Live data from Hacker News

WhatsApp voice calls were used to inject spyware on phones

ft.com

201–210 of 313 posts

Re: WhatsApp voice calls were used to inject spyware on phones

#201
post #88

Earlier quoted context omitted.

> I can 100% confirm that Israelis have absolutely no issues with crossing any kind of boundary. Is this a subtle reference to the Israeli occupation of Palestine?

My comment has nothing to do with Palestine.

Well, it applies perfectly.

Re: WhatsApp voice calls were used to inject spyware on phones

#202

It seems to me that if this is possible an OS software upgrade of some sort is urgently required, in addition to possible updates of WhatsApp. How come there isn’t coverage of this as Android and iOS vulnerabilities?

Gaining control of WhatsApp gains access to any API accessible to WhatsApp. Incompetent reporting may be at fault. On Android, WhatsApp seeks a wide array of permission-controlled APIs. It does so on iOS as well. Once granted, the app has access to any data available through access-allowed APIs. App code goes through an audit process to ensure that the app isn’t using accessible APIs inappropriately, and doesn’t perm…

Very interested to know what this means in practice, particularly for iOS.

AFAIK, there's no permissions which allow you to read SMS messages, take screenshots (unless jailbroken), access photos in the background, access the camera in the background etc etc

Does this just spy on the users Whatsapp activity, or spy on the user in a broader way?

How could the API's whatsapp does have access to be abused?

Re: WhatsApp voice calls were used to inject spyware on phones

#206

Earlier quoted context omitted.

You're still vulnerable then. "Affected versions: ... WhatsApp for iOS prior to v2.19.51" from https://www.facebook.com/security/advisories/cve-2019-3568 The news outlets are all telling us to update, but until WhatsApp/Apple get their act together, there's no point. Worse still, people won't realise they need to do it again and will remain vulnerable indefinitely.

I'm on Android. It auto-updated on May 10th to v2.19.134 "The issue affects WhatsApp for Android prior to v2.19.134"

The problem is iOS AppStore. If you update via the "Updates" tab, you don't get the latest version. But if you search for WhatsApp as if installing it for the first time, then you get the new version.

Re: WhatsApp voice calls were used to inject spyware on phones

#207

Earlier quoted context omitted.

Well, that's your interpretation of the events, and one-sided and not a very truthful one at best.

It is the interpretation of all of the international community except for the US and Israel. The UN has repeatedly voted to recognize this, often being blocked by the US. There is no real controversy on this. Edit: see https://en.wikipedia.org/wiki/United_Nations_Security_Counci... The entire UN Security Council officially recognized this, with even the US not using their veto power (they abstained).

I'm well aware of UN position on Israel, I just don't understand how anyone who knows how this organization operates can pretend it represents "international community" or has any moral authority.

Re: WhatsApp voice calls were used to inject spyware on phones

#208
CVE-2019-3568 suggests this was a buffer overflow. I'd like to understand why this was implemented in native code - Android seems to have an `android.net.rtp` package?

Is this simply for performance, or to enable code-sharing across Android and iOS? Is there anything about WhatsApp's use-case that would prevent an implementation using managed code?

Re: WhatsApp voice calls were used to inject spyware on phones

#210

Earlier quoted context omitted.

You say this as your country is invading and occupying land that doesn’t belong to them and murdering innocents to drive them out. Yeah, nice way to be proud.

very hard to think of any country that has NOT done this. History shows that people and their countries do bad things.

whataboutism
Post reply on HN