Assistant Professor, Information Security

The Munk School of Global Affairs & Public Policy in the Faculty of Arts & Science at the University of Toronto invites applications for a full-time tenure stream position in the area of Information Security. The appointment will be at the rank of Assistant Professor, with an exp … | Continue reading


@citizenlab.ca | 11 months ago

Spyware Targeting Against Serbian Civil Society

We confirm that two members of Serbian civil society were targeted with spyware earlier this year. Both have publicly criticized the Serbian government. We are not naming the individuals at this time by their request. The Citizen Lab’s technical analysis of forensic artifacts was … | Continue reading


@citizenlab.ca | 12 months ago

Submission to the Standing Committee on Public Safety and National Security: Charter analysis concerning cybersecurity and telecommunications reform in Bill C-26

On June 14, 2022, Bill C-26, an Act respecting cybersecurity, amending the Telecommunications Act and making consequential amendments to other Acts, was introduced into Parliament for the first reading by Canada’s Minister of Public Safety, Marco Mendicino. Hearings on Bill C-26 … | Continue reading


@citizenlab.ca | 12 months ago

Chinese censorship following the death of Li Keqiang

As part of our ongoing project monitoring changes to Chinese search censorship, we tracked changes to censorship following Li Keqiang’s death across seven Internet platforms: Baidu, Baidu Zhidao, Bilibili, Microsoft Bing, Jingdong, Sogou, and Weibo. We found that some keyword com … | Continue reading


@citizenlab.ca | 1 year ago

Cybersecurity Will Not Thrive in Darkness

This report offers 29 recommendations to the draft legislation in an effort to correct its secrecy and accountability deficiencies, while also suggesting amendments which would impose some restrictions on the range of powers that the government would be able to wield. It is impor … | Continue reading


@citizenlab.ca | 2 years ago

New Pegasus Spyware Abuses Identified in Mexico

R3D, with technical support from the Citizen Lab, has determined that Mexican journalists and a human rights defender were infected with Pegasus between 2019 and 2021. | Continue reading


@citizenlab.ca | 2 years ago

Statement on the fatal flaws found in a defunct CIA covert communications system

We identified a network of 885 websites and attributed these websites with high confidence as having been used by the United States (US) Central Intelligence Agency (CIA) for covert communication. | Continue reading


@citizenlab.ca | 2 years ago

Apple’s Political Censorship Leaves Taiwan, Remains in Hong Kong

Since our report in August 2021, we find that Apple has eliminated their Chinese political censorship in Taiwan. However, Apple continues to perform broad, keyword-based political censorship outside of mainland China in Hong Kong, despite human rights groups’ recommendations for … | Continue reading


@citizenlab.ca | 2 years ago

Psychological and Emotional War: Digital Transnational Repression in Canada

In this report, we describe how activists and dissidents living in Canada are impacted by digital transnational repression. We conclude that digital transnational repression has a serious impact on these communities, including their ability to undertake transnational advocacy wor … | Continue reading


@citizenlab.ca | 2 years ago

Egyptian political dissident hacked with both Cytrox’s Predator and NSO Pegasus

Two Egyptians—exiled politician Ayman Nour and the host of a popular news program (who wishes to remain anonymous)—were hacked with Predator spyware, built and sold by the previously little-known mercenary spyware developer Cytrox. The phone of Ayman Nour was simultaneously infec … | Continue reading


@citizenlab.ca | 2 years ago

Pandemic Privacy Explained – The Citizen Lab

On September 28, the Citizen Lab published an analysis of COVID-19 data collection practices. In this post, we discuss the significance of the findings with report authors. | Continue reading


@citizenlab.ca | 3 years ago

Devices of Palestinian Human Rights Defenders Hacked with NSO’s Pegasus Spyware

Front Line Defenders’ analysis indicated that six devices belonging to six Palestinian human rights defenders were hacked with Pegasus, a spyware developed by the cyber-surveillance company NSO Group. Both the Citizen Lab and Amnesty International’s Security Lab independently con … | Continue reading


@citizenlab.ca | 3 years ago

NYT Ben Hubbard Hacked with Pegasus After Reporting on Previous Hacking Attempts

Our forensic analysis of two iPhones belonging to Hubbard found evidence of Pegasus infections in July 2020 and June 2021. Notably, these infections occurred after Hubbard reported in January 2020 that we found that he was targeted in 2018 by the Saudi Arabia-linked Pegasus opera … | Continue reading


@citizenlab.ca | 3 years ago

Analysis of collection technologies, data laws and and reforms during Covid-19

In this report, we undertake a preliminary comparative analysis of how different information technologies were mobilized in response to COVID-19 to collect data, the extent to which Canadian laws impeded the response to COVID-19, and the potential consequences of reforming data p … | Continue reading


