Is it that easy to be hacked with WhatsApp?
Well, here's a list of known WhatsApp hacks that were revealed in 2019: Call hack [0]: https://www.wired.com/story/whatsapp-hack-phone-call-voip-bu... Video hack [1]: https://thehackernews.com/2019/11/whatsapp-hacking-vulnerabi... GIF hack [2]: https://thehackernews.com/2019/10/whatsapp-rce-vulnerability... That call hack was famously used by NSO, hitting thousands of people [3]: https://thehackernews.com/2019/10/wha…
Jeff Bezos's phone 'hacked by Saudi crown prince'
251–260 of 327 posts
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#252Earlier quoted context omitted.
Its default settings are nothing to be desired from a messenger app. And for the paltry $200k they are offering for breaking it I'd bet you could find a magnitude more with little effort on the grey markets. But no, absolutely no proof the underlying crypto has been broken. It doesn't need to be when government requests for data stored on their servers does more than enough.
AFAIK, Telegram's private conversations are encrypted with private keys stored on device _only_ (not on the server). At least it's what they claim. If true, government requests for data stored on servers are probably not enough.
* Group chats can only use the default encryption, not end to end encryption.
* The end to end encrypted chats are tied to a single device, and there's no sync across devices (in contrast, all chats on Wire are end to end encrypted and sync across devices within a limited time period).
The default use cases of almost all users has the chat messages stored in plain text on the Telegram servers. This is one of the reasons search (done on the server side) is quite fast on Telegram.
P.S.: Despite these limitations, I prefer Telegram for its superior UX and for not having metadata shared with Facebook. My wish is that someday Telegram makes E2E the default everywhere.
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#253Earlier quoted context omitted.
Has there been any weakness found in Telegram's encryption?
I don't know of any directly related to it's encryption but multiple protest organizers were identified and arrested by the Hong Kong Police Force through Telegram, I'm not 100% sure but I believe they just added lists of suspected phone numbers onto their phones and looked in Telegram see which one's matched to Group admins.
When this design flaw came to be known, Telegram released a newer version where the user has more control on who can know that they're on Telegram. With that change, even if you had someone's number in your contacts list, you wouldn't know if/when they join/are available on Telegram unless they choose to make themselves visible.
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#254Earlier quoted context omitted.
That theory is quite possible. If the police join the group, they know the usernames of all of the people in the group, they can then start adding numbers to their contacts and if any of the usernames from the group show up they can then look up who owns the phone number in the government database.
It surprises me that they don't require both of you to have each others phone numbers in your contacts lists before giving away identifiable information.
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#255Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109
This has been obvious in places like the United Arab Emirates (aka Dubai) where services like FaceTime etc. (sometimes even voice chat in games) are blocked by the government but they allow WhatsApp (but not WhatsApp voice calls).
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#256Earlier quoted context omitted.
EDIT: Was under the impression Telegram served closed source clients. Turns out it does not. I stand corrected. OLD COMMENT: E2e using a client that is not opensource (on a system that is not trusted) is not helping much. E2e where the server is not open source should be okay, because the server-end can only snoop on some meta data (how much, when, what IP, chunk sizes, etc.) but not the content.
The Telegram clients are open source.
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#257Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#258Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#259Earlier quoted context omitted.
Within days of their launch, Telegram was discovered to have huge vulnerabilities that resulted from them rolling their own crypto: https://news.ycombinator.com/item?id=6948742 , so I'm not sure they should be throwing stones about other people's bugs.
I don't even have to open the link to know those are still theoretical vulns at best...because as far as I know, there has been no successful implementation of them.
> there has been no successful implementation of them.
What does this even mean? Only Telegram can perform this active attack, obviously you haven’t seen it implemented.
Re: Jeff Bezos's phone 'hacked by Saudi crown prince'
#260Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109
> WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. This has been obvious in places like the United Arab Emirates (aka Dubai) where services like FaceTime etc. (sometimes even voice chat in games) are blocked by the government but they allow WhatsApp (but not WhatsApp voice calls).