Forwarded from Pavel Durov
In May, I predicted that backdoors in WhatsApp would keep getting discovered, and one serious security issue would follow another, as it did in the past [1]. This week a new backdoor was quietly found in WhatsApp [2]. Just like the previous WhatsApp backdoor and the one before it, this new backdoor made all data on your phone vulnerable to hackers and government agencies. All a hacker had to do was send you a video – and all your data was at the attacker’s mercy [3].
WhatsApp doesn’t only fail to protect your WhatsApp messages – this app is being consistently used as a Trojan horse to spy on your non-WhatsApp photos and messages. Why would they do it? Facebook has been part of surveillance programs long before it acquired WhatsApp [4][5]. It is naive to think the company would change its policies after the acquisition, which has been made even more obvious by the WhatsApp founder’s admission regarding the sale of WhatsApp to Facebook: “I sold my users’ privacy” [6].
Following the discovery of this week’s backdoor, Facebook tried to confuse the public by claiming they had no evidence that the backdoor had been exploited by hackers [7]. Of course, they have no such evidence – in order to obtain it, they would need to be able to analyze videos shared by WhatsApp users, and WhatsApp doesn’t permanently store video files on its servers (instead, it sends unencrypted messages and media of the vast majority of their users straight to Google’s and Apple’s servers [8]). So – nothing to analyze – “no evidence”. Convenient.
But rest assured, a security vulnerability of this magnitude is bound to have been exploited – just like the previous WhatsApp backdoor had been used against human rights activists and journalists naive enough to be WhatsApp users [9][10]. It was reported in September that the data obtained as a result of the exploitation of such WhatsApp backdoors will now be shared with other countries by US agencies [11][12].
Despite this ever-increasing evidence of WhatsApp being a honeypot for people that still trust Facebook in 2019, it might also be the case that WhatsApp just accidentally implements critical security vulnerabilities across all their apps every few months. I doubt that – Telegram, a similar app in its complexity, hasn’t had any issues of WhatsApp-level severity in the six years since its launch. It’s very unlikely that anyone can accidentally commit major security errors, conveniently suitable for surveillance, on a regular basis.
Regardless of the underlying intentions of WhatsApp’s parent company, the advice for their end-users is the same: unless you are cool with all your photos and messages becoming public one day, you should delete WhatsApp from your phone.
[1] – Why WhatsApp will never be secure
[2] – WhatsApp users urged to update app immediately over spying fears
[3] – WhatsApp Android and iOS users are now at risk from malicious video files
[4] – Everything you need to know about PRISM
[5] – NSA taps data from 9 major Net firms
[6] – WhatsApp co-founder Brian Acton: 'I sold my users' privacy'
[7] – Hackers can use a WhatsApp flaw in the way it handles video to take control of your phone
[8] – WhatsApp is storing unencrypted backup data on Google Drive
[9] – WhatsApp hack led to targeting of 100 journalists and dissidents
[10] – Exclusive: Government officials around the globe targeted for hacking through WhatsApp - sources
[11] – Police can access suspects’ Facebook and WhatsApp messages in deal with US
[12] – Facebook, WhatsApp Will Have to Share Messages With U.K.
WhatsApp doesn’t only fail to protect your WhatsApp messages – this app is being consistently used as a Trojan horse to spy on your non-WhatsApp photos and messages. Why would they do it? Facebook has been part of surveillance programs long before it acquired WhatsApp [4][5]. It is naive to think the company would change its policies after the acquisition, which has been made even more obvious by the WhatsApp founder’s admission regarding the sale of WhatsApp to Facebook: “I sold my users’ privacy” [6].
Following the discovery of this week’s backdoor, Facebook tried to confuse the public by claiming they had no evidence that the backdoor had been exploited by hackers [7]. Of course, they have no such evidence – in order to obtain it, they would need to be able to analyze videos shared by WhatsApp users, and WhatsApp doesn’t permanently store video files on its servers (instead, it sends unencrypted messages and media of the vast majority of their users straight to Google’s and Apple’s servers [8]). So – nothing to analyze – “no evidence”. Convenient.
