Live data from Hacker News

WhatsApp voice calls were used to inject spyware on phones

ft.com

151–160 of 313 posts

Re: WhatsApp voice calls were used to inject spyware on phones

#151
post #126
post #112

The title has been modified. WhatsApp voice calls used to inject Israeli spyware on phones

Sure, we take out the baity parts of titles because they produce lousier discussion. This is standard HN moderation: https://news.ycombinator.com/newsguidelines.html . See https://news.ycombinator.com/item?id=19906729 for more explanation.

But isn't it also baity to use 'used to'. My first reaction now was that Whatsapp itself has been inserting spyware into their phone calls, but no longer is (=used to), yet after reading the (non-paywalled) article I now see that a vulnerability in their signaling protocol has been used by others (=used to) to allow remote code injection.

Removing the creator of the spyware part from the title now causes the blame of the spyware to shift to Whatsapp, which is incorrect.

Re: WhatsApp voice calls were used to inject spyware on phones

#153
post #143

Earlier quoted context omitted.

>the Israeli industry has much to gain by advertising their prowess in order to bolster their IT security bone fides internationally Absolutely. The Israeli Cybersecurity brand is built partially on such (sometimes unsubstantial) PR. The bubble is doing well though! almost 500 startups, > 1Billion$ VC funding in 2018 alone. Devs are happy.

Curious as to why you think it's a bubble. Israeli startups have had many successful exits in recent years, although mostly acquisitions, and not many big flops.

It's just my unsubstantial opinion. Too many players raising too much money in a consolidated market. Bar some notable exceptions (NSO), this herd of misguided lemmings has one way out - acquisition by Checkpoint/Imperva/SalesForce.

But maybe I'm wrong and we'll see 100 Mobileyes in the coming decade.

Re: WhatsApp voice calls were used to inject spyware on phones

#154

Earlier quoted context omitted.

Not clear whether you consider this a good thing or a disgrace?

As another israeli - certainly a good thing. For a nation in our position, in a deeply hostile region, where a major military defeat is certain to be genocide, doing everything possible for national defence is the only way possible to survive. Stuxnet in particular is something that I'm extremely proud of.

You say this as your country is invading and occupying land that doesn’t belong to them and murdering innocents to drive them out. Yeah, nice way to be proud.

Re: WhatsApp voice calls were used to inject spyware on phones

#155
post #134

Earlier quoted context omitted.

>All my life I've thought spyware was developed primarily by evil Russian and Chinese hackers. You've led a very sheltered life if you think the Russians and the Chinese have been more evil than the Americans or the Israelis. I suggest reading history - a lot of it. When it comes to governments there are no good guys, only bad guys.

[flagged]

The US has killed millions of people in the last 15 years alone in Iraq, Afghanistan, Libya, Syria, Yemen and a dozen other countries that we have bombed or invaded (including the 8 we are bombing right now). I'm under no illusions about the many despicable things done by the Russians and the Chinese, but its simply absurd to contend that their behavior has any worse than the United States. We have more of our citizens locked in cages than Russia and China combined. We have toppled more governments and invaded more countries than Russia and China combined by a factor of 10 (or more) since the end of World War II. Its astounding how willfully blind people can be when it comes to their own government. We can't become the good guys until people wake up and acknowledge that there haven't been any good guys.

Re: WhatsApp voice calls were used to inject spyware on phones

#157
I am not an expert on RCEs whatsoever but my limited knowledge / gut feeling tells me that one works by after a buffer overflow flipping some bits and

* invoking syscalls

* using (known) kernel vulnerabilities

* libc bugs

* exploiting buggy posix abstraction, etc.

However, here all platforms seem to be exploited, regardless kernels (darwin/linux/windows), process models, libc implementations etc.

I cannot unthink that this was simply doable because WhatsApp had already have code paths to place and run tasks/processes and this exploit works on this, higher level.

Re: WhatsApp voice calls were used to inject spyware on phones

#159
post #126

Earlier quoted context omitted.

Sure, we take out the baity parts of titles because they produce lousier discussion. This is standard HN moderation: https://news.ycombinator.com/newsguidelines.html . See https://news.ycombinator.com/item?id=19906729 for more explanation.

But isn't it also baity to use 'used to'. My first reaction now was that Whatsapp itself has been inserting spyware into their phone calls, but no longer is (=used to), yet after reading the (non-paywalled) article I now see that a vulnerability in their signaling protocol has been used by others (=used to) to allow remote code injection. Removing the creator of the spyware part from the title now causes the blame of…

Ok, let's put a verb in there.
Post reply on HN