Live data from Hacker News

Jeff Bezos's phone 'hacked by Saudi crown prince'

theguardian.com

241–250 of 327 posts

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#241
post #161

Earlier quoted context omitted.

Has there been any weakness found in Telegram's encryption?

Its default settings are nothing to be desired from a messenger app. And for the paltry $200k they are offering for breaking it I'd bet you could find a magnitude more with little effort on the grey markets. But no, absolutely no proof the underlying crypto has been broken. It doesn't need to be when government requests for data stored on their servers does more than enough.

AFAIK, Telegram's private conversations are encrypted with private keys stored on device _only_ (not on the server). At least it's what they claim. If true, government requests for data stored on servers are probably not enough.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#242

Earlier quoted context omitted.

I shudder to think what would have happened if Obama had ultimately refused to give up his personal phone, and every half-talented hacking group on the planet had pwned it six ways from Sunday—what a national security disaster that would have been! Oh wait

The Clinton server wasn't really interesting because she broke the rules...it was because the Chinese/whomever could grab stuff and the owners had plausible deniability.

I'm pretty sure GP was actually referring to President Trump's refusal to give up his personal tweet gun^W^Wsmartphone.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#245

Earlier quoted context omitted.

Its default settings are nothing to be desired from a messenger app. And for the paltry $200k they are offering for breaking it I'd bet you could find a magnitude more with little effort on the grey markets. But no, absolutely no proof the underlying crypto has been broken. It doesn't need to be when government requests for data stored on their servers does more than enough.

Don't even need that, intercepting SMS is enough.

True SMS is not a protection against government but telegram supports the second factor which is password in their case.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#246
post #236

Earlier quoted context omitted.

While David Pecker was involved in the brokering of the hush money deal with Stormy Daniels, which Michael Cohen eventually made (and prosecuted for), the "catch and kill" payment was made to Karen McDougal, which was another Trump affair.

It is insane to me that Trump is a pariah for the religion crowd

> Definition of pariah. 1 : a member of a low caste of southern India. 2 : one that is despised or rejected : outcast.

I'm not sure I understand your comment

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#247

Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109

There are no whatsapp vulnerabilities in this case, or encryption breakdown. To exfiltrate a lot of data as the article says to need sandbox escape and privilege escalation.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#249
post #168
post #165

Earlier quoted context omitted.

Well, > To protect the data that is not covered by end-to-end encryption, Telegram uses a distributed infrastructure. Cloud chat data is stored in multiple data centers around the globe that are controlled by different legal entities spread across different jurisdictions. The relevant decryption keys are split into parts and are never kept in the same place as the data they protect. As a result, several court orders…

Telegram also supports proper E2E in the form of secret chats, though the UX is definitely not as good (for example, last I checked it did not support group chat or multi device.)

EDIT: Was under the impression Telegram served closed source clients. Turns out it does not. I stand corrected.

OLD COMMENT:

E2e using a client that is not opensource (on a system that is not trusted) is not helping much.

E2e where the server is not open source should be okay, because the server-end can only snoop on some meta data (how much, when, what IP, chunk sizes, etc.) but not the content.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#250
post #249
post #168

Earlier quoted context omitted.

Telegram also supports proper E2E in the form of secret chats, though the UX is definitely not as good (for example, last I checked it did not support group chat or multi device.)

EDIT: Was under the impression Telegram served closed source clients. Turns out it does not. I stand corrected. OLD COMMENT: E2e using a client that is not opensource (on a system that is not trusted) is not helping much. E2e where the server is not open source should be okay, because the server-end can only snoop on some meta data (how much, when, what IP, chunk sizes, etc.) but not the content.

The Telegram clients are open source.
Post reply on HN