Skip to content(if available)orjump to list(if available)

Europeans' health data sold to US firm run by ex-Israeli spies

debarshri

I know a thing or two about zivver as i used to hangout with an early eng who was a scala dev.

Idea was end to end encryption. So technically, the new org should not have access to customer data. Company hit gold in the netherlands during covid whe reports had to sent out to users digitally and was always encrypted in EU due to regulations.

It could be different behind the scene. It does not look good for the netherlands where digital sovereignty is the key topic these days.

sva_

> The CEO of the American tech company is a former cyber specialist from an elite unit of the Israeli army, as are several other members of its top management.

This is about Unit 8200? The 'cybersecurity' unit that Israelis can join instead of doing their mandatory military service on the gun? I think this acquisition could indeed be problematic, but this seems like a weird framing. The article could give more context than that.

dundarious

They do more than cybersecurity, they collect and analyze signals intelligence. Tom Clancy's Jack Ryan in the CIA would be in Unit 8200 if he was Israeli -- the unit is not at all purely "techy" in nature. They are also significantly responsible for "analysis" such as target selection, as covered here https://www.972mag.com/lavender-ai-israeli-army-gaza/

everdrive

It's not an opt-out in the literal sense. Everyone is conscripted, and then based on ability people are placed into different units. If you were talented, wouldn't you try to avoid getting put on patrol in Gaza or the West Bank?

barbazoo

“If you were a Russian soldier wouldn’t you rather work in administration in Moscow than invade and murder Ukrainians.”

Sure but the real answer is try what you can to get the fuck out of there so you don’t have to do harm to someone you don’t even know.

codedokode

People in EU buy Russian natural gas and see no problem with it. What are you talking about.

everdrive

A fair point but in that situation it should would be nice to be a desk job while I was waiting for my visa to come through.

tokai

Russian soldiers are volunteers. They sign a contract. When money are involved many many people don't care about inflicting harm to others.

4gotunameagain

Irrespective of talent, I would never agree to contribute even a byte to a country/organisation that commits the atrocities of Israel. Anyone that accepts to join the IDF is morally bankrupt and/or a zionist.

bushbaba

No idea where you live. But I’d hope you’d fight for the safety of your family and neighbors. Thats literally all it means to be in the idf for most.

xenospn

8200 is mandatory military service.

engineerhead

Pretty concerning. Even if a service is EU-based, a foreign acquisition can expose sensitive data to other jurisdictions.

lwn

I used to get multiple Zivver messages a week from the health providers I work with. However, I haven't received a single one since the announcement of the takeover a while ago.

hermanzegerman

I've never seen Zivver used in German Healthcare.

Also Germany uses and is already Rolling out a Matrix-based Messenger and S/MIME-Mail with End-to-End-Encryption for Communication between Healthcare Professionals.

So at least for Germany this is not a problem.

More problematic was our prior health Minister who wanted to make data accessibile to OpenAI et al for "research". That's also why I opted out of the electronic health record

https://www.heise.de/news/Lauterbach-zu-Gesundheitsdaten-Goo...

sallveburrpi

I don’t think you can opt out of the electronic health record long term. We should instead elect officials that can deal with the “Neuland” of the digital age and have some technical chops and don’t immediately cave in when there is some money to be made (in no way implying that you don’t already do this)

hermanzegerman

Right now, you can and should do it.

See https://www.bundesgesundheitsministerium.de/themen/digitalis...

> We should instead elect officials that can deal with the “Neuland” of the digital age and have some technical chops and don’t immediately cave in when there is some money to be made

Yes, but I don't think this will happen during our lifetimes. Especially since the Gematik has shown again and again that they can't be trusted with it

jack_tripper

>I've never seen Zivver used in German Healthcare.

How would you even be sure of this just from what you can see from the outside? That doesn't mean your health insurance company isn't using Zivver internally same how they use Office 365 or SAP. It's not like they tell you all the SW they use.

hermanzegerman

Why would they use it internally?

Internally, you have the Hospital Information System where you can look up all the informations you need.

I can just say I know the inside of one of Germany's biggest Hospitals, since I'm a Doctor. And requesting Patient Data or giving it out to other Parties is unfortunately a Task that Doctors still have to do on their own

And for communication with the outside world it's down to Fax, Phone or Letter.

