Poland’s PM says previous government illegally used Pegasus spyware
apnews.com
apnews.com
Quarter milion iPhones in 2015 in Poland was basically everyone who counts in public life.
https://www.apple.com/legal/transparency/pdf/requests-2015-H...
*Poland: predominately requests from Customs and Revenue Authorities
Not that it's a crystal clear institution, but everything will go around taxes and customs with them, even when it's something rotten.
2 Usage of Pegasus means all intercepts are on the servers in Israel. All Government secrets and potential kompromat transferred to foreign power.
Wait, seriously? Any sources on that? I find it hard to believe that any government would spend $$$ on a security tool that doesn't allow on-prem installation and instead beams all your surveillance to another country.
I guess this is all according to NSO claims. I’d like to see evidence otherwise!
from what I heard about Pegasus: noone could get that malware for themselves to not compromise it, so it's you wanted to hijack some phone you would send them phone number so they could resend exploit again (spyware was not persistent across reboots, so you needed to rehack it every time)
source: https://www.money.pl/archiwum/wiadomosci/artykul/usa;nie;uja...
Indirectly, all software vulnerability tools that send source code and other artefacts to servers outside government's control give third parties access to information about potential attack vectors, software vulnerabilities, and infrastructure layout.
What do these phones look like and who manufactures them?
https://www.funduszsprawiedliwosci.gov.pl
"The Justice Fund provides immediate and free emergency assistance to crime victims, witnesses and their closest relatives, including victims of armed aggression in Ukraine.
You can use the free:
legal aid, psychological help, material assistance"
Quite fitting considering previous corrupt regime was ran by PIS, which doesnt stand for piss but 'Prawo i Sprawiedliwosc' - Law and Justice.
it usually infects the intended target using an exploit (0-day) that doesnt have a fix, if you're asking if there are 0days that can hack modern iPhones, the answer is most likely yes, given the most recent hack against the iPhone of one of the executives of the russian cybersecurity company Kaspersky [1].
They're kind of like arms manufacturers. Do you blame them if your government shoots you?
More like hired hitmen.
There is also insatiable demand for nuclear weapons, but if a private company from the US started selling them to random dictatorships, yes, I would blame them.
Also let’s not compare malware/spyware to nuclear weapons.
Poland can get their hands on any weapon or controlled technology they pretty much want.
And I find it laughable that you out Hungary as a dictatorship it’s an EU member and a NATO member.
Nobody thinks that we can prevent everyone from doing something. The point of regulating (or making it illegal) and then enforcing those laws is to increase friction, increase costs, and thus making the thing difficult enough to obtain that the problems it causes become manageable. If there are 3 vendors of this sort of thing, then shutting down one of them definitely will make it more difficult for would-be customers by increasing costs and risks. Something does not have to be perfect to be good.
> They're kind of like arms manufacturers. Do you blame them if your government shoots you?
When Iran sells weapons to the Russians we definitely blame them, yes. And the Russians for using them, as well.
More useful to blame the systemic issues that allow these things to take place: the one that pops to the front of my mind is that the FCC has such a high degree of standards with modems that it results in a severe lack of competition. Google and Apple choose to release phones without contractually demanding full source access to the entirety of it so that it can be audited by their security teams. Those are things that can and should change.
The problem is not that Google and Apple did not have the opportunity to secure the vulnerable components. The problem is that their best teams with thousands of people and billions of dollars are completely incapable of designing systems secure against moderately resourced attackers.
They openly admit that their systems are defenseless against attackers with resources. Every single time their security is completely invalidated they make press releases like: "It was a unprecedented attack using never-before-seen techniques by highly sophisticated attackers." implying that they can not be blamed because look, they were "highly sophisticated" and it was "unprecedented" there is no way we could stop that. Even though every single attack is described that way.
You would be hard pressed to find a single technically competent security developer in any of these organizations which would claim their systems could stop their systems being totally and utterly compromised and their security completely invalidated by a single, individual, lone competent hacker with a year to work on attacks. A team of 3, forget about it. That is only in the low millions of dollars to completely invalidate their entire security story for all hundreds of millions to billions of systems worldwide.
No, the problem is not a lack of accessibility, effort, resources, or focus. The problem is that all of these large companies have failed for literal decades to develop systems secure against competent attackers. And the entire time they have been intentionally deceiving the public into thinking they can even though they know and admit they can not.
The solution is to stop believing these perennial incompetents and liars until they present solid, auditable proof. At least then they can not suck all of the air out of the room from people who actually know what they are doing.
I don't think they tried. One of their main customer is a 3 letter agency which has no interest that the bugs get fixed.
Edit: I've changed it now.
> However, HN guidelines don't provide guidance in what to do if the title is too long
We can't get to that level of detail in the guidelines—it would make them so long that no one would read them! Except maybe to look for loopholes.
> He was convicted during Tusk’s previous regime (2007-2014) for allegedly abusing his power while pursuing government corruption with “excessive zeal,” but was officially pardoned by then-new President Andrzej Duda in 2015 – a long-standing point of displeasure for the Polish left.
Just one party in this coalition is from the left. The rest is decidedly centre to centre-right.
Hard to treat this piece seriously.
Anyone who can form a coalition can rightfully govern. Those who get the most votes don’t automatically get to govern.