Live data from Hacker News

Jeff Bezos's phone 'hacked by Saudi crown prince'

theguardian.com

141–150 of 327 posts

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#141

Let's assume this is how Bezos's phone was hacked for a second, does anyone think Trump would do anything about it? Sanction Saudia Arabia? Trump didn't lift a finger after the Jamal Khashoggi killing and his son-in-law is deep in various business dealings with MBS and his goons. Hell, Trump is probably happy the Saudis are hacking the phone of his perceived "enemy".

Because the USA is doing the same to them and their political/military/business leaders. This is par for the course. Everyone is hacking everyone. I'm surprised that they (the NSA) didn't give Bezos a hardened phone and full security audit. Maybe he didn't let them.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#142
post #8

Earlier quoted context omitted.

Wouldn't be that surprising. Zero days are available to the highest bidder and Saudi princes have deep pockets.

Honest question. Given that RCE's are extremely rare, can't FB and AAPL announce 100M USD bounty to get them first and patch them, avoiding bad PR and brand impact? Damn, make it 200M?! Or bad actors can easily pay 5x more to exploit said 0 day on a few targets, so hackers will sell to them instead?

I think the problem is that FB or Apple don't really get directly hurt from these exploits being used. Some politician gets hacked and important personal data gets leaked - oh well, there was a bug, we've patched it, one less user out of a few billion. And the vast majority of people probably don't rank this kind of thing very high on their threat model, they're either not going to know or aren't going to care.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#143

Earlier quoted context omitted.

I don't think FB or Apple can win a bidding war with state actors, and especially not a wealthy monarch. I think the problem is these 0 days are worth more to bad actors than the bad press costs companies.

>I don't think FB or Apple can win a bidding war with state actors, and especially not a wealthy monarch. Depends on your personal risk profile, I guess. If I was a highly professional security researcher (one can dream!), the one can find 0 day RCE in whatsapp, well, I would happily accept 10-20M bounty from FB and retire for life, instead of bargaining with wealthy monarch and accepting non-trivial risk of being di…

Indeed, any money after the "never work again and have a decent middle class lifestyle" point is worth significantly less to me than money before that point.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#144

Earlier quoted context omitted.

I don't agree that hacking an app and murder are the same. The state obviously has an interest in preventing murder.

But it doesn't have an interest in protecting your other rights? Interesting.

I don't have a right to be stopped from installing insecure software. Any rights in this area go in pretty much the opposite direction.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#145
post #91

Earlier quoted context omitted.

That's one hell of a tinfoil-hat theory. How would you even orchestrate that from within a public company with so many developers involved?

Boeing's 737 MAX, despite heavy regulations, designed the software to depend on just one sensor. Didn't put any limit on how far down the plane could be pushed. These are not any individual who would do deliberately. I bet these conversations go differently for ex need to certain kinds of debugging vs the improbability of actually pulling off an attack or prioritising a release dealing and making a design decision to…

That seems to support the argument that security vulnerabilities in WhatsApp are most likely unintentional errors / incompetence. Unless you're suggesting the 737 MAX was intentionally sabotaged as well?

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#146

Earlier quoted context omitted.

Boeing's 737 MAX, despite heavy regulations, designed the software to depend on just one sensor. Didn't put any limit on how far down the plane could be pushed. These are not any individual who would do deliberately. I bet these conversations go differently for ex need to certain kinds of debugging vs the improbability of actually pulling off an attack or prioritising a release dealing and making a design decision to…

That seems to support the argument that security vulnerabilities in WhatsApp are most likely unintentional errors / incompetence. Unless you're suggesting the 737 MAX was intentionally sabotaged as well?

It supports the argument that code with major flaws (intentional or not) can make it into production with nobody noticing until consequences of that flaw make its existence clear.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#147
post #37

So MBS or someone in Saudi intelligence is somehow behind the leak of the photos to the National Enquirer, and the subsequent divorce of the Bezos?

That was what Bezos's camp has been saying from almost the very beginning. The news here isn't the suspected involvement of the Saudis, the news is that MBS is directly implicated.

MBS definitely seems pretty brazen. I could totally buy him doing this - effectively social engineering Bezos - over negative stories about Saudi Arabia in the Washington Post. Who better to persuade Bezos to look at a video?

I'm a little surprised Bezos fell for it. Video-triggered vulnerabilities are pretty rare and not something you'd normally be vigilant about, as are world leaders acting as APTs, but he still should've considered the possibility that a giant, powerful nation his ultra-influential newspaper covered might want to target him and would have the capability to do so.

He could've asked an Amazon security analyst to open the video in a sandboxed system, or could've just done so himself. I guess it just never crossed his mind that the (de facto) ruler of Saudi Arabia would phish him.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#148

Earlier quoted context omitted.

It doesn't matter. The Whatsapp exploit affected both IOS and Android: https://appleinsider.com/articles/19/05/13/whatsapp-vulnerab...

That's interesting. How would that work? Under Android, all apps effectively run inside a Java sandbox, right? So how would the attackers be able to install spyware through Whatsapp?

There are more exploit chains for Android and iOS that can be used once RCE is achieved.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#149

Earlier quoted context omitted.

I don't think Google has given us any reason to believe that it was not complicit. For instance, why not include warrant canaries on gmail accounts? There is not really any fundamental difference between abetting the data center breach and opting not to offer warrant canaries. Likely tens of thousands of Google users are searched every day due to easy FISC warrants and wide investigative nets. The state sponsored att…

Warrant cannaries are of dubious legality and have yet to be seriously tested in court. It makes total sense that a large company would not adopt something potentially illegal. A person on StackExchange put it well > The distinction between revealing the existence of the subpoena by action, rather than by inaction, is a false one. It's exactly the kind of cutesy legal formality that non-lawyers love to rely on, but r…

[deleted]
Post reply on HN