@citizenlab.ca | 3 years ago

Pandemic Privacy: A Preliminary Analysis [pdf]

Continue reading


@citizenlab.ca | 3 years ago

NSO Group iMessage Zero-Click Exploit Captured in the Wild

While analyzing the phone of a Saudi activist infected with NSO Group’s Pegasus spyware, we discovered a zero-day zero-click exploit against iMessage. The exploit, which we call FORCEDENTRY, targets Apple’s image rendering library, and was effective against Apple iOS, MacOS and W … | Continue reading


@citizenlab.ca | 3 years ago

Bahraini Government Hacks Activists with NSO Group Zero-Click iPhone Exploits

We identified nine Bahraini activists whose iPhones were successfully hacked with NSO Group’s Pegasus spyware between June 2020 and February 2021. The hacked activists included three members of Waad (a secular Bahraini political society), three members of the Bahrain Center for H … | Continue reading


@citizenlab.ca | 3 years ago

An Analysis of Apple Engraving Censorship Across Six Regions

Within mainland China, we found that Apple censors political content including broad references to Chinese leadership and China’s political system, names of dissidents and independent news organizations, and general terms relating to religions, democracy, and human rights. And ac … | Continue reading


@citizenlab.ca | 3 years ago

Independent Peer Review of AI Forensic Methods for Identifying Pegasus Spyware

Citizen Lab's peer review of Amnesty International's forensic techniques to identify Pegasus spyware concludes they are sound. | Continue reading


@citizenlab.ca | 3 years ago

Hooking Candiru: Another mercenary spyware vendor comes into focus

Candiru is a secretive Israel-based company that sells spyware exclusively to governments. Using Internet scanning, we identified more than 750 websites linked to Candiru’s spyware infrastructure. We found many domains masquerading as advocacy organizations such as Amnesty Intern … | Continue reading


@citizenlab.ca | 3 years ago

Correspondence Between Citizen Lab and NSO Group Regarding the Great iPwn

In its most recent response to the Citizen Lab regarding the The Great iPwn report, NSO Group extended an invitation to meet and discuss the Citizen Lab’s concerns and NSO Group’s “program” in more detail.  We do not believe this invitation is made in good faith and have declined … | Continue reading


@citizenlab.ca | 3 years ago

TikTok vs. Douyin: A Security and Privacy Analysis

A comparative analysis of security, privacy, and censorship issues in TikTok and Douyin, both developed by ByteDance. | Continue reading


@citizenlab.ca | 3 years ago

Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

Government operatives used NSO Group’s Pegasus spyware to hack 36 personal phones belonging to journalists, producers, anchors, and executives at Al Jazeera. The journalists were hacked by four Pegasus operators, including one operator MONARCHY that we attribute to Saudi Arabia, … | Continue reading


@citizenlab.ca | 3 years ago

Cyberespionage Using SS7 via Circles

Circles is a surveillance firm that reportedly exploits weaknesses in the global mobile phone system to snoop on calls, texts, and the location of phones around the globe, and is affiliated with NSO Group, which develops the oft-abused Pegasus spyware. Using Internet scanning, we … | Continue reading


@citizenlab.ca | 3 years ago

To Surveil and Predict: A Human Rights Analysis of Algorithmic Policing Canada

This report examines algorithmic technologies that are designed for use in criminal law enforcement systems, including a human rights and constitutional law analysis of the potential use of algorithmic policing technologies. | Continue reading


@citizenlab.ca | 4 years ago

Algorithmic Policing in Canada Explained

On September 1st, the Citizen Lab and the International Human Rights Program at the University of Toronto’s Faculty of Law released a report that investigated the use and human rights implications of algorithmic policing practices in Canada. This document provides a summary of th … | Continue reading


@citizenlab.ca | 4 years ago

A Timeline of Information Control on Chinese Social Media During Covid-19

As a follow-up to our March 2020 report, we conducted daily tests on WeChat and collected 2,174 censored keywords between January to May 2020. This data provides a view into how narratives and messaging on the pandemic are controlled and molded on social media in China. | Continue reading


@citizenlab.ca | 4 years ago

Keep the Open Technology Fund Open

The encroachments to OTF highlight why independent and transparent funding sources for research and development on Internet freedom are so important. Providing this type of support within a large government organisation can be difficult. OTF was an example of how to do that right … | Continue reading


