Live data from Hacker News

WhatsApp voice calls were used to inject spyware on phones

ft.com

141–150 of 313 posts

Re: WhatsApp voice calls were used to inject spyware on phones

#142
post #132
post #120

Earlier quoted context omitted.

Absolutely. But no more naughty than USA or Israel, as far as I can tell.

Hmm, I don’t want to get into a state wickedness bidding war, but the US/Israel are democracies where you are unlikely to be eg locked up without a fair trial. Contrast with the fate of the Uighurs. In foreign policy it’s more balanced (supporting Syria vs Saudi Arabia) but even there, Russia is clearly trying to subvert foreign democracies. China is (perhaps reasonably) pushing for more power in Asia. And while the…

And you think the US isn't trying to subvert foreign democracies?

Re: WhatsApp voice calls were used to inject spyware on phones

#143
post #25

It's not just the NSO group. Hacking Team is not exactly shy about the services they offer. https://en.wikipedia.org/wiki/Hacking_Team FinFisher: https://en.wikipedia.org/wiki/FinFisher MiniPanzer: https://en.wikipedia.org/wiki/MiniPanzer_and_MegaPanzer

Yeah, there's a cottage industry of security firms who sell exploits to the U.S. government directly or indirectly through big defense contractors. Many, and I personally have assumed _most_ (but without checking), are American firms. And, frankly, the Israeli industry has much to gain by advertising their prowess in order to bolster their IT security bone fides internationally. American firms are probably more discr…

>the Israeli industry has much to gain by advertising their prowess in order to bolster their IT security bone fides internationally

Absolutely. The Israeli Cybersecurity brand is built partially on such (sometimes unsubstantial) PR.

The bubble is doing well though! almost 500 startups, > 1Billion$ VC funding in 2018 alone. Devs are happy.

Re: WhatsApp voice calls were used to inject spyware on phones

#144
post #36

It's not just the NSO group. Hacking Team is not exactly shy about the services they offer. https://en.wikipedia.org/wiki/Hacking_Team FinFisher: https://en.wikipedia.org/wiki/FinFisher MiniPanzer: https://en.wikipedia.org/wiki/MiniPanzer_and_MegaPanzer

Wow! I had no idea there was a whole industry selling spyware to dictatorships. Surveillance equipment, yes, but not actual hacking tools. Really sickening. Must be why governments in Europe are so afraid of Huawei building 5G networks - they will only run Chinese spyware.

The Israeli military-industrial ELINT industry and C4I people sell stuff to all sorts of authoritarian regimes. Even the ones that the US and UK won't touch.

Re: WhatsApp voice calls were used to inject spyware on phones

#145
post #143
post #25

Earlier quoted context omitted.

Yeah, there's a cottage industry of security firms who sell exploits to the U.S. government directly or indirectly through big defense contractors. Many, and I personally have assumed _most_ (but without checking), are American firms. And, frankly, the Israeli industry has much to gain by advertising their prowess in order to bolster their IT security bone fides internationally. American firms are probably more discr…

>the Israeli industry has much to gain by advertising their prowess in order to bolster their IT security bone fides internationally Absolutely. The Israeli Cybersecurity brand is built partially on such (sometimes unsubstantial) PR. The bubble is doing well though! almost 500 startups, > 1Billion$ VC funding in 2018 alone. Devs are happy.

Curious as to why you think it's a bubble. Israeli startups have had many successful exits in recent years, although mostly acquisitions, and not many big flops.

Re: WhatsApp voice calls were used to inject spyware on phones

#146
post #12

Earlier quoted context omitted.

They managed to destroy Iranian nuclear centrifuges using a very sophisticated attack. Read up on Stuxnet. Also, as an Israeli, I can 100% confirm that Israelis have absolutely no issues with crossing any kind of boundary. The fact that others think that such a thing as "boundaries" exist only serves as an advantage.

Not clear whether you consider this a good thing or a disgrace?

As another israeli - certainly a good thing. For a nation in our position, in a deeply hostile region, where a major military defeat is certain to be genocide, doing everything possible for national defence is the only way possible to survive. Stuxnet in particular is something that I'm extremely proud of.

Re: WhatsApp voice calls were used to inject spyware on phones

#147
post #84

Earlier quoted context omitted.

They're a government that the US recognizes, and that's widely recognized by other governments that the US recognizes. That makes them legitimate. Terrorists by definition do not include legitimate governments. Anyone that doesn't agree is a "terrorist sympathizer". I don't necessarily agree, but that's just how it is.

But no "government" was involved. This is a private company with international investors. Why isn't anyone mad at Apple who (falsely) advertises iOS as being "Secure By Design?"

> This is a private company with international investors.

Knowing nothing about the company in question, I'm still certain that most of its founders, investors and employees come from 8200. So, government doesn't need to be formally involved in any way, it's just the same social circles, everybody just knows everyone.

Re: WhatsApp voice calls were used to inject spyware on phones

#149
post #75

Earlier quoted context omitted.

But time is enough. New bugs can be introduced with the next update.

The update can be analyzed to see what was changed, even if we only have the binary executable. If we know that an app contains intentional bugs, just looking at where the update made changes could eliminate a lot of looking & find the bugs even faster! There are many automated tools that can do this too, eg. Fuzzing. The updates can also hint us where the previous bug was and what to look out for in the future. So,…

Oh, so you are reverse engineering and thoroughly analyzing every WhatsApp update? That's reassuring. Cause otherwise I'd have said nobody does this on a regular basis which would mean it still is a viable method.

Re: WhatsApp voice calls were used to inject spyware on phones

#150

Wonder if this affects Signal, too.

My gut tells me no. Signal switched over to using the Signal Protocol for call signaling. It had used a few different signaling standards over the years (when it used to be called Redphone). However, it's impossible to really know for sure as the server component for calls is a proprietary black box.

Agreed. It seems more plausible that the "injected code" would be limited to (1) the WhatsApp app, and (2) the infrastructure outside of the Signal Protocol implementation. If true, this still poses a problem to comms/calls secured end-to-end with the Signal Protocol impl - because once decrypted on the client, the rest of the WhatsApp may be compromised and able to exfil comms.

I will be surprised, if this vuln allows the attacker control outside of the WhatsApp app sandbox to other parts of iOS.

(I will be less surprised if the above is possible in Android)

Post reply on HN