WhatsApp Remote Code Execution in Video Call
nvd.nist.gov
nvd.nist.gov
Edit: actually no, XPC Services are Mac only so wouldn’t help on iOS.
WASI would be the closest thing to a secure runtime
Both Apple and Google have tried to isolate media codecs more since, but apparently not enough.
Sure it is might convenient for NSA who probably use it when it is found , but is less likely that company of cisco size can intentionally do something like that coordinated and keep it secret too.
I mean its the same theory as letsencrypt sending your ssl cert to other sources after giving it to you for free.
Or the Weather app on every iphone being a nice direct way to track a phone location throughout the day.
PS: of course this is all wild speculation, but fun wild speculation ;)
They're rather scant on detail. Anyone know if this was exploited in the wild? Or who discovered it otherwise?
I'm also wondering if it was disclosed as part of an equities process, given the target and the type of bug.
Temporal safety does not require a borrow checker etc, you can use a GC and get it.
Quite frankly, manually indexing into an array should be entirely avoided if possible, even more so with safety critical software.
Ie. You can still steal someone's entire conversation history.
However what they can do is everything the app can do: - get your contacts - get your messages - get your photos - get your location - get the people you chat with - read the stati of your contacts
therefore i would assume with the right tools you can directly identify a phone use, its social circle, most talked topics on an "encrypted messenger" and since the messages are right there: sentiment analysis of conversations had and therefore social status of the pople you chat with
actually its quite terrifying. but so is the idea also that our faces and words are being handed through the world by a tech company without international regulations...... soooo business as usual =)
Huh, I guess you can finally run your own software on your iPhone. Whatsapp FTW.
this does not make them more trustworthy
> There have also been many attempts by various governments to publicly force Apple to insert backdoors or prevent them from fixing security vulnerabilities which have failed.
Except in china, I suppose.
I actually worked at Apple a few years ago in security. I was wondering why we didn't E2EE photos. The reason seemed to be - from what other engineers told me - is that it was at the behest of law enforcement. Lot easier to cooperate with LE and comply with NSLs when you can simply hand over the data they need.
Until Apple end-to-end encrypts these two things, it's all for naught. It doesn't fucking matter if your HomeKit data is E2EE if someone can take a look at your nudes without any cryptographic barrier.
Take that for what you will. Having worked at both companies during my career in a security capacity, I see no reason to trust one over the other wrt cloud services.
N.B. There are people at Apple that are very passionate about security and privacy. I was privileged to work with these people during my career. They really try to - and do - make a difference. My post is not an attack on them, but on the wider vision of the company, which is somewhat hypocritical.
It isn't meaningfully different from saying that Google/Apple can pretend to put the real App in the App Store but replace it with one that has a backdoor. This is entirely possible. But also the risk of this is extremely high and people do decompile apps like Signal, WhatsApp, and Telegram (albeit this can only go so far). These are all high profile and highly scrutinized apps. It is just fear mongering.
While I don't know if the current incarnations of Nix/Guix will succeed, I think we are slowly making progress towards reproducible builds everywhere.
Yes: https://www.quora.com/What-is-a-coders-worst-nightmare/answe...
Also, I remember in the 90's, people talking about a virus that infect pascal source code files. Memory is spotty about it.
> While I don't know if the current incarnations of Nix/Guix will succeed, I think we are slowly making progress towards reproducible builds everywhere.
Fortunately, the answer is also positive here.
I love static analysis for vuln detection. I did my PhD on it. It remains my day job. It helps us find vulns. It doesn't actually convert us from unsafe software to safe software.
I love open source. In so many ways it is uniquely responsible for the development of our technology landscape. It is observably not a meaningfully different path to secure code than closed source development.
If you want my opinion, there is a huge gap between the tiny portion of open source projects that get any real professional scrutiny and the rest of the open source ecosystem. For something like the linux kernel, there are a lot of professionals who are deliberately focusing their novel tools at it and reporting issues. This is clearly better than nothing - though I'm not certain it is so much better than nothing to call it a big win. And this is the result of a large number of different teams all looking at this one codebase.
But pretty much immediately below "the linux kernel" in visibility, everybody stops caring. Even hugely deployed security-critical open source projects that manage media decoding and network stacks get absolutely zero professional analysis. All these projects get is the useless "drive-by CVE-report" garbage where somebody throws an off the shelf system at the repo and reports everything it spits out, no matter how useless the report.
There is some automation out there. It is largely worthless. Some stuff is real like "hey, you've got a private key committed over here" but pretty quickly you run into high false positive rate garbage when looking at automated systems.
I don't think "long tail" is a good way to put it. Both OpenSSL and Log4j had millions of deployments and had pretty major bugs. I'd argue it's Linux then everything else.
(In fact, this impossibility is a big part of why I'm so bullish on redbean - being really small means really fast and really really secure. It is a joy to deal with so few moving parts in a server!)
You can publish a best-paper in ICSE if you could pull this off. There are so many things that make this challenging. For starters, we don't even have the ground truth for what bugs exist. Even just looking at bugs we've already skewed our process dramatically based on the various different development processes of different projects.
