Jeff Bezos's phone 'hacked by Saudi crown prince'
theguardian.com
theguardian.com
If that were true, Bezos's case would be an example of how that approach to security is double-edged. Backdoors can be just as useful to foreign intelligence as they are to whoever pushed for their implementation.
Also, FWIW we know that Google did this with its data center breach and likely many other cases.
At WhatsApp/Google scale the attack is extremely cost effective.
My point is that all indications point to Google being unbelievably cooperative with the US Government, essentially allowing whatever legal or extralegal (per Snowden) back doors were requested.
It is not much of a leap to conclude that Google was both aware and cooperative with the harvesting of unencrypted traffic. This does not mean that all employees were aware of it.
The analysis should be to discover how few employees would have had to be complicit for the attack to be carried out successfully.
There is no way that such an attack would succeed if too many were aware, since it is obviously in the extralegal (Snowden revelation) category, and since most Google employees are ethical humans, it would have provoked outrage if widely known.
[1] https://www.zdnet.com/article/meet-muscular-nsa-accused-of-t...
There is not really any fundamental difference between abetting the data center breach and opting not to offer warrant canaries. Likely tens of thousands of Google users are searched every day due to easy FISC warrants and wide investigative nets.
The state sponsored attacks on Google would of course allow Google to plausibly deny cooperation, but obviously Google has every incentive to cooperate fully, as is evidenced by the lack of warrant canaries.
A person on StackExchange put it well
> The distinction between revealing the existence of the subpoena by action, rather than by inaction, is a false one. It's exactly the kind of cutesy legal formality that non-lawyers love to rely on, but real judges ignore. If you tell someone: "Hey, you know John Smith's three sons, Joe, Ted, and Bill? Joe and Ted are good people; they have never molested any children. As for Bill--well, I don't have anything to say about Bill." If Bill is not a child molester, you have defamed him, and you are not going to convince a judge otherwise. [1]
Here's how the EFF puts it.
> Are there any cases upholding warrant canaries?
> Not yet. EFF believes that warrant canaries are legal, and the government should not be able to compel a lie. To borrow a phrase from Winston Churchill, no one can guarantee success in litigation, but only deserve it.
I'm also not sure how warrant canaries relate to your parents' point.
The same applies to declining to cooperate with government surveillance operations. We don't really know how the government likes it when a big company obstructs its surveillance goals.
On HN today was a headline about Apple reversing course on a business decision voluntarily, simply to please government.
> I'm also not sure how warrant canaries relate to your parents' point.
The points above I believe link the two business decisions.
Doing it this way you only really have to control a core part of the release team to hide the slight of hand between the published version and the clean 'published' version.
Alternatively just bury the same thing deep in the codebase using techniques like people use for the Obfuscated C competition every year. Any changes could be delayed/deprioritized/handled by a team in the know about the backdoor.
Just underfund the security department, don't adopt systems/languages that prevent the worse bugs, and keep the core protocol proprietary.
On the other side let the governments invest in operations to hack the product.
For instance, anything that can hook directly on a build machine, or artifact upload, or even just simply precompiled into one of the black-box 3rd party dependencies that basically never get recompiled.
All of these mechanism have vectors that would be easy to obfuscate and don't rely on any changes to any repo code. I think there is a good chance that a normal engineer could likely hide something that could make it into a final build product.
Now, combine that with the fact that even the most open of companies have some sort of protected infrastructure (Could be permissions on an S3 bucket, locked data-center or even just a locked away Cat-5 cable in the process. Someone high in the org could easily inject some process that could stay hidden from even the most prying of internal eyes.
Now, while I agree that it's a bit tinfoil-hat-y to believe that this actually -is- happening. I absolutely believe that the technical capability is both there and well within practical effort. And combine this with a few bad incentives it's easy to see how it -could- happen.
I'd also say it's not completely unrelated. Let's consider a hidden build machine process. Once you've hidden that, preventing modifications to the build process by people "not in the know" makes it much less likely that said process can be discovered (either on purpose or accident) If everyone can and does have full access to those build machines it increases the likelihood that someone making a modification could run into said process.
These are not any individual who would do deliberately. I bet these conversations go differently for ex need to certain kinds of debugging vs the improbability of actually pulling off an attack or prioritising a release dealing and making a design decision to implement a feature in a specific way which is intended to be updated later on opening up windows for attack. They would genuinely be improbable unless someone knows that they are there and committed enough to try.
