Forwarded from Pavel Durov
In May, I predicted that backdoors in WhatsApp would keep getting discovered, and one serious security issue would follow another, as it did in the past [1]. This week a new backdoor was quietly found in WhatsApp [2]. Just like the previous WhatsApp backdoor and the one before it, this new backdoor made all data on your phone vulnerable to hackers and government agencies. All a hacker had to do was send you a video – and all your data was at the attacker’s mercy [3].
WhatsApp doesn’t only fail to protect your WhatsApp messages – this app is being consistently used as a Trojan horse to spy on your non-WhatsApp photos and messages. Why would they do it? Facebook has been part of surveillance programs long before it acquired WhatsApp [4][5]. It is naive to think the company would change its policies after the acquisition, which has been made even more obvious by the WhatsApp founder’s admission regarding the sale of WhatsApp to Facebook: “I sold my users’ privacy” [6].
Following the discovery of this week’s backdoor, Facebook tried to confuse the public by claiming they had no evidence that the backdoor had been exploited by hackers [7]. Of course, they have no such evidence – in order to obtain it, they would need to be able to analyze videos shared by WhatsApp users, and WhatsApp doesn’t permanently store video files on its servers (instead, it sends unencrypted messages and media of the vast majority of their users straight to Google’s and Apple’s servers [8]). So – nothing to analyze – “no evidence”. Convenient.
But rest assured, a security vulnerability of this magnitude is bound to have been exploited – just like the previous WhatsApp backdoor had been used against human rights activists and journalists naive enough to be WhatsApp users [9][10]. It was reported in September that the data obtained as a result of the exploitation of such WhatsApp backdoors will now be shared with other countries by US agencies [11][12].
Despite this ever-increasing evidence of WhatsApp being a honeypot for people that still trust Facebook in 2019, it might also be the case that WhatsApp just accidentally implements critical security vulnerabilities across all their apps every few months. I doubt that – Telegram, a similar app in its complexity, hasn’t had any issues of WhatsApp-level severity in the six years since its launch. It’s very unlikely that anyone can accidentally commit major security errors, conveniently suitable for surveillance, on a regular basis.
Regardless of the underlying intentions of WhatsApp’s parent company, the advice for their end-users is the same: unless you are cool with all your photos and messages becoming public one day, you should delete WhatsApp from your phone.
[1] – Why WhatsApp will never be secure
[2] – WhatsApp users urged to update app immediately over spying fears
[3] – WhatsApp Android and iOS users are now at risk from malicious video files
[4] – Everything you need to know about PRISM
[5] – NSA taps data from 9 major Net firms
[6] – WhatsApp co-founder Brian Acton: 'I sold my users' privacy'
[7] – Hackers can use a WhatsApp flaw in the way it handles video to take control of your phone
[8] – WhatsApp is storing unencrypted backup data on Google Drive
[9] – WhatsApp hack led to targeting of 100 journalists and dissidents
[10] – Exclusive: Government officials around the globe targeted for hacking through WhatsApp - sources
[11] – Police can access suspects’ Facebook and WhatsApp messages in deal with US
[12] – Facebook, WhatsApp Will Have to Share Messages With U.K.
WhatsApp doesn’t only fail to protect your WhatsApp messages – this app is being consistently used as a Trojan horse to spy on your non-WhatsApp photos and messages. Why would they do it? Facebook has been part of surveillance programs long before it acquired WhatsApp [4][5]. It is naive to think the company would change its policies after the acquisition, which has been made even more obvious by the WhatsApp founder’s admission regarding the sale of WhatsApp to Facebook: “I sold my users’ privacy” [6].
Following the discovery of this week’s backdoor, Facebook tried to confuse the public by claiming they had no evidence that the backdoor had been exploited by hackers [7]. Of course, they have no such evidence – in order to obtain it, they would need to be able to analyze videos shared by WhatsApp users, and WhatsApp doesn’t permanently store video files on its servers (instead, it sends unencrypted messages and media of the vast majority of their users straight to Google’s and Apple’s servers [8]). So – nothing to analyze – “no evidence”. Convenient.
