Live data from Hacker News

WhatsApp voice calls were used to inject spyware on phones

ft.com

211–220 of 313 posts

Re: WhatsApp voice calls were used to inject spyware on phones

#211

Updated WhatsApp on my iphone just now. The version I got was 2.19.50. According to the CVE it's still vulnerable. Unable to get 2.19.51 which is the first fixed version. Is this just me? Or is everyone else updating to a still-vulnerable version?

Have you tried pulling down on the updates screen of the iOS app store? It refreshes the list of apps to be updated.

Re: WhatsApp voice calls were used to inject spyware on phones

#213

It seems to me that if this is possible an OS software upgrade of some sort is urgently required, in addition to possible updates of WhatsApp. How come there isn’t coverage of this as Android and iOS vulnerabilities?

Gaining control of WhatsApp gains access to any API accessible to WhatsApp. Incompetent reporting may be at fault. On Android, WhatsApp seeks a wide array of permission-controlled APIs. It does so on iOS as well. Once granted, the app has access to any data available through access-allowed APIs. App code goes through an audit process to ensure that the app isn’t using accessible APIs inappropriately, and doesn’t perm…

There should be different permissions for foreground and background access to APIs.

Re: WhatsApp voice calls were used to inject spyware on phones

#214

Earlier quoted context omitted.

The update can be analyzed to see what was changed, even if we only have the binary executable. If we know that an app contains intentional bugs, just looking at where the update made changes could eliminate a lot of looking & find the bugs even faster! There are many automated tools that can do this too, eg. Fuzzing. The updates can also hint us where the previous bug was and what to look out for in the future. So,…

Oh, so you are reverse engineering and thoroughly analyzing every WhatsApp update? That's reassuring. Cause otherwise I'd have said nobody does this on a regular basis which would mean it still is a viable method.

Their is an entire industry that either is already or definitely would be doing this if there were deliberate bugs in Apps.

Re: WhatsApp voice calls were used to inject spyware on phones

#215

"update the app" is the sum of the advice? how about telling us how to check if this exploit was used, how to remove the spyware, etc?

I'm not sure what can be done nowadays. In the past you would say, format disks and go back to a backup before the threatening event happened. But nowadays all our stuff is in the cloud and you can only go back to the state from 10 minutes ago, and all our disks are flash drives that you can't fully format as an end user. Maybe you can just accept that some virusses will always be there and act accordingly.

Some of us do snapshot backups.

Would be nice to have a tool that everyone on the planet could use to run against those backups and find a common source of the infections, along with an idea of when it was found in the wild.

Re: WhatsApp voice calls were used to inject spyware on phones

#216
post #132
post #120

Earlier quoted context omitted.

Absolutely. But no more naughty than USA or Israel, as far as I can tell.

Hmm, I don’t want to get into a state wickedness bidding war, but the US/Israel are democracies where you are unlikely to be eg locked up without a fair trial. Contrast with the fate of the Uighurs. In foreign policy it’s more balanced (supporting Syria vs Saudi Arabia) but even there, Russia is clearly trying to subvert foreign democracies. China is (perhaps reasonably) pushing for more power in Asia. And while the…

[deleted]

Re: WhatsApp voice calls were used to inject spyware on phones

#217

Updated WhatsApp on my iphone just now. The version I got was 2.19.50. According to the CVE it's still vulnerable. Unable to get 2.19.51 which is the first fixed version. Is this just me? Or is everyone else updating to a still-vulnerable version?

You need to go to the app store app, then the updates tab and pull down to refresh(yes, the updates tab, not WhatsApp listing in the store). When you do that, you'll see the newest version becomes available for update. This happens whenever an update is set to phased release and hasn't reached 100% yet.

Re: WhatsApp voice calls were used to inject spyware on phones

#218
post #7

All my life I've thought spyware was developed primarily by evil Russian and Chinese hackers. But apparently also by Israeli developers with their government's blessing and open endorsement. That's some very shady stuff. Before someone says something about government surveillance of fiber cables. Yes, that is also bad, but exploiting vulnerabilities to install spyware on peoples phones... It crosses yet another line…

> That's some very shady stuff.

By them, I’m not surprised. And I’m not being anti Semitic. I’m just calling fact.

Re: WhatsApp voice calls were used to inject spyware on phones

#219
post #125

Earlier quoted context omitted.

I took it out because the thread was veering into generic flamewar about Israel. Actually we often remove country names from titles because they trigger people into making more nationalistic comments, which are equal parts indignant and boring.

That's a bit of a pathetic policy if you ask me. In my opinion a country who permits this type of behaviour shouldn't be shielded from the ensuing negative press. If anything it might encourage otherwise unaware citizens to put pressure on the government to do something about it.

Q.E.D.

Re: WhatsApp voice calls were used to inject spyware on phones

#220
post #91
post #63

Earlier quoted context omitted.

I agree. Nobody should underestimate the Mossad: https://youtu.be/bJujIwtdk8w

From my favourite Usenix paper ( https://www.usenix.org/system/files/1401_08-12_mickens.pdf ): Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from ChEaPestPAiNPi11s@virus-basket.biz.ru. If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT. The Mos…

I would have labeled the article a piece of defeatism disguised as satire, if not for this:

Security research is the continual process of discovering that your spaceship is a deathtrap. However, as John F. Kennedy once said, “SCREW IT WE’RE GOING TO THE MOON.” I cannot live my life in fear because someone named PhreakusMaximus at DefConHat 2014 showed that you can induce peanut allergies at a distance using an SMS message and a lock of your victim’s hair. If that’s how it is, I accept it and move on. Thinking about security is like thinking about where to ride your motorcycle: the safe places are no fun, and the fun places are not safe. I shall ride wherever my spirit takes me, and I shall find my Gigantic Martian Insect Party, and I will, uh, probably be rent asunder by huge cryptozoological mandibles, but I will die like Thomas Jefferson: free, defiant, and without a security label.

This I like.

Post reply on HN