An interview with Paragon Solutions CEO Andrew Boyd, who says the US spyware maker lacks visibility into customer targeting data and has no "kill switch"
First reported by Wired ·
Spyware makers cannot be trusted to self-regulate their products. All three big clouds have a kill switch. All three big clouds have robust logging. All three big clouds have robust logging.
Paragon Solutions, a spyware maker recently acquired by US firm AE Industrial Partners, faces allegations that its Graphite spyware was used to infect over 60 phones in more than 20 countries, including journalists and activists. Despite a zero-tolerance policy for customer abuse, Paragon's new CEO, Andrew Boyd, stated the company canceled its contracts with Italy's intelligence agencies not due to verified misuse, but because the relationship was deemed too risky following the allegations. Boyd further revealed that Paragon lacks visibility into customer targeting data and has no "kill switch" to disable misuse, relying instead on customers admitting faults or third parties uncovering issues. He explained that mandatory logging or oversight would deter potential customers concerned about privacy of their sensitive targeting information. This candid admission comes as Paragon, now merged with REDLattice, aims to overcome its foreign ownership hurdles and expand into the US market, despite critics like Citizen Lab and Senator Ron Wyden highlighting the significant lack of accountability and transparency in its operations.
Paragon's lack of technical oversight and absence of a "kill switch" for misuse positions it as a less accountable entity compared to competitors like NSO Group, despite claims of superior practices. The company prioritizes customer privacy regarding targeting data over ensuring responsible use, a strategy that CEO Andrew Boyd describes as a necessary "balancing act" for business viability. This approach, however, raises concerns about the potential for unchecked misuse of powerful surveillance tools, particularly as the company seeks to leverage its recent US acquisition to expand its market reach.
The revelations from Paragon's CEO signal a critical juncture for the offensive cyber industry, highlighting a fundamental tension between commercial interests and ethical oversight. The industry's inability to self-regulate effectively, as evidenced by Paragon's stance on transparency and accountability, may necessitate stronger legislative and regulatory intervention. This situation underscores the challenges faced by US entities acquiring foreign spyware companies and the ongoing debate surrounding the responsible development and deployment of surveillance technologies globally.
AI-written summary. May contain errors.