42 ms·
WhatsApp voice calls were used to inject spyware on phones
- rhamzeh 7y agoNon-paywalled article on this: https://9to5mac.com/2019/05/13/whatsapp-vulnerability-israeli-spyware/ https://9to5mac.com/2019/05/13/whatsapp-vulnerability-israel...
- mcintyre1994 7y agoAlso BBC one: https://www.bbc.co.uk/news/technology-48262681 https://www.bbc.co.uk/news/technology-48262681
- neonate 7y agohttp://archive.is/kDz13 http://archive.is/kDz13
- ngold 7y agoYou the real mvp. Thanks.
- kristofferR 7y ago1.1.1.1 mirror: https://archivecaslytosk.onion.pet/kDz13 https://archivecaslytosk.onion.pet/kDz13
- Theboda 7y agoThanks!
- forgotmypw3 7y agoWhatsApp voice calls used to inject Israeli spyware on phones Messaging app discovers vulnerability that has been open for weeks NSO's Pegasus software can allegedly penetrate any iPhone via one simple missed call on WhatsApp Mehul Srivastava in Tel Aviv MAY 13, 2019 Print this page A vulnerability in the messaging app WhatsApp has allowed attackersto inject commercial Israeli spyware on to phones, the company and a spyware technology dealer said. WhatsApp, which is used by 1.5bn people worldwide, discovered in early May that attackers were able to install surveillance software on to both iPhones and Android phones by ringing up targets using the app’s phone call function. The malicious code, developed by the secretive Israeli company NSO Group, could be transmitted even if users did not answer their phones, and the calls often disappeared from call logs, said the spyware dealer, who was recently briefed on the WhatsApp hack. WhatsApp is too early into its own investigations of the vulnerability to estimate how many phones were targeted using this method, a person familiar with the issue said. As late as Sunday, as WhatsApp engineers raced to close the loophole, a UK-based human rights lawyer’s phone was targeted using the same method. Researchers at the University of Toronto’s Citizen Lab said they believed that the spyware attack on Sunday was linked to technology developed by NSO, which was recently valued at $1bn in a leveraged buyout that involved the UK private equity fund Novalpina Capital. NSO’s flagship product is Pegasus, a program that can turn on a phone’s microphone and camera, trawl through emails and messages and collect location data. NSO advertises its products to Middle Eastern and Western intelligence agencies, and says Pegasus is intended for governments to fight terrorism and crime. In the past, human rights campaigners in the Middle East have received text messages over WhatsApp that contained links that would download Pegasus to their phones. WhatsApp said that teams of engineers had worked around the clock in San Francisco and London to close the vulnerability. It began rolling out a fix to its servers on Friday last week, WhatsApp said, and issued a patch for customers on Monday. The US Department of Justice has also begun looking into the situation. “This attack has all the hallmarks of a private company known to work with governments to deliver spyware that reportedly takes over the functions of mobile phone operating systems,” the company said. “We have briefed a number of human rights organisations to share the information we can, and to work with them to notify civil society.” NSO said it had carefully vetted customers and investigated any abuse. Asked about the WhatsApp attacks, NSO said it was investigating the issue. “Under no circumstances would NSO be involved in the operating or identifying of targets of its technology, which is solely operated by intelligence and law enforcement agencies,” the company said. “NSO would not, or could not, use its technology in its own right to target any person or organisation, including this individual [the UK lawyer].” NSO declined to comment on whether it had hacked WhatsApp’s messaging service, and marketed the technology to clients, or on the US DoJ inquiry. The UK lawyer, who declined to be identified, has helped a group of Mexican journalists and government critics and a Saudi dissident living in Canada, sue NSO in Israel, alleging that the company shares liability for any abuse of its software by clients. John Scott-Railton, a seniorresearcher at the University of Toronto’s Citizen lab, said the attack had failed. “We had a strong suspicion that the person’s phone was being targeted, so we observed the suspected attack, and confirmed that it did not result in infection,” said Mr Scott-Railton. “We believe that the measures that WhatsApp put in place in the last several days prevented the attacks from being successful.” Other lawyers working on the cases have been approached by people pretending to be potential clients or donors, who then try and obtain information about the ongoing lawsuits, the Associated Press reported in February. “It's upsetting but not surprising that my team has been targeted with the very technology that we are raising concerns about in our lawsuits,” said Alaa Mahajne, a Jerusalem-based lawyer who is handling lawsuits from the Mexican and Saudi citizens. “This desperate reaction to hamper our work and silence us, itself shows how urgent the lawsuits are, as we can see that the abuses are continuing.” On Tuesday, NSO will also face a legal challenge to its ability to export its software, which is regulated by the Israeli ministry of defence. Amnesty International, which identified an attempt to hack into the phone of one its researchers, is backing a group of Israeli citizens and civil rights group in a filing in Tel Aviv asking the ministry of defence to cancel NSO’s export licence. “NSO Group sells its products to governments who are known for outrageous human rights abuses, giving them the tools to track activists and critics. The attack on Amnesty International was the final straw,” said Danna Ingleton, deputy director of Amnesty Tech. “The Israeli ministry of defence has ignored mounting evidence linking NSO Group to attacks on human rights defenders. As long as products like Pegasus are marketed without proper control and oversight, the rights and safety of Amnesty International’s staff and that of other activists, journalists and dissidents around the world is at risk.” Copyright The Financial Times Limited 2019. All rights reserved.
