EU parliament member hit by Israeli Candiru spyware
twitter.com
twitter.com
Like presumably law makers would be target #1 for espionage.
Heck most ordinary people get phishing emails on a regular basis.
Idk, i guess i was expecting something more sophisticated based on the headline than just: spear phishing attempt foiled after user fails to click on the suspicious link.
> If the claims are correct, just opening the link would have compromised the phone
I'm not sure if that is being claimed. The twitter post just said the link would have "exposed" them to spyware. One possible interpretation is that simply viewing the link in a web browser would be enough, but i think another interpretation is that the link contained some sort of malicious download. No way to know with the info we are given. I agree that a zero-day in a web browser would certainly be more interesting, i'm just not sure that is the case here.
yes, this class of exploits definitely exists (a while ago there was one that worked just receiving a text message!) and is the primary reason why apple offers the lockdown mode for these sorts of people who actually might be the target of these advanced threats. Lockdown mode severely reduces the amount of “auto” shit that happens in the background, which ruins the experience but is also more secure against this style of attack.
The first rule of iPhone security is that you do not control the attack surface against a sufficiently large government.
https://www.haaretz.com/israel-news/2024-05-28/ty-article/.p...
Not to mention the wiretapping of phones of members of the Palestinian authority, probably lots more that we just are not aware of.
I think in western discourse it's common to treat Israel like a hurricane or some other natural disaster and not a state with agency. It is framed as Israel "just being there" and not as them choosing to occupy an area and subjugate people, so much so that they designate a huge chunk of their GDP to the endeavor and require continuous funding from the US.
Sorry if what I am saying is confusing, I am struggling to articulate the point I want to make. My point is mostly that sure, while wiretapping is several magnitudes less bad than murdering civilians and foreign aid workers, they are only capable of doing it so trivially because of their position of occupation, which is by design.
Israel is very laissez-faire about regulating the tech industry because it employs almost 10% of the country. As such, offensive security companies sell to anyone who isn't on the US Sanctions list.
The question is which buyer did the attack.
Hidden between the lines of the reporting is that it might be Hungarian intelligence [0]
Imo, the bigger question is why Hungary, Poland, Spain, Greece, and Cyprus (all countries part of the recent EU Spyware Scandal) [1] continue to allow their Interior Ministries to attack the phones of both domestic and foreign opponents, and are abusing "Spyware for political gain" [2].
[0] - https://www.politico.eu/newsletter/brussels-playbook/orban-c...
[1] - https://www.politico.eu/article/parliament-defense-subcommit...
[2] - https://www.politico.eu/article/eu-spyware-probe-slams-gover...
It's also a national security issue given that Israel may be piggybacking on the spying.
While this doesn't mean that there probably isn't some phoning in, it's extremely difficult to obfuscate.
That said, the act of purchasing a product like this can absolutely be used as leverage, but that's any sort of weapons sale (which this functionally is)
Definitely not an expert but I'm presuming they take advantage of the "helpful" behaviour those apps have to preview content and then pair that with some sort of exploit in the library that parses/displays the content. So say they have an exploit in a jpeg library that whatsapp uses then they send a specially-crafted jpeg via whatsapp, whatsapp "previews" the image and that triggers the exploit to compromise the jpeg library and pwn the user.
[1] https://www.ft.com/content/4da1117e-756c-11e9-be7d-6d846537a...
[2] https://appleinsider.com/articles/23/06/01/zero-click-ios-ma...
Also these attacks are aimed at individuals and executed by state actors. They likely already knew what phone, OS, and browser the MEP was using and selected an appropriate attack from the catalog.
They might also have specific software installed across most of them that could be part of the targeting.
This has been the reality of mobile phone security for almost a decade now. Any sufficiently-complex digital system will be rife with UB and exploits.
phishing -> fishing -> bad fish
Sci-Fi Author: In my book I invented the Torment Nexus as a cautionary tale
Tech Company: At long last, we have created the Torment Nexus from classic sci-fi novel Don't Create The Torment Nexus
11:49 PM · 8 nov 2021
So either the engineers have changed fundamentally, or ...
(just the logical conclusion of the statement, intentionally made blank)
Those get little air time in hard progressive or far right spaces since these anti liberal influence operations mostly promote hard progressive and far right perspectives.
Example: the far right tries to depict the left as degenerates who want to make all children gay just because they support introducing LGBT+ friendly material to the school education. I'm sure some people buy that and hence become more inclined to reject the left, as who wants to "force" children to become homosexual, or transgender, right?!
Now, whether China/Russia are doing it or not, I have no idea, and I suspect no one here does. But even if they do, I have trouble seeing how they would be more capable than Europe and the US, who clearly also try pretty hard to promote their own values elsewhere, so they can hardly complain about others doing it.