@citizenlab.ca | 4 years ago

Dark Basin Uncovering a Hack-for-Hire Operation

Over the course of our multi-year investigation, we found that Dark Basin likely conducted commercial espionage on behalf of their clients against opponents involved in high profile public events, criminal cases, financial transactions, news stories, and advocacy. This report hig … | Continue reading


@citizenlab.ca | 4 years ago

WeChat Surveillance Explained

This document provides a summary of the Citizen Lab's WeChat surveillance research findings, as well as questions and answers from the resesearch team. | Continue reading


@citizenlab.ca | 4 years ago

We Chat, They Watch: How International Users Build Chinese Censorship Apparatus

WeChat communications conducted entirely among non-China-registered accounts are subject to pervasive content surveillance that was previously thought to be exclusively reserved for China-registered accounts. | Continue reading


@citizenlab.ca | 4 years ago

Zoom rolled their own encryption scheme, transmit keys through servers in China

This report examines the encryption that protects meetings in Zoom and finds that they have made their own encryption scheme and has significant weaknesses. | Continue reading


@citizenlab.ca | 4 years ago

Censored Contagion: How Information on the Coronavirus Is Managed on YY / WeChat

The analysis of YY and WeChat indicates broad censorship—blocking sensitive terms as well as general information and neutral references—potentially limiting the public’s ability to access information that may be essential to their health and safety. | Continue reading


@citizenlab.ca | 4 years ago

New York Times Journalist Targeted by Saudi-Linked Pegasus Spyware Operator

New York Times journalist Ben Hubbard was targeted with NSO Group’s Pegasus spyware via a June 2018 SMS message promising details about “Ben Hubbard and the story of the Saudi Royal Family.” The SMS contained a hyperlink to a website used by a Pegasus operator that we call KINGDO … | Continue reading


@citizenlab.ca | 4 years ago

Whatsapp Attributes Hack of 1,400 Users to NSO Group Technology

Citizen Lab senior researcher John Scott-Railton discuss why WhatsApp is suing NSO Group after discovering their spyware was used to target 1,4000 users—100 of whom were members of civil society—and why this is a significant bellwether. | Continue reading


@citizenlab.ca | 5 years ago

Tibetan Groups Targeted with 1-Click Mobile Exploits

This is the first documented case of one-click mobile exploits used to target Tibetan groups, and reflects an escalation in the sophistication of digital espionage threats targeting the community. | Continue reading


@citizenlab.ca | 5 years ago

An Analysis of WeChat’s Realtime Image Filtering in Chats

In this work, we study how Tencent implements image filtering on WeChat. We found that Tencent implements realtime, automatic censorship of chat images on WeChat based on what text is in an image and based on an image’s visual similarity to those on a blacklist. Tencent facilitat … | Continue reading


@citizenlab.ca | 5 years ago

The Predator in Your Pocket

The report includes technical elements associated with stalkerware applications, marketing activities, and compliance with Canadian privacy legislation. | Continue reading


@citizenlab.ca | 5 years ago

Burned After Reading: Endless Mayfly’s Ephemeral Disinformation Campaign

Using Endless Mayfly as an illustration, this highlights the challenges of investigating & addressing disinformation from research & policy perspectives. | Continue reading


@citizenlab.ca | 5 years ago

An analysis of censorship in Chinese open source projects

A new paper by the Citizen Lab investigates how Chinese censorship reaches independent developers and reveals that, while developers include censorship lists in open source projects, there is little apparent similarity in these blacklists, raising several questions about their or … | Continue reading


@citizenlab.ca | 5 years ago

Supporters of Mexico’s Soda Tax Targeted with NSO Exploit Links (2017)

An investigation revealing that Mexican soda tax supporters were targeted with NSO Group's government-exclusive spyware and exploit framework. | Continue reading


@citizenlab.ca | 5 years ago

The Million Dollar Dissident: iPhone 0-Days Used Against Human Rights Defenders

Ahmed Mansoor was targeted by NSO Group, an Israel-based “cyber war” company that sells Pegasus, a government-exclusive “lawful intercept” spyware product. | Continue reading


@citizenlab.ca | 5 years ago

Tracking NSO Group’s Pegasus Spyware to Operations in 45 Countries

In this post, we develop new Internet scanning techniques to identify 45 countries in which operators of NSO Group’s Pegasus spyware may be conducting operations. | Continue reading


@citizenlab.ca | 6 years ago

We (Can't) Chat: Report on WeChat Censorship

This report analyzes the information control practices related to a national crackdown on Chinese rights lawyers and activists on two leading Chinese social media networks. We document the Search filtering on Weibo, China’s Twitter-like service, as well as keyword and image censo … | Continue reading


@citizenlab.ca | 6 years ago