Live data from Hacker News

NSO hacked WhatsApp to spy on top government officials at U.S. allies

reuters.com

81–90 of 321 posts

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#81
post #5

Sometimes you just feel like using Signal instead

I mean, Signal is open source and not owned by Facebook, so I'm not sure why anybody uses WhatsApp instead.

Because everyone uses it. Once a social app becomes mainstream it gets a giant advantage due to the amount of inertia needed to switch entire social circles to a new platform.

Most new social platforms that make it big don't really take over older ones, they just grab a younger generation - usually just by being the network their parents aren't in.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#82

Earlier this month the DOJ asked Facebook to "halt end-to-end encryption" by adding a backdoor to all of Facebook's apps. Perhaps this is a reason. https://www.engadget.com/2019/10/03/doj-facebook-end-to-end-...

Why would facebook comply?

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#83

Which is hilarious and hypocritical, since the government keeps talking about making end-to-end encryption apps illegal to distribute without backdoors. Now they're using an encryption app with a backdoor,* and they're upset about it? I thought this is what they wanted! *I know, I know, this probably wasn't done with a backdoor -- it's just funnier to lie in this context.

"Rules for thee but not for me."

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#85
post #19

The article claims that "a flaw in WhatsApp-owned servers" was used to "take over users’ phones". This seems to imply that the hackers were able to escape from the WhatsApp mobile app to perform other actions on the phones. How would this be possible? Or is this just likely careless journalism, and the exploit was that the server breach allowed the attackers to exfiltrate WhatsApp data only?

> How would this be possible? Anecdotally, from a friend at WhatsApp, their engineering has been distracted by integration with Facebook. Holes that would have been patched in an independent WhatsApp may have been left to fester in the-now Facebookdivision.

I think OP is asking how NSO was able to escape the phone's sandbox model. To do that, they would need an exploit for the phone's OS, in addition to the WhatsApp exploit. So, the obvious question: which operating systems were specifically targeted?

Another comment mentions Pegasus... that was an iOS exploit patched in 9.3.5 (3 years ago). Does that line up with the timeline of this article?

Given that Android exploits are far more common than iOS, I would expect they had one of those too.

But then, where are Apple and Google in this case? It wasn't solely Facebook who was exploited; their app was just the initial vector to escalate to an attack on the OS. NSO probably could have achieved the same with dozens of other apps, but WhatsApp was chosen because of ease of deliverability (messaging) and popularity.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#86
post #12

Earlier quoted context omitted.

Who's to say Signal will protect you any better against targeted remote-code-execution attacks from well-funded cyber mercenaries like NSO?

How many people actually worry about these spy agencies? If a state actor wants you or your information they'll just pull up in a black van and take you and use a $5 wrench to beat it out of you.

I get the implication but America isn't Russia and they just don't do it, too big of a headache, too easy to blowback into political realm. Officers hate when clandestine work erupts into public political drama.

Plus, why would you hire a team of people to kidnap a citizen and beat them when you can assign a ticket to a government blackhat at the NSA who will run the commands against your devices and take what they need without you ever knowing.

Even then, there is substantial risk of whistleblowing for illegal data collection against citizens (Snowden et al) so they would instead in a clandestine manner ask a fellow member of the Five Eyes to perform the surveillance "legally".

Our society has known about Five Eye roundabout spy agreements for a long time and has largely shrugged, so the risk of public political blowback doing this would be minimal.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#87

The article doesn't really say what hackers had access to, but it sounds like they had full control over their phones. There is a lot bigger story here and I'd love to read a post-mortem in a few months. Also, WhatsApp is such an obvious target for a state actor. I saw several articles of the last year that mentioned Jared Kushner using Whatsapp so I assume a lot of government folks use it for off the books "encrypte…

It says the hackers had access to WhatsApp servers, so they can tell who is talking to whom, and depending on how WhatsApp does encryption they may have been able to decrypt messages. I say may, because WhatsApp had pitched itself as an encrypted messaging system, though personally I’d bet they could because it’s easy to claim your service is encrypted and yet still design backdoors for yourself.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#88
post #12

Earlier quoted context omitted.

Who's to say Signal will protect you any better against targeted remote-code-execution attacks from well-funded cyber mercenaries like NSO?

How many people actually worry about these spy agencies? If a state actor wants you or your information they'll just pull up in a black van and take you and use a $5 wrench to beat it out of you.

I get your point that a highly-motivated attacker has other, less sophisticated, ways of getting to your data.

However, if we're playing poker and I learn your tell, it's in my best interest that you are naive to that fact. While not the best analogy, I would think that the same concept would apply to state actors.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#89

Earlier quoted context omitted.

I mean, Signal is open source and not owned by Facebook, so I'm not sure why anybody uses WhatsApp instead.

It's a much better app, user experience-wise. I prefer Signal for obvious reasons, but WhatsApp is easier to use (and has a much better web interface).

I agree, but when the people you want to talk to are on WhatsApp already...

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#90
post #69

Earlier quoted context omitted.

It is, but when you create a new contact you are trusting the WhatsApp service that the public key of the other party actually is their public key. The service can always give both parties a key of their own making instead of the actual keys of the parties. IIRC you can verify the public keys via QR codes but maybe such verification wasn't part of security practices. Thus if you hack the service, you may be able to r…

This case is much simpler than that: there was a buffer overflow exploited in WhatsApp clients. https://nvd.nist.gov/vuln/detail/CVE-2019-3568

Yeah, the exploit has absolutely nothing at all to do with message encryption. It's just your run-of-the-mill security hole that happens in other software all the time. As such, most of the comments in this thread are completely off base.

What makes it notable is which app it was found in, the reach of that app's userbase, and that a company was selling these exploit services.

Post reply on HN