Live data from Hacker News

NSO hacked WhatsApp to spy on top government officials at U.S. allies

reuters.com

41–50 of 321 posts

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#41
post #19

The article claims that "a flaw in WhatsApp-owned servers" was used to "take over users’ phones". This seems to imply that the hackers were able to escape from the WhatsApp mobile app to perform other actions on the phones. How would this be possible? Or is this just likely careless journalism, and the exploit was that the server breach allowed the attackers to exfiltrate WhatsApp data only?

It was done using pegasus exploit from NSO. A missed video call to the target on WhatsApp was all that necessary to deliver the payload, escape the sandbox & exploit the operating system.

What WhatsApp & CitizenLab said to the victims in India about the attack[0].

[0]: https://scroll.in/latest/942218/nagpur-lawyer-notified-by-wh...

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#42

Dozens of tech companies around the world that were established in the last 4-5 years were done so entirely for the purpose of being fronts for spy agencies to engage in the vast collection of data. This extends also to shipping, licensing, and auditing companies. One example is https://www.pacificbasin.com/en/fleet/fleet.php Somehow they’ve managed to assemble the worlds 2nd largest cargo fleet in terms of dry weigh…

Can you provide any sources? Surprised to see Credit Karma on here...

It comes mainly from mapping the subdomains over time and analysis of the ASNs. This is key. You will often see a company with perhaps 200 or so subdomains, that only does business in the United States.

But then you will see one subdomain that maps to ASN 4803 or whatever, which then leads to “China Telecom xinjiang”. In fact I encourage you to type:

org:”China Telecom xinjiang” “NSFOCUS” into Shodan.

Also look at the capital expenditures psychz.net claims on their about page. There is no IaaS company in the world that can afford to lay down as much hardware as they are claiming.

Another thing btw is these sites never seem to have job openings. That is common pattern that applies to perhaps 60% of the firms listed.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#43
post #5

Sometimes you just feel like using Signal instead

I mean, Signal is open source and not owned by Facebook, so I'm not sure why anybody uses WhatsApp instead.

they have features signal has not yet copied and probably won't (statuses e.g.)

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#44

Dozens of tech companies around the world that were established in the last 4-5 years were done so entirely for the purpose of being fronts for spy agencies to engage in the vast collection of data. This extends also to shipping, licensing, and auditing companies. One example is https://www.pacificbasin.com/en/fleet/fleet.php Somehow they’ve managed to assemble the worlds 2nd largest cargo fleet in terms of dry weigh…

Yeah, gonna need a source on Proton and Credit Karma

Consider it a conspiracy theory. Extraordinary claims require extraordinary evidence.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#45

But I thought WhatsApp was end-to-end encrypted?

If you want secure your top choices, in my opinion, are Signal and Wire -- and I like Wire better because I can sign up with a burner account or seemingly random alias on my ProtonMail account.

But don't just take my word for it -- here's a good place to start your own research: https://www.securemessagingapps.com/

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#46

Earlier quoted context omitted.

Can you provide any sources? Surprised to see Credit Karma on here...

It comes mainly from mapping the subdomains over time and analysis of the ASNs. This is key. You will often see a company with perhaps 200 or so subdomains, that only does business in the United States. But then you will see one subdomain that maps to ASN 4803 or whatever, which then leads to “China Telecom xinjiang”. In fact I encourage you to type: org:”China Telecom xinjiang” “NSFOCUS” into Shodan. Also look at th…

These claims are not credible. Publish your analysis techniques & results.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#47

Dozens of tech companies around the world that were established in the last 4-5 years were done so entirely for the purpose of being fronts for spy agencies to engage in the vast collection of data. This extends also to shipping, licensing, and auditing companies. One example is https://www.pacificbasin.com/en/fleet/fleet.php Somehow they’ve managed to assemble the worlds 2nd largest cargo fleet in terms of dry weigh…

Umm.. That's some fun tale.

Highwinds - a software company that sold usenet server. 1995 or so. Really high performance one. Later went into usenet hosting.

Choopa - a hosting company that started as a porn DVD ripper. When you provide lots of porn, you get lots of connectivity. At which point someone goes "Why don't we sell the excess? We already paying for it" Sounds familiar?

LeaseWeb - a really old hosting company. Predates Amazon.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#48
post #12
post #5

Sometimes you just feel like using Signal instead

Who's to say Signal will protect you any better against targeted remote-code-execution attacks from well-funded cyber mercenaries like NSO?

How many people actually worry about these spy agencies? If a state actor wants you or your information they'll just pull up in a black van and take you and use a $5 wrench to beat it out of you.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#49
post #19

The article claims that "a flaw in WhatsApp-owned servers" was used to "take over users’ phones". This seems to imply that the hackers were able to escape from the WhatsApp mobile app to perform other actions on the phones. How would this be possible? Or is this just likely careless journalism, and the exploit was that the server breach allowed the attackers to exfiltrate WhatsApp data only?

> How would this be possible?

Anecdotally, from a friend at WhatsApp, their engineering has been distracted by integration with Facebook. Holes that would have been patched in an independent WhatsApp may have been left to fester in the-now Facebookdivision.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#50

The article doesn't really say what hackers had access to, but it sounds like they had full control over their phones. There is a lot bigger story here and I'd love to read a post-mortem in a few months. Also, WhatsApp is such an obvious target for a state actor. I saw several articles of the last year that mentioned Jared Kushner using Whatsapp so I assume a lot of government folks use it for off the books "encrypte…

A buddy of mine is Special Forces (U.S.). He said JSOC recently banned use of WhatsApp and encouraged everyone to switch to the open-source Signal (another encrypted messaging app). Allegedly WhatsApp uses Signal's encryption (OpenWhisper) but I stopped trusting it the second Facebook bought them out.

Approx 20 months ago, numerous people I had contact with working in western military special operations units dropped WhatsApp in a fairly brief period of time.
Post reply on HN