But rest assured, a security vulnerability of this magnitude is bound to have been exploited – just like the previous WhatsApp backdoor had been used against human rights activists and journalists naive enough to be WhatsApp users [9][10]. It was reported in September that the data obtained as a result of the exploitation of such WhatsApp backdoors will now be shared with other countries by US agencies [11][12].
Despite this ever-increasing evidence of WhatsApp being a honeypot for people that still trust Facebook in 2019, it might also be the case that WhatsApp just accidentally implements critical security vulnerabilities across all their apps every few months. I doubt that – Telegram, a similar app in its complexity, hasn’t had any issues of WhatsApp-level severity in the six years since its launch. It’s very unlikely that anyone can accidentally commit major security errors, conveniently suitable for surveillance, on a regular basis.
Regardless of the underlying intentions of WhatsApp’s parent company, the advice for their end-users is the same: unless you are cool with all your photos and messages becoming public one day, you should delete WhatsApp from your phone.
[1] – Why WhatsApp will never be secure
[2] – WhatsApp users urged to update app immediately over spying fears
[3] – WhatsApp Android and iOS users are now at risk from malicious video files
[4] – Everything you need to know about PRISM
[5] – NSA taps data from 9 major Net firms
[6] – WhatsApp co-founder Brian Acton: 'I sold my users' privacy'
[7] – Hackers can use a WhatsApp flaw in the way it handles video to take control of your phone
[8] – WhatsApp is storing unencrypted backup data on Google Drive
[9] – WhatsApp hack led to targeting of 100 journalists and dissidents
[10] – Exclusive: Government officials around the globe targeted for hacking through WhatsApp - sources
[11] – Police can access suspects’ Facebook and WhatsApp messages in deal with US
[12] – Facebook, WhatsApp Will Have to Share Messages With U.K.
Forwarded from LikeBot
Telegram
BOTMAN
😂😂😂😂
Forwarded from Telegram Contests
Upcoming Telegram contests in 2021
🏆 2021 iOS Interface Animation Contest – January 15
🏆 2021 Android Interface Contest – January 30
🏆 2021 Data Clustering Contest – January 30
🏆Audio and Video Stream Processing for Calls – February 15
🏆2021 Animated Sticker Contest – March 1
🏆 GIF Animation Contest – March 15
The total prize fund for Telegram contests in 2021 is expected to reach $1,000,000.
Additional details about each of the contests will be published on this channel. You can already sign up for participation using @ContestBot.
Good luck and Happy New Year!
🏆 2021 iOS Interface Animation Contest – January 15
🏆 2021 Android Interface Contest – January 30
🏆 2021 Data Clustering Contest – January 30
🏆Audio and Video Stream Processing for Calls – February 15
🏆2021 Animated Sticker Contest – March 1
🏆 GIF Animation Contest – March 15
The total prize fund for Telegram contests in 2021 is expected to reach $1,000,000.
Additional details about each of the contests will be published on this channel. You can already sign up for participation using @ContestBot.
Good luck and Happy New Year!
Forwarded from Telegram Contests
Update on the Second Round of the iOS Contest:
Given the strict deadlines, we decided to evaluate all apps supporting at least WatchOS 7. Support for WatchOS 6 will still bring you bonus points, but is no longer obligatory.
Given the strict deadlines, we decided to evaluate all apps supporting at least WatchOS 7. Support for WatchOS 6 will still bring you bonus points, but is no longer obligatory.
