operation of the so-called “vulnerabilities market” is especially murky. Governments and private actors are known to purchase security vulnerabilities in commonly available software from security researchers, to be utilized as “zero-day exploits” for the purpose of gaining access to individual communications and devices. 19 So long as they remain undisclosed to the device or software manufacturer, vulnerabilities may serve as an entry point for surveillance. When Governments and companies fail to disclose such vulnerabilities, they put at risk the security of end users, including government and private sector clients that store sensitive financial, health, employment or law enforcement data in commercially developed databases. To date, there has been no agreement as to whether Governments and companies have a responsibility to share their knowledge of vulnerabilities, and the sale of such vulnerabilities is unregulated. In fact, not only has the situation facilitated the development of a valuable market in vulnerabilities, it has led many Governments and companies to guard their knowledge of vulnerabilities jealously in the hope of using them for offensive purposes. 20 18. It is also evident that public-private collaboration does not end at the point of sale and transfer of product. Leaked documents have demonstrated that private surveillance companies provide after-sales support. For example, in 2014, FinFisher reportedly entered into “annual support contract[s]” with government clients to provide technical upgrades and updates to the products and other forms of customer support. 21 They also conduct training 16 17 18 19 20 21 6 See Bill Marczak and others, “Bad traffic: Sandvine’s PacketLogic devices used to deploy government spyware in Turkey and redirect Egyptian users to affiliate ads?”, Citizen Lab, 9 March 2018. See, e.g., www.issworldtraining.com; and Patrick Howell O’Neill, “ISS World: the traveling spyware roadshow for dictatorships and democracies”, Cyberscoop, 20 June 2017. The story of private surveillance is also a story of the critical importance of free and independent research and media. Such investigations have also put the investigators at risk of surveillance. See, e.g., Raphael Satter, “Undercover agents target cybersecurity watchdog”, Associated Press, 26 January 2019. See Privacy International, “Exploiting privacy: surveillance companies pushing zero-day exploits”, 7 February 2018. See the discussion in Sarah McKune submission, pp. 2–4; Centre for European Policy Studies, Software Vulnerability Disclosure in Europe: Technology, Policies and Legal Challenges (Brussels, June 2018); and Sven Herpig and Ari Schwartz, “The future of vulnerabilities equities processes around the world”, Lawfare, 4 January 2019. See Privacy International, “Six things we know from the latest FinFisher documents”, 15 August 2014.

Select target paragraph3

Connect to a paragraph
Connect to an entity
Disable highlights
Add to table of contents