Live data from Hacker News

Jeff Bezos's phone 'hacked by Saudi crown prince'

theguardian.com

291–300 of 327 posts

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#291

Earlier quoted context omitted.

I guess Khashoggi must have really annoyed MBS. This has now cost the Saudis at least ten times as much goodwill as all anti-Saudi editorials in the Post and everywhere else together. That, or it was a favour to MBS American friends. The other people involved (David Pecker et al) and MBS do share a few friends in the White House, who also seem obsessed with the Washington Post and Bezos himself.

Saudi Arabia has a lot of exiles and so far as I know, it's not murdering everyone who criticizes them. Khashoggi is was not simply a journalist but a member of an influential family with Saudi Arabia [1]. MBS has dealt quite brutally with a variety of his internal opponents without Saudi Arabia. Murdering Khashoggi was something of a statement that MBS wouldn't let his direct opponents escape to other countries to o…

“Only a little bit murdery” - op

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#292

Earlier quoted context omitted.

What encryption? Last I checked, there was no E2E group encryption (Telegram has a bizarre web page claiming that TLS to their servers addresses the privacy threat), and 1:1 E2E is disabled by default.

For a very long time there was no TLS to Telegram servers, only their own MTProto. I think they introduced TLS wrapping at some point as an anti-censorship measure, not sure if that’s even deployed in all markets. E: Well, I took a look at the desktop client with wireshark. It appears to just do MTProto on port 443, not TLS. When I use iptables to drop traffic on port 443, it falls back to MTProto over HTTP(!). They…

Common security wasn't respected at Vkontakte as well. The social network was serving plain http login form and internal communication unencrypted until 2013[0].

I reminisce that when Durov was questioned about the abscence of secure connection to the servers, he told it's a too much of overhead and may impact QoS badly.

Some time they rolled out an `always use https` option and buried it deep in the user preferences. Meaning most of non-tech savvy audience kept using the service unaware they are not secure.

The obvious pattern here is they tend to use plain http as a default transport unerminig established security practices.

[0] https://translate.google.com/translate?sl=auto&tl=en&u=https...

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#293
post #27

Earlier quoted context omitted.

Where's the Feds on this? I don't find it comforting that attacks happening on the US's free press go unanswered by law enforcement. We should be indicting MBS.

When a foreign government does something, the legal system is not the appropriate mechanism to enforce international norms. It lacks both jurisdiction as well as enforceability. There is no global legal system. We are not a united planet.

You do have a point here, but it doesn’t hold up when the DOJ has such an extensive history of going after other state sponsored hacking.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#294
post #290

Earlier quoted context omitted.

Trevor Perrin and Moxie Marlinspike won the Levchin Prize at Real World Crypto for Signal's cryptography; the Levchin Prize referees are a who's who of academic cryptography, including Dan Boneh, Kenny Paterson, and Nigel Smart; other Levchin winners have included Hugo Krawczyk, Mihir Bellare, and Joan Daemon. Any suggestion that Telegram's cryptography is somehow comparable owing to "half of them Ph.D's in math", or…

Signal protocol might be airtight but nobody knows if any part of an app that is built on top of it doesn't leak keys somewhere in the pipeline. All crypto protocols work under certain assumptions and no protocol is 100% secure from all possible misuses when Mallory owns certain portions of infrastructure.

Of course they do. Reading bytecode is not much harder than reading source. Even reading decompiled binaries isn’t so hard.

There is zero compelling reason to believe that signal is uniquely flawed.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#295
post #284

Last time I stayed at an AirBnb in Prague, the owners preferred method of communication was WhatsApp. When I went to install it I was confronted with no other choice than allowing it to import all my contacts, even though there was only one person I wanted to communicate with. I was aware of these vulnerabilities and generally am protective of handing out PII, especially information others have entrusted to me. So I…

Somewhat recent Android versions have work profile which at the very least gives you a sandbox for all apps you want to be isolated from the main profile. Unfortunately, all those work profile apps still share data between themselves. Maybe it was improved lately.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#296
post #290

Earlier quoted context omitted.

Signal protocol might be airtight but nobody knows if any part of an app that is built on top of it doesn't leak keys somewhere in the pipeline. All crypto protocols work under certain assumptions and no protocol is 100% secure from all possible misuses when Mallory owns certain portions of infrastructure.

Of course they do. Reading bytecode is not much harder than reading source. Even reading decompiled binaries isn’t so hard. There is zero compelling reason to believe that signal is uniquely flawed.

Outside Signal app, if e.g. I incorporate the protocol to my own app via the provided source code, am I prevented from leaking keys?

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#297

Earlier quoted context omitted.

When a foreign government does something, the legal system is not the appropriate mechanism to enforce international norms. It lacks both jurisdiction as well as enforceability. There is no global legal system. We are not a united planet.

You do have a point here, but it doesn’t hold up when the DOJ has such an extensive history of going after other state sponsored hacking.

The DOJ goes after operatives and individuals - not heads of state or states themselves.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#298
post #174

Earlier quoted context omitted.

I don't think Google has given us any reason to believe that it was not complicit. For instance, why not include warrant canaries on gmail accounts? There is not really any fundamental difference between abetting the data center breach and opting not to offer warrant canaries. Likely tens of thousands of Google users are searched every day due to easy FISC warrants and wide investigative nets. The state sponsored att…

There were a bunch of Google engineers who worked through Christmas that year who sure we're pretty pissed off about the unexpected work and were furious at the NSA.

Of course. Most Google engineers would not be involved in it, and would of course be doing their best to keep Google's customers' data secure.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#299

Earlier quoted context omitted.

You do have a point here, but it doesn’t hold up when the DOJ has such an extensive history of going after other state sponsored hacking.

The DOJ goes after operatives and individuals - not heads of state or states themselves.

According to this story MBS is an operative. If heads of state decide to become operatives, perhaps they should lose any protections that might normally be afforded to them.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#300

Don't deal with the Saudis. History will look back on you the same way it looks back on people shaking hands with Hitler. I'm not kidding.

The US is the world's largest weapons exporter and Saudi Arabia is the world's largest weapon importer. I'm not sure even a Hitler level calamity would make the US stop dealing with them. They're holding their hands and complementing their "leadership skills" ffs...
Post reply on HN