Forwarded from PMO🔴MARINE 🟣CHIEFCOOK🔵CHEF🟢SHIP🟡COOK🟠GALLEY (👽)
b.com/google/cld3
external/github.com/google/compact_enc_det
external/github.com/google/crc32c
external/github.com/google/dart-gl
external/github.com/google/EarlGrey
external/github.com/google/eDistantObject
external/github.com/google/error-prone
external/github.com/google/flatbuffers
external/github.com/google/glslang
external/github.com/google/go-cmp
external/github.com/google/gofountain
external/github.com/google/go-genproto
external/github.com/google/google-api-go-client
external/github.com/google/google-api-python-client
external/github.com/google/googletest
external/github.com/google/google-toolbox-for-mac
external/github.com/google/go-querystring
external/github.com/google/gtest-parallel
external/github.com/google/GTXiLib
external/github.com/google/libprotobuf-mutator
external/github.com/google/material-design-icons
external/github.com/google/material-text-accessibility-ios
external/github.com/google/oauth2client
external/github.com/google/oboe
external/github.com/google/open-vcdiff
external/github.com/google/protobuf
external/github.com/google/proto-quic
external/github.com/google/pywebsocket
external/github.com/google/quic-trace
external/github.com/google/quiver-dart
external/github.com/google/re2
external/github.com/google/shaderc
external/github.com/google/skylark
external/github.com/google/snappy
external/github.com/google/starlark-go
external/github.com/google/subcommands
external/github.com/google/syzygy
external/github.com/google/truth
external/github.com/google/uuid
external/github.com/google/vector_math.dart
external/github.com/googleapis/gax-go
external/github.com/googleapis/googleapis
external/github.com/google-ar/arcore-android-sdk
external/github.com/GoogleChrome/custom-tabs-client
A mirror of https://chromium.googlesource.com/custom-tabs-client
external/github.com/GoogleCloudPlatform/appengine-gcs-client
external/github.com/GoogleCloudPlatform/appengine-pipelines
external/github.com/GoogleCloudPlatform/compute-image-packages
external/github.com/GoogleCloudPlatform/docker-credential-gcr
external/github.com/GoogleCloudPlatform/endpoints-proto-datastore
external/github.com/GoogleCloudPlatform/go-endpoints
external/github.com/GoogleCloudPlatform/google-cloud-go
external/github.com/GoogleCloudPlatform/google-cloud-go-testing
external/github.com/googlei18n/emoji-segmenter
external/github.com/googlei18n/sfntly
external/github.com/googlesamples/cardboard-java
external/github.com/googlevr/gvr-android-sdk
external/github.com/go-ole/go-ole
external/github.com/gopherjs/gopherjs
external/github.com/gorhill/cronexpr
external/github.com/gorilla/mux
external/github.com/gorilla/websocket
external/github.com/go-sql-driver/mysql
external/github.com/go-tomb/tomb
external/github.com/go-warnings/warnings
external/github.com/go-yaml/yaml
external/github.com/gperftools/gperftools
external/github.com/gradle/gradle
external/github.com/grpc/grpc
external/github.com/grpc/grpc-go
external/github.com/g-truc/glm
external/github.com/guelfey/go.dbus
external/github.com/hamcrest/OCHamcrest
external/github.com/harfbuzz/harfbuzz
external/github.com/hashicorp/errwrap
external/github.com/hashicorp/golang-lru
external/github.com/hashicorp/go-multierror
external/github.com/howeyc/fsnotify
external/github.com/immersive-web/webxr-samples
external/github.com/inconshreveable/mousetrap
external/github.com/intel/tinycbor
external/github.com/jasmine/jasmine
external/github.com/jayway/powermock
external/github.com/jbenet/go-context
external/github.com/jcgregorio/httplib2
external/github.com/jjlee/mechanize
external/github.com/jmoiron/sqlx
external/github.com/jtolds/gls
external/github.com/juju/errors
external/github.com/julienschmidt/httprouter
external/github.com/kardianos/osext
external/github.com/kennethreitz/requests
external/github.com/kevinburke/ssh_config
external/github.com/khaledhosny/ots
external/github.com/KhronosGroup/glslang
external/github.com/KhronosGroup/SPIRV-Cross
external/github.com/KhronosGroup/SPIRV-Headers
external/github.com/KhronosGroup/SPIRV-Tools
external/github.com/KhronosGroup/Vulkan-Headers
external/github.com/Khronos
external/github.com/google/compact_enc_det
external/github.com/google/crc32c
external/github.com/google/dart-gl
external/github.com/google/EarlGrey
external/github.com/google/eDistantObject
