Live data from Hacker News

WhatsApp voice calls were used to inject spyware on phones

ft.com

91–100 of 313 posts

Re: WhatsApp voice calls were used to inject spyware on phones

#91
post #63
post #12

Earlier quoted context omitted.

They managed to destroy Iranian nuclear centrifuges using a very sophisticated attack. Read up on Stuxnet. Also, as an Israeli, I can 100% confirm that Israelis have absolutely no issues with crossing any kind of boundary. The fact that others think that such a thing as "boundaries" exist only serves as an advantage.

I agree. Nobody should underestimate the Mossad: https://youtu.be/bJujIwtdk8w

From my favourite Usenix paper (https://www.usenix.org/system/files/1401_08-12_mickens.pdf):

Basically, you’re either dealing with Mossad or not-Mossad.

If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from ChEaPestPAiNPi11s@virus-basket.biz.ru.

If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT. The Mossad is not intimidated by the fact that you employ https://. If the Mossad wants your data, they’re going to use a drone to replace your cellphone with a piece of uranium that’s shaped like a cellphone, and when you die of tumors filled with tumors, they’re going to hold a press conference and say “It wasn’t us” as they wear t-shirts that say “IT WAS DEFINITELY US,” and then they’re going to buy all of your stuff at your estate sale so that they can directly look at the photos of your vacation instead of reading your insipid emails about them.

And:

Threat: The Mossad doing Mossad things with your email account

Solution: Magical amulets? Fake your own death, move into a submarine? YOU’RE STILL GONNA BE MOSSAD’ED UPON

(That's perhaps a little too light-hearted humor, considering the youtube link in the post I'm responding to...)

Re: WhatsApp voice calls were used to inject spyware on phones

#92
post #5

Interesting! Google's Project Zero team investigated WhatsApp's and Facetime's video conferencing last year: "Overall, WhatsApp signalling seemed like a promising attack surface, but we did not find any vulnerabilities in it. There were two areas where we were able to extend the attack surface beyond what is used in the basic call flow. First, it was possible to send signalling messages that should only be sent after…

NSO wasn't the group that did the WhatsApp hack. They are the software the hacker installs after they exploit has been found.

Re: WhatsApp voice calls were used to inject spyware on phones

#93
post #38

Earlier quoted context omitted.

Or Android devices for that matter; app code is sandboxed and signed, and requires user interaction to download any non store code

The secure enclaves on Android smartphones have a poor track record. Even the top-of-the-line manufacturers have seen published hacks of their TEE environments, and those are usually just the tip of the iceberg. Android is incomparable to Apple's platform in this regard. (I'm not trying to argue the iPhone is unhackable, though.) FWIW, I'm an Android user.

The Pixel 3 has a "Titan M" chip with much reduced attack surface compared to the TEE. Don't otherwise know much about it.

Re: WhatsApp voice calls were used to inject spyware on phones

#95

Earlier quoted context omitted.

I think you don’t know much about apartheid or the situation in Israel / Palestine to compare the two.

Both of us can say this, it’s unproductive. The situation in Israel and the occupied territory is grossly unfair.

By occupied territory I assume you're referring to USA, Canada, Australia, as well as any other country in the Western Hemisphere.

Re: WhatsApp voice calls were used to inject spyware on phones

#96
post #7

All my life I've thought spyware was developed primarily by evil Russian and Chinese hackers. But apparently also by Israeli developers with their government's blessing and open endorsement. That's some very shady stuff. Before someone says something about government surveillance of fiber cables. Yes, that is also bad, but exploiting vulnerabilities to install spyware on peoples phones... It crosses yet another line…

I would be shocked if any moderately wealthy government hasn't crossed that line. This is child's play for cyber warfare.

Re: WhatsApp voice calls were used to inject spyware on phones

#97
post #36

Earlier quoted context omitted.

Wow! I had no idea there was a whole industry selling spyware to dictatorships. Surveillance equipment, yes, but not actual hacking tools. Really sickening. Must be why governments in Europe are so afraid of Huawei building 5G networks - they will only run Chinese spyware.

It's not that much different from mercenary outfits like The Company Formerly Known As Blackwater. They offer services to all sorts of unsavory regimes. Hackers for hire are just another iteration on the idea.

No, it is very much dissimilar. Security personnel who work for Blackwater make a conscious decision to do so and are flown overseas to physically enact Blackwater's business decisions. Many (maybe most?) of the people who sell vulnerabilities and (to a lesser extent) exploitation tools to spyware firms are selling through brokers, and aren't directly connected to the ultimate end purpose of their work.

You can say that people who sell vulnerabilities to unaffiliated-seeming, neutral-seeming, innocuous-seeming brokers ought to know better where their work is going to end up, and I suppose that's true, but it's still not the same dynamic as exists with Blackwater.

Re: WhatsApp voice calls were used to inject spyware on phones

#98
post #75

Earlier quoted context omitted.

It's not a decent solution, because it doesn't take much to find these vulnerabilities, just a matter of time.

But time is enough. New bugs can be introduced with the next update.

The update can be analyzed to see what was changed, even if we only have the binary executable. If we know that an app contains intentional bugs, just looking at where the update made changes could eliminate a lot of looking & find the bugs even faster! There are many automated tools that can do this too, eg. Fuzzing. The updates can also hint us where the previous bug was and what to look out for in the future.

So, nope. Introducing security bugs and backdoors just makes it insecure for everyone.

Re: WhatsApp voice calls were used to inject spyware on phones

#99

I guess these types of vulnerabilities could be placed intentionally. It would allow certain agencies to again access via "exploit" and all the while claim they support user privacy. These companies are under pressure from governments (like the recent Australian government law to requiring access to encrypted messages). Seems like a decent solution for company and governments.

Do a Google search for "underhanded C contest".

Re: WhatsApp voice calls were used to inject spyware on phones

#100
post #7

All my life I've thought spyware was developed primarily by evil Russian and Chinese hackers. But apparently also by Israeli developers with their government's blessing and open endorsement. That's some very shady stuff. Before someone says something about government surveillance of fiber cables. Yes, that is also bad, but exploiting vulnerabilities to install spyware on peoples phones... It crosses yet another line…

I remember when "spyware" was just malicious advertising programs designed to sell your browser history + replace ads.

(Eg: https://en.wikipedia.org/wiki/CoolWebSearch)

The MySpace era was a simpler time...

Post reply on HN