Live data from Hacker News

Jeff Bezos's phone 'hacked by Saudi crown prince'

theguardian.com

151–160 of 327 posts

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#151
post #150

So, anyone want to hazard a guess on why the prince would want the optics of being seen to have been responsible for the hack (as opposed to trying to cover that up by, say, not using his very own account)?

Simple. To flex and show that he is untouchable and that nobody ever holds him accountable.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#152

Earlier quoted context omitted.

The Saudi Royal Family simply do not care and walk around with impunity. They thumb their nose at the law and the world order and think they deserve to do whatever they want. This is exactly the same as the Khagoshi execution where overwhelming evidence and implication, but, play naive and put on a big sham investigation. Just how when Russian agents poisoned the Skripals and said they were their to view a church ste…

This does seem the most likely, as hard as it is to believe. I guess when you have hierarchies based on blood rather than competency, this is what you end up with.

That and no outside government has every held them accountable for anything. Or him accountable for anything.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#153

This sounded plausible until I read the first sentence. Why would MBS be the one executing the attack, and using his personal account to do it?

The Saudi Royal Family simply do not care and walk around with impunity. They thumb their nose at the law and the world order and think they deserve to do whatever they want. This is exactly the same as the Khagoshi execution where overwhelming evidence and implication, but, play naive and put on a big sham investigation. Just how when Russian agents poisoned the Skripals and said they were their to view a church ste…

Of course, the nation that the Saudi's rely on for aid and military hardware could pressure them. But that would require some minimal commitment to human rights and a free press. And no personal desire to silence criticism from the WaPo by it's president.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#155

Earlier quoted context omitted.

Can you elaborate on the google data center breach? Are you saying it was orchestrated by google?

Not orchestrated, but happily tolerated. All Google needs is to be able to plausibly deny complicity, but the other practices of Google (such as not offering warrant canaries on all Google accounts) indicate that Google is eager to cooperate and please governments, so it would have been easy to leave a few doors unlocked, hire a plant (with solid itsec skills), etc.

Was this reported in the news? Why did I not hear about it?

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#156
post #91

Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109

That's one hell of a tinfoil-hat theory. How would you even orchestrate that from within a public company with so many developers involved?

You just need to control the upstream libraries and have some subtle memory overflow. No dodgy commits other than a "update libXYZ to latest patch".

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#157

Earlier quoted context omitted.

I don't think Google has given us any reason to believe that it was not complicit. For instance, why not include warrant canaries on gmail accounts? There is not really any fundamental difference between abetting the data center breach and opting not to offer warrant canaries. Likely tens of thousands of Google users are searched every day due to easy FISC warrants and wide investigative nets. The state sponsored att…

Warrant cannaries are of dubious legality and have yet to be seriously tested in court. It makes total sense that a large company would not adopt something potentially illegal. A person on StackExchange put it well > The distinction between revealing the existence of the subpoena by action, rather than by inaction, is a false one. It's exactly the kind of cutesy legal formality that non-lawyers love to rely on, but r…

I would just point out there is a very clear legal distinction between action and inaction. Further, all of this only applies to the issuance and proper service of an order compelling silence. I think the EFF’s common statement that if the canary requires affirmative action to not deploy the court is in a tough spot to compel that action. Also, I can say with a large amount of certainty, that no judge blatantly ignores procedural or semantic formalities out of hand. The judge in question may way the relevant factors and disagree with an argument, although some judges built caseloads of precedent on just such minor quibbles, but it is literally the judges job to at least consider a technical argument on its merits.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#158
post #91

Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109

That's one hell of a tinfoil-hat theory. How would you even orchestrate that from within a public company with so many developers involved?

It's very easy: hire more developers than security engineers.

Vulnerabilities will appear and be discovered by the security analysts in your government.

Whey they suspect other countries have the same 0days they'll notify you of it and you fix it.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#159

Earlier quoted context omitted.

It doesn't matter. The Whatsapp exploit affected both IOS and Android: https://appleinsider.com/articles/19/05/13/whatsapp-vulnerab...

That's interesting. How would that work? Under Android, all apps effectively run inside a Java sandbox, right? So how would the attackers be able to install spyware through Whatsapp?

They only had to spy on whatsapp, so they could do it all in the same sandbox.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#160
post #68

One thing which this article doesn't address at all, is what is the beef between MBS and Bezos? Why would the Saudi prince leak this data? How did Amazon upset him?

Join the dots... Who had a beef with Bezos and was friendly with MBS?

Tim Cook, for one.
Post reply on HN