- byron_wan 7y agoIs this the full FT article?
- tekknolagi 7y agoLooks like it, from the archive.is link above.
- macintux 7y agoNice of you to include the copyright line in your violation of same.
- galadran 7y agoInteresting! Google's Project Zero team investigated WhatsApp's and Facetime's video conferencing last year: "Overall, WhatsApp signalling seemed like a promising attack surface, but we did not find any vulnerabilities in it. There were two areas where we were able to extend the attack surface beyond what is used in the basic call flow. First, it was possible to send signalling messages that should only be sent after a call is answered before the call is answered, and they were processed by the receiving device. Second, it was possible for a peer to send voip_options JSON to another device. WhatsApp could reduce the attack surface of signalling by removing these capabilities." "Using this setup, I was able to fuzz FaceTime calls and reproduce the crashes. I reported three CVEs in FaceTime based on this work." WhatsApp: https://googleprojectzero.blogspot.com/2018/12/adventures-in-video-conferencing-part-4.html https://googleprojectzero.blogspot.com/2018/12/adventures-in... Facetime: https://googleprojectzero.blogspot.com/2018/12/adventures-in-video-conferencing-part-2.html https://googleprojectzero.blogspot.com/2018/12/adventures-in... In both cases, the close source nature of the applications stymied their efforts. Looks like NSO was willing to spend more time and resources!
- pvg 7y agoIn both cases, the close source nature of the applications stymied their efforts. Why do you say that? In the WhatsApp case, they were able to repeatedly modify the code and also yank it out and run it in their own controlled environment, etc.
- criley2 7y agoFrom my experience, working with real source from the repo with comments etc is very different than working with reverse engineered binaries. That's probably what they're referring to.
- pvg 7y agoThe post says "the close[d] source nature of the applications stymied their efforts" not "finding security bugs is harder than not-finding security bugs". I didn't read anything in the linked post that supports the former statement, the latter one (or variants) seems obvious.
- aaomidi 7y agoHow were they able to install spyware on iOS devices?
- deleted 7y ago[deleted]
- xenospn 7y agoSince there's no version information available, I think it's safe to assume they haven't been doing it on iOS for several years.
- thinkling 7y agoIt's not clear to me if you're right, but I would rephrase the issue this way: If there's a vulnerability in Whatsapp, the injected code should only affect Whatsapp. Otherwise, it's (also) a vulnerability in iOS.
- askvictor 7y agoOr Android devices for that matter; app code is sandboxed and signed, and requires user interaction to download any non store code
- wahern 7y agoThe secure enclaves on Android smartphones have a poor track record. Even the top-of-the-line manufacturers have seen published hacks of their TEE environments, and those are usually just the tip of the iceberg. Android is incomparable to Apple's platform in this regard. (I'm not trying to argue the iPhone is unhackable, though.) FWIW, I'm an Android user.
- bjourne 7y agoAll my life I've thought spyware was developed primarily by evil Russian and Chinese hackers. But apparently also by Israeli developers with their government's blessing and open endorsement. That's some very shady stuff. Before someone says something about government surveillance of fiber cables. Yes, that is also bad, but exploiting vulnerabilities to install spyware on peoples phones... It crosses yet another line that shouldn't ever be crossed.
