Live data from Hacker News

WhatsApp voice calls were used to inject spyware on phones

ft.com

281–290 of 313 posts

Re: WhatsApp voice calls were used to inject spyware on phones

#281
post #202

Earlier quoted context omitted.

Gaining control of WhatsApp gains access to any API accessible to WhatsApp. Incompetent reporting may be at fault. On Android, WhatsApp seeks a wide array of permission-controlled APIs. It does so on iOS as well. Once granted, the app has access to any data available through access-allowed APIs. App code goes through an audit process to ensure that the app isn’t using accessible APIs inappropriately, and doesn’t perm…

Very interested to know what this means in practice, particularly for iOS. AFAIK, there's no permissions which allow you to read SMS messages, take screenshots (unless jailbroken), access photos in the background, access the camera in the background etc etc Does this just spy on the users Whatsapp activity, or spy on the user in a broader way? How could the API's whatsapp does have access to be abused?

> access photos in the background

Google photos on iOS is able to upload my photos in the background so its possible

Re: WhatsApp voice calls were used to inject spyware on phones

#282
post #277

Earlier quoted context omitted.

Cursory Google searches seem to indicate that the same policy isn't applied for Chinese or Russian cyber threats. You also didn't remove the country name in other recent news, despite the production of even lousier discussion: https://news.ycombinator.com/item?id=19638357 https://news.ycombinator.com/item?id=19634570 The moderation is inconsistent.

I'm not claiming consistency. For one thing, we don't come close to seeing everything that gets posted here. If you see a particularly bad post get away without moderation, the likeliest explanation is that we didn't see it. We can't be consistent about what we don't see. There are a ton of other considerations, though, and it gets complicated quickly. I'm always happy to discuss specific cases, but general arguments…

> I'm always happy to discuss specific cases

If so, then maybe you can explain why you didn't change "Israel’s Beresheet Spacecraft Moon Landing Attempt Appears to End in Crash" and "A private spacecraft from Israel will attempt a moon landing Thursday" to "Private Spacecraft Moon Landing Attempt Appears to End in Crash" and "A private spacecraft will attempt a moon landing Thursday" respectively?

I think your attempt at reducing nationalistic flame wars is very misguided, because I want to read what people think. If HN readers want to flame each other then I would like to have the chance to read the flames even if I'd likely scroll past them. But if you are going to do it, at least be consistent.

Re: WhatsApp voice calls were used to inject spyware on phones

#283
post #208

CVE-2019-3568 suggests this was a buffer overflow. I'd like to understand why this was implemented in native code - Android seems to have an `android.net.rtp` package? Is this simply for performance, or to enable code-sharing across Android and iOS? Is there anything about WhatsApp's use-case that would prevent an implementation using managed code?

Is Android.net.rtp available on every support Android and Google Library version combination that WhatsApp natively supports?

AIUI, no. That package was added in Honeycomb (API level 12), whereas WhatsApp currently supports Gingerbread (API level 10).

However, two API levels of compat. seems like a good trade to me in order to avoid an RCE.

Re: WhatsApp voice calls were used to inject spyware on phones

#284
post #253
post #208

CVE-2019-3568 suggests this was a buffer overflow. I'd like to understand why this was implemented in native code - Android seems to have an `android.net.rtp` package? Is this simply for performance, or to enable code-sharing across Android and iOS? Is there anything about WhatsApp's use-case that would prevent an implementation using managed code?

Also, what exploitation mitigations are broken on Android/iOS such that a buffer overflow is reliably exploitable? Are their implementations of ASLR useless? Is it trivially bypassed? Is mandatory code-signing not enabled/enforced?

All very good questions, hopefully we can get some more information as time progresses (maybe a PoC, or at least a technical write-up on the specifics)

Re: WhatsApp voice calls were used to inject spyware on phones

#285
post #196
post #105

Earlier quoted context omitted.

> Is this a cultural thing Israelis in general are very blunt and perfectly willing to question superiors and voice opinions and questions in situations where Americans never would. This includes the military where subordinates would question a superior in a way that would never fly in an American military (and probably others). Israelis on the street will voice opinions to strangers in a way that would be perceived…

> Israelis in general are very blunt and perfectly willing to question superiors and voice opinions and questions in situations where Americans never would. This includes the military where subordinates would question a superior in a way that would never fly in an American military (and probably others). Well, they claim they are but you don't see anything at least from outside. From outside it seems they are easily…

You have this strange assumption that people are supposed to find something wrong with surveillance projects.

> Working on surveillance projects is rather embraced and you even receive strong social support for it.

That's right, because there's nothing wrong with it.

> So I don't get how do you compare it to the US!

Because I'm not comparing surveillance projects, I'm comparing modes of speaking.

> Whereas in the US you would have a hard time to convince people to work on surveillance projects and even then often people end up having a hard time with their moral values even when they are not directly doing anything wrong.

Because it's quite obvious to the ordinary Israeli that surveillance projects save lives, so obviously they would want to work on it.

The US isn't under quite the same level of attack, although it's far from clear there is supposed to be something wrong with it in the US either.

Re: WhatsApp voice calls were used to inject spyware on phones

#286
post #174
post #105

Earlier quoted context omitted.

> Is this a cultural thing Israelis in general are very blunt and perfectly willing to question superiors and voice opinions and questions in situations where Americans never would. This includes the military where subordinates would question a superior in a way that would never fly in an American military (and probably others). Israelis on the street will voice opinions to strangers in a way that would be perceived…

> Israelis on the street will voice opinions to strangers in a way that would be perceived as incredibly rude elsewhere, but is normal in Israel. What do you mean, for example?

