Live data from Hacker News

NSO hacked WhatsApp to spy on top government officials at U.S. allies

reuters.com

51–60 of 321 posts

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#51

Earlier quoted context omitted.

Can you provide any sources? Surprised to see Credit Karma on here...

It comes mainly from mapping the subdomains over time and analysis of the ASNs. This is key. You will often see a company with perhaps 200 or so subdomains, that only does business in the United States. But then you will see one subdomain that maps to ASN 4803 or whatever, which then leads to “China Telecom xinjiang”. In fact I encourage you to type: org:”China Telecom xinjiang” “NSFOCUS” into Shodan. Also look at th…

So you're saying "typical intelligence analyst stuff" is the reasoning here?

Generally analysts produce questions which operations runs down to figure out if what they think is going on, is actually going on.

Correct me if I'm wrong here but you're basically saying that you have done the first part and found some suspicious links but not the second part do develop actual evidence one way or the other, is that a fair assessment?

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#52

Earlier quoted context omitted.

Not that I'm dissing Signal (it is my preferred platform, sadly not most used), but don't both WA and Signal use Open Whispers systems? So isn't there the potential that the same exploit might work on Signal?

WhatsApp allegedly uses an implementation of the OpenWhisper encryption system that Signal created (and still uses). However as there is no source code available unlike Signal, there's no way to verify if WhatsApp "really" is using it (or using it correctly).

Couldn't you determine by looking at the code in the APK, at least for Android?

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#53

Dozens of tech companies around the world that were established in the last 4-5 years were done so entirely for the purpose of being fronts for spy agencies to engage in the vast collection of data. This extends also to shipping, licensing, and auditing companies. One example is https://www.pacificbasin.com/en/fleet/fleet.php Somehow they’ve managed to assemble the worlds 2nd largest cargo fleet in terms of dry weigh…

Umm.. That's some fun tale. Highwinds - a software company that sold usenet server. 1995 or so. Really high performance one. Later went into usenet hosting. Choopa - a hosting company that started as a porn DVD ripper. When you provide lots of porn, you get lots of connectivity. At which point someone goes "Why don't we sell the excess? We already paying for it" Sounds familiar? LeaseWeb - a really old hosting compan…

Look into something called Reverse Mergers btw.

Old dying hosting companies were the perfect cover to be acquired by spy agencies.

You’ll notice a large posting of press releases and apparent spending in the last 4-5 years though still for all.

http://dcsmanage.com out of Los Angeles is another one btw...

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#54

Earlier quoted context omitted.

Can you provide any sources? Surprised to see Credit Karma on here...

It comes mainly from mapping the subdomains over time and analysis of the ASNs. This is key. You will often see a company with perhaps 200 or so subdomains, that only does business in the United States. But then you will see one subdomain that maps to ASN 4803 or whatever, which then leads to “China Telecom xinjiang”. In fact I encourage you to type: org:”China Telecom xinjiang” “NSFOCUS” into Shodan. Also look at th…

Never heard of psychz.net.

Are you suggesting they are an "open secret"? EG, They are not "covert", but they are secretive in that they only sell to maybe western intelligence agencies, etc. Could be why they never have real "openings", they got a hot pipeline constantly exiting from the intelligence community looking to make some real money.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#56
post #12
post #5

Sometimes you just feel like using Signal instead

Who's to say Signal will protect you any better against targeted remote-code-execution attacks from well-funded cyber mercenaries like NSO?

Yeah, I pretty much assume that targeted attacks will always succeed when a well-funded state actor is involved.

For me, I look at encryption as a mitigation for surveillance. Anything that increases the marginal cost to monitor an individual makes broad surveillance less economic.

Signal will always have the edge for surveillance due to the relative difficulty of hiding a back door. Whatsapp will always be suspect in that they could easily be forwarding everyone’s messages to third parties.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#57

Earlier quoted context omitted.

Not that I'm dissing Signal (it is my preferred platform, sadly not most used), but don't both WA and Signal use Open Whispers systems? So isn't there the potential that the same exploit might work on Signal?

WhatsApp allegedly uses an implementation of the OpenWhisper encryption system that Signal created (and still uses). However as there is no source code available unlike Signal, there's no way to verify if WhatsApp "really" is using it (or using it correctly).

This is true, but that also doesn't answer the question. It still leads to a possibility. The hack could also sidestep OW in some other way and only be WA specific, but still begs the question. Security is a constant cat and mouse game, so if someone says: "well, that only affects WhatsApp, it won't affect us -- even though we use the same underlying structure." sounds kinda naive.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#58

Earlier quoted context omitted.

Yeah, gonna need a source on Proton and Credit Karma

Consider it a conspiracy theory. Extraordinary claims require extraordinary evidence.

> Extraordinary claims require extraordinary evidence.

To be considered "proven", sure, maybe. But no such thing is needed to merely consider an idea. Look at all the "facts" that have widespread belief, look at all the "not exactly accurate" various organizations broadcast, that turn into very strongly believed "facts" in the public mind.

There's so much obvious lying going on nowadays, and so many perfectly reasonable concerns dismissed as conspiracy theories, that that phrase no longer has any negative connotations for me. In fact, anything remotely complex that doesn't have an air of a conspiracy to it makes me at least as suspicious, kind of in the "which part of this story is untrue, and why" sense.

But hey, each to his own. If you choose to consider only authorized truths, that's your prerogative.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#59
post #5

Sometimes you just feel like using Signal instead

I mean, Signal is open source and not owned by Facebook, so I'm not sure why anybody uses WhatsApp instead.

Last I checked Signal's UX was worse enough that I'd be fighting a real uphill battle to get my friend group to switch.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#60

Earlier quoted context omitted.

Can you provide any sources? Surprised to see Credit Karma on here...

It comes mainly from mapping the subdomains over time and analysis of the ASNs. This is key. You will often see a company with perhaps 200 or so subdomains, that only does business in the United States. But then you will see one subdomain that maps to ASN 4803 or whatever, which then leads to “China Telecom xinjiang”. In fact I encourage you to type: org:”China Telecom xinjiang” “NSFOCUS” into Shodan. Also look at th…

Wait... you're basing this based on who the domain is registered with?
Post reply on HN