Vulnerabilities will appear and be discovered by the security analysts in your government.
Whey they suspect other countries have the same 0days they'll notify you of it and you fix it.
> The encryption of Signal (=WhatsApp, FB) was funded by the US Government. I predict a backdoor will be found there within 5 years from now.
He seems to enjoy throwing out loosly supported accusations. He might be right in some of them, but stopped clocks and so forth.
He's also been accused himself of deliberately sabotaging the security of his own encrypted messenger app (Telegram). There's no real evidence, but he did hire a bunch of math PhDs to figure out encryption from first principles
> The team behind Telegram, led by Nikolai Durov, consists of six ACM champions, half of them Ph.Ds in math. It took them about two years to roll out the current version of MTProto. Names and degrees may indeed not mean as much in some fields as they do in others, but this protocol is the result of thougtful and prolonged work of professionals. [1]
Note: Signal, like TOR, is funded in part by the Open Technology Fund of Radio Free Asia, which is controlled and funded by Congress. So far there has been no public evidence that this funding has come with any malicious strings. The stated goal of the fund is to promote democracy in developing countries, and Signal and TOR are obviously in line with that overt goal. Radio Free Asia used to be a CIA front during the Cold War, but there's been no public evidence that the transfer of control away from the CIA to Congress was in any way a sham.
[0]: https://techcrunch.com/2017/09/18/signal-moxie-marlinspike-t...
Any suggestion that Telegram's cryptography is somehow comparable owing to "half of them Ph.D's in math", or that Signal's extensively-reviewed cryptography is backdoored, is pretty clearly risible.
OTF, meanwhile, funded basically the whole of the privacy-preserving cryptography field, for years (they may still, for all I know); for many years, they were simply throwing money at privacy projects to hire 3rd party auditors, none of whom were at all affiliated with OTF (how I know this is that we participated). People who claim OTF is somehow a snakey USG backdooring enterprise are saying more about themselves than they are about any kind of sophisticated understanding of how crypto software is built.
And for the paltry $200k they are offering for breaking it I'd bet you could find a magnitude more with little effort on the grey markets.
But no, absolutely no proof the underlying crypto has been broken. It doesn't need to be when government requests for data stored on their servers does more than enough.
So far, Roskomnadzor has "no urgent request" to include Viber and WhatsApp messengers in the register of organizers and distributors of information. According to Interfax, this was stated by the head of the Department, Alexander Zharov. He was asked when these companies will be included in the register. "We had a stormy substantive dialogue with the telegram messenger," the official recalled. "We are consulting with all other companies on this topic until there is an urgent request to include them in the register."
Maybe gn. Zharov uses whatsapp for chatting with his family and they didn’t like the appearance of mail.ru’s tamtam.chat.
* Group chats can only use the default encryption, not end to end encryption.
* The end to end encrypted chats are tied to a single device, and there's no sync across devices (in contrast, all chats on Wire are end to end encrypted and sync across devices within a limited time period).
The default use cases of almost all users has the chat messages stored in plain text on the Telegram servers. This is one of the reasons search (done on the server side) is quite fast on Telegram.
P.S.: Despite these limitations, I prefer Telegram for its superior UX and for not having metadata shared with Facebook. My wish is that someday Telegram makes E2E the default everywhere.
When this design flaw came to be known, Telegram released a newer version where the user has more control on who can know that they're on Telegram. With that change, even if you had someone's number in your contacts list, you wouldn't know if/when they join/are available on Telegram unless they choose to make themselves visible.
E: Well, I took a look at the desktop client with wireshark. It appears to just do MTProto on port 443, not TLS. When I use iptables to drop traffic on port 443, it falls back to MTProto over HTTP(!).
They list some alternate transports on their website, but it looks like you need to host them yourself. https://core.telegram.org/mtproto/transports
I reminisce that when Durov was questioned about the abscence of secure connection to the servers, he told it's a too much of overhead and may impact QoS badly.
Some time they rolled out an `always use https` option and buried it deep in the user preferences. Meaning most of non-tech savvy audience kept using the service unaware they are not secure.
The obvious pattern here is they tend to use plain http as a default transport unerminig established security practices.