I think they're also trying to break the wests spirit in terms of faith in democracy and the state of the world right now for policy and political/military advantage. In my eyes the US is currently one big foreign infleunce experiment right now via facebook
It's not like the USA will stop interfering with the world if they succeed, which I suppose may be their motivation? To the contrary, a messed up USA is incredibly dangerous. It could end up in the hands of extremists (well, it kind of already did before) who have no qualms starting a war against Russia, which would be completely devastating for Russia (maybe also for the USA, but from Russia's point of view, that wouldn't matter much).
The media makes it look like Russia is some teenager hooligan in the world stage, doing destructive things without motivation just for the sake of it, which just doesn't make sense to me at all.
https://www.theguardian.com/us-news/2020/feb/10/sheldon-adel...
https://www.reuters.com/world/us/republican-mega-donor-adels...
I'm pro-Israel, but the current Israel government is widely called far right by the mainstream media, so I don't not know what to make of your comment at all.
If you talk about general influencing: It has been known for decades that the USSR and its successors have influence operations. No need to mention it. It would be interesting though to follow the money: Perhaps your innocent "liberal" mainstream operation that is anti-meritocracy and therefore undermines the West is financed by Russia.
And anti meritocracy seems to be a very effective idea to push, I was more considering shattering faith in the future and changing policy personally.
Also account created 2 hours ago and only comment is on this israel post^
(*) https://www.statista.com/statistics/257337/total-lobbying-sp...
America literally produces movies about "Captain America", a heroic do-gooder who has superhuman strength, speed and endurance and who wears a flag as an outfit. In these movies he saves the entire planet. America spends like a hundred million dollars every year on that alone.
Is that not what the senate subcommittee has been discussing for the past two years?
(Twitter tankies are annoying, but mostly on their own initiative)
That’s really in direct opposition to their stated aims and it just seems like a false equivalence.
Also, Russia and China aren't seen as allies by basically anyone in the west. But yeah, sure then we should treat Israel like we do Russia and China though, but I'm not sure you would.
In this case you triggered another commenter into a complete misunderstanding (https://news.ycombinator.com/item?id=41066935), taking your comment to be not only serious but also representative of the community. Given the high level of inflammation around this topic (everywhere, including on HN), that is seriously not cool.
If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html and sticking to the rules in the future, we'd appreciate it. It looks like you've been breaking them for quite a long time, not just with drive-by flamebait like the above and https://news.ycombinator.com/item?id=41066717, but also with ideological battle comments generally. If you want to keep posting here, we need you (as with any other user) to drop that.
Btw, you don't need screenshots of HN comments. Anyone with 'showdead' turned on in their profile can read the original: https://news.ycombinator.com/item?id=41066729.
All: if you turn 'showdead' on, please don't forget that you did so, because we sometimes get emails from people asking "how can you possibly condone $horrible-comment appearing on HN?" when in reality the account has been banned for years.
HN does get some genuinely antisemitic comments, most of which get posted by one or two serial trolls who keep making new accounts. We ban those whenever we see their latest incarnations—it's a whack-a-mole thing.
Edit: please see https://news.ycombinator.com/item?id=41071782 and https://news.ycombinator.com/item?id=41071809 also. I've replied in each place you posted this because people often jump to wrong conclusions about the community and it's important not to do that.
might I also suggest that sufficiently skilled efforts to direct a conversation will not be detected by most conversation participants.
Keeping away, no. But they are trying hard and mostly succeed to deviate the discussion.
.. and, even more importantly, the censorship cannot be considered successful on the part of the agency doing the censorship unless a) the victim audience do not know the censored information, and b) never know that things were censored.
It would appear that attempted obfuscation over this very issue can be observed in a multitude of forms ...
If you do actually follow the topic very closely, or read one or two comments further down in this thread you would have come across this link to pro-israeli astro turfing zoom call tutorials by the idf https://www.leefang.com/p/inside-the-pro-israel-information and many other examples
Unless it's the US as hacker. Then no one is inpressed.
(It’s from the EU’s diplomatic service so it should be considered geopolitically self-interested)
This phenomenon is generic and happens with all repeated/related stories. People only interpret it differently in this case because they're conditioned to treat this topic as a special case. They therefore assume there must be some special thing going on. Both sides of the conflict do this, btw.
They allowed 9/11 to happen (they knew because they spied on Americans through a company called Amdocs)
They stole nuclear weapons from USA through a company called NUMEC
They killed JFK when he tried to investigate them for stealing nuclear material,
To this day, Israel maintains an arsenal of nuclear weapons, which they use to threaten other countries, while simultaneously preventing other nations from procuring nuclear weapons
They perpetuated a genocide, with the secret objective of setting conditions for a religious ritual involving a red heifer sacrifice leading to the destruction of the Al Aqsa mosque ( seriously)
They sold US electronic warfare technology to China,
They deliberarely sunk the USS liberty killing US sailors, and then had their corrupt US politicians try to cover it up,
everybody is constantly a target of attacks but what makes it to the news is the journalist choice
It's only two year's imprisonment, but there's presumably a lot of participants in the exploit development etc.