Modern Australian
Men's Weekly

.

what you need to know to protect yourself

  • Written by Robert Merkel, Lecturer in Software Engineering, Monash University

It’s been a day of high-profile security incidents.

First there was news the popular WhatsApp messenger app was hacked. Updated versions of WhatsApp have been released, which you should install if you’re one of the more than one billion people who use the app.

There was also news of several security flaws in the majority of Intel processors, found in many of the world’s desktop, laptop and server computers.

Software patches to prevent exploitation of these hardware flaws have been released by several vendors, including Microsoft. You should install security updates from vendors promptly, including these.

WhatsApp hack revealed

The WhatsApp news was revealed first by the Financial Times, which says the bug was used in an attempt to access content on the phone of a UK-based human rights lawyer.

Read more: Becoming more like WhatsApp won't solve Facebook’s woes – here's why

The lawyer reported unusual activity on his phone to the Citizen Lab, an academic research centre that focuses on digital espionage. The centre then contacted WhatsApp, which had independently noted signs of some kind of hack and put in place preliminary preventative measures in its network infrastructure.

When asked by the Financial Times how many users were attacked using this vulnerability, a WhatsApp spokesperson said “a number in the dozens would not be inaccurate”.

Facebook, the corporate parent of WhatsApp, has issued a technical notice about the vulnerability, saying versions of WhatsApp for iOS, Android, Windows Phone (and the lesser-known Tizen platform used in Samsung smart watches) were affected.

Evading end-to-end encryption

Messages and calls on WhatsApp are end-to-end encrypted, which means they are practically invulnerable to being read while in transit.

The only way an attacker can gain access to the contents of WhatsApp messages and calls is at either end, on the sending or receiving device.

Unfortunately, in this case, by modifying the sequence of data sent to a phone to initiate a call, an attacker could take over the WhatsApp application running on the device.

This would cause it to do whatever the attacker wishes, which could include sending the unscrambled WhatsApp messages directly to the attacker.

While on its own the vulnerability does not appear to give the attackers full access to everything on a target phone, it could well be used in combination with other vulnerabilities to gain full access and control.

Suspicions fall on NSO Group

Unlike the Intel processor flaws, which were discovered by academic and commercial researchers and are not known to have been used for hacking to date, the WhatsApp security bug was discovered because of hacking activity.

The Financial Times attributes the hacking attempts using the bug to software developed by the NSO Group.

Facebook, while not naming NSO, told the Financial Times:

[…] the attack has all the hallmarks of a private company known to work with governments to deliver spyware that reportedly takes over the functions of mobile phone operating systems.

NSO Group is an Israel-based company that sells intelligence-gathering software – essentially, mobile phone spyware – to governments around the world.

Software sold by NSO Group has previously been implicated in attempts to spy on an Emirati human rights activist, Mexican journalists, and other civil society targets.

The UK human rights lawyer targeted using the WhatsApp bug was representing the Mexican journalists previously allegedly targeted using NSO Group software.

We’re not likely targets

While this particular bug is no longer a problem if you’ve updated WhatsApp, in general there is relatively little an average citizen targeted by this kind of spyware can do about it.

what you need to know to protect yourself Make sure you WhatsApp app is up-to-date. WhatsApp Android app/Screenshot

This genre of bug-exploiting spyware is highly unlikely to be used by anyone other than governments, and then only to target a relatively small number of people. But the lawyer in this latest case says he does not know who is behind his WhatsApp hack.

Sooner or later, the use of spyware is inevitably detected, and the bug used to install it is found and fixed. The more phones are attacked, the quicker this will occur.

In the Australian context, software bugs are not the only means available to law enforcement to access encrypted messaging.

Read more: Why we need to fix encryption laws the tech sector says threaten Australian jobs

The controversial Access and Assistance legislation, approved late last year, contains provisions that can require software and hardware developers to provide assistance to law enforcement and intelligence agencies to access communications, including those secured with end-to-end encryption.

