Live data from Hacker News

WhatsApp voice calls were used to inject spyware on phones

ft.com

261–270 of 313 posts

Re: WhatsApp voice calls were used to inject spyware on phones

#261

Why is that even possible? It's horrifying that simple voice calls via an app allow that kind of attack.

Cellular broadband modems are running a tiny OS that can be hacked by sending SMS messages with a carefully crafted NUL byte. Battlestar Galactica’s “no networking, no wireless” computer restriction exists for a very good reason.

Re: WhatsApp voice calls were used to inject spyware on phones

#263
post #262

FT.com worst site in the world.. I thought you can't link things that require a subscription to read?

For these, there is a link below the headline titled "web" - click this, it opens in a search that when clicked through allows reading.

Wow, TIL. Thanks!

Re: WhatsApp voice calls were used to inject spyware on phones

#266
post #200
post #91

Earlier quoted context omitted.

From my favourite Usenix paper ( https://www.usenix.org/system/files/1401_08-12_mickens.pdf ): Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from ChEaPestPAiNPi11s@virus-basket.biz.ru. If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT. The Mos…

> ...they’re going to hold a press conference and say “It wasn’t us” as they wear t-shirts that say “IT WAS DEFINITELY US,” and then they’re going to buy all of your stuff at your estate sale so that they can directly look at the photos of your vacation instead of reading your insipid emails about them. That's basically Israel's attitude on anything: doing anything they want without any kind of boundaries, then denyi…

> Like having snipers shooting at thousands of civilians, kids, journalists, paramedics, who are protesting inside their own borders.

Ugh... this is so myopic and sounds like you're intentionally not telling the truth.

all those "kids", "journalists", and "paramedics" were shown to be carrying bombs or other explosives.

Re: WhatsApp voice calls were used to inject spyware on phones

#267
post #56
post #5

Interesting! Google's Project Zero team investigated WhatsApp's and Facetime's video conferencing last year: "Overall, WhatsApp signalling seemed like a promising attack surface, but we did not find any vulnerabilities in it. There were two areas where we were able to extend the attack surface beyond what is used in the basic call flow. First, it was possible to send signalling messages that should only be sent after…

In both cases, the close source nature of the applications stymied their efforts. Why do you say that? In the WhatsApp case, they were able to repeatedly modify the code and also yank it out and run it in their own controlled environment, etc.

From my experience, working with real source from the repo with comments etc is very different than working with reverse engineered binaries.

That's probably what they're referring to.

Re: WhatsApp voice calls were used to inject spyware on phones

#268
post #36

Earlier quoted context omitted.

Wow! I had no idea there was a whole industry selling spyware to dictatorships. Surveillance equipment, yes, but not actual hacking tools. Really sickening. Must be why governments in Europe are so afraid of Huawei building 5G networks - they will only run Chinese spyware.

The Israeli military-industrial ELINT industry and C4I people sell stuff to all sorts of authoritarian regimes. Even the ones that the US and UK won't touch.

Based on the Phalcon affair I don't think Israel exports to anyone the US didn't want them to have it, the last time they tried it basically toppled an Israeli government.

Re: WhatsApp voice calls were used to inject spyware on phones

#269
post #56

Earlier quoted context omitted.

In both cases, the close source nature of the applications stymied their efforts. Why do you say that? In the WhatsApp case, they were able to repeatedly modify the code and also yank it out and run it in their own controlled environment, etc.

From my experience, working with real source from the repo with comments etc is very different than working with reverse engineered binaries. That's probably what they're referring to.

The post says "the close[d] source nature of the applications stymied their efforts" not "finding security bugs is harder than not-finding security bugs". I didn't read anything in the linked post that supports the former statement, the latter one (or variants) seems obvious.

Re: WhatsApp voice calls were used to inject spyware on phones

#270
post #126

Earlier quoted context omitted.

Sure, we take out the baity parts of titles because they produce lousier discussion. This is standard HN moderation: https://news.ycombinator.com/newsguidelines.html . See https://news.ycombinator.com/item?id=19906729 for more explanation.

Cursory Google searches seem to indicate that the same policy isn't applied for Chinese or Russian cyber threats. You also didn't remove the country name in other recent news, despite the production of even lousier discussion: https://news.ycombinator.com/item?id=19638357 https://news.ycombinator.com/item?id=19634570 The moderation is inconsistent.

> The moderation is inconsistent

When is it ever consistent...

Post reply on HN