Live data from Hacker News

Jeff Bezos's phone 'hacked by Saudi crown prince'

theguardian.com

161–170 of 327 posts

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#161

Earlier quoted context omitted.

Pavel Durov also said > The encryption of Signal (=WhatsApp, FB) was funded by the US Government. I predict a backdoor will be found there within 5 years from now. He seems to enjoy throwing out loosly supported accusations. He might be right in some of them, but stopped clocks and so forth. He's also been accused himself of deliberately sabotaging the security of his own encrypted messenger app (Telegram). There's n…

Trevor Perrin and Moxie Marlinspike won the Levchin Prize at Real World Crypto for Signal's cryptography; the Levchin Prize referees are a who's who of academic cryptography, including Dan Boneh, Kenny Paterson, and Nigel Smart; other Levchin winners have included Hugo Krawczyk, Mihir Bellare, and Joan Daemon. Any suggestion that Telegram's cryptography is somehow comparable owing to "half of them Ph.D's in math", or…

Has there been any weakness found in Telegram's encryption?

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#162

Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109

Pavel Durov also said > The encryption of Signal (=WhatsApp, FB) was funded by the US Government. I predict a backdoor will be found there within 5 years from now. He seems to enjoy throwing out loosly supported accusations. He might be right in some of them, but stopped clocks and so forth. He's also been accused himself of deliberately sabotaging the security of his own encrypted messenger app (Telegram). There's n…

> like TOR

From my understanding, TOR was created with the intent of hiding US intelligence communications[0]. From my naive understanding, this only works if 1) no one else can back door it (which is critical since it is presumed you're using it to hide from highly technical state actors) 2) there are a sufficient number of users that are not intelligence actors (so you can hide among them. Otherwise you get "Oh, that person connected to a TOR node, let's go pick them up and grab their computer").

Maybe I'm naive, but it seems like the crypto people and the US government have aligned interests here.

> The stated goal of the fund is to promote democracy in developing countries

With an additional alignment of interests, I think many believe that being able to "talk shit" on your leaders is a key part to democracy. And if you're able to do this without fear of your government coming after you (aka: backdoors), then you will freely acknowledge your dissent, find support, and democracy is the likely outcome. I'm not sure if that's true, but I've definitely heard intelligence people suggest that.

So even if it was controlled by the CIA, would this be an issue? It seems like it is actively in their best interest to use real encryption and no backdoors. You don't want all your potential rebels to get caught. You want them to be able to organize out of the eyes of the government that the CIA is trying to overthrow. Having a backdoor just puts a timebomb on it, and one that isn't going to last very long.

Or I guess there's another answer to this. The CIA is pretty fucking dumb. Which is a reasonable answer that I'll accept too, but I think the people working on this stuff would be well aware (since they're probably experts in hacking similarly encrypted systems)

[0] https://en.wikipedia.org/wiki/Onion_routing

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#163
post #96
post #15

I wonder how often less high profile folks get hit with stuff like this? On one hand, zero days are rare and expensive. OTOH someone who isn't the CEO of a major company might not notice the malware, or if they do, not know they should forward it to an organization like Citizen Lab.

> zero days are rare really?

Zero days are plentiful. But there are only a handful that you could buy today which could potentially give you access to a CEO's phone. The only other option is to build your own team to find a zero day for you, which is not cheap or quick.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#164

Earlier quoted context omitted.

Honest question. Given that RCE's are extremely rare, can't FB and AAPL announce 100M USD bounty to get them first and patch them, avoiding bad PR and brand impact? Damn, make it 200M?! Or bad actors can easily pay 5x more to exploit said 0 day on a few targets, so hackers will sell to them instead?

The actual prices are in the $100k-$200k range. $1m if you are extremely generous.

I wonder what size the supply is. How many could you buy immediately or over time?

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#165

Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109

Well,

> To protect the data that is not covered by end-to-end encryption, Telegram uses a distributed infrastructure. Cloud chat data is stored in multiple data centers around the globe that are controlled by different legal entities spread across different jurisdictions. The relevant decryption keys are split into parts and are never kept in the same place as the data they protect. As a result, several court orders from different jurisdictions are required to force us to give up any data.

https://telegram.org/faq#q-do-you-process-data-requests

If we register Telegram, Telegram has our master key. I am not sure they are really that secure. Yes, it makes politically hard to disclose any data, but it does not mean impossible.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#166
post #37

Earlier quoted context omitted.