external/github.com/google/error-prone
external/github.com/google/flatbuffers
external/github.com/google/glslang
external/github.com/google/go-cmp
external/github.com/google/gofountain
external/github.com/google/go-genproto
external/github.com/google/google-api-go-client
external/github.com/google/google-api-python-client
external/github.com/google/googletest
external/github.com/google/google-toolbox-for-mac
external/github.com/google/go-querystring
external/github.com/google/gtest-parallel
external/github.com/google/GTXiLib
external/github.com/google/libprotobuf-mutator
external/github.com/google/material-design-icons
external/github.com/google/material-text-accessibility-ios
external/github.com/google/oauth2client
external/github.com/google/oboe
external/github.com/google/open-vcdiff
external/github.com/google/protobuf
external/github.com/google/proto-quic
external/github.com/google/pywebsocket
external/github.com/google/quic-trace
external/github.com/google/quiver-dart
external/github.com/google/re2
external/github.com/google/shaderc
external/github.com/google/skylark
external/github.com/google/snappy
external/github.com/google/starlark-go
external/github.com/google/subcommands
external/github.com/google/syzygy
external/github.com/google/truth
external/github.com/google/uuid
external/github.com/google/vector_math.dart
external/github.com/googleapis/gax-go
external/github.com/googleapis/googleapis
external/github.com/google-ar/arcore-android-sdk
external/github.com/GoogleChrome/custom-tabs-client
A mirror of https://chromium.googlesource.com/custom-tabs-client
external/github.com/GoogleCloudPlatform/appengine-gcs-client
external/github.com/GoogleCloudPlatform/appengine-pipelines
external/github.com/GoogleCloudPlatform/compute-image-packages
external/github.com/GoogleCloudPlatform/docker-credential-gcr
external/github.com/GoogleCloudPlatform/endpoints-proto-datastore
external/github.com/GoogleCloudPlatform/go-endpoints
external/github.com/GoogleCloudPlatform/google-cloud-go
external/github.com/GoogleCloudPlatform/google-cloud-go-testing
external/github.com/googlei18n/emoji-segmenter
external/github.com/googlei18n/sfntly
external/github.com/googlesamples/cardboard-java
external/github.com/googlevr/gvr-android-sdk
external/github.com/go-ole/go-ole
external/github.com/gopherjs/gopherjs
external/github.com/gorhill/cronexpr
external/github.com/gorilla/mux
external/github.com/gorilla/websocket
external/github.com/go-sql-driver/mysql
external/github.com/go-tomb/tomb
external/github.com/go-warnings/warnings
external/github.com/go-yaml/yaml
external/github.com/gperftools/gperftools
external/github.com/gradle/gradle
external/github.com/grpc/grpc
external/github.com/grpc/grpc-go
external/github.com/g-truc/glm
external/github.com/guelfey/go.dbus
external/github.com/hamcrest/OCHamcrest
external/github.com/harfbuzz/harfbuzz
external/github.com/hashicorp/errwrap
external/github.com/hashicorp/golang-lru
external/github.com/hashicorp/go-multierror
external/github.com/howeyc/fsnotify
external/github.com/immersive-web/webxr-samples
external/github.com/inconshreveable/mousetrap
external/github.com/intel/tinycbor
external/github.com/jasmine/jasmine
external/github.com/jayway/powermock
external/github.com/jbenet/go-context
external/github.com/jcgregorio/httplib2
external/github.com/jjlee/mechanize
external/github.com/jmoiron/sqlx
external/github.com/jtolds/gls
external/github.com/juju/errors
external/github.com/julienschmidt/httprouter
external/github.com/kardianos/osext
external/github.com/kennethreitz/requests
external/github.com/kevinburke/ssh_config
external/github.com/khaledhosny/ots
external/github.com/KhronosGroup/glslang
external/github.com/KhronosGroup/SPIRV-Cross
external/github.com/KhronosGroup/SPIRV-Headers
external/github.com/KhronosGroup/SPIRV-Tools
external/github.com/KhronosGroup/Vulkan-Headers
external/github.com/Khronos
Forwarded from >/ VolunteerSupport
With me, the sun is shining, it's not the night, the darkness of the night is in your heart
https://news.1rj.ru/str/durovschat/896429
https://news.1rj.ru/str/durovschat/896429
Forwarded from >/ VolunteerSupport
With me, the sun is shining, it's not the night, the darkness of the night is in your heart
https://news.1rj.ru/str/durovschat/896429
https://news.1rj.ru/str/durovschat/896429