> Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc.
This basically means if your device is compromised, expect malware to be able to read all content (including Signal, WhatsApp messages). Nothing new. The way it's phrased makes it sound like Signal, WhatsApp have vulnerabilities, but no, the intention is sensationalism over sound analysis.
Yes, that's nothing new, and it's obvious to us here on HN.
However, I disagree that the intention can only be sensationalism. The average computer/smartphone user (or journalist!) absolutely does not understand that if their device's operating system is compromised, that so are all the apps they run. Saying that messages can be intercepted before they are encrypted is worth pointing out as a realistic consequence of someone's device being compromised; a consequence that J. Random Journalist would not realize if it were not specifically pointed out.
Bypass encryption means they broke the protocol. They could say "also malware can read your private messages and anything else on your phone". But no, bypassing encryption sounds a lot better. Fake news.
I don't read it that way. To me, if they meant they broke the protocol, they would say "broke the encryption" or "defeated the encryption". "Bypass" implies to me that they get the information without interacting with the encryption.
English is my second language but i used to think security bypass means breaking the protection. Especially considering the title focuses on the messengers.
"Bypass" means to go around something in order to avoid it. If there was a traffic jam on the highway, you could bypass it by exiting the highway and traveling down a side street.
"Bypassing encryption" then would mean to avoid the encryption step. Maybe it has a different meaning in the security community, but if taken literally, the phrase is accurate.
The iOS attack breakdown lists a combination of vulnerabilities in very old versions of iOS, vulnerabilities first published by jailbreak teams, and a couple purchased vulnerabilities. The breakdown ends with a publicly jailbroken iOS version.
The Smart TV implant appears to just be a modified version of an open source firmware replacement project.
Jailbreak teams publish widely and open source (mostly) they are actually the CIA's opponents burning zero days which they would much rather keep to themselves. The CIA would undoubtedly be customers of companies like Vupen and Zerodium though.
- Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc.
- Dozens of O-day attacks again Andriod and iPhone.
Pretty powerful stuff.