But rest assured, a security vulnerability of this magnitude is bound to have been exploited – just like the previous WhatsApp backdoor had been used against human rights activists and journalists naive enough to be WhatsApp users [9][10]. It was reported in September that the data obtained as a result of the exploitation of such WhatsApp backdoors will now be shared with other countries by US agencies [11][12].
Despite this ever-increasing evidence of WhatsApp being a honeypot for people that still trust Facebook in 2019, it might also be the case that WhatsApp just accidentally implements critical security vulnerabilities across all their apps every few months. I doubt that – Telegram, a similar app in its complexity, hasn’t had any issues of WhatsApp-level severity in the six years since its launch. It’s very unlikely that anyone can accidentally commit major security errors, conveniently suitable for surveillance, on a regular basis.
Regardless of the underlying intentions of WhatsApp’s parent company, the advice for their end-users is the same: unless you are cool with all your photos and messages becoming public one day, you should delete WhatsApp from your phone.
[1] – Why WhatsApp will never be secure
[2] – WhatsApp users urged to update app immediately over spying fears
[3] – WhatsApp Android and iOS users are now at risk from malicious video files
[4] – Everything you need to know about PRISM
[5] – NSA taps data from 9 major Net firms
[6] – WhatsApp co-founder Brian Acton: 'I sold my users' privacy'
[7] – Hackers can use a WhatsApp flaw in the way it handles video to take control of your phone
[8] – WhatsApp is storing unencrypted backup data on Google Drive
[9] – WhatsApp hack led to targeting of 100 journalists and dissidents
[10] – Exclusive: Government officials around the globe targeted for hacking through WhatsApp - sources
[11] – Police can access suspects’ Facebook and WhatsApp messages in deal with US
[12] – Facebook, WhatsApp Will Have to Share Messages With U.K.
Ну да, не девяностые
https://meduza.io/feature/2019/11/21/my-sami-siloviki
https://meduza.io/feature/2019/11/21/my-sami-siloviki
Meduza
Мы сами — силовики
В России существует рынок негосударственного политического насилия. Его услугами пользуются разные клиенты, в том числе власти — для борьбы с общественными и гражданскими активистами, конкурентами и даже госслужащими. Участники этого насыщенного рынка — близкие…
Forwarded from Против жуликов и воров
⚡️Руслан Шаведдинов задержан неподалёку от офиса ФБК.
Twitter
Alexey Navalny
Сотрудника ФБК Руслана @shaveddinov снова задержали недалеко от офиса. Уже в который раз. Ехала бы эта полиция уже прокурора Попова задерживать и спрашивать откуда у него деньги на гостиницы
https://youtu.be/O2W0N3uKXmo ура, можно будет теперь не только в Beat Saber играть
YouTube
Half-Life: Alyx Announcement Trailer
Return to Half-Life in VR, March 23, 2020.
https://half-life.com/alyx
Available for pre-purchase on Steam: https://store.steampowered.com/app/546560/HalfLife_Alyx/
Set between the events of Half-Life and Half-Life 2, Half-Life: Alyx is a new full-length…
https://half-life.com/alyx
Available for pre-purchase on Steam: https://store.steampowered.com/app/546560/HalfLife_Alyx/
Set between the events of Half-Life and Half-Life 2, Half-Life: Alyx is a new full-length…
Forwarded from Медуза — все новости
В Москве напали на основателя Conflict Intelligence Team Руслана Левиева
https://meduza.io/news/2019/11/27/v-moskve-napali-na-osnovatelya-conflict-intelligence-team-ruslana-levieva
https://meduza.io/news/2019/11/27/v-moskve-napali-na-osnovatelya-conflict-intelligence-team-ruslana-levieva
Meduza
В Москве напали на основателя Conflict Intelligence Team Руслана Левиева
Основатель расследовательской группы Conflict Intelligence Team (CIT) Руслан Левиев сообщил, что на него напали в Москве.
