Live data from Hacker News

Espionage Against the European Parliament

citizenlab.ca

101–110 of 145 posts

Re: Espionage Against the European Parliament

#101

Isn't it the problem with software architecture choices like large monolitic kernels, lots of unnecessary telemetry/marketing services, legacy APIs, unsafe languages like C, lack of static analysis, etc? You should threat a phone as an infected ground and do not keep anything important there. Some leaders simply do not use smartphones and are protected from electronic spyware.

Which is difficult since smartphones are used as 2FA, and not every service has web interface, only mobile one (some banks, chats, dating, uber, etc..)

Re: Espionage Against the European Parliament

#102

Would lockdown mode on iOS stop this?

Probably, that's the point of it, however your smartphone becomes a very dumbphone in lockdown mode, intentionally to reduce attack surface. It's only really practical if you just need a dumb phone system endpoint to send and receive SMS and PSTN calls and check the time.

Re: Espionage Against the European Parliament

#103
post #100

> It is important to note that threat notifications from Apple and other companies are not real-time alerts. They are typically sent to users in batches, often months or more after targeting takes place. Wow, so Apple is able to detect threat, but does not remove or prevent it, and waits silently for months before notifying a user? If this is not a security theatre I don't know what is.

> I don't know what is.

PRISM.

Re: Espionage Against the European Parliament

#104
post #93

Earlier quoted context omitted.

Yes and my perspective is that GDPR has harmed EU startups and helped US companies by virtue of them being incumbents and having the resources to dedicate to compliance. Probably can't be fixed as easily now because of corporate culture around standards like SOC2 and ISO27001... Which I think are more harmful to security than helpful as they create complacency and hinder progress by creating barriers.

that is most of the EU legislation making/operating companies, getting access to banking, hiring, etc.. all those things are catered towards multinationals by endless bureaucracy and requirements that need consultants/lawyers it's by design

At the same time there are plenty of European companies, so clearly the increased barriers aren't a deal breaker.

Re: Espionage Against the European Parliament

#106
post #92

How is it that any NSO employee is still able to travel outside Israel without getting arrested? Seems like they're involved in criminal conspiracies in like half the countries in the world.

same for CIA/NSA employees/contractors right?

CIA/NSA personnel use cover identities when working abroad and conceal their association with CIA/NSA: https://theintercept.com/snowden-sidtoday/3676073-cover-anon...

Re: Espionage Against the European Parliament

#107
post #27

Earlier quoted context omitted.

True but one would hope though that people dealing with national security would follow more than your average employee.

> True but one would hope though that people dealing with national security would follow more than your average employee. The more important you are the more you may think that exceptions can be made for you.

Then it seems the person is not suitable if they don't understand the gravity and their exposure

Re: Espionage Against the European Parliament

#108

Earlier quoted context omitted.

In this case he was investigating misuse of Pegasus spyware specifically, and was targeted with it while doing so. That's obstruction of justice, morally speaking, and would feel very scary, in that it would make you feel that this company might be so powerful that investigating it is personally dangerous.

Alternate spin: He now has a conflict of interest. He’s now too biased to work on the committee.

For who?

Re: Espionage Against the European Parliament

#109

> we note an overlap between the first infection and a previously identified Pegasus campaign targeting Russian and Belarusian-speaking exiled journalists and activists in Europe, suggesting a Pegasus customer with authorization to spy in multiple European countries is responsible. Who has "authorization to spy in multiple European countries"? In this older article [0] about one of the mentioned russian exiles case i…

[deleted]

Re: Espionage Against the European Parliament

#110
post #101

Isn't it the problem with software architecture choices like large monolitic kernels, lots of unnecessary telemetry/marketing services, legacy APIs, unsafe languages like C, lack of static analysis, etc? You should threat a phone as an infected ground and do not keep anything important there. Some leaders simply do not use smartphones and are protected from electronic spyware.

Which is difficult since smartphones are used as 2FA, and not every service has web interface, only mobile one (some banks, chats, dating, uber, etc..)

m.uber.com

Never had a bank without a usable web app. You should consider the same!

Stop shooting the web in the foot.

Post reply on HN