Urgent.News

What's breaking now, across thousands of outlets.

Tech

An interview with Paragon Solutions CEO Andrew Boyd, who says the US spyware maker lacks visibility into customer targeting data and has no "kill switch" (Kim Zetter/Wired)

In an exclusive interview with WIRED, Paragon Solutions CEO Andrew Boyd reveals the limits of the company's promise …

Andrew Boyd, the CEO of Paragon Solutions, spoke candidly with Wired about the company's handling of allegations surrounding its Graphite spyware. Weeks after the Israeli-owned firm was acquired by US equity firm AE Industrial Partners in December 2024 and merged with REDLattice, WhatsApp alleged that Paragon's Graphite spyware had been used to infect over 60 individuals in more than 20 countries, including journalists and activists.

Most targets were unnamed, but Citizen Lab at the University of Toronto identified two journalists and two activists in Italy. Italian authorities denied any misuse.

Paragon and its new US owners initially declined to comment on the allegations, even as WhatsApp sent a cease-and-desist letter to Paragon. However, Boyd revealed in the interview that the company simply "fired" Italy from its contracts due to the risk posed by the allegations. Boyd said there was no Paragon investigation into the matter, and the company did not follow up with WhatsApp or Citizen Lab to confirm whether the allegations were true or to cancel contracts in other affected countries.

What sets Paragon apart is its lack of technical visibility into customer targeting data and the absence of a "kill switch" to disable customers when misuse occurs. Boyd explained that the company can only detect misuse if customers come forward or if third parties uncover it. Furthermore, he revealed that Paragon's updates are critical for the spyware's functionality and are frequent, lasting only 12 hours before they become ineffective.

Boyd stated that Paragon customers can enable logging for some systems, but the company has no access to these logs and does not want access.

Boyd emphasized that there is a delicate balance between privacy and security, and their approach is the best balance. He pointed out that no one would buy Paragon's products if the company could see sensitive targeting information or logs containing it. However, critics argue that this lack of oversight and transparency puts Paragon at a disadvantage compared to NSO Group, another major spyware maker.

NSO claims to have a kill switch and keeps "tamper-proof" logs, which customers are contractually obligated to provide if allegations of misuse arise. Boyd's admission of Paragon's lack of oversight and accountability has sparked debate about the industry's self-regulation and the need for greater transparency and accountability.

Written by urgent.news from Techmeme's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at wired.com →

More in Tech

More from Thursday 1 October →