[0] https://translate.google.com/translate?sl=auto&tl=en&u=https...
Could you expand on their usage of TLS and HTTP? Surely they don't send anything in plain-text over HTTP?
I thought they used TLS wrapping in some markets for censorship resistance, but apparently that is not the case unless you set up your own proxy.
You of all should know better than to conflate the general concept of encryption with the very nice special case that is end-to-end encryption!
> and 1:1 E2E is disabled by default.
It is not disabled in any way. It just isn't default.
There are really enough real reasons to criticize Telegram, absolutely no reason to 1. redefine words to have narrower definitions 2. Write outright misinformation.
I respect you a whole lot but your somewhat sloppy handling of facts detract a whole lot from the overall image.
While there's only one vuln that have been discussed publicly at HN. The only issue is they are in russian as well.
At least one more was exposed[0] by the same person shortly after, i mean days after the initial. Over here[1] the same researcher wonders whether any other flaws exist.
And here's[2] how the self-proclaimed `part time-troll` Pavel Durov (the Telegram CEO) reacts to [1]. To me it's obvious he is being haugty towards HN community with `venerable HN cryptographers`.
To add to his general slandering approach towards competition while handling own product flaws without any transparency and publicity mind his company is now under investigation by SEC[3].
[0] https://translate.google.com/translate?sl=auto&tl=en&u=https...
[1] https://translate.google.com/translate?sl=auto&tl=en&u=https...
[2] https://translate.google.com/translate?hl=&sl=ru&tl=en&u=htt...
[3] https://www.natlawreview.com/article/let-slip-dogs-war-sec-v...
There is zero compelling reason to believe that signal is uniquely flawed.
Open source vs closed source is not meaningful here.
From my understanding, TOR was created with the intent of hiding US intelligence communications[0]. From my naive understanding, this only works if 1) no one else can back door it (which is critical since it is presumed you're using it to hide from highly technical state actors) 2) there are a sufficient number of users that are not intelligence actors (so you can hide among them. Otherwise you get "Oh, that person connected to a TOR node, let's go pick them up and grab their computer").
Maybe I'm naive, but it seems like the crypto people and the US government have aligned interests here.
> The stated goal of the fund is to promote democracy in developing countries
With an additional alignment of interests, I think many believe that being able to "talk shit" on your leaders is a key part to democracy. And if you're able to do this without fear of your government coming after you (aka: backdoors), then you will freely acknowledge your dissent, find support, and democracy is the likely outcome. I'm not sure if that's true, but I've definitely heard intelligence people suggest that.
So even if it was controlled by the CIA, would this be an issue? It seems like it is actively in their best interest to use real encryption and no backdoors. You don't want all your potential rebels to get caught. You want them to be able to organize out of the eyes of the government that the CIA is trying to overthrow. Having a backdoor just puts a timebomb on it, and one that isn't going to last very long.
Or I guess there's another answer to this. The CIA is pretty fucking dumb. Which is a reasonable answer that I'll accept too, but I think the people working on this stuff would be well aware (since they're probably experts in hacking similarly encrypted systems)
https://support.torproject.org/about/why-is-it-called-tor/
Note: even though it originally came from an acronym,
Tor is not spelled "TOR". Only the first letter is
capitalized. In fact, we can usually spot people
who haven't read any of our website (and have
instead learned everything they know about Tor from
news articles) by the fact that they spell it wrong.does the theory suggest that US DoJ does not know how to exploit these backdoors, but other agencies (CIA/NSA, foreign intel services) do?
If anything there's incentive to do so even if they do, in creating plausible deniability.
> To protect the data that is not covered by end-to-end encryption, Telegram uses a distributed infrastructure. Cloud chat data is stored in multiple data centers around the globe that are controlled by different legal entities spread across different jurisdictions. The relevant decryption keys are split into parts and are never kept in the same place as the data they protect. As a result, several court orders from different jurisdictions are required to force us to give up any data.
https://telegram.org/faq#q-do-you-process-data-requests
If we register Telegram, Telegram has our master key. I am not sure they are really that secure. Yes, it makes politically hard to disclose any data, but it does not mean impossible.
OLD COMMENT:
E2e using a client that is not opensource (on a system that is not trusted) is not helping much.
E2e where the server is not open source should be okay, because the server-end can only snoop on some meta data (how much, when, what IP, chunk sizes, etc.) but not the content.