And that will be replaced with KIM in the future

user_7832

> Fax, Phone or Letter

That's interesting because in The Netherlands most of my doctor's communications come through email (and zivver), followed by snail mail.

jack_tripper

It's always companies run by Unit 8200 ex-Israeli spies that are running these telemetry-/ad- surveillance dragnets, and there's never any retaliatory action against them.

Like how about a call to Benny's office saying "hey buddy, reign your dogs in, our citizens are off limits"?

jdietrich

Unit 8200 hand-picks the best and brightest young Israelis and trains them in computer science. You might as well say "It's always MIT" - of course an elite educational institution produces a lot of successful startups.

If you're looking for a sinister plot, look no further than In-Q-Tel.

Fnoord

MIT students have different loyalty than to a fascist government like Trump's administration. The political situation in USA is also not like the one in Israel (which country is a direct result of the outcome of WWII and hatred by nazi-Germany, who are in constant fight with their neighbors). It isn't a fair comparison. One should also take into account that Mossad's way of operating is aggressive.

The English article doesn't mention this, but vulnerabilities were found in Zivver. See my comment elsewhere in the thread referring to the Dutch version of the article.

foundddit

It's really, truly strange just how intertwined the US is with Israeli spies at all levels. If people affiliated with The Netherlands or Rwanda had this much influence in the US, nobody would tolerate it.

coliveira

At this point it's all a i-controlled spy operation everywhere in the US. Just check where the main "cyber-security" firms come from. They're just fronts for spy operations.

jack_tripper

It helps when majority of US congress is composed of highly convicted Zionists or on AIPAC payroll because their alternative is being JFKd.

ishi

It isn't a "telemetry-/ad- surveillance dragnet". Kitenet's product is a "Private Data Network (PDN) to control, monitor, and secure data exchanged between people, machines, and systems across user collaboration, automated workflows, and enterprise AI".

It stands to reason that ex-cryptographers from Unit 8200 would use the expertise they gained to launch legitimate companies that provide cybersecurity solutions.

diydsp

It's not inevitable. It's up to us in a shared world to decide how to govern ourselves and live our lives. Not to be at the whims of a small group of powerful strangers.

stocksinsmocks

I think it’s much more likely they’re creating honeypots as contractors. There is a lot more money in surveillance than privacy

ishi

Is there any factual basis to this claim, or just your personal opinion? It's like claiming Oracle's real business isn't a database, but rather stealing customers data which was stored in Oracle's databases. Or practically any other company that has access to customers data.

user_7832

Why would you assume the said counties wouldn't want their citizens surveilled? "But they will know what our citizens do..." yeah unfortunately 5 eyes proves otherwise.

Govt surveillance is a big club, and you ain't in it.

user_7832

I am... really not sure why this comment is getting downvoted? It's not really a conspiracy theory so many years after Snowden now, is it?

tonyhart7

acting like they arent already controlling gov politician

null

[deleted]

juggert

[flagged]

mikkupikku

Online scamming and malware are Israel's most cherished national industry, they've been specializing in this stuff for nearly 30 years:

https://en.wikipedia.org/wiki/Download_Valley

> Download Valley is a cluster of software companies in Israel, producing and delivering adware to be installed alongside downloads of other software.[1] The primary purpose is to monetize shareware and downloads. These software items are commonly browser toolbars, adware, browser hijackers, spyware, and malware. Another group of products are download managers, possibly designed to induce or trick the user to install adware, when downloading a piece of desired software or mobile app from a certain source.

> Although the term references Silicon Valley, it does not refer to a specific valley or any geographical area. Many of the companies are located in Tel Aviv and the surrounding region. It has been used by Israeli media[2] as well as in other reports related to IT business.[3]

Getting an Israeli extradited is almost impossible, their in-group ethnic bias is so strong that they even fight the extradition of rapists. The Israeli government would rather see a jewish rapist escape justice in Israel than face justice in a gentile nation. Extraditing some businessmen who merely scam and destroy people's computers? Fat chance in hell.

https://en.wikipedia.org/wiki/Malka_Leifer_affair

https://www.cbsnews.com/news/how-jewish-american-pedophiles-...

pricechild

Could the same not be said about the US?

