Report on analysis ...
 
Notifications
Clear all

Report on analysis of Jeff Bezos' iPhone

13 Posts
6 Users
0 Reactions
1,788 Views
(@the_grinch)
Estimable Member
Joined: 14 years ago
Posts: 136
 

They didn't say if they referred it to law enforcement, but I'd suspect they'd do as others had and when the time came turned the image(s) over to law enforcement.

I agree they have an uphill battle if they truly are saying Saudi Arabia did this. Nothing in this report would have me confident enough to say that. Also, I definitely wouldn't continue to utilize the device.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

While I agree that the owner should not continue to utilize the device for normal usage, I'd recommend having someone in the lab use the phone, just so that they could determine what data was leaving the phone (i.e., the uptick in data leaving the phone after the video was received).


   
ReplyQuote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
Topic starter  

An interesting supplement on the (missing) decryption of the WhatsApp video

https://blog.erratasec.com/2020/01/how-to-decrypt-whatsapp-end-to-end.html

Particularly worth of note (IMHO) is the conclusion

Conclusion

The report from FTI doesn't find evidence. Instead, it finds the unknown. It can't decrypt the .enc file from WhatsApp. It therefore concludes that it must contains some sort of evil malware hidden on that that encryption – encryption which they can't break.

But this is nonsense. They can easily decrypt the file, and prove conclusively whether it contains malware or exploits.

They are reluctant to do this because then their entire report would fall apart. Their conclusion is based upon Bezos's phone acting strange after receiving that video. If that video is decrypted and shown not to contain a hack of some sort, then the rest of the reasoning is invalid. Even if they find other evidence that Bezos's phone was hacked, there would no longer anything linking to the Saudis.

jaclaz


   
ReplyQuote
Page 2 / 2
Share: