Live data from Hacker News

NSO hacked WhatsApp to spy on top government officials at U.S. allies

reuters.com

91–100 of 321 posts

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#91
post #59

Earlier quoted context omitted.

Last I checked Signal's UX was worse enough that I'd be fighting a real uphill battle to get my friend group to switch.

That's reasonable, I suppose I'm lucky to have a friend group that universally prefers open source sorftware to good UX -- there was never really a question for us.

It's a little eye opening to me that anyone could have a friend group that "universally prefers open source software to good UX".

I have and use Signal with some friends, but there are also loads of people I communicate with who couldn't even tell you what open source software is, let alone articulate a preference for it over good UX.

Are all of your friends software engineers and/or technophiles?

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#92

> Sources familiar with WhatsApp’s internal investigation into the breach said a “significant” portion of the known victims are high-profile government and military officials spread across at least 20 countries on five continents. Welp!

I know a military contractor working on stuff for non-Nato airforces. These guys use WattsApp for everything. It blew my mind.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#93
post #80

Which is hilarious and hypocritical, since the government keeps talking about making end-to-end encryption apps illegal to distribute without backdoors. Now they're using an encryption app with a backdoor,* and they're upset about it? I thought this is what they wanted! *I know, I know, this probably wasn't done with a backdoor -- it's just funnier to lie in this context.

The real irony comes from an Administration who ran on the odious idea of "locking up" government employees who mishandled communications, who then turns around and begins a mass campaign of mishandling communications...

"You're doing mishandling of communications wrong. Here, let me show you how to really mishandle communications."

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#94

The article doesn't really say what hackers had access to, but it sounds like they had full control over their phones. There is a lot bigger story here and I'd love to read a post-mortem in a few months. Also, WhatsApp is such an obvious target for a state actor. I saw several articles of the last year that mentioned Jared Kushner using Whatsapp so I assume a lot of government folks use it for off the books "encrypte…

A buddy of mine is Special Forces (U.S.). He said JSOC recently banned use of WhatsApp and encouraged everyone to switch to the open-source Signal (another encrypted messaging app). Allegedly WhatsApp uses Signal's encryption (OpenWhisper) but I stopped trusting it the second Facebook bought them out.

I have been using signal for awhile and I try to convince people to use it, however I'm curious if using signal would have prevented this. It sounds like they got into WhatsApp servers and then did something else to get full access to people's phones.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#95
post #6

No one who wants to talk securely should ever use a facebook-owned channel in the first place.

Unless you're arguing that Facebook-owned channels are more prone to security bugs, I don't see how this conversation is useful. Let's not forget that whatsapp is end-to-end encrypted by default; they literally brought end-to-end encryption to the masses.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#96

Earlier quoted context omitted.

> How would this be possible? Anecdotally, from a friend at WhatsApp, their engineering has been distracted by integration with Facebook. Holes that would have been patched in an independent WhatsApp may have been left to fester in the-now Facebookdivision.

I think OP is asking how NSO was able to escape the phone's sandbox model. To do that, they would need an exploit for the phone's OS, in addition to the WhatsApp exploit. So, the obvious question: which operating systems were specifically targeted? Another comment mentions Pegasus... that was an iOS exploit patched in 9.3.5 (3 years ago). Does that line up with the timeline of this article? Given that Android exploit…

>Given that Android exploits are far more common than iOS, I would expect they had one of those too.

The Pixel was the only device that was not pwned in the 2017 Mobile Pwn2Own competition - the iPhone, running iOS 11.1, was exploited 4 times via both WiFi and Safari.

I'd be incredinly surprised if NSO were able to compromise an up to date Pixel phone.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#97
post #12

Earlier quoted context omitted.

Who's to say Signal will protect you any better against targeted remote-code-execution attacks from well-funded cyber mercenaries like NSO?

How many people actually worry about these spy agencies? If a state actor wants you or your information they'll just pull up in a black van and take you and use a $5 wrench to beat it out of you.

The state actor will have a more difficult time doing that if you are living in a different country. Exploits don't care about borders: https://www.voanews.com/africa/ethiopia-accused-using-spywar...

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#98
post #12

Earlier quoted context omitted.

Who's to say Signal will protect you any better against targeted remote-code-execution attacks from well-funded cyber mercenaries like NSO?

How many people actually worry about these spy agencies? If a state actor wants you or your information they'll just pull up in a black van and take you and use a $5 wrench to beat it out of you.

Much of what NSO Group does is sell to smaller despotic regimes who then use them to spy on dissidents who live abroad and would be quite hard (and embarrassing) to black-bag. Not everyone can send a murder team to Stockholm (or wherever).

Some despotic regimes do have large kidnap-and-murder programs (ex Rwanda) but if you just want to keep tabs on exiled dissidents and learn exactly who they're talking with back home, NSO Group has a product for you.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#99
post #77

Earlier quoted context omitted.

Facebook didn't buy Signal. One of the original executives from Facebook left to help start the Signal foundation with Moxie precisely because he had become sick of Facebook's insane behavior.

I think you misinterpreted the parent comment—I read it to mean that they stopped trusting WhatsApp as soon as Facebook bought them despite using the same technology as Signal. Your interpretation might be right, though.

No, you're correct. I stopped trusting WhatsApp after the Facebook acquisition.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#100
post #69

Earlier quoted context omitted.

It is, but when you create a new contact you are trusting the WhatsApp service that the public key of the other party actually is their public key. The service can always give both parties a key of their own making instead of the actual keys of the parties. IIRC you can verify the public keys via QR codes but maybe such verification wasn't part of security practices. Thus if you hack the service, you may be able to r…

This case is much simpler than that: there was a buffer overflow exploited in WhatsApp clients. https://nvd.nist.gov/vuln/detail/CVE-2019-3568

Oh thanks, this wasn't mentioned in the linked article.
Post reply on HN