Live data from Hacker News

Jeff Bezos's phone 'hacked by Saudi crown prince'

theguardian.com

261–270 of 327 posts

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#261

Earlier quoted context omitted.

I thought the Whatsapp desktop client was just a glorified remote control for the phone, and could not actually function as a standalone client by itself?

It is a remote control, but a case could be made that even though the prince had the phone with him, someone did it from his computer [ Of course assuming he was not looking at his phone at that time. ] I am not on prince's side, just saying ...

If you're thinking of a private actor, I think that once you have access to MBS phone, you run to Doha before attacking Bezos. Qatar would pay a ton of money for that access.

If you're thinking of a state actor except Saudi Arabia, I think there would be much easier and more discreet vectors to Jeff Bezos Whatsapp than MBS phone (literally almost any of Bezos other contacts would be less risky).

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#262

This gives me tremendous respect for Jeff. Most likely his marriage fell apart because of this costing him personally ~25B. But that means that he didn't give in to whatever Mr Prince wanted.

Yes, it seems he was pretty hardcore about it. "Go ahead, publish it."

Since J. Edgar Hoover, it is has been an open secret that blackmail drives the upper echelon of politics and media. The Bill Clinton thing is another example, pretty sure he put his foot down and said fuck it, hence Lewinsky turning up with a tainted dress from 8 months ago, and down goes the U.S. president. How many just acquiesce and play along quietly?

More people should have guts like Bezos (probably did). Though at some point, I'm sure the shadow people will just fall back on good old violence, like the Epstein case.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#264

Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109

Pavel Durov also said > The encryption of Signal (=WhatsApp, FB) was funded by the US Government. I predict a backdoor will be found there within 5 years from now. He seems to enjoy throwing out loosly supported accusations. He might be right in some of them, but stopped clocks and so forth. He's also been accused himself of deliberately sabotaging the security of his own encrypted messenger app (Telegram). There's n…

It is spelled "Tor".

https://support.torproject.org/about/why-is-it-called-tor/

    Note: even though it originally came from an acronym,
    Tor is not spelled "TOR". Only the first letter is
    capitalized. In fact, we can usually spot people 
    who haven't read any of our website (and have 
    instead learned everything they know about Tor from 
    news articles) by the fact that they spell it wrong.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#265
post #161

Earlier quoted context omitted.

Has there been any weakness found in Telegram's encryption?

What encryption? Last I checked, there was no E2E group encryption (Telegram has a bizarre web page claiming that TLS to their servers addresses the privacy threat), and 1:1 E2E is disabled by default.

For a very long time there was no TLS to Telegram servers, only their own MTProto. I think they introduced TLS wrapping at some point as an anti-censorship measure, not sure if that’s even deployed in all markets.

E: Well, I took a look at the desktop client with wireshark. It appears to just do MTProto on port 443, not TLS. When I use iptables to drop traffic on port 443, it falls back to MTProto over HTTP(!).

They list some alternate transports on their website, but it looks like you need to host them yourself. https://core.telegram.org/mtproto/transports

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#266
post #215

Earlier quoted context omitted.

Its default settings are nothing to be desired from a messenger app. And for the paltry $200k they are offering for breaking it I'd bet you could find a magnitude more with little effort on the grey markets. But no, absolutely no proof the underlying crypto has been broken. It doesn't need to be when government requests for data stored on their servers does more than enough.

Meanwhile, whatsapp still not blocked in Russia and there is no good explanation for that besides: So far, Roskomnadzor has "no urgent request" to include Viber and WhatsApp messengers in the register of organizers and distributors of information. According to Interfax, this was stated by the head of the Department, Alexander Zharov. He was asked when these companies will be included in the register. "We had a stormy…

If you know some basic things about Russian government, this can easily be explained by the fact that policy makers are very inefficient, incompetent in technical matters and more often than not decisions are very poorly researched. Just look at the fact that Telegram still works everywhere or the way that even the supposedly most secret russian organization (the secret military police GRU) have handled the poisoning of Sergei and Yulia Skripal, and subsequent outage of the agent that did it... It seems that russian governemnt or police still have a hard time understanding even the basics of what the internet is and how the information can be shared or found or leaked in our age. So banning of Telegram vs not banning of Whatsapp really does not say a lot.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#268

Earlier quoted context omitted.

I don't even have to open the link to know those are still theoretical vulns at best...because as far as I know, there has been no successful implementation of them.

You’re full of shit. There’s nothing theoretical about that vulnerability (almost certainly a deliberately planted backdoor), it allows the Telegram servers to selectively MITM private chats. > there has been no successful implementation of them. What does this even mean? Only Telegram can perform this active attack, obviously you haven’t seen it implemented.

+1, it was not the bugs I thought it was, extracting foot from mouth - sorry.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#269

Earlier quoted context omitted.

The Clinton server wasn't really interesting because she broke the rules...it was because the Chinese/whomever could grab stuff and the owners had plausible deniability.

I'm pretty sure GP was actually referring to President Trump's refusal to give up his personal tweet gun^W^Wsmartphone.

I'm just talking tech, not partisan politics.
Post reply on HN