- StanislavPetrov 7y ago>All my life I've thought spyware was developed primarily by evil Russian and Chinese hackers. You've led a very sheltered life if you think the Russians and the Chinese have been more evil than the Americans or the Israelis. I suggest reading history - a lot of it. When it comes to governments there are no good guys, only bad guys.
- dash2 7y agoI’ve read a lot of history. Your last statement is kind of fair. Your first statement is not. (Does eg US imperialism make Roosevelt no better than Hitler? Of course not.) The Russians and Chinese are doing many things worse than what the US does: Ukraine, the Uighurs.... Both are far less bound by the rule of law. Neither have any serious form of democracy. False equivalence is a specious but dangerous form of reasoning.
- StanislavPetrov 7y agoThe US has killed millions of people in the last 15 years alone in Iraq, Afghanistan, Libya, Syria, Yemen and a dozen other countries that we have bombed or invaded (including the 8 we are bombing right now). I'm under no illusions about the many despicable things done by the Russians and the Chinese, but its simply absurd to contend that their behavior has any worse than the United States. We have more of our citizens locked in cages than Russia and China combined. We have toppled more governments and invaded more countries than Russia and China combined by a factor of 10 (or more) since the end of World War II. Its astounding how willfully blind people can be when it comes to their own government. We can't become the good guys until people wake up and acknowledge that there haven't been any good guys.
- roywiggins 7y agoIt's not just the NSO group. Hacking Team is not exactly shy about the services they offer. https://en.wikipedia.org/wiki/Hacking_Team https://en.wikipedia.org/wiki/Hacking_Team FinFisher: https://en.wikipedia.org/wiki/FinFisher https://en.wikipedia.org/wiki/FinFisher MiniPanzer: https://en.wikipedia.org/wiki/MiniPanzer_and_MegaPanzer https://en.wikipedia.org/wiki/MiniPanzer_and_MegaPanzer
- wahern 7y agoYeah, there's a cottage industry of security firms who sell exploits to the U.S. government directly or indirectly through big defense contractors. Many, and I personally have assumed _most_ (but without checking), are American firms. And, frankly, the Israeli industry has much to gain by advertising their prowess in order to bolster their IT security bone fides internationally. American firms are probably more discrete, so tabulating widely published exploits by country of origin wouldn't be a great metric to determine which country is doing the most work crafting exploits.
- avip 7y ago>the Israeli industry has much to gain by advertising their prowess in order to bolster their IT security bone fides internationally Absolutely. The Israeli Cybersecurity brand is built partially on such (sometimes unsubstantial) PR. The bubble is doing well though! almost 500 startups, > 1Billion$ VC funding in 2018 alone. Devs are happy.
- golergka 7y agoCurious as to why you think it's a bubble. Israeli startups have had many successful exits in recent years, although mostly acquisitions, and not many big flops.
- avip 7y agoIt's just my unsubstantial opinion. Too many players raising too much money in a consolidated market. Bar some notable exceptions (NSO), this herd of misguided lemmings has one way out - acquisition by Checkpoint/Imperva/SalesForce. But maybe I'm wrong and we'll see 100 Mobileyes in the coming decade.
- darkestloud 7y agoNice to see Israel not only colonizing and occupying land, but supporting terrorist organizations that attack human rights advocates.
- agrapa 7y agoYou mean colonizing and occupying its own land. That would be like saying the Choctaw are occupying Florida.
- Paraesthetic 7y agoNice little bit of anti-Semitism there
- a-dub 7y agoMaybe that would explain the mysterious WhatsApp voice call I received about a week ago in the middle of the night from an unknown number? It's still in the history so maybe that means it didn't work?
- MagicPropmaker 7y agoAre you involved with anything that would make you think you'd be worth someone's time and money to be spying on? Most likely it was a wrong number.
- JacobHenner 7y agoWonder if this affects Signal, too.
- joecool1029 7y agoMy gut tells me no. Signal switched over to using the Signal Protocol for call signaling. It had used a few different signaling standards over the years (when it used to be called Redphone). However, it's impossible to really know for sure as the server component for calls is a proprietary black box.
- jtl999 7y ago> However, it's impossible to really know for sure as the server component for calls is a proprietary black box. I thought that changed after migrating to WebRTC? Although I haven't tried to spin up my own Signal server, modify the APK and see what works and doesn't work.
