Live data from Hacker News

WhatsApp voice calls were used to inject spyware on phones

ft.com

101–110 of 313 posts

Re: WhatsApp voice calls were used to inject spyware on phones

#101
post #97

Earlier quoted context omitted.

It's not that much different from mercenary outfits like The Company Formerly Known As Blackwater. They offer services to all sorts of unsavory regimes. Hackers for hire are just another iteration on the idea.

No, it is very much dissimilar. Security personnel who work for Blackwater make a conscious decision to do so and are flown overseas to physically enact Blackwater's business decisions. Many (maybe most?) of the people who sell vulnerabilities and (to a lesser extent) exploitation tools to spyware firms are selling through brokers, and aren't directly connected to the ultimate end purpose of their work. You can say t…

Normally I agree with you on almost everything in this realm, since, well, it's your field of expertise.

But XE/Blackwater/whatever has plenty of support staff enabling operators overseas. Just because you don't carry an M4 while you cash your check from the organization doesn't mean you aren't helping them in their missions.

If you sell vulns and tools to spyware firms, you know exactly who the most likely high bidders are. It ain't the Bill and Melinda Gates Foundation.

Re: WhatsApp voice calls were used to inject spyware on phones

#102
post #97

Earlier quoted context omitted.

No, it is very much dissimilar. Security personnel who work for Blackwater make a conscious decision to do so and are flown overseas to physically enact Blackwater's business decisions. Many (maybe most?) of the people who sell vulnerabilities and (to a lesser extent) exploitation tools to spyware firms are selling through brokers, and aren't directly connected to the ultimate end purpose of their work. You can say t…

Normally I agree with you on almost everything in this realm, since, well, it's your field of expertise. But XE/Blackwater/whatever has plenty of support staff enabling operators overseas. Just because you don't carry an M4 while you cash your check from the organization doesn't mean you aren't helping them in their missions. If you sell vulns and tools to spyware firms, you know exactly who the most likely high bidd…

Those people actually work for Blackwater. People who sell vulnerabilities by and large have only a vague idea of their customers. Many exploit developers would, for instance, draw a line between enablement of FVEY national SIGINT and shady spyware shops like NSO, and can rationalize that it's the good guys who are getting their bugs.

I'm not saying that makes it OK (I think the opposite thing, in fact, though I feel like I always need to add the disclaimer that the kinds of bugs that have commercial/operational relevance aren't the kind I develop). I'm saying that the dynamics are different than they are with Blackwater.

Re: WhatsApp voice calls were used to inject spyware on phones

#104
post #97

Earlier quoted context omitted.

It's not that much different from mercenary outfits like The Company Formerly Known As Blackwater. They offer services to all sorts of unsavory regimes. Hackers for hire are just another iteration on the idea.

No, it is very much dissimilar. Security personnel who work for Blackwater make a conscious decision to do so and are flown overseas to physically enact Blackwater's business decisions. Many (maybe most?) of the people who sell vulnerabilities and (to a lesser extent) exploitation tools to spyware firms are selling through brokers, and aren't directly connected to the ultimate end purpose of their work. You can say t…

This kind of story in particular sure reads like digital mercenaries to me. It's not quite the same as what Hacking Group does! But a shady corporation hired former NSA hackers and partnered closely with the UAE to the point that the hackers themselves get cold feet because they learn exactly what their consulting was being used for.

I don't know enough about Hacking Group to know how closely they work with the people they sell to.

https://www.reuters.com/investigates/special-report/usa-spyi...

Re: WhatsApp voice calls were used to inject spyware on phones

#105
post #12

Earlier quoted context omitted.

They managed to destroy Iranian nuclear centrifuges using a very sophisticated attack. Read up on Stuxnet. Also, as an Israeli, I can 100% confirm that Israelis have absolutely no issues with crossing any kind of boundary. The fact that others think that such a thing as "boundaries" exist only serves as an advantage.

Interesting to hear about this lack of boundaries among Israelis, is this only for non-Israelis or do you/they cross each others boundaries? Is this a cultural thing, why do you think this the case?

> Is this a cultural thing

Israelis in general are very blunt and perfectly willing to question superiors and voice opinions and questions in situations where Americans never would. This includes the military where subordinates would question a superior in a way that would never fly in an American military (and probably others).

Israelis on the street will voice opinions to strangers in a way that would be perceived as incredibly rude elsewhere, but is normal in Israel.

Re: WhatsApp voice calls were used to inject spyware on phones

#106
post #22
post #12

Earlier quoted context omitted.

They managed to destroy Iranian nuclear centrifuges using a very sophisticated attack. Read up on Stuxnet. Also, as an Israeli, I can 100% confirm that Israelis have absolutely no issues with crossing any kind of boundary. The fact that others think that such a thing as "boundaries" exist only serves as an advantage.

> The fact that others think that such a thing as "boundaries" exist only serves as an advantage. Isn't this how villains in Marvel movies work?

"Russia has no boundaries."—V. Putin

Re: WhatsApp voice calls were used to inject spyware on phones

#107
post #91
post #63

Earlier quoted context omitted.

I agree. Nobody should underestimate the Mossad: https://youtu.be/bJujIwtdk8w

From my favourite Usenix paper ( https://www.usenix.org/system/files/1401_08-12_mickens.pdf ): Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from ChEaPestPAiNPi11s@virus-basket.biz.ru. If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT. The Mos…

Don't f*ck with Israel ¯\_(ツ)_/¯

Re: WhatsApp voice calls were used to inject spyware on phones

#108
post #12

Earlier quoted context omitted.

They managed to destroy Iranian nuclear centrifuges using a very sophisticated attack. Read up on Stuxnet. Also, as an Israeli, I can 100% confirm that Israelis have absolutely no issues with crossing any kind of boundary. The fact that others think that such a thing as "boundaries" exist only serves as an advantage.

> I can 100% confirm that Israelis have absolutely no issues with crossing any kind of boundary. Is this a subtle reference to the Israeli occupation of Palestine?

"occupation"? Dude, c'mon.

Re: WhatsApp voice calls were used to inject spyware on phones

#110
post #36

Earlier quoted context omitted.

Wow! I had no idea there was a whole industry selling spyware to dictatorships. Surveillance equipment, yes, but not actual hacking tools. Really sickening. Must be why governments in Europe are so afraid of Huawei building 5G networks - they will only run Chinese spyware.

Huawei's equipment will almost assuredly run anyone's spyware. Huawei uses a medley of ancient, highly vulnerable OpenSSL libraries sprinkled through their basestation code, and apparently they've forgone any kind of version control to ensure an optimally confusing work environment for their development teams: https://hmgstrategy.com/resource-center/articles/2019/04/04/... Frankly, these products are likely unmaintai…

Huawei's software development practices seem quite horrifying. Critical systems like these ideally would be written in specially-designed programming languages that support mathematically proving correctness (Coq comes to mind). There's probably still room in the programming language design field to create new languages that are user-friendly but also integrate Coq-like systems plus other verifiability and correctness techniques into the language itself.
Post reply on HN