This has been obvious in places like the United Arab Emirates (aka Dubai) where services like FaceTime etc. (sometimes even voice chat in games) are blocked by the government but they allow WhatsApp (but not WhatsApp voice calls).
Not a big problem if you're the top dog and most foreign countries can't do much in practice even if they have the intelligence...
I don't think "I would have gotten away with it!" is a compelling argument, but I'm not a Scooby Doo villain.
The comments about timing, malice, financial consequences, etc., are all fair for making a case that the hacks and leaks are scummy, but the Bezos's are in charge of their own relationship, or lack thereof.
That, or it was a favour to MBS American friends. The other people involved (David Pecker et al) and MBS do share a few friends in the White House, who also seem obsessed with the Washington Post and Bezos himself.
https://www.thedailybeast.com/how-trumps-fixers-silenced-sto...
I'm not sure I understand your comment
Khashoggi is was not simply a journalist but a member of an influential family with Saudi Arabia [1]. MBS has dealt quite brutally with a variety of his internal opponents without Saudi Arabia. Murdering Khashoggi was something of a statement that MBS wouldn't let his direct opponents escape to other countries to oppose him.
To be clear, the murder was a horrific act by a brutal theocratic regime, I'm not noting these factor to condone it in any way but merely to give background.
[1] For example, this Khashoggi was a relative of Adnan Khashoggi, once know as the world's largest arms dealer.
No matter how much I couch and balance my words, there's always someone ready to jump in with the crude simplification. Frick-off, jeesh.
And to further clarify, the Saudis don't murder exiles, in particular, wholesale. They do murder the Houthas and several other groups wholesale.
Or MBS massively miscalculated. I can't imagine being Lord Emperor gives you many opportunities for people to tell you you're wrong about stuff
We should be indicting MBS.
If anything, it's more plausible to have been directed by the President (though it probably wasn't) than for any consequences of these actions to come from this administration (which certainly won't happen).
You’re not going to get any investment from Saudi Arabia that doesn’t go through him.
It lacks both jurisdiction as well as enforceability.
There is no global legal system. We are not a united planet.
There are a lot of possibilities here, what a wild story.
https://www.thedailybeast.com/mistress-lauren-sanchezs-broth...
I'm a little surprised Bezos fell for it. Video-triggered vulnerabilities are pretty rare and not something you'd normally be vigilant about, as are world leaders acting as APTs, but he still should've considered the possibility that a giant, powerful nation his ultra-influential newspaper covered might want to target him and would have the capability to do so.
He could've asked an Amazon security analyst to open the video in a sandboxed system, or could've just done so himself. I guess it just never crossed his mind that the (de facto) ruler of Saudi Arabia would phish him.
Hacking a phone is small potatoes.
Who are the bad guys again? Didn't watch the tele today, they usually tell me.
Also, how much of an amateur hacker would you have to be to launch an attack from your own personal device?
But I'm puzzled that Bezos would be corresponding with MBS on the same device that he uses for potentially embarrassing personal stuff. Isn't that just a totally obvious OPSEC fail?
Edit: But that's what he did, isn't it?
And how could that be considered safe?
The problem is that even the head of a ginormous company with a strong connection to computer security generally (through AWS) is going to take actions based on convenience rather than OPSEC discipline.
I think it's natural for any given human to chat with all one's friend on the same level, with the same device and so-forth. A given individual can train themselves to have hard walls in their personal dealings but I'd suspect that individual would be a mid-level specialist, not the owner/manager/CEO who gets their position by their ability to manage and connect with people, not through technical expertise.
I mean, I'd be gobsmacked if he mixed personal and business on the same devices. That could be disastrous, not just embarrassing. So a third device category doesn't seem unworkable.
Edit: Also, wouldn't someone like Bezos have security advisers? And how could they have failed to warn him?
One could make a similar argument about MBS, of course.
Of MBS doing his own spying and hacking is another way topmost people are becoming "do it yourself-ers".
https://www.grassley.senate.gov/sites/default/files/document...
Billionaires on the other hand...
https://en.wikipedia.org/wiki/Pegasus_(spyware)
https://citizenlab.ca/2019/10/nso-q-cyber-technologies-100-n...
https://citizenlab.ca/2018/06/government-spyware-surveillanc...
https://citizenlab.ca/2017/02/bittersweet-nso-mexico-spyware...
On one hand, zero days are rare and expensive.
OTOH someone who isn't the CEO of a major company might not notice the malware, or if they do, not know they should forward it to an organization like Citizen Lab.
really?
You use zero, someone notice, it gets fixed.
And yes, they are rare compared to the vast # of known vulns.
Ideally if given the choice, you'd utilize a known vuln against outdated software rather than risk burning your zero day.
Zero days are expensive for individuals and small companies, but what happens when state actors are involved?
That's what I am questioning.
There are many sysadmins, key executives in tech companies, or open source contributors who may not be "high profile" in the traditional sense but be juicy targets. Arguably there are more useful targets to hack than a CEO who's assuming their every move is being studied and always keeps truly sensitive conversations verbal.
Anyone have any additional details? I understand that it was a WhatsApp vulnerability (Pegasus?) but I’d still like to know more about the device.
1: https://www.vice.com/en_us/article/v74v34/saudi-arabia-hacke...
https://www.ohchr.org/Documents/Issues/Expression/SRsSumexFr...
more: https://www.ohchr.org/EN/NewsEvents/Pages/DisplayNews.aspx?N...
[0] https://nakedsecurity.sophos.com/2019/11/20/update-whatsapp-...
Any rough theories on how this sort of thing can happen? How can an app go from parsing metadata to executing foreign code?
[1] https://context-cdn.washingtonpost.com/notes/prod/default/do...
[2] https://www.facebook.com/security/advisories/cve-2019-3568
[3] https://arstechnica.com/information-technology/2019/05/whats...
Who had a beef with Bezos and was friendly with MBS?
Lauren Sanchez(bezos' new girfiend) along with her brother Michael(who is also her agent), leaked the story to force Bezos to divorce his wife and get along with her.
Explanation 2:
The crown prince of Saudi Arabia personally sent a trojan file, downloaded all the data, distributed it through a gossip rag he happens to be friends with, for some kind of revenge/message
I get why Bezos has to go with explanation 2 because explanation 1 would indicate the girl he wants to have sex with or her brother is manipulative. I dont see why the rest of us have to go along with this. Even this anonymous source says he has "high confidence" not anywhere near certainty.
A country like Saudia Arabia is going to use every tactic possible to combat their asymmetry with the West. It's not the crown prince personally having someone cook up a trojan for him -- it's their national apparatus deciding that free potential leverage over influential Americans is a worthwhile pursuit.
I was aware of these vulnerabilities and generally am protective of handing out PII, especially information others have entrusted to me. So I didn't give it access to hundreds of business and personal contacts spanning decades of work and life.
How do others deal with this who perhaps don't have the choice to just say "I'm going to text you instead for the 4 days we are going to have a need to communicate"? Do you keep a full set of contact data outside your phone's contacts for information you don't want shared? Private and public contacts?
And thats just the public markets. Imagine the advantage you would have in startup investing if you could covertly read all the internal discussions, the founders texts and emails, remotely access their meetings with lawyers, accountants and other VCs.
No wonder SA is suddenly interested in Silicon Valley
Most likely his marriage fell apart because of this costing him personally ~25B. But that means that he didn't give in to whatever Mr Prince wanted.
Since J. Edgar Hoover, it is has been an open secret that blackmail drives the upper echelon of politics and media. The Bill Clinton thing is another example, pretty sure he put his foot down and said fuck it, hence Lewinsky turning up with a tainted dress from 8 months ago, and down goes the U.S. president. How many just acquiesce and play along quietly?
More people should have guts like Bezos (probably did). Though at some point, I'm sure the shadow people will just fall back on good old violence, like the Epstein case.
> Large amounts of data were exfiltrated from Bezos’s phone within hours
I could see a cross-platform WhatsApp message that leaked WhatsApp data?
As well as sending whatever is in its directory or using a local priv escalation.
Secondly, Saudi's don't have their own advanced cyber capabilities (unlike Iran, UAE, Israel, etc), they rely on buying help. And single use, no interaction, 0day RCEs for recent phones (and we can assume latest iOS or Pixel) are not that available. So they used what they could get their hands on.
It beats me that they couldn't steal the phone of someone else in Bezos's WhatsApp contacts and impersonate them. Maybe Bezos wouldn't have opened the attachment. But overall, I think they are just dumb.