You are right to question how many eyes are on typical random libraries. The answer is zero. Even huge libraries have extremely few eyes on them. When it comes to "many eyes" it is actually basically just the linux kernel and a very small number of other projects that get this sort of attention. The large majority of all open source projects, even those used by millions of projects, get zero meaningful attention beyond "hey I threw my tool at everything on github and spammed owners with nearly useless reports."
I suspect once C has been supplanted all the way down the stack it might actually be feasible to eliminate these kind of vulnerabilities entirely for apps where security is of utmost importance.
The problem is that many think they need to write their application using a macro assembler to this day.
Actually, macro assemblers are better than C regarding security, because they don't do optimizations that wipe out code sections.
Nice theory, but most of the time it's "just use zlib, bro, it's battle tested".
The root problem here is that users want lots of features. Each added feature, particularly super complex ones like video, takes away from security. There is not point in spending a lot of time on your own code if you are going to end up invoking a whole lot of code that you can't control.
[1] https://googleprojectzero.blogspot.com/2020/08/exploiting-an...
Do devs have to implement these features in shitty memory-unsafe languages?
Alt url as nvd is under load: Critical WhatsApp vulnerabilities patched https://www.malwarebytes.com/blog/news/2022/09/critical-what...
Edit: I forgot to mention almost all spam is from verified whatapps business accounts. So I believe they/FB are selling data directly under their updated TOS.
Now it's starting to get worse and worse.
I block SMS notifications since I only get spam there (I'm Brazilian, SMS is basically dead here)
Wait until the EU-mandated intercompatibility kicks in.
For me is such an enormous privacy violation that I removed the client (which is also a memory hog) and now use only the browser version.
That is a great idea. But can you delete the app from your phone once connected to the web browser?
The WhatsApp authentication SMS message can be sent to your (real) phone, and then manually transcribe the auth code into WhatsApp on the Android VM.
I did this for a while.
We sell financial services in a developing country. We're not a mobile app—we're just a mobile-first website (a common gripe on HN is 'there's too many apps, just make a website'. Well, we're one of them).
We need to be able to get in touch with our customers for transactional purposes (changes to their account, delivery notifications, login links, that sort of thing). Our customers don't have email. SMS gets filtered at the phone level (and uses untrustworthy, shared numbers). The only option is WhatsApp.
Most of the world does not have a computer, they have a phone. So at this point it's either WA or a native app + push notifications. Which would you prefer?
Just for reference, facebook has pretty strict guidelines for sending unsolicited messages.
In order for us to send you an unsolicited message, that message must use a preapproved template. Those templates are not supposed to be used for marketing purposes (although it's easy enough to craft a seemingly transactional template that is actually marketing). And there's also some cases that are a bit of a gray area.
However, in our experience, users are brutal flagging spammy messages as spammy, and facebook has pretty strict deliverability rules. If your quality drops, your messages stop being delivered.
All in all, I think it's pretty fair.
The native app, no question. Why would I want to make a facebook account just to get notifications from a third party (you)?
"Since the creation of WhatsApp, there's hardly been a moment in which it was secure: every few months researchers uncover a new security issue in the app. I wrote about this in detail 2 years ago (read here if you missed it). Nothing has changed since then.
It would be hard to believe that the technical team of WhatsApp is so consistently incompetent. Telegram, a far more sophisticated app, has never had security issues of such severity."
If Whatsapp has voluntarily been adding these issues, or has been targeted somehow, I would love to dig into research related to that. I'll check out the details regarding this attack in some hours.
This perspective seems extreme given the current evidence though. Switch to something like Matrix for sure though u.u
Edit: I'm not a proponent for whatsapp. I just understand telegram also isn't the best, and has a good incentive to shit on whatsapp
Why would anyone use Telegram over something end to end encrypted, like Signal, Matrix, WhatsApp, Facebook Messenger, etc.?
Some people care more about these than security or privacy. It's that simple.
As for monetization, I believe they have premium stickers and such.
My personal assessment is that if you have to communicate something that must not ever leak out, you shouldn’t use a chat app at all, period — because in many many cases my interlocutor is less careful than I am (or their degree of carefulness is unknown). You can use an E2E video app but not a chat app. Telegram’s video is E2E.
If my entire Telegram history leaks out, I estimate that I’ll be in a bit of trouble, but not significant trouble.
Of course, I might be wrong. In fact, while writing this comment I realized that the risk is probably somewhat bigger than I think it is, and in an ideal world using E2E would be advisable.
However, this isn’t “why you should use Telegram” but rather “why do you use Telegram”, so this is why I use it — significantly better UX, partly network effect, and partly that leaking my entire history is not even in the top 100 worries I have in life.
Those could all be avoided by not using C.
I guarantee you if we all switched to Telegram nothing would change, and I would bet money these exploits boil down to open source libraries which are commonly used in these apps.
It does not pay to be high browed with security. Even Chrome, with all its investment into security, gets pwned on a regular basis.
This says a lot more about the technical competence of Pavel Durov than it does of the WhatsApp team.
For starters: https://nitter.net/durov/status/873870658874355713