Live data from Hacker News

EU parliament member hit by Israeli Candiru spyware

twitter.com

101–110 of 192 posts

Re: EU parliament member hit by Israeli Candiru spyware

#101
post #54

Not to downplay, but i would assume high profile people like EU parliment members would be targeted with phishing emails on a near daily basis. Like presumably law makers would be target #1 for espionage. Heck most ordinary people get phishing emails on a regular basis. Idk, i guess i was expecting something more sophisticated based on the headline than just: spear phishing attempt foiled after user fails to click on…

Well, it wasn’t phishing. If the claims are correct, just opening the link would have compromised the phone. If that’s true, I find it try extraordinary. Phishing is just having a fake webpage asking for credentials, right? Infecting a phone with spyware just by visiting a webpage is much harder and much worse.

Spear phishing is usually inclusive of attacks from an email that involve tricking the user into doing something unsafe. E.g. see definition https://www.trendmicro.com/vinfo/us/security/definition/spea...

> If the claims are correct, just opening the link would have compromised the phone

I'm not sure if that is being claimed. The twitter post just said the link would have "exposed" them to spyware. One possible interpretation is that simply viewing the link in a web browser would be enough, but i think another interpretation is that the link contained some sort of malicious download. No way to know with the info we are given. I agree that a zero-day in a web browser would certainly be more interesting, i'm just not sure that is the case here.

Re: EU parliament member hit by Israeli Candiru spyware

#102
post #43

I notice issues relating to these groups (israeli cyber groups) are very quick to be denied or delegitimised on HN

This applies to any Western government interest group, at least for small submissions or individual comments that relate to those organizations. Large ones like the Assange release cannot be suppressed, but are full of pro-government comments that would not have been made by any software engineer before 2015. So either the engineers have changed fundamentally, or ...

[flagged]

Re: EU parliament member hit by Israeli Candiru spyware

#103
post #19
post #16

Earlier quoted context omitted.

I don't see a she said? Being the devils advocate is fine, but if you have to invent your own she to say something, that's just bad faith isn't it?

"He said, she said" is a common phrase used in English when there are conflicting opinions with little fact. The gender is largely irrelevant. The phrase may also be applied in situations where the conflicting opinions don't come from individuals but instead from ungendered organizations!

The point wasn't about gender, it was that there don't seem to be any conflicting opinions. At least so far, no one is denying that the link was spyware, or that the spyware in question was made by Candiru, or that Candiru is an Israeli company that makes spyware. So there is no he said, she said.

If Candiru were to issue a statement saying "this was not spyware made by us", then yes, it would be a case of he said, she said.

Re: EU parliament member hit by Israeli Candiru spyware

#104
post #69

Earlier quoted context omitted.

...or it's non-software-engineers writing those pro-government comments. (just the logical conclusion of the statement, intentionally made blank)

Why couldn't the software engineers change? The geopolitical scene is much different today, and it's easy to see threats coming from your opposite pole

Can you elaborate what in your opinion changed in the geopolitical scene?

Re: EU parliament member hit by Israeli Candiru spyware

#105

[flagged]

More to the point, there actually is evidence of a connection to the Israeli government, inasmuch as "Candiru" was financed by the same people behind NSO, "Founders Group", and both of these entities have very clear ties to Mossad:

https://www.dimse.info/candiru/

"TheMarker Claims that NSO is also a customer of Candiru as it is often seen contacting the surreptitious firm for some espionage-related projects. Two industry sources said the main Candiru financial backer was Founders Group, cofounded by one of the three men who set up NSO, Omri Lavie."

And then, there is its Board of Directors:

"As surveillance industry sources also told Forbes, one of the lead investors is Founders Group managing partner Isaac Zack. According to Pitchbook, Zack is also a board member at wireless charging startup Humavox and at Sepio Systems. The latter is a cybersecurity company, focused on doing the exact opposite of Candiru: protecting hardware from being turned into silent surveillance devices. Its board also includes Tamir Pardo, the former head of the Mossad, Israel’s intelligence agency."

https://www.forbes.com/sites/thomasbrewster/2019/10/03/meet-...

Re: EU parliament member hit by Israeli Candiru spyware

#106
post #74
post #51

[flagged]

Inaction is an action. Facilitating the development and sale of malware while benefiting from it through tax revenue and hard power with full awareness is, to me, enablement. The action taken against such vendors proved nominal, as they still continue to operate with no shortage of news stories like this one. It would be naive to think the government itself would not use such a powerful source of intel. Regardless of…

[deleted]

Re: EU parliament member hit by Israeli Candiru spyware

#107

I notice issues relating to these groups (israeli cyber groups) are very quick to be denied or delegitimised on HN

No they're not. You're the top comment on this post, despite contributing very little to this discussion. Israel and the geopolitics around mercenary spyware coming out of that country is a very regular occurrence on this site. Despite a few instances of people trying to downplay the connection or redirect the conversation, there is ample discussion of this topic. I know this because I follow this topic closely and r…

might I suggest that 'allowed discussion' isn't at all a metric by which to judge whether or not there are efforts to delegitimize a topic.

might I also suggest that sufficiently skilled efforts to direct a conversation will not be detected by most conversation participants.

Re: EU parliament member hit by Israeli Candiru spyware

#109
post #102
post #43

Earlier quoted context omitted.

This applies to any Western government interest group, at least for small submissions or individual comments that relate to those organizations. Large ones like the Assange release cannot be suppressed, but are full of pro-government comments that would not have been made by any software engineer before 2015. So either the engineers have changed fundamentally, or ...

[flagged]

[flagged]

Re: EU parliament member hit by Israeli Candiru spyware

#110

the spyware and other cyberattacks get published very selectively everybody is constantly a target of attacks but what makes it to the news is the journalist choice

But, who sent the attack is the news. Sure we’re always bombarded with attacks by random cyber gangs, but when you’re targeted by an organization with official credentials that tends to raise some eyebrows.
Post reply on HN