Live data from Hacker News

US judge finds NSO Group liable for hacking journalists via WhatsApp

reuters.com

141–150 of 306 posts

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#141
post #136

Earlier quoted context omitted.

Usually zero days being used in the wild get found and analyzed. Who else is making exploit packages like this other than state actors?

[flagged]

What exploit packages in recent years that aren’t NSO haven’t been attributed to an APT?

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#142

I thought Whatsapp and signal share the same encryption

It was a buffer overflow in a VOIP stack:

* https://www.theverge.com/2019/5/14/18622744/whatsapp-spyware...

Interestingly enough, Signal (and others) had the same sort of vulnerability on Android from a WebRTC stack:

* https://googleprojectzero.blogspot.com/2020/08/exploiting-an...

The big issue in both cases is that the exploit was triggered before the user answered the call.

I think the moral here is that a secure messenger should not execute inherently insecure code (i.e.complex code) on behalf of entities that are not really well trusted by the user. The default should be always plain text.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#143
post #135

It is hard to believe that NSO group is allowed to operate. They sell technology to horrible places, they cause death torture, and a host of less horrible things. Yet they are protected by the US and Israel, which I believe is the case that they have backdoors into all of it, and getting the targets to actually install this malware on their own saves a lot time. All good, except for the actual real world victims.

[flagged]

[flagged]

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#146

Earlier quoted context omitted.

Valuations don’t really matter in their playing field. It’s more about power and politics, rather than raw numbers.

[flagged]

I'd imagine they have a very limited market as in who they can sell their products and services to, for reasons that might make political power more interesting than valuation.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#148
post #146

Earlier quoted context omitted.

[flagged]

I'd imagine they have a very limited market as in who they can sell their products and services to, for reasons that might make political power more interesting than valuation.

I don't know about that. Something I think a lot of people sleep on with this stuff is that most countries have multiple security agencies, and you generally cut deals with them individually. The market for this stuff is bigger than it looks.

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#149

It is hard to believe that NSO group is allowed to operate. They sell technology to horrible places, they cause death torture, and a host of less horrible things. Yet they are protected by the US and Israel, which I believe is the case that they have backdoors into all of it, and getting the targets to actually install this malware on their own saves a lot time. All good, except for the actual real world victims.

> It is hard to believe that NSO group is allowed to operate. They sell technology to horrible places, they cause death torture, and a host of less horrible things. That describes the entire Israeli defence industry, and a fair sized portion of Israel's cybersecurity industry, based on the stomach-churning sales pitches I've received. NSO are not unique, they just got unlucky.

> based on the stomach-churning sales pitches I've received.

Care to elaborate? This could be news story-worthy

Re: US judge finds NSO Group liable for hacking journalists via WhatsApp

#150

It is hard to believe that NSO group is allowed to operate. They sell technology to horrible places, they cause death torture, and a host of less horrible things. Yet they are protected by the US and Israel, which I believe is the case that they have backdoors into all of it, and getting the targets to actually install this malware on their own saves a lot time. All good, except for the actual real world victims.

[flagged]
Post reply on HN