Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

- Smart TV turned into listening devices with fake off mode?

- Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc.

- Dozens of O-day attacks again Andriod and iPhone.

Pretty powerful stuff.



> Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc.

This basically means if your device is compromised, expect malware to be able to read all content (including Signal, WhatsApp messages). Nothing new. The way it's phrased makes it sound like Signal, WhatsApp have vulnerabilities, but no, the intention is sensationalism over sound analysis.


Yes, that's nothing new, and it's obvious to us here on HN.

However, I disagree that the intention can only be sensationalism. The average computer/smartphone user (or journalist!) absolutely does not understand that if their device's operating system is compromised, that so are all the apps they run. Saying that messages can be intercepted before they are encrypted is worth pointing out as a realistic consequence of someone's device being compromised; a consequence that J. Random Journalist would not realize if it were not specifically pointed out.


Bypass encryption means they broke the protocol. They could say "also malware can read your private messages and anything else on your phone". But no, bypassing encryption sounds a lot better. Fake news.


I don't read it that way. To me, if they meant they broke the protocol, they would say "broke the encryption" or "defeated the encryption". "Bypass" implies to me that they get the information without interacting with the encryption.


I agree with you on the semantics. They didn't break the encryption, but they certainly did get around it / bypass it.


English is my second language but i used to think security bypass means breaking the protection. Especially considering the title focuses on the messengers.


"Bypass" means to go around something in order to avoid it. If there was a traffic jam on the highway, you could bypass it by exiting the highway and traveling down a side street.

"Bypassing encryption" then would mean to avoid the encryption step. Maybe it has a different meaning in the security community, but if taken literally, the phrase is accurate.


We basically need to just accept: "If you have a device, it is being monitored, PERIOD."


No mention of Windows Phone. I guess I'm safe =)


Sure, maybe, but there are very few of your kind left. ;)


I'm pretty sure I have a Nokia 3310 in one cupboard or another, maybe I'll dig it out and swap my SIM to it...


Try nokia 3310. They made new ones recently.


The iOS attack breakdown lists a combination of vulnerabilities in very old versions of iOS, vulnerabilities first published by jailbreak teams, and a couple purchased vulnerabilities. The breakdown ends with a publicly jailbroken iOS version.

The Smart TV implant appears to just be a modified version of an open source firmware replacement project.


I was upset that our government is exploiting our consumer devices. Now I'm upset that our government isn't exploiting our consumer devices better.


> vulnerabilities first published by jailbreak teams,

I guess we now know who is sponsoring these jailbreak guys and why.


Jailbreak teams publish widely and open source (mostly) they are actually the CIA's opponents burning zero days which they would much rather keep to themselves. The CIA would undoubtedly be customers of companies like Vupen and Zerodium though.


> I guess we now know who is sponsoring these jailbreak guys and why.

One of the vulnerabilities on the iOS page is from a team I had founded a few years ago. I certainly do not recall us getting a check from the CIA.


What would be the point of the CIA sponsoring jailbreak teams? The exploits they find are generally burned very quickly.


> Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc

I wish I could say that I'm surprised but no... not surprised at all. Same for the IoT stuff.


Why would you be surprised by the fact that if your phone is compromised, even the best encryption software in the world isn't going to help?


Another victim of sensationalism.


The conclusions are correct. Talking about them isn't sensationalist just because you think they're foreseeable.


I refered to "being not surprised that encryption is broken". There was nothing relevant to encr in the document. The title is wrong.


Who said "being not surprised that encryption is broken"??? Read the quote again: "Intercepting audio/texts before encryption"

I'm not surprised that they can INTERCEPT and read ALL your communications... jeez


Ok in that sense i am wrong. But it could mean sometging else.


Yep. We all knew it was happening but turn a blind eye.

And then one of these revelations are exposed and we all start wearing tin foil hats for a month or two.


The big question for me is: What's the alternative?

AFAIK, there's no secure replacement for most IoT stuff, or phones.


It's 0-day, not O-day.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: