3 ms·
I think there is some bit of over-simplification in the argument that just because video can't be decrypted, it is likely benign. The acknowledgement of a buffe
by bhaavan 7y ago
I think there is some bit of over-simplification in the argument that just because video can't be decrypted, it is likely benign.
The acknowledgement of a buffer overflow exploit by facebook through a CVE (https://www.facebook.com/security/advisories/cve-2019-11931 https://www.facebook.com/security/advisories/cve-2019-11931) points to a definite vulnerability in Whatsapp which can be abused through a video.
Timeline wise, it seems highly likely that it could have been abused.
- mirimir 7y agoSure. But the point is that the file could have been decrypted by this approach. And it wasn't done, even though the data was available in the backup. Unless there's something wrong with the approach described in TFA.
- ealexhudson 7y agoI don't think the article is making a great argument the video is benign; however, they're making a decent argument that the investigation was incomplete and doesn't present any non-circumstantial evidence of Saudi involvement. Like you say, the CVE is interesting, and I don't think there's a public description of the flaw. The article doesn't actually analyse the video: which is a bit odd since they are able to decrypt it. If the flaw is a buffer overflow in the MPEG stream parsing, it appears it would be reasonably easy to demonstrate that the MP4 file in question had been specially crafted, even if you couldn't directly demonstrate the exploit....
- mirimir 7y agoNo, they couldn't decrypt the file on Bezos' phone. Because they don't have the phone, or even the file. TFA actually says that clearly: > Remember that this example is a video a friend sent to me, and not the original video sent by MBS to Bezos. But the same principle applies. Simply look in that file in the backup, extract the URL and mediakey, insert into this program, and you'll get that file decrypted. What they've demonstrated is a method that should work on Bezos' phone. Edit: OK, I see that they get the encrypted file from the WhatsApp server: > mediaurl = https://mmg-fna.whatsapp.net/d/f/[string].enc https://mmg-fna.whatsapp.net/d/f/[string].enc So might the Saudi file in question have been deleted from WhatsApp? Could the Saudis have done that?
- ealexhudson 7y agoWhatsApp themselves may have deleted it, who knows. I guess the point is, they claim to have the file, but haven't attempted to analyse it. I don't think anyone was claiming it wasn't video - it plays in the app, so clearly the majority of the data is indeed regular MPEG. And it's difficult to prove that an exploit _isn't_ present, especially if the payload could be hidden in the video stream (since you could control the video frames, you can likely hide a significant amount of data before you need to resort to actual steganography). But, given the claim (that a remote exploit was used to gain C&C over the phone), there must be _something_ odd in there: metadata that doesn't make sense, frames of video not used, etc. - because there's an overflow (which probably means some byte index or something in the metadata is bad) and an exploit (there's a payload in there making use of the overflow). At the very least, some regular software like ffmpeg will complain during decoding that stuff doesn't make sense.