Live data from Hacker News

Jeff Bezos's phone 'hacked by Saudi crown prince'

theguardian.com

211–220 of 327 posts

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#211

Earlier quoted context omitted.

This sort of thing blows my mind. Any rough theories on how this sort of thing can happen? How can an app go from parsing metadata to executing foreign code?

It's called C. It's incredibly hard to write secure code in it.

I thought whatsapp was erlang?

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#212

Earlier quoted context omitted.

This sort of thing blows my mind. Any rough theories on how this sort of thing can happen? How can an app go from parsing metadata to executing foreign code?

It's called C. It's incredibly hard to write secure code in it.

Is there any C in WhatsApp?

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#213

Explanation 1: Lauren Sanchez(bezos' new girfiend) along with her brother Michael(who is also her agent), leaked the story to force Bezos to divorce his wife and get along with her. Explanation 2: The crown prince of Saudi Arabia personally sent a trojan file, downloaded all the data, distributed it through a gossip rag he happens to be friends with, for some kind of revenge/message I get why Bezos has to go with exp…

[deleted]

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#214

Explanation 1: Lauren Sanchez(bezos' new girfiend) along with her brother Michael(who is also her agent), leaked the story to force Bezos to divorce his wife and get along with her. Explanation 2: The crown prince of Saudi Arabia personally sent a trojan file, downloaded all the data, distributed it through a gossip rag he happens to be friends with, for some kind of revenge/message I get why Bezos has to go with exp…

Is explanation 2 supposed to be outlandish?

A country like Saudia Arabia is going to use every tactic possible to combat their asymmetry with the West. It's not the crown prince personally having someone cook up a trojan for him -- it's their national apparatus deciding that free potential leverage over influential Americans is a worthwhile pursuit.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#215
post #161

Earlier quoted context omitted.

Has there been any weakness found in Telegram's encryption?

Its default settings are nothing to be desired from a messenger app. And for the paltry $200k they are offering for breaking it I'd bet you could find a magnitude more with little effort on the grey markets. But no, absolutely no proof the underlying crypto has been broken. It doesn't need to be when government requests for data stored on their servers does more than enough.

Meanwhile, whatsapp still not blocked in Russia and there is no good explanation for that besides:

So far, Roskomnadzor has "no urgent request" to include Viber and WhatsApp messengers in the register of organizers and distributors of information. According to Interfax, this was stated by the head of the Department, Alexander Zharov. He was asked when these companies will be included in the register. "We had a stormy substantive dialogue with the telegram messenger," the official recalled. "We are consulting with all other companies on this topic until there is an urgent request to include them in the register."

Maybe gn. Zharov uses whatsapp for chatting with his family and they didn’t like the appearance of mail.ru’s tamtam.chat.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#216
post #161

Earlier quoted context omitted.

Has there been any weakness found in Telegram's encryption?

Its default settings are nothing to be desired from a messenger app. And for the paltry $200k they are offering for breaking it I'd bet you could find a magnitude more with little effort on the grey markets. But no, absolutely no proof the underlying crypto has been broken. It doesn't need to be when government requests for data stored on their servers does more than enough.

Don't even need that, intercepting SMS is enough.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#217

So MBS or someone in Saudi intelligence is somehow behind the leak of the photos to the National Enquirer, and the subsequent divorce of the Bezos?

Isn’t it entirely possible that MBS simply had a phone that was easier to hack than Bezos? That was the first thing I thought of.

Also, how much of an amateur hacker would you have to be to launch an attack from your own personal device?

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#218
post #4

I'm glad it's fixed now. https://www.facebook.com/security/advisories/cve-2019-11931

Why do you think it was CVE-2019-11931? The Facebook vs. NSO lawsuit[1] mentions CVE-2019-3568[2]. CVE-2019-3568 was widely reported in May to have been exploited by NSO group[3].

[1] https://context-cdn.washingtonpost.com/notes/prod/default/do...

[2] https://www.facebook.com/security/advisories/cve-2019-3568

[3] https://arstechnica.com/information-technology/2019/05/whats...

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#219
post #12
post #4

I'm glad it's fixed now. https://www.facebook.com/security/advisories/cve-2019-11931

At the time, FB said it didn't believe the bug had been exploited: In this instance there is no reason to believe users were impacted. [0] The alleged hack of Bezos happened in May 2018, about 18 months after the Nov 2019 bug fix. I wonder if FB's statement was just boilerplate PR or if they really did substantial forensics to have "no reason to believe users were impacted". [0] https://nakedsecurity.sophos.com/2019/…

As I mentioned in my other comment, I see no reason to think that CVE-2019-11931 was exploited by NSO Group.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#220

Earlier quoted context omitted.

Can you elaborate on the google data center breach? Are you saying it was orchestrated by google?

Not orchestrated, but happily tolerated. All Google needs is to be able to plausibly deny complicity, but the other practices of Google (such as not offering warrant canaries on all Google accounts) indicate that Google is eager to cooperate and please governments, so it would have been easy to leave a few doors unlocked, hire a plant (with solid itsec skills), etc.

I was at Google at the time of the Snowden disclosures. People there were furious, and encrypting internal traffic became a top priority immediately afterwards.
Post reply on HN