I suspect it'd have a different spin put on it.

ipaddr

No the US has no issue with extradition.

wslh

[flagged]

dmix

Based on your wiki almost all of those are from 2010 era and shut down long ago

The US has always had a number of grey market scammy businesses like those too. Lots of countries do.

sumalamana

Israel is gonna have a really big PR problem as the boomer generation ages and dies.

Cyph0n

They already have a major PR problem and are scrambling to fix it.

What they don’t realize is that given the enormity of the crimes they committed (heck, still are committing!), nothing short of accountability will help cleanse their reputation.

jack_tripper

The patch is already on the way: Any public criticism of Israel will be labeled as anti-semitism and any anti-israel posts in US and EU social media will be removed for breaking ToS and "hate speech" laws, similar to what Germany already has in place.

jijijijij

PR only matters in free democracies.

nunobrito

Yes. The newer generations are far more aware of what is happening.

juggerlt

[flagged]

kittikitti

The comment section for this post has so many people trying to downplay the issue, it's absurd. Thanos did way less and it was a huge public scandal with people being sent to jail. I wonder if anyone will get any accountability at all from this?

whimsicalism

Theranos did way less? There isn’t even any malfeasance documented in this article whereas Theranos intentionally defrauded many many people.

Honestly, what are you on about?

o999

[flagged]

kingleopold

come on, one is ally that do genoc1de and other one is just criminal. Not fair comparison.

null

[deleted]

unyttigfjelltol

TL;DR: An EU health data firm run by ex-military cryptographers offers a web portal for encrypting documents, which inherently exposes unencrypted documents to the company and US national security laws. The media outlet incidentally also doubts the trustworthiness of military veterans from Israel.

Even following the "if there's smoke there's fire" model, unclear there's a strong scent of "smoke" here. One could write a similar guilt-by-historical-association article concerning anyone, in the same position, really. Obviously if you're uploading a file to a 3d party website, the vendor has some technical access, this should be warned.

pareidolia

The bigger problem is that this model is inherently flawed. Even if end-to-end encryption with browser crypto were implemented, there is never any security since the code in the browser can simply be swapped with compromised code that diverts the plaintext somewhere.

I've been forced to use this service, by way of healthcare professionals just disclosing correspondence to this service without asking for my consent.

Smeerlappen.

tucnak

> there is never any security since the code in the browser can simply be swapped with compromised code that diverts the plaintext somewhere.

This is not the case in the land of DICE-like key derivation; see TKey protocol for example. You can download and run an actual rv32 program on actual FPGA over WebUSB without having to worry about its provenance. If the program is modified, firmware will derive a completely different key.

pareidolia

Zivver is a web application. The javascript that comes with the webpage can change at any time for any reason, as Zivver sees fit.

_el1s7

Security is an illusion.

pareidolia

Then reply with your passwords.

Fnoord

It isn't merely a health data firm. It is used to share information between government and civilians and NGOs and civilians, and among these are health services. For example, Immigration and Naturalisation Service of The Netherlands (IND) uses it, too. Another example is also mentioned in the article, about court communication in The Netherlands. Even my kid's school uses it.

The company Zivver was Dutch and started out because the Dutch did not want to be dependent on third parties for confident data (health being an example). Therefore, Zivver shouldn't have been sold, given the importance of the data.

That it is irrelevant the (parent) company is located in USA I do not agree with. The fascist leader of said country is pressuring EU, and has tools available to do so (CLOUD act). Furthermore, he has proven to not care about legal status and legality, and has told big tech to ignore the European law. Besides, if you control the software code, you can hack around it being FOSS (see also why OpenPGP.js is vulnerable to such attack).

Moreover, in the Dutch version of this article, security researchers easily found vulnerabilities in the software. They claim to have zero knowledge, which is BS. If one of the two parties does not have a Zivver account, the data is send plain text as well.

It isn't far fetched to believe Kiteworks is a front for the Israeli intelligence apparatus.

techsystems

I used this in NL with the government. What can I do?

nunobrito

Not much, your data is already outside the EU being archived and processed by other countries.

null

[deleted]