Live data from Hacker News

Espionage Against the European Parliament

citizenlab.ca

121–130 of 145 posts

Re: Espionage Against the European Parliament

#121

- extremely stupid question: can they hack you with pegasus spyware if you use a nokia 1100? - if yes -> extremely stupid suggestion: why cant people in government positions use a nokia 1100 as work phone and some other phone as a personal phone?

If you're using a nokia, there's no need for expensive mercenary spyware because your messages and calls aren't E2EE.

If they did want to use spyware, it would be significantly cheaper because that phone is (decades?) out of date misses (thousands?) security patches.

Re: Espionage Against the European Parliament

#122
post #21

One interesting thing here, is they imply that both confidential personal medical information and confidential gov docs might have been compromised via the same phone. Does EU parliment not have a policy of seperating work and personal devices?

If you're off sick and need to provide a doctor's letter, at some point it will need to touch your employer servers. Just one example.

Re: Espionage Against the European Parliament

#123
post #115

Earlier quoted context omitted.

and also a good description of Apple APN notifications being pushed to a Garmin watch, or a car, or your off-brand earbuds.

Which, again, is not meaningfully different. Yet it seems you insinuated so. Can you explain in detail?

[flagged]

Re: Espionage Against the European Parliament

#124
post #101

Earlier quoted context omitted.

Which is difficult since smartphones are used as 2FA, and not every service has web interface, only mobile one (some banks, chats, dating, uber, etc..)

m.uber.com Never had a bank without a usable web app. You should consider the same! Stop shooting the web in the foot.

With the banks I use, the difference is:

A) on mobile, use my face or 6-digit pin to get in.

B) on web, go get my wallet where my ID is, hunt for the USB digital ID reader, grab a USB-C adapter, put everything together, and either confirm the certificate with a PIN I always forget or use the bank’s own calculator for a login code.

Not exactly a fair setup for the web.

Re: Espionage Against the European Parliament

#125
post #124

Earlier quoted context omitted.

m.uber.com Never had a bank without a usable web app. You should consider the same! Stop shooting the web in the foot.

With the banks I use, the difference is: A) on mobile, use my face or 6-digit pin to get in. B) on web, go get my wallet where my ID is, hunt for the USB digital ID reader, grab a USB-C adapter, put everything together, and either confirm the certificate with a PIN I always forget or use the bank’s own calculator for a login code. Not exactly a fair setup for the web.

If you want to sacrifice security for convenience, that’s a different conversation than “I’m forced to”.

Storing credentials and passkeys in browser password manager (backed up to Google or Apple) and using autofill is pretty normal stuff for mobile users today.

(Not being able to find your credentials or keep your gear in order is also not a great reason to shoot the web in the foot!)

Re: Espionage Against the European Parliament

#127
post #115

Earlier quoted context omitted.

and also a good description of Apple APN notifications being pushed to a Garmin watch, or a car, or your off-brand earbuds.

Which, again, is not meaningfully different. Yet it seems you insinuated so. Can you explain in detail?

Hopefully it wasn’t you who flagged me after asking me to explain in detail…

Re: Espionage Against the European Parliament

#128

Earlier quoted context omitted.

> There is something called the five eyes agreement that does draw that line. Believe such nonsense at your own peril. https://en.wikipedia.org/wiki/Israeli_espionage_in_the_Unite... > In 1951, Mossad and the Central Intelligence Agency agreed not to spy on each other and US and Israeli services cooperated closely since then. > Nevertheless, there were strong indications afterwards of ongoing Israeli espionage agains…

I'm curious what peril your cynicism about the five eyes agreement has saved you from.

The peril of sleeping easy at night, comfortable in the fantasy where no one would ever spy on me just because they pinky promised not to. Not keen on believing evil bits either.

Re: Espionage Against the European Parliament

#129
post #112

Earlier quoted context omitted.

> How would notifications be meaningfully different from these? Ephemeral transit layer owned by third-parties constantly, vs cold storage of secrets your architecture owns from start to finish.

> Ephemeral transit layer owned by third-parties constantly This is a good description of SMS and RCS.

[deleted]

Re: Espionage Against the European Parliament

#130

Would lockdown mode on iOS stop this?

Probably, that's the point of it, however your smartphone becomes a very dumbphone in lockdown mode, intentionally to reduce attack surface. It's only really practical if you just need a dumb phone system endpoint to send and receive SMS and PSTN calls and check the time.

Mine has been on lockdown mode for months and all I’ve noticed is some images not loading on sites.
Post reply on HN