Live data from Hacker News

Jeff Bezos's phone 'hacked by Saudi crown prince'

theguardian.com

311–320 of 327 posts

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#311
post #285

Apparently I’m the only person on earth who wants to know what kind of phone Bezos was using, which OS version, etc. It seems like this detail is conveniently being left out of every story. Anyone have any additional details? I understand that it was a WhatsApp vulnerability (Pegasus?) but I’d still like to know more about the device.

According to vice [1] he was using an iPhone X.

1: https://www.vice.com/en_us/article/v74v34/saudi-arabia-hacke...

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#312
post #291

Earlier quoted context omitted.

Saudi Arabia has a lot of exiles and so far as I know, it's not murdering everyone who criticizes them. Khashoggi is was not simply a journalist but a member of an influential family with Saudi Arabia [1]. MBS has dealt quite brutally with a variety of his internal opponents without Saudi Arabia. Murdering Khashoggi was something of a statement that MBS wouldn't let his direct opponents escape to other countries to o…

“Only a little bit murdery” - op

No matter how I try to balance: "these are people who are killers and venally evil in nearly every sense of the word" and "But they are still intelligent and because they aim to maintain their significant power, they have to act in a measured, limited way that still involved logic and allows most 'little people' to go about their business AND we need to understand logic of these things BECAUSE these people influence so much.".

No matter how much I couch and balance my words, there's always someone ready to jump in with the crude simplification. Frick-off, jeesh.

And to further clarify, the Saudis don't murder exiles, in particular, wholesale. They do murder the Houthas and several other groups wholesale.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#313
post #285

Apparently I’m the only person on earth who wants to know what kind of phone Bezos was using, which OS version, etc. It seems like this detail is conveniently being left out of every story. Anyone have any additional details? I understand that it was a WhatsApp vulnerability (Pegasus?) but I’d still like to know more about the device.

Office of the High Commissioner for Human Rights report confirms it was iOS (page 2)

https://www.ohchr.org/Documents/Issues/Expression/SRsSumexFr...

more: https://www.ohchr.org/EN/NewsEvents/Pages/DisplayNews.aspx?N...

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#314

Earlier quoted context omitted.

I shudder to think what would have happened if Obama had ultimately refused to give up his personal phone, and every half-talented hacking group on the planet had pwned it six ways from Sunday—what a national security disaster that would have been! Oh wait

The Clinton server wasn't really interesting because she broke the rules...it was because the Chinese/whomever could grab stuff and the owners had plausible deniability.

There wasn't much classified stuff to grab, if the FBI report is to be believed.

https://www.grassley.senate.gov/sites/default/files/document...

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#315
post #296

Earlier quoted context omitted.

Outside Signal app, if e.g. I incorporate the protocol to my own app via the provided source code, am I prevented from leaking keys?

Exactly what is your point? Durov is talking about Signal, not some hypothetical application you came up with to leak keys.

Wasn't he talking about WhatsApp that integrates Signal protocol? Asking if integrating protocol allows the "host" app to leak keys is completely valid.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#316

Earlier quoted context omitted.

As an engineer that has basic permissions to our build and deployment system (unrelated non communication application) I could pretty easily think of multiple steps in the build where I could inject and link in pretty much arbitrary code. For instance, anything that can hook directly on a build machine, or artifact upload, or even just simply precompiled into one of the black-box 3rd party dependencies that basically…

Is the "our" you're referring to Whatsapp? If not, then I'm not sure how much we can derive from your experience. There are places that take build and deployment security much more seriously than what you're describing.

My point specifically is that by increasing build and deployment security. You actually are decreasing the amount of people who can potentially review and audit the build. Thus making it more likely that someone in power could introduce a backdoor that nobody else in the large org knows about.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#317

Earlier quoted context omitted.

Is the "our" you're referring to Whatsapp? If not, then I'm not sure how much we can derive from your experience. There are places that take build and deployment security much more seriously than what you're describing.

My point specifically is that by increasing build and deployment security. You actually are decreasing the amount of people who can potentially review and audit the build. Thus making it more likely that someone in power could introduce a backdoor that nobody else in the large org knows about.

I don't think that's true? Increasing build security is about limited the number of folks who can modify the process. That's orthogonal to auditability.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#318
post #291

Earlier quoted context omitted.

“Only a little bit murdery” - op

No matter how I try to balance: "these are people who are killers and venally evil in nearly every sense of the word" and "But they are still intelligent and because they aim to maintain their significant power, they have to act in a measured, limited way that still involved logic and allows most 'little people' to go about their business AND we need to understand logic of these things BECAUSE these people influence…

Relax I was just joking - I get what you’re trying to say

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#319
post #285

Apparently I’m the only person on earth who wants to know what kind of phone Bezos was using, which OS version, etc. It seems like this detail is conveniently being left out of every story. Anyone have any additional details? I understand that it was a WhatsApp vulnerability (Pegasus?) but I’d still like to know more about the device.

iphone X A1901. Hacked by Al Qahtani and co. soon after the video was sent, the egress on the iphone has increased astonishingly to 29000 %.

Re: Jeff Bezos's phone 'hacked by Saudi crown prince'

#320
post #188
post #110

Earlier quoted context omitted.

If you aren't a high profile target, you may not be worthy of being targeted specifically. Of course, as in the Ashley Madison and Equifax cases, you might be compromised along with thousands of others. Zero days are expensive for individuals and small companies, but what happens when state actors are involved?

>If you aren't a high profile target, you may not be worthy of being targeted specifically. That's what I am questioning. There are many sysadmins, key executives in tech companies, or open source contributors who may not be "high profile" in the traditional sense but be juicy targets. Arguably there are more useful targets to hack than a CEO who's assuming their every move is being studied and always keeps truly sen…

Some CEOs have “cube” as their password and got their company hacked. Please don’t say who, but it happens.
Post reply on HN