Earlier quoted context omitted.
So you're saying "typical intelligence analyst stuff" is the reasoning here? Generally analysts produce questions which operations runs down to figure out if what they think is going on, is actually going on. Correct me if I'm wrong here but you're basically saying that you have done the first part and found some suspicious links but not the second part do develop actual evidence one way or the other, is that a fair…
I am writing this all on a phone and I am more than happy to produce a 5000 word report which will be posted in 96 hours. I will follow up via a comment here and also send to Michael Forsythe at the New York Times for additional review. You have my word. EDIT: 5000 words not pages
NSO hacked WhatsApp to spy on top government officials at U.S. allies
261–270 of 321 posts
Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies
#262Earlier quoted context omitted.
If one assumes that WhatsApp are implementing the protocol as well as signal are (which I do), then I think there are three questions in deciding what is more secure: 1. Do you trust Facebook (or open whisper systems) with your metadata/expect them to delete it? 2. How likely are there to be bugs (in the app, not in the protocol itself) which lead to exploits. On the one hand WhatsApp probably have more people workin…
Even of they implement the Signal protocol, they have additional modifications to support ads, which increases the attack surface.
Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies
#263Use Matrix (Riot.im is a great client) Or Signal, but without the phone number signup
If that's the case, the articles are focusing too much on WhatsApp failure, but not enough on the failure of the Android OS. To me there is some kind of shared responsibility between the app and the OS here.
Who knows how many CVEs are hiding in the Signal and Riot.im apps? And Riot.im asks for many permission...
Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies
#264Dozens of tech companies around the world that were established in the last 4-5 years were done so entirely for the purpose of being fronts for spy agencies to engage in the vast collection of data. This extends also to shipping, licensing, and auditing companies. One example is https://www.pacificbasin.com/en/fleet/fleet.php Somehow they’ve managed to assemble the worlds 2nd largest cargo fleet in terms of dry weigh…
The rise in shipping company fronts may potentially be attributed to miniature nuclear weapons payloads within shipping containers for rapid and unstoppable payload delivery at close proximity to enemy lines. Btw intelligence agencies are using invisible image watermarking technologies to track users.
Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies
#265Earlier quoted context omitted.
So you're saying "typical intelligence analyst stuff" is the reasoning here? Generally analysts produce questions which operations runs down to figure out if what they think is going on, is actually going on. Correct me if I'm wrong here but you're basically saying that you have done the first part and found some suspicious links but not the second part do develop actual evidence one way or the other, is that a fair…
I am writing this all on a phone and I am more than happy to produce a 5000 word report which will be posted in 96 hours. I will follow up via a comment here and also send to Michael Forsythe at the New York Times for additional review. You have my word. EDIT: 5000 words not pages
Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies
#266Earlier quoted context omitted.
I think you misinterpreted the parent comment—I read it to mean that they stopped trusting WhatsApp as soon as Facebook bought them despite using the same technology as Signal. Your interpretation might be right, though.
No, you're correct. I stopped trusting WhatsApp after the Facebook acquisition.
Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies
#267The article doesn't really say what hackers had access to, but it sounds like they had full control over their phones. There is a lot bigger story here and I'd love to read a post-mortem in a few months. Also, WhatsApp is such an obvious target for a state actor. I saw several articles of the last year that mentioned Jared Kushner using Whatsapp so I assume a lot of government folks use it for off the books "encrypte…
Based on the U.K. news, approximately everyone in parliament uses WhatsApp to talk/scheme with one another
Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies
#268Earlier quoted context omitted.
A buddy of mine is Special Forces (U.S.). He said JSOC recently banned use of WhatsApp and encouraged everyone to switch to the open-source Signal (another encrypted messaging app). Allegedly WhatsApp uses Signal's encryption (OpenWhisper) but I stopped trusting it the second Facebook bought them out.
If one assumes that WhatsApp are implementing the protocol as well as signal are (which I do), then I think there are three questions in deciding what is more secure: 1. Do you trust Facebook (or open whisper systems) with your metadata/expect them to delete it? 2. How likely are there to be bugs (in the app, not in the protocol itself) which lead to exploits. On the one hand WhatsApp probably have more people workin…
Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies
#269Earlier quoted context omitted.
Security by using obscure software has its own problems, alas. You have less eyeballs looking for exploits on the good guys side as well. So problems stay open.
Within my experience, security by obscurity works only if you're low profile. If significant amounts of money will be spent decrypting your mess, it's game over. OTOH, we usually only hear about the failed attempts, so there's a selection bias.
I agree about the low profile being necessary (even if not sufficient).
Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies
#270Earlier quoted context omitted.
Security by using obscure software has its own problems, alas. You have less eyeballs looking for exploits on the good guys side as well. So problems stay open.
The more obsure and different the less likely. If closed source the knowledge belongs to the creators. If the circle is extremely small the chance of that knowledge being shared with your enemy is low. It goes up when that circle is increased. When you want the biggest circle open source is safer. If your circle is small closed will be safer.
But in any case, the original comment was using 'obscure' in the sense of uncommon not in the sense of 'secret'. As far as I can tell.