Live data from Hacker News

Jeff Bezos's phone 'hacked by Saudi crown prince'

theguardian.com

271–280 of 327 posts

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#271

Pavel Durov argued that WhatsApp's vulnerabilities are intentionally created as part of surveillance programs with government agencies. [1] If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation. [1] https://t.me/s/durov/109

>Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation.

Not a big problem if you're the top dog and most foreign countries can't do much in practice even if they have the intelligence...

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#272
post #161

Earlier quoted context omitted.

Has there been any weakness found in Telegram's encryption?

What encryption? Last I checked, there was no E2E group encryption (Telegram has a bizarre web page claiming that TLS to their servers addresses the privacy threat), and 1:1 E2E is disabled by default.

> What encryption? Last I checked, there was no E2E group encryption

You of all should know better than to conflate the general concept of encryption with the very nice special case that is end-to-end encryption!

> and 1:1 E2E is disabled by default.

It is not disabled in any way. It just isn't default.

There are really enough real reasons to criticize Telegram, absolutely no reason to 1. redefine words to have narrower definitions 2. Write outright misinformation.

I respect you a whole lot but your somewhat sloppy handling of facts detract a whole lot from the overall image.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#273
post #13

So MBS or someone in Saudi intelligence is somehow behind the leak of the photos to the National Enquirer, and the subsequent divorce of the Bezos?

The Bezos's are responsible for their actions, and their decision to divorce, but yes, the leak could have been via saudis...

I'm surprised this take is so controversial. Bezos didn't deserve to get hacked and exposed like this, but the hack exposed infidelity. The hack didn't plant fully fabricated evidence of infidelity.

I don't think "I would have gotten away with it!" is a compelling argument, but I'm not a Scooby Doo villain.

The comments about timing, malice, financial consequences, etc., are all fair for making a case that the hacks and leaks are scummy, but the Bezos's are in charge of their own relationship, or lack thereof.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#274
post #244

I pointed this out 11 months ago: https://news.ycombinator.com/item?id=19122206

Some informative links to make you scared about democracy, or just your safety:

https://en.wikipedia.org/wiki/Pegasus_(spyware)

https://citizenlab.ca/2019/10/nso-q-cyber-technologies-100-n...

https://citizenlab.ca/2018/06/government-spyware-surveillanc...

https://citizenlab.ca/2017/02/bittersweet-nso-mexico-spyware...

https://citizenlab.ca/

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#276
The wider question here is how to handle Saudi Arabian trades in Western markets. Every and any deal undertaken by a state actor (MBS, any of the 1000s of princes the place is littered with, the sovereign wealth fund or the state or semi state companies) could well be the result of insider trading...

And thats just the public markets. Imagine the advantage you would have in startup investing if you could covertly read all the internal discussions, the founders texts and emails, remotely access their meetings with lawyers, accountants and other VCs.

No wonder SA is suddenly interested in Silicon Valley

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#277
post #107
post #101

Earlier quoted context omitted.

My first pass at a way would have some point in the code where various hooks can be triggered for a feature like downloading a file under the guise of creating previews of various types of files and simply have the production build sent to the Google Play store include an additional small plugin that looks for a specific header and then hands over the keys to the kingdom to whatever payload it finds. It's simple and…

Its probably easier to just bribe/compromise the on-site DBA who has access to the physical hardware. Dump the raw data and decrypt/analyze it offsite.

It's a little unclear what was actually compromised in this if it was just what was available WhatsApp on their end that's definitely an easy way. If it's more that WhatsApp was being used to read more data from the phone than what had already been sent via WhatsApp (or if WhatsApp doesn't have access to things sent because it's E2E encrypted) it'd require something more complex than that.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#278

Earlier quoted context omitted.

Pavel Durov also said > The encryption of Signal (=WhatsApp, FB) was funded by the US Government. I predict a backdoor will be found there within 5 years from now. He seems to enjoy throwing out loosly supported accusations. He might be right in some of them, but stopped clocks and so forth. He's also been accused himself of deliberately sabotaging the security of his own encrypted messenger app (Telegram). There's n…

It is spelled "Tor". https://support.torproject.org/about/why-is-it-called-tor/ Note: even though it originally came from an acronym, Tor is not spelled "TOR". Only the first letter is capitalized. In fact, we can usually spot people who haven't read any of our website (and have instead learned everything they know about Tor from news articles) by the fact that they spell it wrong.

Thank you. I didn't know.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#279

Earlier quoted context omitted.

What encryption? Last I checked, there was no E2E group encryption (Telegram has a bizarre web page claiming that TLS to their servers addresses the privacy threat), and 1:1 E2E is disabled by default.

> What encryption? Last I checked, there was no E2E group encryption You of all should know better than to conflate the general concept of encryption with the very nice special case that is end-to-end encryption! > and 1:1 E2E is disabled by default. It is not disabled in any way. It just isn't default. There are really enough real reasons to criticize Telegram, absolutely no reason to 1. redefine words to have narro…

I rest my case.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#280

Earlier quoted context omitted.

The texts were leaked by the brother of the mistress. https://www.thedailybeast.com/mistress-lauren-sanchezs-broth...

No, that's what The Inquirer and others said as cover. There was no proof of that, and this article from the Guardian goes into those details as well.

No proof to the contrary either, other than a privately contracted forensics firm's assessment. WSJ reported both angles. Both theories are plausible.
Post reply on HN