Forwarded from Навальный
Понедельник. Серое утро. Работа. Тоска.
Хорошо, что есть ФБК.
Начните свою неделю с истории красивой любви из нашего нового расследования.
Гарантирую, вы отлично проведёте следующие 29 минут:
https://youtu.be/bkdzT5cOiSQ
Хорошо, что есть ФБК.
Начните свою неделю с истории красивой любви из нашего нового расследования.
Гарантирую, вы отлично проведёте следующие 29 минут:
https://youtu.be/bkdzT5cOiSQ
YouTube
Яхта. Самолёт. Девушка. Запретная любовь за ваш счёт
Любовная история, из-за которой заблокированы тысячи интернет-сайтов. Неужели такое возможно?
Запросто, если в деле замешан "кошелёк Путина" и чудовищная коррупция, благодаря которой любовница-телеведущая с государственного канала живёт жизнью настоящей королевы.…
Запросто, если в деле замешан "кошелёк Путина" и чудовищная коррупция, благодаря которой любовница-телеведущая с государственного канала живёт жизнью настоящей королевы.…
Forwarded from ЕГОР
Больше миллиона ВИЧ-инфицированных россиян. И это только официальные данные. Неизвестно сколько людей живут в незнании, проводя вечера в тиндере и не предохраняясь. Симптомов может не быть месяцами, ребята. Пожалуйста, не поленитесь сдать анализ на ВИЧ. Это НЕ стыдно.
Forwarded from TJ
Во всемирный день борьбы со СПИДом Роспотребнадзор поделился безрадостной статистикой.
Число ВИЧ-инфицированных в России превысило миллион человек, а в 2018 году от болезни умерло рекордное число россиян — 37,7 тысяч человек. И это только по официальным данным.
https://tjournal.ru/129078
Число ВИЧ-инфицированных в России превысило миллион человек, а в 2018 году от болезни умерло рекордное число россиян — 37,7 тысяч человек. И это только по официальным данным.
https://tjournal.ru/129078
Forwarded from Полыхание усиливается (David Homak)
Что, дошутились? Дошутились, да?
Meduza
«Исламское государство» объявило о причастности к атаке в Лондоне через российский мессенджер TamTam. Террористы перешли туда из телеграма
«Исламское государство» опубликовало первое заявление о своей ответственности за теракт в Лондоне в российском мессенджере TamTam, заявил изданию Insider бельгийский эксперт по джихадистским группировкам Питер Ван Остайен. По его словам, заявление террористов…
Forwarded from AudD
The web is one of the most powerful tools we’ve ever had to transform our lives for the better.
Never before has the web’s power for good been more under threat.
It doesn’t have to be this way. We can — and must — fight for the #WebWeWant.
contractfortheweb.org
Never before has the web’s power for good been more under threat.
It doesn’t have to be this way. We can — and must — fight for the #WebWeWant.
contractfortheweb.org
Forwarded from Денис Чужой про комедию
BBC News Русская служба
В России показали три серии "Слуги народа". Из первой вырезали шутку о Путине
Российский телеканал ТНТ показал три серии сериала "Слуга народа", главную роль в котором исполнил Владимир Зеленский. Это произошло после встречи президентов России и Украины в Париже. Из первой серии исчезла шутка о Владимире Путине. Остальные серии покажут…
Forwarded from Медуза — LIVE
ТНТ больше не будет показывать сериал «Слуга народа», главную роль в котором сыграл Владимир Зеленский. Телепрограмму ТНТ срочно меняют, пишут «Ведомости». На телеканале утверждают, что изначально собирались показать только первые три серии «Слуги народа».
https://mdza.io/6k6zMxmXDJo
https://mdza.io/6k6zMxmXDJo
Meduza
ТНТ снял с эфира сериал «Слуга народа» с Владимиром Зеленским. Его показывали всего день
Телеканал ТНТ больше не будет показывать сериал «Слуга народа», главную роль в котором сыграл действующий президент Украины Владимир Зеленский. Об этом сообщают «Ведомости».