- cottsak 7y agoAgreed. It seems more plausible that the "injected code" would be limited to (1) the WhatsApp app, and (2) the infrastructure outside of the Signal Protocol implementation. If true, this still poses a problem to comms/calls secured end-to-end with the Signal Protocol impl - because once decrypted on the client, the rest of the WhatsApp may be compromised and able to exfil comms. I will be surprised, if this vuln allows the attacker control outside of the WhatsApp app sandbox to other parts of iOS. (I will be less surprised if the above is possible in Android)
- fxfan 7y agoIs there anybody here who doesn't install apps on their phones? I just use it for browsing and email.
- olivermarks 7y agohttps://www.zerohedge.com/news/2019-05-13/secretive-israeli-company-uses-whatsapp-voice-calls-install-spyware-phones https://www.zerohedge.com/news/2019-05-13/secretive-israeli-...
- sb057 7y agoThis is the same country that has a secret nuclear stockpile (developed in partnership with Apartheid South Africa) with plans to use the threat of bombing their European "allies" as blackmail. https://en.wikipedia.org/wiki/Samson_Option https://en.wikipedia.org/wiki/Samson_Option
- coreman 7y agoThe "Samson Option" is a conspiracy theory that if Israel is ever at the brink of destruction it will nuke Europe and America. It is a conspiracy theory based on the ramblings of one Israeli historian and one American author. Israel has nuclear weapons and its MAD policies are probably the same as other nuclear powers. It's funny because Putin has actually said that Russia will end up destroying the entire world in retaliation if Russia is ever attacked with nuclear weapons. But for some reason you don't see this quote get the same attention as the "Samson Option". ‘Why would we want a world without Russia?' Days later, he reiterated his stance, implying that nuclear war — a “disaster for the entire world” — would be a response to a major attack against Russia: “as a citizen of Russia and the head of the Russian state, I must ask myself: ‘Why would we want a world without Russia?'” ‘Why would we want a world without Russia?' https://www.japantimes.co.jp/opinion/2019/01/27/commentary/world-commentary/putin-and-the-apocalypse/ https://www.japantimes.co.jp/opinion/2019/01/27/commentary/w...
- lostlogin 7y ago> Israel has nuclear weapons and its MAD policies are probably the same as other nuclear powers. But with a much more controversial relationship with it neighbours, who’s land it illegally occupies and state policies that are compared to apartheid policies.
- lostmsu 7y agoMuch more controversial, than Russian? At least those poor folks in Palestine have an incompatible religion, which I could not say about Ukraine.
- thelittleone 7y agoI guess these types of vulnerabilities could be placed intentionally. It would allow certain agencies to again access via "exploit" and all the while claim they support user privacy. These companies are under pressure from governments (like the recent Australian government law to requiring access to encrypted messages). Seems like a decent solution for company and governments.
- bouncycastle 7y agoIt's not a decent solution, because it doesn't take much to find these vulnerabilities, just a matter of time.
- lixtra 7y agoBut time is enough. New bugs can be introduced with the next update.
- bouncycastle 7y agoThe update can be analyzed to see what was changed, even if we only have the binary executable. If we know that an app contains intentional bugs, just looking at where the update made changes could eliminate a lot of looking & find the bugs even faster! There are many automated tools that can do this too, eg. Fuzzing. The updates can also hint us where the previous bug was and what to look out for in the future. So, nope. Introducing security bugs and backdoors just makes it insecure for everyone.
- iforgotpassword 7y agoOh, so you are reverse engineering and thoroughly analyzing every WhatsApp update? That's reassuring. Cause otherwise I'd have said nobody does this on a regular basis which would mean it still is a viable method.
- gdfasfklshg4 7y ago
- sara7262 7y agoNow you can judge who is lying or who is telling the truth Just watch this and save yourself from others https://howto105.blogspot.com/2019/03/detect-lie1.html https://howto105.blogspot.com/2019/03/detect-lie1.html Love between lion and man See in video how much they are taking care of each others http://bit.ly/2Yh5oBe http://bit.ly/2Yh5oBe Very funny pets video of 2019 Just watch I am sure you can't control your laugh http://bit.ly/2E1UsQs http://bit.ly/2E1UsQs Love of elephant With human,see this video http://bit.ly/2Jg49Pp http://bit.ly/2Jg49Pp
- seattlebarley 7y agoOy vey!
