Live data from Hacker News

Espionage Against the European Parliament

citizenlab.ca

131–140 of 145 posts

Re: Espionage Against the European Parliament

#131
post #82

Earlier quoted context omitted.

If a notification is dismissed on iphone, there's indeed no central UI to see it again on the phone. That's a sad state of iphone. Many people have asked, but Apple just doesn't care enough to do it. Now I hope this kind of high-profile security incidents could nudge Apple towards taking action.

Any source for that “Apple just doesn’t care”, as opposed to thinking there are security/privacy tradeoffs or other considerations that cut against such a feature?

With modern cryptography techniques, Apple could certainly do it if they cared enough. I guess the potential benefit doesn't justify the potential effort and cost related to the change, from Apple management point of view.

Re: Espionage Against the European Parliament

#132
post #24
post #6

Earlier quoted context omitted.

"he did not recall receiving the Apple notifications" so he didn't notice them.

That is kind of surprising given he is on the comittee investigating pegasus. I'd assume someone on the comittee would be paying much more attention to this than a normal person. I wonder what triggered him to suspect he was hacked then. Since presumably something triggered him to have his phone forensically investigated.

People seem to have this fiction that parliamentarians working on a committee actually have some expertise. This can happen but is actually rare. They are not elected for skill but for political reasons, and then the parties pawn them to different committees.

So in other words he probably speaks about security, whatever his staffers feed him, but most likely has no clue whatsoever what it's about.

Re: Espionage Against the European Parliament

#133

> we note an overlap between the first infection and a previously identified Pegasus campaign targeting Russian and Belarusian-speaking exiled journalists and activists in Europe, suggesting a Pegasus customer with authorization to spy in multiple European countries is responsible. Who has "authorization to spy in multiple European countries"? In this older article [0] about one of the mentioned russian exiles case i…

It's authorisation by the Israeli company providing Pegasus. So anyone who either pays enough or is serving Israeli interests.

Re: Espionage Against the European Parliament

#134
post #17

Around that time a lot of politicians in Greece had their phones hacked by Pegasus. It's an ongoing scandal in Greece that never got fully resolved, although all evidence indicate that it was an operation orchestrated by the office of the prime minister in coordination with the local intelligence service. So I wouldn't call that an attack against the European parliament.

No, it was the Predator rootkit that presumably was introduced directly from the PM to infect many politicians, even of his own party. This lead to the uncovering of the long-standing agricultural scandal of OPEKEPE gov org and is going to lead to the largest constitutional change in modern Greek history, after and only if he wins the elections next spring: among others lifting of minister immunity and reduction of the number of parliament members. Through the revelation of corrupt politicians' acts based on their phone data leakage, the public opinion turns against them and accepts the changes easier.

Re: Espionage Against the European Parliament

#135
post #124

Earlier quoted context omitted.

m.uber.com Never had a bank without a usable web app. You should consider the same! Stop shooting the web in the foot.

With the banks I use, the difference is: A) on mobile, use my face or 6-digit pin to get in. B) on web, go get my wallet where my ID is, hunt for the USB digital ID reader, grab a USB-C adapter, put everything together, and either confirm the certificate with a PIN I always forget or use the bank’s own calculator for a login code. Not exactly a fair setup for the web.

My bank supports both SMS and push notification for 2FA. Also PIN code in an app is probably local and doesn't protect from a kernel exploit. I hope you do not keep too much money in the bank.

Re: Espionage Against the European Parliament

#136
post #124

Earlier quoted context omitted.

m.uber.com Never had a bank without a usable web app. You should consider the same! Stop shooting the web in the foot.

With the banks I use, the difference is: A) on mobile, use my face or 6-digit pin to get in. B) on web, go get my wallet where my ID is, hunt for the USB digital ID reader, grab a USB-C adapter, put everything together, and either confirm the certificate with a PIN I always forget or use the bank’s own calculator for a login code. Not exactly a fair setup for the web.

My bank supports Ubikeys for 2FA, but you cannot disable the SMS authentication. So you may as well use your phone.

Re: Espionage Against the European Parliament

#137
post #115

Earlier quoted context omitted.

Which, again, is not meaningfully different. Yet it seems you insinuated so. Can you explain in detail?

Hopefully it wasn’t you who flagged me after asking me to explain in detail…

I did not flag you, but I certainly see why someone might.

Re: Espionage Against the European Parliament

#139
post #124

Earlier quoted context omitted.

With the banks I use, the difference is: A) on mobile, use my face or 6-digit pin to get in. B) on web, go get my wallet where my ID is, hunt for the USB digital ID reader, grab a USB-C adapter, put everything together, and either confirm the certificate with a PIN I always forget or use the bank’s own calculator for a login code. Not exactly a fair setup for the web.

My bank supports both SMS and push notification for 2FA. Also PIN code in an app is probably local and doesn't protect from a kernel exploit. I hope you do not keep too much money in the bank.

I think the in-app PIN code and/or biometric ID is merely a convenience to avoid typing your password all the time. I’ve never used a banking app that doesn’t offer both, and then ask for your real login details every now and then.

As a stay-at-home dad: my bank account is indeed not worth attacking.

Post reply on HN