That was what Bezos's camp has been saying from almost the very beginning. The news here isn't the suspected involvement of the Saudis, the news is that MBS is directly implicated.

MBS definitely seems pretty brazen. I could totally buy him doing this - effectively social engineering Bezos - over negative stories about Saudi Arabia in the Washington Post. Who better to persuade Bezos to look at a video? I'm a little surprised Bezos fell for it. Video-triggered vulnerabilities are pretty rare and not something you'd normally be vigilant about, as are world leaders acting as APTs, but he still sh…

Pretty brazen? Don't forget that the WP reported that US intelligence intercepted comms from Saudi officials discussing a plan ordered by MBS to lure Jamal Khashoggi from his home in Virginia and then subsequently had him cut into pieces in an embassy.

Hacking a phone is small potatoes.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#167

Earlier quoted context omitted.

MBS definitely seems pretty brazen. I could totally buy him doing this - effectively social engineering Bezos - over negative stories about Saudi Arabia in the Washington Post. Who better to persuade Bezos to look at a video? I'm a little surprised Bezos fell for it. Video-triggered vulnerabilities are pretty rare and not something you'd normally be vigilant about, as are world leaders acting as APTs, but he still sh…

Pretty brazen? Don't forget that the WP reported that US intelligence intercepted comms from Saudi officials discussing a plan ordered by MBS to lure Jamal Khashoggi from his home in Virginia and then subsequently had him cut into pieces in an embassy. Hacking a phone is small potatoes.

Yeah, I was using semi-facetious understatement. He's very brazen for someone in his position.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#168
post #165

Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109

Well, > To protect the data that is not covered by end-to-end encryption, Telegram uses a distributed infrastructure. Cloud chat data is stored in multiple data centers around the globe that are controlled by different legal entities spread across different jurisdictions. The relevant decryption keys are split into parts and are never kept in the same place as the data they protect. As a result, several court orders…

Telegram also supports proper E2E in the form of secret chats, though the UX is definitely not as good (for example, last I checked it did not support group chat or multi device.)

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#169

Earlier quoted context omitted.

Pavel Durov also said > The encryption of Signal (=WhatsApp, FB) was funded by the US Government. I predict a backdoor will be found there within 5 years from now. He seems to enjoy throwing out loosly supported accusations. He might be right in some of them, but stopped clocks and so forth. He's also been accused himself of deliberately sabotaging the security of his own encrypted messenger app (Telegram). There's n…

> like TOR From my understanding, TOR was created with the intent of hiding US intelligence communications[0]. From my naive understanding, this only works if 1) no one else can back door it (which is critical since it is presumed you're using it to hide from highly technical state actors) 2) there are a sufficient number of users that are not intelligence actors (so you can hide among them. Otherwise you get "Oh, th…

From what I recall, talking to one of the Tor founders about this, Tor was created with overseas US military personnel in mind. E.g. A soldier’s location could be compromised through foreign ISPs if they accessed sites like .mil domains directly. Tor was a way of preventing this problem. There were other use cases but this one stood out for me and it was one of the initial ones considered.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#170
post #161

Earlier quoted context omitted.

Trevor Perrin and Moxie Marlinspike won the Levchin Prize at Real World Crypto for Signal's cryptography; the Levchin Prize referees are a who's who of academic cryptography, including Dan Boneh, Kenny Paterson, and Nigel Smart; other Levchin winners have included Hugo Krawczyk, Mihir Bellare, and Joan Daemon. Any suggestion that Telegram's cryptography is somehow comparable owing to "half of them Ph.D's in math", or…

Has there been any weakness found in Telegram's encryption?

Its default settings are nothing to be desired from a messenger app.

And for the paltry $200k they are offering for breaking it I'd bet you could find a magnitude more with little effort on the grey markets.

But no, absolutely no proof the underlying crypto has been broken. It doesn't need to be when government requests for data stored on their servers does more than enough.

Post reply on HN