- WC3w6pXxgGd 7y agoAnd nobody was surprised.
- accountwhatever 7y agoWhy was the word "Israeli" removed from the title?
- zaroth 7y agoOT, but scroll down with “showdead” and it should become apparent exactly why. It is HN trying to promote substantive discussion on the topic without devolving into flame war.
- coincite 7y agoWouldn't want to awaken any latent anti-semitism or have people start looking into Israeli spying operations on Americans like those covered in The Lobby.
- dang 7y agoI took it out because the thread was veering into generic flamewar about Israel. Actually we often remove country names from titles because they trigger people into making more nationalistic comments, which are equal parts indignant and boring.
- accountwhatever 7y agoOh, I see, that makes a lot of sense actually. Thank you for your service!
- dang 7y agoIt's not much of a service but I appreciate the kind words.
- anonymousDan 7y agoThat's a bit of a pathetic policy if you ask me. In my opinion a country who permits this type of behaviour shouldn't be shielded from the ensuing negative press. If anything it might encourage otherwise unaware citizens to put pressure on the government to do something about it.
- kurthr 7y agoThe title has been modified. WhatsApp voice calls used to inject Israeli spyware on phones
- dang 7y agoSure, we take out the baity parts of titles because they produce lousier discussion. This is standard HN moderation: https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html. See https://news.ycombinator.com/item?id=19906729 https://news.ycombinator.com/item?id=19906729 for more explanation.
- nomercy400 7y agoBut isn't it also baity to use 'used to'. My first reaction now was that Whatsapp itself has been inserting spyware into their phone calls, but no longer is (=used to), yet after reading the (non-paywalled) article I now see that a vulnerability in their signaling protocol has been used by others (=used to) to allow remote code injection. Removing the creator of the spyware part from the title now causes the blame of the spyware to shift to Whatsapp, which is incorrect.
- dang 7y agoOk, let's put a verb in there.
- bjourne 7y agoCursory Google searches seem to indicate that the same policy isn't applied for Chinese or Russian cyber threats. You also didn't remove the country name in other recent news, despite the production of even lousier discussion: https://news.ycombinator.com/item?id=19638357 https://news.ycombinator.com/item?id=19638357 https://news.ycombinator.com/item?id=19634570 https://news.ycombinator.com/item?id=19634570 The moderation is inconsistent.
- d0100 7y ago> The moderation is inconsistent When is it ever consistent...
- OrgNet 7y agoYeah, don't install any Facebook app... use the web if you need to use their service... same advice has always been true.
- EGreg 7y agoWe need open source software to decentralize large companies’ closed server farms and WhatsApp.
- codesr129 7y agoFor better or worse, we are living in a world that is going through a great consolidation of wealth and power. Israel is a major beneficiary of the fiscal consolidation that we see happening around the world. Currently, there are more multimillionaire households in Israel per capita than the United States, Britain, Canada, Sweden and even Denmark! As a United States citizen, it saddens me that our country is heavily focused on equipping and supporting a foreign entity that has been known to violate international laws and break their own agreements with the Palestinians (Oslo Accords) (Illegal Settlements in Internationally Contested Land). There is a long legacy of broken promises on behalf of Israel. Their reputation in the international community is bad for a reason, it is indeed an apartheid state and has been since its inception in 1948. As humans, I believe that we have a moral obligation to ensure that a basic level of quality of life can be enjoyed for ourselves. If we are fortunate enough to be blessed with an abundance of resources, then our obligation to ensure a basic level of quality of life can be attained for our neighbors as well. We see this natural progression very clearly in America and other countries. When an individual grew up in an impoverished neighborhood and eventually becomes a celebrity, they invariably elect to give back to the community, supporting their neighborhood and hoping to help others achieve a basic level of quality of life that we all as humans are entitled to. The responsibility that we have as humans to help others has and always will be held by the individual or country that is doing better off in terms of resources, knowledge, experience or financial variables. A change must happen for the betterment of humankind. It is not the Palestinians fault that they were subjected to a full-scale military invasion in 1948 followed by 70 years of humiliation and severely degrading living conditions. The Palestinians in Gaza are unable to travel by Land, Air or Sea, their basic human right of freedom of movement has been restricted. The living conditions are wretched as a result of many restrictions imposed by Israel. The United Nations has deemed Gaza uninhabitable due to poor drinking water and lack of electricity. Currently, the annual income per capita in Gaza is $1,826. It's my understanding that anything is allowed by some, as mentioned previously in this thread – boundaries are drawn with the intention of breaking them - these boundaries are both physical and abstract ones. I am sure that the intention would be to go much further than simply crossing boundaries but to rewrite the entire playbook.