If they think you didn't dress your child properly they'll tell you. Or they'll hear you talking about something and give you advice on what to do without any embarrassment on that fact that they overheard you.

You're fighting with your teen, in the US everyone would turn away and pretend not to hear, in Israel they'll just openly talk to you about their own teen and what they did, etc. and then half the bus would chime in. They're all really nice about it mind you, just trying to help.

Israelis think of everyone as part of their personal family, even strangers are really distant relatives, is I guess a good way to put it.

Re: WhatsApp voice calls were used to inject spyware on phones

#287
post #275

Earlier quoted context omitted.

The US has killed millions of people in the last 15 years alone in Iraq, Afghanistan, Libya, Syria, Yemen and a dozen other countries that we have bombed or invaded (including the 8 we are bombing right now). I'm under no illusions about the many despicable things done by the Russians and the Chinese, but its simply absurd to contend that their behavior has any worse than the United States. We have more of our citize…

The US has not killed millions of people in the last 15 years that is just a blatantly false statement. A quick search on Google or Wikipedia will refute your claim instantly. Can you provide a decent source for your millions of casualties claim or for you claim about the US toppling more Governments than Russia/China? I bet you can’t. Judging by your username I believe you know some things about history. Why spread…

[deleted]

Re: WhatsApp voice calls were used to inject spyware on phones

#288
post #91

Earlier quoted context omitted.

From my favourite Usenix paper ( https://www.usenix.org/system/files/1401_08-12_mickens.pdf ): Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from ChEaPestPAiNPi11s@virus-basket.biz.ru. If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT. The Mos…

Fun fact: The mossad ran a job ad on facebook a while ago, which involved a sequence of riddles. First discover a server based on some random seeming sequence of characters on an image. Then you had to solve a number of programming puzzles. I stopped at the third one, because I don't actually want to work there.

Suddenly I’m less impressed in the Mossad. Really they recruit hackers on FB?

If I do a quick samples of people I know, there’s a super high correlation in being a hacker/developer and not using Facebook. Maybe they should try HN instead.

Re: WhatsApp voice calls were used to inject spyware on phones

#289
post #153

Earlier quoted context omitted.

It's just my unsubstantial opinion. Too many players raising too much money in a consolidated market. Bar some notable exceptions (NSO), this herd of misguided lemmings has one way out - acquisition by Checkpoint/Imperva/SalesForce. But maybe I'm wrong and we'll see 100 Mobileyes in the coming decade.

At the risk of being pedantic- did you by chance mean "unsubstantiated"? :-) unsubstantiated (adj)- not supported or proven by evidence. unsubstantial (adj)- lacking material substance

Thanks. Your correction is welcome and not pedantic at all (it's rather substantial). More so as I've repeated this mistake twice.

Re: WhatsApp voice calls were used to inject spyware on phones

#290
post #277

Earlier quoted context omitted.

I'm not claiming consistency. For one thing, we don't come close to seeing everything that gets posted here. If you see a particularly bad post get away without moderation, the likeliest explanation is that we didn't see it. We can't be consistent about what we don't see. There are a ton of other considerations, though, and it gets complicated quickly. I'm always happy to discuss specific cases, but general arguments…

> I'm always happy to discuss specific cases If so, then maybe you can explain why you didn't change "Israel’s Beresheet Spacecraft Moon Landing Attempt Appears to End in Crash" and "A private spacecraft from Israel will attempt a moon landing Thursday" to "Private Spacecraft Moon Landing Attempt Appears to End in Crash" and "A private spacecraft will attempt a moon landing Thursday" respectively? I think your attemp…

In one case I didn't see the article and in the other it didn't cross my mind. But also, that topic isn't so highly charged, and I didn't see nationalistic flamewar getting in there.

You're asking for a level of consistency in moderation that we can't deliver. I'd have to hold far more information in my head to come up with a consistent set of principles that would cover everything we do. Such a set would be inordinately complicated and impossible to explain or defend, so what would be the point.

> I want to read what people think.

Me too. But you can't read everything people think, because comments influence what gets posted in response. If a discussion becomes a flamewar, you're going to get the angry thoughts of the flamers, but lose the thoughts of those the flames drive away. It's a tradeoff—we can't have both. On HN the non-flamey, thoughtful comments take precedence, because that's the only way to optimize for HN remaining interesting. This is one area where I think we really are consistent, or at least I hope we are.

Look at it this way: each post changes the kind of site HN is. The container isn't static—it's altered by what people add to it. Our goal is optimize that container for curiosity. This is a global optimization problem, so it's important not to get distracted by local optima. Our experience with things like nationalistic flames is that while such comments are sometimes interesting (and certainly the topics are of great world significance), the type of discussion they lead to is reliably worse. What we do is: extrapolate the vector of a given comment and ask what its shaping influence is on the site as a whole. Is it to make HN more, or less, interesting? Where more, we either do nothing or steer towards; where less, we steer away. In the case of flamewars, steering away means doing things to prevent the flames from spreading. There are various tools for that—digging trenches, pouring water, etc. Picking which to use where is more of an art and I wouldn't say we're particularly consistent on that level. But the fundamental principle is very consistent—there's only one, and it motivates literally everything we do here.

Post reply on HN