WhatsUpp with Commercial Hacking Tools in Government Hands?

If you're like 1.5 billion other people on the planet – or if you are Jared Kushner – you conduct a lot of your personal or business conversations on WhatsApp, the Facebook-owned messaging app that says it's largely impervious to snoopers, hackers, and spooks.

But according to a bombshell report in The Financial Times earlier this week, the app has long contained a critical flaw that's enabled hackers to tap into your smartphone just by placing a WhatsApp voice call to you.

The hack relied on a program written by the Israeli tech firm NSO, which designs powerful snooping tools for law enforcement and counterterrorism officials in the Middle East and "western countries."

But it appears that political dissidents, human rights activists, and even a lawyer filing a liability suit against NSO itself were targeted – the FT report doesn't say who the attackers were.

WhatsApp says the bug has been fixed as of Monday. But this story – in which a commercial hacking program sold to governments was used to violate people's privacy and snoop on dissidents –illustrates a few big political challenges that we've highlighted in discussions about cybersecurity.

Cyber-arms control is hard. Cyberweapons, being scripts of computer code, can be very hard to control and contain, even with close oversight of who gets to buy them.

Mission creep is easy. Companies like NSO say they sell these products only to police and counterterrorism officials – but once they are in government hands, they can be used (or sold, or stolen) for other purposes or by other parts of the state.

Liability is murky. Who should be held accountable here: NSO for developing a product that was used beyond its (presumably) stated intent? Or WhatsApp for failing to guarantee the security of its own platform?

Surveillance and espionage are hardly new. But never before has there been a device that contained as much data about your thoughts, habits, preferences, movements, and personal relationships as the device you're holding or reading right this second.

The upshot: With hackers, governments, and commercial developers all trying to figure out how best to crack into it – what are the rules of the game?

More from GZERO Media

Secretary of Treasury Janet Yellen speaks about her key priorities for the 2024 Annual Meetings of the IMF and World Bank during a press conference in Washington DC, USA, on October 22, 2024, at the Department of Treasury Headquarters.
(Photo by Lenin Nolly/NurPhoto)

The International Monetary Fund and World Bank released their much-watched World Economic Outlook on Tuesday, projecting that the world economy will grow by 3.2% in 2025 as inflation cools to an average of 4.3%.

North Carolina Lieutenant Governor Mark Robinson, whom Republican presidential candidate and former U.S. President Donald Trump has endorsed in the race to be the state's next governor, speaks before his arrival for a rally in Greensboro, North Carolina, U.S., March 2, 2024.
REUTERS/Jonathan Drake

When Americans head to the polls on Nov. 5, they’ll vote for more than just the next president.

Russian President Vladimir Putin attends a welcoming ceremony for participants of the BRICS Summit in Kazan, Russia October 22, 2024.
REUTERS/Maxim Shemetov/Pool TPX IMAGES OF THE DAY

For an “isolated” world leader with a global arrest warrant to his name, Vladimir Putin is throwing a pretty decent party this week. Russia is hosting a summit of the BRICS+, a loose grouping of Global “South” countries led by Brazil, Russia, India, China, and South Africa.

In the last year, the cyber threat landscape continued to become more dangerous and complex. The malign actors of the world are becoming better resourced and better prepared, with increasingly sophisticated tactics, techniques, and tools that challenge even the world’s best cybersecurity defenders. Microsoft published its 5th annual Microsoft Digital Defense Report sharing insights and trends from cyberattacks between July 2023 and June 2024. Explore the findings here.

Walmart is fueling American jobs and strengthening communities by investing in local businesses. Athletic Brewing landed a deal with Walmart in 2021. Since then, co-founders Bill Shufelt and John Walker have hired more than 200 employees and built a150,000-square-foot brewery in Milford, CT. Athletic Brewing is one of many US-based suppliers working with Walmart. By 2030, the retailer is estimated to support the creation of over 750,000 US jobs by investing an additional $350 billion in products made, grown, or assembled in America. Learn more about Walmart’s commitment to US manufacturing.

- YouTube

BRICS Summit: A "new world order" or already a relic of the past? Is Sinwar's death the beginning of the end of the war in Gaza? Yankees versus Dodgers. Who's winning? Ian Bremmer shares his insights on global politics this week on World In :60.

The US Commerce Department is looking into whether Taiwan Semiconductor Manufacturing Company, the world’s largest contract chipmaker, is — knowingly or unknowingly — producing computer chips for the Chinese technology giant Huawei.