- jpangs88 7y agoThis was behind a paywall, here is a similar article: https://www.bbc.com/news/technology-48262681 https://www.bbc.com/news/technology-48262681
- dbrgn 7y agoHere's an article without paywall: https://www.bbc.com/news/technology-48262681 https://www.bbc.com/news/technology-48262681
- joshlk 7y agoThe article is behind a paywall. Here is a BBC link: https://www.bbc.co.uk/news/technology-48262681 https://www.bbc.co.uk/news/technology-48262681
- deleted 7y ago[deleted]
- kmarc 7y agoI am not an expert on RCEs whatsoever but my limited knowledge / gut feeling tells me that one works by after a buffer overflow flipping some bits and * invoking syscalls * using (known) kernel vulnerabilities * libc bugs * exploiting buggy posix abstraction, etc. However, here all platforms seem to be exploited, regardless kernels (darwin/linux/windows), process models, libc implementations etc. I cannot unthink that this was simply doable because WhatsApp had already have code paths to place and run tasks/processes and this exploit works on this, higher level.
- SeriousM 7y agoPaywall, really?
- ezequiel-garzon 7y agoIt seems to me that if this is possible an OS software upgrade of some sort is urgently required, in addition to possible updates of WhatsApp. How come there isn’t coverage of this as Android and iOS vulnerabilities?
- floatingatoll 7y agoGaining control of WhatsApp gains access to any API accessible to WhatsApp. Incompetent reporting may be at fault. On Android, WhatsApp seeks a wide array of permission-controlled APIs. It does so on iOS as well. Once granted, the app has access to any data available through access-allowed APIs. App code goes through an audit process to ensure that the app isn’t using accessible APIs inappropriately, and doesn’t permit unapproved code execution. This vulnerability allows an attacker to execute unapproved code in the WhatsApp context. Any API that iOS or Android offer WhatsApp under normal circumstances is now attacker-controlled. The two questions unanswered by the press to date are simple. On iOS and on Android, can the attacker’s code be terminated by force-quitting and uninstalling WhatsApp? Either the attack is persistent only because it sets up shop inside the app, which may have OS-granted background and/or screen-off execution rights, and thus can be terminated simply by quitting and removing the app — or, the attack gains persistence beyond the confines of the app. Media reports are unclear on this point. If the OS offers apps endpoints that an app executing attacker-controlled code can use to infect the OS with persistent attack code that executes outside the app’s boundaries and remains after app uninstallation, then that’s absolutely a flaw in the design of the OS. As you say, “Android and iOS vulnerabilities”. Is this the case?
- iicc 7y agoDo you happen to know if upgrading the app would remove persistence (inside the app)?
- floatingatoll 7y agoWithout knowing how they infect the app? No, I cannot know.
- 7y ago
- whycomb 7y agoUpdated WhatsApp on my iphone just now. The version I got was 2.19.50. According to the CVE it's still vulnerable. Unable to get 2.19.51 which is the first fixed version. Is this just me? Or is everyone else updating to a still-vulnerable version?
- majjam 7y agoJust updated via UK iOS app store and its 2.19.50
- whycomb 7y agoYou're still vulnerable then. "Affected versions: ... WhatsApp for iOS prior to v2.19.51" from https://www.facebook.com/security/advisories/cve-2019-3568 https://www.facebook.com/security/advisories/cve-2019-3568 The news outlets are all telling us to update, but until WhatsApp/Apple get their act together, there's no point. Worse still, people won't realise they need to do it again and will remain vulnerable indefinitely.
- crucialfelix 7y agoI'm on Android. It auto-updated on May 10th to v2.19.134 "The issue affects WhatsApp for Android prior to v2.19.134"
- whycomb 7y agoThe problem is iOS AppStore. If you update via the "Updates" tab, you don't get the latest version. But if you search for WhatsApp as if installing it for the first time, then you get the new version.