There remains a small possibility that someone hacked the phone of MbS (I mean, everyone has thoughts about doing that) and then pivoted to attacking people in his contacts. But the whole NSO group involvement makes me think it wasn't that.
Call hack [0]: https://www.wired.com/story/whatsapp-hack-phone-call-voip-bu...
Video hack [1]: https://thehackernews.com/2019/11/whatsapp-hacking-vulnerabi...
GIF hack [2]: https://thehackernews.com/2019/10/whatsapp-rce-vulnerability...
That call hack was famously used by NSO, hitting thousands of people [3]: https://thehackernews.com/2019/10/whatsapp-nso-group-malware...
Hack that let anyone crash the apps for all members of a group chat [4]: https://thehackernews.com/2019/12/whatsapp-group-crash.html
I think I'm actually missing one more. These are just the widely known ones, mind you, and just for 2019.
Geez that seems pretty incompetent.
Not saying this happened ... but there are many ways to blame it on prince and many ways to defend him (and blame a subordinate).
I am not on prince's side, just saying ...
If you're thinking of a state actor except Saudi Arabia, I think there would be much easier and more discreet vectors to Jeff Bezos Whatsapp than MBS phone (literally almost any of Bezos other contacts would be less risky).
Any more information on how this type of attack works? Is it a vulnerability in Whatsapp, or was whatsapp just the delivery platform?
So, not snapchat, but whatsapp. And it's quite surprising for me. So, Saudis have 0 days which work on whatsapp on iphone (I suppose Bezos uses iphone)? I mean, FB and AAPL, which both can afford tens of billions in security research, were pwned by saudi 0day? hmmm...
To be clear for anyone else reading, photo library access is required to browse the photo library from within WhatsApp, it's not required to share arbitrary photos to WhatsApp from the photo app via the OS's built-in share feature.
That way someone on the payroll of nefarious inc. my decide to share it with Google or Apple the same time as their boss.
No idea about nefarius, but when I talked with someone in a similar role the answer was work conditions. It was apparently easier to get a remote role with a flexible schedule at a more "sketchy" company.
Very good pay; the ability to work remotely; pride/prestige; community; political reasons.
Being a good digital thief is still very lucrative, especially for people living in low income areas with relatively lax law enforcement. These people can run encrypted computer extortions, steal bitcoin wallets, run/sell botnets, fence digital goods, run underground ad networks, and consult.
They pay barely enough to say they're willing to pay, but they don't really care.
Depends on your personal risk profile, I guess. If I was a highly professional security researcher (one can dream!), the one can find 0 day RCE in whatsapp, well, I would happily accept 10-20M bounty from FB and retire for life, instead of bargaining with wealthy monarch and accepting non-trivial risk of being dismembered with some blunt tools in embassy of Turkey or somewhere else.
I wonder how many Alexas there are in Saudi.
But yeah, it won't end because of morality.
That brings a lot more questions though; who actually sent the message? Was it a man-in-the-middle situation? Was MBS's WhatsApp account compromised? Did someone else use MBS physical phone to do this? Was it a third party?
Interesting and strange story all around.
That’s likely to be a small set.
> One observer said the alleged targeting of Bezos reflected the ‘personality-based’ environment in which the crown prince operates.
So it seems plausible that he and his advisers just assumed that they were technical enough to avoid attribution.
It does seem that there's more known than suspicious timing:
> The Guardian understands a forensic analysis of Bezos’s phone, and the indications that the “hack” began within an infected file from the crown prince’s account, has been reviewed by Agnès Callamard, the UN special rapporteur who investigates extrajudicial killings. It is understood that it is considered credible enough for investigators to be considering a formal approach to Saudi Arabia to ask for an explanation.
But then, even if they have conclusive evidence that said file is malware, some third party might have compromised MBS' account.
Not sure whether this is a yet another fake story sponsored by the Qataris, who infiltrated the liberal western media with their isalmist and ultra left minions all over in the name of diversity, since their rift with the Saudis in mid 2017 or the richest man on Earth is actually retarded enough to chat with a head of state like Saudi Arabia on fucking WhatsApp
Not based on the Saudi's not buying zero-day-exploits, but on them using them from the crown prince's account directly against Jeff.