3 ms·
Just checked if I was affected and happily I found I'd set every possible setting to private or disabled. I figure five eyes already had this information. I th
by cryptarch 9y ago
Just checked if I was affected and happily I found I'd set every possible setting to private or disabled.
I figure five eyes already had this information. I think they would have tools to decrypt all communications from any app, by using rooted phones that scan their own memory for common crypto libraries and then extract the keys.
On the initial run it would not know where to look, and the phone would be set up to go through a proxy that blocks all non-decryptable communications, to avoid detection. A profile would be extracted to quickly and silently extract the keys from the phone's memory and subsequently send them to the decrypting proxy.
Then on the second run, the phone would be wiped/reset and the decrypting/blocking proxy would attempt to decrypt the communications that are now extracted from the phone in real-time. The wipe functions to avoid detection (it makes it look like the phone is simply crashing). Perhaps the wipe would include changing some device ID's and the source IP.
Rinse, repeat until only decryptable signals leave the phone.
(Something similar could be done with stubbing the encryption code in memory and then "moving" it to the proxy.)
Either based on virtualization tools or on memory inspection. Or perhaps ring -1 based.
The kind of tool I wish every techy had, so they could easily discover what their apps are really doing.
I've seen footage, I stay noided, I've seen footage, I stay-
Edit: If you know of similar or related tooling, please let me know! I want this software.
- jmanderley 9y agoYou are affected: There's no way to disable the "online" status display when the app is opened in WhatsApp.
- julioneander 9y agoIf there was a way of tricking the app to think it is always online, the real status could be obfuscated. WhatsApp probably uses some Android and iOS API to know when it's open, tapping into that could confuse the app and make the online status pretty useless. LineageOS (previously CyanogenMod) had a Privacy Blocker or something like that, which you could block specific apps access to major APIs like Media Access, Phone ID Access, etc. It's been a while since I last used that, don't know if it still exists, but it sure helped my paranoia. It was fun seeing apps trying to access all sorts of stuff on my phone just to see them being denied access. Nice Death Grips reference btw.
- sandov 9y agoI think that rather than deny access, it feeded the app with randomly generated data.