Live data from Hacker News

Jeff Bezos's phone 'hacked by Saudi crown prince'

theguardian.com

111–120 of 327 posts

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#111
post #91

Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109

That's one hell of a tinfoil-hat theory. How would you even orchestrate that from within a public company with so many developers involved?

Well, it doesn't have to be that complicated.

Just underfund the security department, don't adopt systems/languages that prevent the worse bugs, and keep the core protocol proprietary.

On the other side let the governments invest in operations to hack the product.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#112
post #109
post #93

Earlier quoted context omitted.

Considering how few developers understand the subtleties of security, it would not be all that difficult. Also, FWIW we know that Google did this with its data center breach and likely many other cases. At WhatsApp/Google scale the attack is extremely cost effective.

Are you referring to the data center breaches exposed by the Snowden leaks? Because Google claimed that they were unaware of the breach and quickly took action to correct it [1]. Are you suggesting that Google was complicit? [1] https://www.zdnet.com/article/meet-muscular-nsa-accused-of-t...

I don't think Google has given us any reason to believe that it was not complicit. For instance, why not include warrant canaries on gmail accounts?

There is not really any fundamental difference between abetting the data center breach and opting not to offer warrant canaries. Likely tens of thousands of Google users are searched every day due to easy FISC warrants and wide investigative nets.

The state sponsored attacks on Google would of course allow Google to plausibly deny cooperation, but obviously Google has every incentive to cooperate fully, as is evidenced by the lack of warrant canaries.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#114

Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109

Pavel Durov also said

> The encryption of Signal (=WhatsApp, FB) was funded by the US Government. I predict a backdoor will be found there within 5 years from now.

He seems to enjoy throwing out loosly supported accusations. He might be right in some of them, but stopped clocks and so forth.

He's also been accused himself of deliberately sabotaging the security of his own encrypted messenger app (Telegram). There's no real evidence, but he did hire a bunch of math PhDs to figure out encryption from first principles

> The team behind Telegram, led by Nikolai Durov, consists of six ACM champions, half of them Ph.Ds in math. It took them about two years to roll out the current version of MTProto. Names and degrees may indeed not mean as much in some fields as they do in others, but this protocol is the result of thougtful and prolonged work of professionals. [1]

Note: Signal, like TOR, is funded in part by the Open Technology Fund of Radio Free Asia, which is controlled and funded by Congress. So far there has been no public evidence that this funding has come with any malicious strings. The stated goal of the fund is to promote democracy in developing countries, and Signal and TOR are obviously in line with that overt goal. Radio Free Asia used to be a CIA front during the Cold War, but there's been no public evidence that the transfer of control away from the CIA to Congress was in any way a sham.

[0]: https://techcrunch.com/2017/09/18/signal-moxie-marlinspike-t...

[1]: https://news.ycombinator.com/item?id=6916860

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#115
post #93

Earlier quoted context omitted.

Considering how few developers understand the subtleties of security, it would not be all that difficult. Also, FWIW we know that Google did this with its data center breach and likely many other cases. At WhatsApp/Google scale the attack is extremely cost effective.

Can you elaborate on the google data center breach? Are you saying it was orchestrated by google?

Not orchestrated, but happily tolerated. All Google needs is to be able to plausibly deny complicity, but the other practices of Google (such as not offering warrant canaries on all Google accounts) indicate that Google is eager to cooperate and please governments, so it would have been easy to leave a few doors unlocked, hire a plant (with solid itsec skills), etc.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#116

Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109

one thing that needs to be accounted for is that, IIRC, we just recently had US AG Barr make a stink about encryption based on Facebook tech (either WhatsApp/Messenger i believe) being some anti-law enforcement issue.

does the theory suggest that US DoJ does not know how to exploit these backdoors, but other agencies (CIA/NSA, foreign intel services) do?

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#117
post #91

Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109

That's one hell of a tinfoil-hat theory. How would you even orchestrate that from within a public company with so many developers involved?

As an engineer that has basic permissions to our build and deployment system (unrelated non communication application) I could pretty easily think of multiple steps in the build where I could inject and link in pretty much arbitrary code.

For instance, anything that can hook directly on a build machine, or artifact upload, or even just simply precompiled into one of the black-box 3rd party dependencies that basically never get recompiled.

All of these mechanism have vectors that would be easy to obfuscate and don't rely on any changes to any repo code. I think there is a good chance that a normal engineer could likely hide something that could make it into a final build product.

Now, combine that with the fact that even the most open of companies have some sort of protected infrastructure (Could be permissions on an S3 bucket, locked data-center or even just a locked away Cat-5 cable in the process. Someone high in the org could easily inject some process that could stay hidden from even the most prying of internal eyes.

Now, while I agree that it's a bit tinfoil-hat-y to believe that this actually -is- happening. I absolutely believe that the technical capability is both there and well within practical effort. And combine this with a few bad incentives it's easy to see how it -could- happen.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#118

One thing which this article doesn't address at all, is what is the beef between MBS and Bezos? Why would the Saudi prince leak this data? How did Amazon upset him?

Bezos owns the Washington Post. Jamal Khashoggi was a journalist for WaPo.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#119

Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109

one thing that needs to be accounted for is that, IIRC, we just recently had US AG Barr make a stink about encryption based on Facebook tech (either WhatsApp/Messenger i believe) being some anti-law enforcement issue. does the theory suggest that US DoJ does not know how to exploit these backdoors, but other agencies (CIA/NSA, foreign intel services) do?

There's no incentive to not publicly make a stink about encryption, even if they have backdoors.

If anything there's incentive to do so even if they do, in creating plausible deniability.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#120

Whatsapp allows desktop clients. I use it too. It is technically possible for someone to hijack this desktop client and do this without MBS's involvement, as long as MBS authorized that desktop. I think you need proximity, but you can have a computer near the prince, and that computer being remotely controlled by someone sitting far away. Not saying this happened ... but there are many ways to blame it on prince and…

I thought the Whatsapp desktop client was just a glorified remote control for the phone, and could not actually function as a standalone client by itself?

It is a remote control, but a case could be made that even though the prince had the phone with him, someone did it from his computer [ Of course assuming he was not looking at his phone at that time. ]

I am not on prince's side, just saying ...

Post reply on HN