Live data from Hacker News

NSO hacked WhatsApp to spy on top government officials at U.S. allies

reuters.com

271–280 of 321 posts

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#271

Earlier quoted context omitted.

That guardian article was pretty bad. It scared a lot of people from WhatsApp (which is still in general mode secure than most options) to text messaging by claiming that this was somehow some huge security flaw. From WhatsApp’s point of view this was a reasonable ux trade off. It is a major pain point of signal when it does this (particularly in group chats where it is more likely to happen). But I agree that from a…

Sorry, but his is a major security flaw. WhatApp, their mothership Facebook, or any party who can coerce them into doing so (e.g. the US government), can use this to rekey targets with their own keys, virtually undetectable by most regular users, thereby completely MITMing the message exchanges. Even moxie, who created this stuff, more or less admitted this[0], by saying the rekeying notification is the only defense,…

Anyone expecting secure messaging from WhatsApp must have Rekeying Notification set ON. Compare it to having a lock installed and using the key to close the lock.

Personally I can not imagine Human Rights Activist having the Rekeying Notification set OFF.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#272

Earlier quoted context omitted.

Sorry, but his is a major security flaw. WhatApp, their mothership Facebook, or any party who can coerce them into doing so (e.g. the US government), can use this to rekey targets with their own keys, virtually undetectable by most regular users, thereby completely MITMing the message exchanges. Even moxie, who created this stuff, more or less admitted this[0], by saying the rekeying notification is the only defense,…

Anyone expecting secure messaging from WhatsApp must have Rekeying Notification set ON. Compare it to having a lock installed and using the key to close the lock. Personally I can not imagine Human Rights Activist having the Rekeying Notification set OFF.

This is not like a lock and using the key. Not in the very least. It has as much to do with a psychical lock as it has to to with a toaster or a banana. Nothing.

>Personally I can not imagine Human Rights Activist having the Rekeying Notification set OFF.

I can. A lot of those people are not tech savvy. And the targets of e.g. the most recent NSO story weren't just activists, but a lot of other people too, politicians, state officials, lawyers, journalists, etc.

And on top of that, this system becomes MITMable as soon as one of the communicating parties has notifications off (or ignores them, which then comes back to the UX and education issue).

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#274
"Prior to notifying victims, WhatsApp checked the target list against existing law enforcement requests for information relating to criminal investigations, such as terrorism or child exploitation cases. But the company found no overlap, said a person familiar with the matter. Governments can submit such requests for information to WhatsApp through an online portal the company maintains."

There is already an official backdoor, or how should I understand that?

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#275
post #173

Earlier quoted context omitted.

Hypocritical? How many of your personal secrets (or even your corporate secrets) would cause >= thousands of people to die or >= billions of taxpayer dollars to be lost if they were leaked?

Suppose I am a pedophile and somebody discovers that. They then use that as a leverage against me to perform something entirely else, which is illegal, too. In the context of our society, me being a pedophile is better than me being a pedophile who also does other illegal things to cover that up.

I suspect your example would be more compelling if you used a first breach in ethics that would be less heinous. Cheating on your spouse is a common one to defend privacy of bad people; tax dodging if you want something illegal.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#277
post #45

But I thought WhatsApp was end-to-end encrypted?

If you want secure your top choices, in my opinion, are Signal and Wire -- and I like Wire better because I can sign up with a burner account or seemingly random alias on my ProtonMail account. But don't just take my word for it -- here's a good place to start your own research: https://www.securemessagingapps.com/

Why is Wechat missing on that list?

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#279

"Prior to notifying victims, WhatsApp checked the target list against existing law enforcement requests for information relating to criminal investigations, such as terrorism or child exploitation cases. But the company found no overlap, said a person familiar with the matter. Governments can submit such requests for information to WhatsApp through an online portal the company maintains." There is already an official…

You have it correct. Nearly every major US provider maintains some sort of online interface for law enforcement to submit requests. The level of information provided via these means varies, but they are obligated to respond to legitimate requests with wharever data they have on hand.

Dont like it? Go with a security-minded service like signal. Or, better yet, something totally severless and open source.

Re: NSO hacked WhatsApp to spy on top government officials at U.S. allies

#280

"Prior to notifying victims, WhatsApp checked the target list against existing law enforcement requests for information relating to criminal investigations, such as terrorism or child exploitation cases. But the company found no overlap, said a person familiar with the matter. Governments can submit such requests for information to WhatsApp through an online portal the company maintains." There is already an official…

You have it correct. Nearly every major US provider maintains some sort of online interface for law enforcement to submit requests. The level of information provided via these means varies, but they are obligated to respond to legitimate requests with wharever data they have on hand. Dont like it? Go with a security-minded service like signal. Or, better yet, something totally severless and open source.

I don't use WhatsApp. But if they have an official backdoor, then it's not really e2e encrypted. Until now I thought, at least the official statement was, WhatsApp is truly e2e encrypted. Just that.
Post reply on HN