- crucialfelix 7y agoYep sure, I was just reporting from the Android side since your comment caused me to go check.
- 7y ago
- billysielu 7y ago"update the app" is the sum of the advice? how about telling us how to check if this exploit was used, how to remove the spyware, etc?
- scraegg 7y agoI'm not sure what can be done nowadays. In the past you would say, format disks and go back to a backup before the threatening event happened. But nowadays all our stuff is in the cloud and you can only go back to the state from 10 minutes ago, and all our disks are flash drives that you can't fully format as an end user. Maybe you can just accept that some virusses will always be there and act accordingly.
- Scoundreller 7y agoSome of us do snapshot backups. Would be nice to have a tool that everyone on the planet could use to run against those backups and find a common source of the infections, along with an idea of when it was found in the wild.
- vardump 7y agoMy desktop WhatsApp on macOS is crashing pretty regularly, once every few days. Really makes me wonder if I'm being targeted using similar exploits.
- kuroguro 7y agoIt's probably the link preview preload. It can't handle certain sites and crashes almost instantly when trying to send a link.
- scraegg 7y agoWhat about Wechat? There are lots of seemingly pretty girls trying to voice or video call these days. Either I'm suddenly rich in their eyes or there's something fishy going on.
- toyg 7y agoThat’s the more traditional scamming/phishing, which has been going on since the days of ICQ...
- wil421 7y agoName a chat app and I can provide a link or comment from someone saying the same thing about pretty scam girls. Facebook, Whatspp, Gmail, Kik, Snapchat, Instagram, and even BBSes, AOL, IRC etc...
- scraegg 7y agoWhat I saw on FB is automatic replies from bots. What I know from Skype are african boys who try to earn their next beer in an internet cafe by acting they would be a girl. I can confirm it's all not that.
- 0898 7y agoJust to be clear – does this affect iPhone, or just Android?
- dschuetz 7y agoWhy is that even possible? It's horrifying that simple voice calls via an app allow that kind of attack.
- floatingatoll 7y agoCellular broadband modems are running a tiny OS that can be hacked by sending SMS messages with a carefully crafted NUL byte. Battlestar Galactica’s “no networking, no wireless” computer restriction exists for a very good reason.
- ricg 7y agoCan the WhatsApp-injected spyware escape the iOS App Sandbox?
- 1f60c 7y agoI was wondering the same. I would hope no, but even so, WhatsApp has plenty of permissions that make it a valuable target.
- lol768 7y agoCVE-2019-3568 suggests this was a buffer overflow. I'd like to understand why this was implemented in native code - Android seems to have an `android.net.rtp` package? Is this simply for performance, or to enable code-sharing across Android and iOS? Is there anything about WhatsApp's use-case that would prevent an implementation using managed code?
- auiya 7y agoAlso, what exploitation mitigations are broken on Android/iOS such that a buffer overflow is reliably exploitable? Are their implementations of ASLR useless? Is it trivially bypassed? Is mandatory code-signing not enabled/enforced?
- lol768 7y agoAll very good questions, hopefully we can get some more information as time progresses (maybe a PoC, or at least a technical write-up on the specifics)
- floatingatoll 7y agoIs Android.net.rtp available on every support Android and Google Library version combination that WhatsApp natively supports?
- lol768 7y agoAIUI, no. That package was added in Honeycomb (API level 12), whereas WhatsApp currently supports Gingerbread (API level 10). However, two API levels of compat. seems like a good trade to me in order to avoid an RCE.
- floatingatoll 7y agoHow many millions of users would be excluded if they chose that path, and are their controlling shareholders okay with that reduction of active users?
- anonymousDan 7y agoCan anyone advise on minimum version numbers containing the patch (on IOS and Android)?
- floatingatoll 7y agoListed here: https://www.facebook.com/security/advisories/cve-2019-3568 https://www.facebook.com/security/advisories/cve-2019-3568
- stunt 7y agoI wonder! Should we call it a vulnerability or a leaked backdoor? Besides, I think if it was from any other developer, probably it would be removed from the AppStore and force delete from user devices.
- ccnafr 7y agoI like it how Facebook doesn't mention anything in the WhatsApp changelog about this.
