Earlier quoted context omitted.
I’m sure it was completely Israeli government involvement with the technologically advanced US playing no lead role. ...
The US provides the VC funding.
WhatsApp voice calls were used to inject spyware on phones
291–300 of 313 posts
Re: WhatsApp voice calls were used to inject spyware on phones
#292Earlier quoted context omitted.
Is Android.net.rtp available on every support Android and Google Library version combination that WhatsApp natively supports?
AIUI, no. That package was added in Honeycomb (API level 12), whereas WhatsApp currently supports Gingerbread (API level 10). However, two API levels of compat. seems like a good trade to me in order to avoid an RCE.
Re: WhatsApp voice calls were used to inject spyware on phones
#293Interesting! Google's Project Zero team investigated WhatsApp's and Facetime's video conferencing last year: "Overall, WhatsApp signalling seemed like a promising attack surface, but we did not find any vulnerabilities in it. There were two areas where we were able to extend the attack surface beyond what is used in the basic call flow. First, it was possible to send signalling messages that should only be sent after…
Re: WhatsApp voice calls were used to inject spyware on phones
#294Earlier quoted context omitted.
> But no "government" was involved. Huh? This is Israel. And some of us are mad at Google and Apple for selling such insecure-by-design junk. By that I mean that apps are trusted more than (and can't fully be controlled by) device owners.
I don’t think the trust policy has much to do with this. At the end of the day, an app exploit is an app exploit, and if an app can make calls, an app exploit will be able to make calls too. As long as the exploit is not allowed to burrow in the OS proper, it likely wouldn’t be any different on Linux or a BlackPhone.
Re: WhatsApp voice calls were used to inject spyware on phones
#295Earlier quoted context omitted.
The update can be analyzed to see what was changed, even if we only have the binary executable. If we know that an app contains intentional bugs, just looking at where the update made changes could eliminate a lot of looking & find the bugs even faster! There are many automated tools that can do this too, eg. Fuzzing. The updates can also hint us where the previous bug was and what to look out for in the future. So,…
Oh, so you are reverse engineering and thoroughly analyzing every WhatsApp update? That's reassuring. Cause otherwise I'd have said nobody does this on a regular basis which would mean it still is a viable method.
There is also a black-market that can be even more lucrative. A bug could be jackpot for criminals.
See also https://en.m.wikipedia.org/wiki/Market_for_zero-day_exploits
So yes, I'm pretty sure that there are various teams, including white-hats such as Google, black-hats, nation-states such as China / Russia, analyzing each and every update.
There was also an interesting article on hackernews a while back demonstrating the technique, there are some nice tools for this. Sorry, can't find the link now.
Re: WhatsApp voice calls were used to inject spyware on phones
#296Earlier quoted context omitted.
> I'm always happy to discuss specific cases If so, then maybe you can explain why you didn't change "Israel’s Beresheet Spacecraft Moon Landing Attempt Appears to End in Crash" and "A private spacecraft from Israel will attempt a moon landing Thursday" to "Private Spacecraft Moon Landing Attempt Appears to End in Crash" and "A private spacecraft will attempt a moon landing Thursday" respectively? I think your attemp…
In one case I didn't see the article and in the other it didn't cross my mind. But also, that topic isn't so highly charged, and I didn't see nationalistic flamewar getting in there. You're asking for a level of consistency in moderation that we can't deliver. I'd have to hold far more information in my head to come up with a consistent set of principles that would cover everything we do. Such a set would be inordina…
They are right there, in light-gray color at the bottom of the respective articles. Now that you have been made aware for the problem, will you change those articles' titles? I don't understand how you can claim one title is "baitsy" while the other to examples are not.
Re: WhatsApp voice calls were used to inject spyware on phones
#297Earlier quoted context omitted.
Oh, so you are reverse engineering and thoroughly analyzing every WhatsApp update? That's reassuring. Cause otherwise I'd have said nobody does this on a regular basis which would mean it still is a viable method.
Their is an entire industry that either is already or definitely would be doing this if there were deliberate bugs in Apps.
Re: WhatsApp voice calls were used to inject spyware on phones
#298Earlier quoted context omitted.
> doing anything they want [...] then denying brazingly That’s actually a time-honoured Russian/Soviet SOP, currently embodied by Mr. Sergey Lavrov. The USSR had a lot of influence on early Israel, and it shows in many little things like this.
I'd say it has more to do with the very Jewish concept of chutzpah . According to Wikipedia, the term is used "to describe someone who has overstepped the boundaries of accepted behavior" and "Chutzpah amounts to a total denial of personal responsibility, which renders others speechless and incredulous". The term used to have a very negative connotation, but interestingly, Google says "usually used approvingly". It s…
Also seems to be a pretty accurate description of SV/startup culture too...
Re: WhatsApp voice calls were used to inject spyware on phones
#299Earlier quoted context omitted.
At the risk of being pedantic- did you by chance mean "unsubstantiated"? :-) unsubstantiated (adj)- not supported or proven by evidence. unsubstantial (adj)- lacking material substance
Thanks. Your correction is welcome and not pedantic at all (it's rather substantial). More so as I've repeated this mistake twice.
I see what you did there.