Live data from Hacker News

EU parliament member hit by Israeli Candiru spyware

twitter.com

71–80 of 192 posts

Re: EU parliament member hit by Israeli Candiru spyware

#71

Earlier quoted context omitted.

I don't know if this needs to be stated, but the idea is that they're intentionally named after unpleasant or evil things. Presumably as a way of saying: "We're dangerous/edgy/hard-core; no skulduggery is beneath us."

I never made that connection. The Palantiri in LOTR were neither inherently good nor evil, they were "seeing stones" with both communication and remote-viewing capabilities, equivalent to a what an iPhone, CCTV cam, or spy satellite can do today. It's an appropriate and cool name for a company whose whole mission is "intelligence gathering". (Yes, it is true that Sauron corrupted Saruman while communicating to him vi…

> The Palantiri in LOTR were neither inherently good nor evil, they were "seeing stones" with both communication and remote-viewing capabilities, equivalent to a what an iPhone, CCTV cam, or spy satellite can do today.

Within the context of LOTR's narrative, they were tools that were corrupted by evil and employed to unambiguously evil ends.

A weapon such as a warhammer is also just a tool, and Morgoth had his hammer Grond. If a company names themselves after Grond, it's safe to surmise that they're trying to be dark/edgy and convey a certain posture or attitude. It would be silly for them to say, "well ackshually it's just a warhammer, and a warhammer is an ethically neutral tool, whether it's good or evil is down to its wielder, and ultimately it's no big deal."

Re: EU parliament member hit by Israeli Candiru spyware

#72
post #2

Sounds more like it missed. They sent him a link, and he was wise enough to not click on it.

I wonder how that was supposed to work? Am I to believe that they have exploits for every browser engine on every OS that infect my phone just by visiting a page? Chrome on Android and WebKit on iOS? That would be concerning, but how realistic is that?

I would guess/assume that work phones of MEPs are restricted to a specific set of manufacturers and models, which makes targeting different from having to consider all options.

They might also have specific software installed across most of them that could be part of the targeting.

Re: EU parliament member hit by Israeli Candiru spyware

#74
post #51

[flagged]

Inaction is an action. Facilitating the development and sale of malware while benefiting from it through tax revenue and hard power with full awareness is, to me, enablement. The action taken against such vendors proved nominal, as they still continue to operate with no shortage of news stories like this one.

It would be naive to think the government itself would not use such a powerful source of intel. Regardless of your political affiliation, states act according to their self-interest. In international politics, the only constraints are what you can do, and how much you can get away with. If one can find a reasonable motive and prove a possible causal link, absent of further evidence, the prior is guilty.

Re: EU parliament member hit by Israeli Candiru spyware

#78
post #70

Earlier quoted context omitted.

Seems to be a pattern in these circles - there's at least also Palantir, named after the crystal ball that corrupted Saruman in The Lord of the Rings.

To be fair it is a pretty cool/appropriate name for their line of work

If we're being fair, they're an evil company that does evil work for evil people. It's abhorrent that they're using Tolkien to give themselves nerd-appeal.

Re: EU parliament member hit by Israeli Candiru spyware

#79
post #43

I notice issues relating to these groups (israeli cyber groups) are very quick to be denied or delegitimised on HN

This applies to any Western government interest group, at least for small submissions or individual comments that relate to those organizations. Large ones like the Assange release cannot be suppressed, but are full of pro-government comments that would not have been made by any software engineer before 2015. So either the engineers have changed fundamentally, or ...

I can see that there is way less interest in Russia China stuff with additional positions against these countries. There where usually is rationally irrationality takes place and most people avoid to say anything.

Re: EU parliament member hit by Israeli Candiru spyware

#80

Earlier quoted context omitted.

Don’t we live in a world where zero click exploits are a thing? I thought the target didn’t have to click the links just receive them

That's why I disable HTML in emails

Just to be aware that's a start but it's not a full mitigation. Some of the prominent zeroclick exploits have been "rich content" in messaging products such as whatsapp[1] and imessage[2].

Definitely not an expert but I'm presuming they take advantage of the "helpful" behaviour those apps have to preview content and then pair that with some sort of exploit in the library that parses/displays the content. So say they have an exploit in a jpeg library that whatsapp uses then they send a specially-crafted jpeg via whatsapp, whatsapp "previews" the image and that triggers the exploit to compromise the jpeg library and pwn the user.

[1] https://www.ft.com/content/4da1117e-756c-11e9-be7d-6d846537a...

[2] https://appleinsider.com/articles/23/06/01/zero-click-ios-ma...

Post reply on HN