Updated WhatsApp on my iphone just now. The version I got was 2.19.50. According to the CVE it's still vulnerable. Unable to get 2.19.51 which is the first fixed version. Is this just me? Or is everyone else updating to a still-vulnerable version?
WhatsApp voice calls were used to inject spyware on phones
211–220 of 313 posts
Re: WhatsApp voice calls were used to inject spyware on phones
#212http://archive.is/kDz13
Re: WhatsApp voice calls were used to inject spyware on phones
#213It seems to me that if this is possible an OS software upgrade of some sort is urgently required, in addition to possible updates of WhatsApp. How come there isn’t coverage of this as Android and iOS vulnerabilities?
Gaining control of WhatsApp gains access to any API accessible to WhatsApp. Incompetent reporting may be at fault. On Android, WhatsApp seeks a wide array of permission-controlled APIs. It does so on iOS as well. Once granted, the app has access to any data available through access-allowed APIs. App code goes through an audit process to ensure that the app isn’t using accessible APIs inappropriately, and doesn’t perm…
Re: WhatsApp voice calls were used to inject spyware on phones
#214Earlier quoted context omitted.
The update can be analyzed to see what was changed, even if we only have the binary executable. If we know that an app contains intentional bugs, just looking at where the update made changes could eliminate a lot of looking & find the bugs even faster! There are many automated tools that can do this too, eg. Fuzzing. The updates can also hint us where the previous bug was and what to look out for in the future. So,…
Oh, so you are reverse engineering and thoroughly analyzing every WhatsApp update? That's reassuring. Cause otherwise I'd have said nobody does this on a regular basis which would mean it still is a viable method.
Re: WhatsApp voice calls were used to inject spyware on phones
#215"update the app" is the sum of the advice? how about telling us how to check if this exploit was used, how to remove the spyware, etc?
I'm not sure what can be done nowadays. In the past you would say, format disks and go back to a backup before the threatening event happened. But nowadays all our stuff is in the cloud and you can only go back to the state from 10 minutes ago, and all our disks are flash drives that you can't fully format as an end user. Maybe you can just accept that some virusses will always be there and act accordingly.
Would be nice to have a tool that everyone on the planet could use to run against those backups and find a common source of the infections, along with an idea of when it was found in the wild.
Re: WhatsApp voice calls were used to inject spyware on phones
#216Earlier quoted context omitted.
Absolutely. But no more naughty than USA or Israel, as far as I can tell.
Hmm, I don’t want to get into a state wickedness bidding war, but the US/Israel are democracies where you are unlikely to be eg locked up without a fair trial. Contrast with the fate of the Uighurs. In foreign policy it’s more balanced (supporting Syria vs Saudi Arabia) but even there, Russia is clearly trying to subvert foreign democracies. China is (perhaps reasonably) pushing for more power in Asia. And while the…
Re: WhatsApp voice calls were used to inject spyware on phones
#217Updated WhatsApp on my iphone just now. The version I got was 2.19.50. According to the CVE it's still vulnerable. Unable to get 2.19.51 which is the first fixed version. Is this just me? Or is everyone else updating to a still-vulnerable version?
Re: WhatsApp voice calls were used to inject spyware on phones
#218All my life I've thought spyware was developed primarily by evil Russian and Chinese hackers. But apparently also by Israeli developers with their government's blessing and open endorsement. That's some very shady stuff. Before someone says something about government surveillance of fiber cables. Yes, that is also bad, but exploiting vulnerabilities to install spyware on peoples phones... It crosses yet another line…
By them, I’m not surprised. And I’m not being anti Semitic. I’m just calling fact.
Re: WhatsApp voice calls were used to inject spyware on phones
#219Earlier quoted context omitted.
I took it out because the thread was veering into generic flamewar about Israel. Actually we often remove country names from titles because they trigger people into making more nationalistic comments, which are equal parts indignant and boring.
That's a bit of a pathetic policy if you ask me. In my opinion a country who permits this type of behaviour shouldn't be shielded from the ensuing negative press. If anything it might encourage otherwise unaware citizens to put pressure on the government to do something about it.
Re: WhatsApp voice calls were used to inject spyware on phones
#220Earlier quoted context omitted.
I agree. Nobody should underestimate the Mossad: https://youtu.be/bJujIwtdk8w
From my favourite Usenix paper ( https://www.usenix.org/system/files/1401_08-12_mickens.pdf ): Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from ChEaPestPAiNPi11s@virus-basket.biz.ru. If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT. The Mos…
Security research is the continual process of discovering that your spaceship is a deathtrap. However, as John F. Kennedy once said, “SCREW IT WE’RE GOING TO THE MOON.” I cannot live my life in fear because someone named PhreakusMaximus at DefConHat 2014 showed that you can induce peanut allergies at a distance using an SMS message and a lock of your victim’s hair. If that’s how it is, I accept it and move on. Thinking about security is like thinking about where to ride your motorcycle: the safe places are no fun, and the fun places are not safe. I shall ride wherever my spirit takes me, and I shall find my Gigantic Martian Insect Party, and I will, uh, probably be rent asunder by huge cryptozoological mandibles, but I will die like Thomas Jefferson: free, defiant, and without a security label.
This I like.