A/HRC/41/35
users in Turkey and the Syrian Arab Republic to download spyware when they attempted to
download legitimate software applications. 16
Public-private collaboration
15.
Governments and the private sector are close collaborators in the market for digital
surveillance tools. Governments have requirements that their own departments and agencies
may be unable to satisfy. Private companies have the incentives, the expertise and the
resources to meet those needs. They meet at global and regional trade shows designed, like
dating services, to bring them together. 17 From there, they determine whether they are a
match. Whether companies carry out any kind of due diligence to evaluate the human rights
record of purchasers is unknown.
16.
The seller’s intentions may be legitimate. It may be that companies genuinely intend
their products to be deployed for “lawful interception” by authorized public authorities
against legitimate targets, with the authorization of judicial or other independent actors.
However, this cannot be known for certain because every aspect of such collaboration –
from due diligence and sales to end-user support – typically operates with limited oversight
and transparency. In fact, nearly all the publicly available information about the private
surveillance industry has been gathered during the forensic work carried out by nongovernmental and academic institutions, such as Citizen Lab, and investigative reporting. 18
17.
The operation of the so-called “vulnerabilities market” is especially murky.
Governments and private actors are known to purchase security vulnerabilities in
commonly available software from security researchers, to be utilized as “zero-day
exploits” for the purpose of gaining access to individual communications and devices. 19 So
long as they remain undisclosed to the device or software manufacturer, vulnerabilities may
serve as an entry point for surveillance. When Governments and companies fail to disclose
such vulnerabilities, they put at risk the security of end users, including government and
private sector clients that store sensitive financial, health, employment or law enforcement
data in commercially developed databases. To date, there has been no agreement as to
whether Governments and companies have a responsibility to share their knowledge of
vulnerabilities, and the sale of such vulnerabilities is unregulated. In fact, not only has the
situation facilitated the development of a valuable market in vulnerabilities, it has led many
Governments and companies to guard their knowledge of vulnerabilities jealously in the
hope of using them for offensive purposes. 20
18.
It is also evident that public-private collaboration does not end at the point of sale
and transfer of product. Leaked documents have demonstrated that private surveillance
companies provide after-sales support. For example, in 2014, FinFisher reportedly entered
into “annual support contract[s]” with government clients to provide technical upgrades and
updates to the products and other forms of customer support. 21 They also conduct training
16
17
18
19
20
21
6
See Bill Marczak and others, “Bad traffic: Sandvine’s PacketLogic devices used to deploy
government spyware in Turkey and redirect Egyptian users to affiliate ads?”, Citizen Lab, 9 March
2018.
See, e.g., www.issworldtraining.com; and Patrick Howell O’Neill, “ISS World: the traveling spyware
roadshow for dictatorships and democracies”, Cyberscoop, 20 June 2017.
The story of private surveillance is also a story of the critical importance of free and independent
research and media. Such investigations have also put the investigators at risk of surveillance. See,
e.g., Raphael Satter, “Undercover agents target cybersecurity watchdog”, Associated Press, 26
January 2019.
See Privacy International, “Exploiting privacy: surveillance companies pushing zero-day exploits”, 7
February 2018.
See the discussion in Sarah McKune submission, pp. 2–4; Centre for European Policy Studies,
Software Vulnerability Disclosure in Europe: Technology, Policies and Legal Challenges (Brussels,
June 2018); and Sven Herpig and Ari Schwartz, “The future of vulnerabilities equities processes
around the world”, Lawfare, 4 January 2019.
See Privacy International, “Six things we know from the latest FinFisher documents”, 15 August
2014.
Select target paragraph3
Connect to a paragraph
Connect to an entity
Disable highlights
Add to table of contents