The use of this kind of spyware – sold to countries with dubious human rights credentials, and used to target activists, journalists and lawyers – is disturbing.

I have previously argued that the international trade in such powerful tools should be curtailed. But fortunately, as insidious as they are, their reach is limited and likely to remain so.

Authors: Robert Merkel, Lecturer in Software Engineering, Monash University

Read more http://theconversation.com/whatsapp-hacked-and-bugs-in-intel-chips-what-you-need-to-know-to-protect-yourself-117173

Powering Shepparton’s Businesses: Expert Commercial Electrical Services You Can Count On

When it comes to running a successful business, having reliable, compliant, and efficient electrical systems is non-negotiable. From small retail ou...

Maximise Efficiency: Cleaner Solar Panels for Optimal Performance

Solar panels are a smart investment in energy efficiency, sustainability, and long-term savings—especially here in Cairns, where the tropical sun ...

7 Common Air Conditioner Issues in Melbourne – And How to Fix Them

Image by freepik Living in Melbourne, we all know how unpredictable the weather can be. One moment it’s cold and windy, the next it’s a scorchin...

Powering Palm QLD with Reliable Electrical Solutions

Image by pvproductions on Freepik When it comes to finding a trustworthy electrician Palm QLD locals can count on, the team at East Coast Sparkies s...

The Smart Way to Grow Online: SEO Management Sydney Businesses Can Rely On

If you’re a Sydney-based business owner, you already know the digital space is crowded. But with the right strategy, you don’t need to shout the...

What Your Car Says About You: The Personality Behind the Vehicle

You can tell a lot about someone by the car they drive—or at least, that’s what people think. True Blue Mobile Mechanics reckon the car says a l...

The Confidence Curve: Why Boudoir Photography Is the Empowerment Trend You Didn’t Know You Needed

Boudoir photography has been quietly taking over social feeds, Pinterest boards, and personal milestones—and for good reason. It’s not just abou...

Understanding Level 2 Electricians: Why Sydney Residents Need Licenced Experts for Complex Electrical Work

When it comes to electrical work around the home or business, not all electricians are created equal. In Sydney, particularly when you're dealing wi...

Retirement Anchored in Model Boat Building for Waterford’s Doug Unsold

WATERFORD — When Doug Unsold sees his ship come in, it’s usually one he’s crafted with his own hands. The 67-year-old retiree from Waterford ...

The Science Behind Alarm Clocks and Your Circadian Rhythm

Waking up on time isn’t just about setting an alarm—it’s about working with your body, not against it. At the heart of every restful night and...

How to Use Plants to Create a Calming Atmosphere in Your Home

In today’s fast-paced world, cultivating a calm, soothing environment at home has never been more important. Whether you live in a busy urban apar...

How Maths Tutoring Can Help Students Master Maths

Mathematics can be a daunting subject for many students, often causing stress and frustration. However, maths tutoring has proven to be an effective...

Refurbished iPads Are Better Than New Ones (Here's Why)

Image by rawpixel.com on Freepik Apple's refurbished iPad program has quietly become one of the best deals in tech. While everyone obsesses over the ...

Your Guide to Finding the Right GP: What Perth City Doctors Offer Today

Choosing a General Practitioner (GP) is one of the most important health decisions you’ll make. Luckily, Perth’s vibrant CBD now hosts a new ge...

Why Every Mining Operation Needs a Robust Safety Management System

Mining is one of the backbones of the Australian economy, particularly in Western Australia. Back in 2019-20, mining contributed 10.4% of Australia...

Australian Classic Literature Enjoys Resurgence

Welcome back to the good old days of storytelling! As the modern world becomes increasingly more demanding, returning to childhood favourites offers...

How to Choose the Right Lawyers in Sydney for Your Situation

When faced with a legal issue, selecting the right legal representation can make all the difference. Whether you're dealing with a personal injury, ...

Building a Governance Model for Headless Content Management at Scale

Image by pch.vector on Freepik There's never been a better time to implement a headless content management system (CMS) to gain the flexibility and ...