- cricalix 7y agoApple won't let you change a changelog after the binary is built and put on the store. So if you want to get a fix out, but not alert people that you're on to them, you have to put out a changelog that just says something like "Bugfixes". Then you have to build another build and submit another changelog, but Apple probably won't let you issue builds that are duplicates...
- jonplackett 7y agoIsn’t this also a screw up by Apple? Isn’t Sandboxing supposed to prevent this from getting any worse than hacking the app itself?
- floatingatoll 7y agoIsn’t every article about this saying it persists, without saying how or whether it’s a sandbox escape? If it just spins up bad code in WhatsApp space, that’s sufficient to spy on you.
- jonplackett 7y agoI'm sure I saw one say it infected the OS. I would like to know some more proper details too.
- auiya 7y agoUserspace isolation doesn't matter when the malware only cares about what's in userspace.
- Yuval_Halevi 7y agoWhatsApp belongs to Facebook Some of the largest data breaches in the last few years related to facebook and yet They continue do whatever they want GDPR made no difference at all... Only hurt the small-medium business FB, Google, Aamazon just keep doing whatever they want, protected by army of lawyers
- throwawawawawa 7y agoFor better or worse, we are living in a world that is going through a great consolidation of wealth and power. Israel is a major beneficiary of the fiscal consolidation that we see happening around the world. Currently, there are more multimillionaire households in Israel per capita than the United States, Britain, Canada, Sweden and even Denmark! As a United States citizen, it saddens me that our country is heavily focused on equipping and supporting a foreign entity that has been known to violate international laws and break their own agreements with the Palestinians (Oslo Accords) (Illegal Settlements in Internationally Contested Land). There is a long legacy of broken promises on behalf of Israel. Their reputation in the international community is bad for a reason, it is indeed an apartheid state and has been since its inception in 1948. As humans, I believe that we have a moral obligation to ensure that a basic level of quality of life can be enjoyed for ourselves. If we are fortunate enough to be blessed with an abundance of resources, then our obligation to ensure a basic level of quality of life can be attained for our neighbors as well. We see this natural progression very clearly in America and other countries. When an individual grew up in an impoverished neighborhood and eventually becomes a celebrity, they invariably elect to give back to the community, supporting their neighborhood and hoping to help others achieve a basic level of quality of life that we all as humans are entitled to. The responsibility that we have as humans to help others has and always will be held by the individual or country that is doing better off in terms of resources, knowledge, experience or financial variables. A change must happen for the betterment of humankind. It is not the Palestinians fault that they were subjected to a full-scale military invasion in 1948 followed by 70 years of humiliation and severely degrading living conditions. The Palestinians in Gaza are unable to travel by Land, Air or Sea, their basic human right of freedom of movement has been restricted. The living conditions are wretched as a result of many restrictions imposed by Israel. The United Nations has deemed Gaza uninhabitable due to poor drinking water and lack of electricity. Currently, the annual income per capita in Gaza is $1,826. It's my understanding that anything is allowed by some, as mentioned previously in this thread – boundaries are drawn with the intention of breaking them - these boundaries are both physical and abstract ones. I am sure that the intention would be to go much further than simply crossing boundaries but to rewrite the entire playbook.
- deleted 7y ago[deleted]
- redskull 7y agoFT.com worst site in the world.. I thought you can't link things that require a subscription to read?
- leoh 7y agoSpooky. I just travelled to Israel and this evening, at around 3 AM, iOS notified me that WhatsApp had been accessing my location in the background, which I had never seen before except when sharing my location with a friend.
- TheSmoke 7y agois this how saudi activists were tracked or uae tapped the phones of govt officials from various countries?
- GMLOOKO 7y agoA
- oneluv1464 7y agoGREETINGS EVERYONE, are you looking for a LEGIT and Trustworthy HACKERS with 100% Guarantee, Fast Delivery in an hour and no Trace. contact Wizard at cyberwizard1995@gmail.com are the Best in any hacking Services. He's ready to render and attend to your job with swift response and No delay at all. I contacted him and he gave me access to spy my husband Instagram, whatsapp messages, what'sapp voice call and video calls, Text messages, Email, Facebook, phone Gallery and other social media, it was then I know my husband is on dating site. You can also text/whatsapp him at +1 662 727 5740. I introduced my friend to him he also repaired her credit score, she applied for $200k loan and it was approved.