Advertisement
Advertisement

“It sounds like something on the, you know, what they call the operate, operated on the phone itself,” Clegg said. “It can’t have been anything on the, when the message was sent, in transit, because that’s end-to-end encrypted on WhatsApp.”

Clegg went on to compare the hack to opening a malicious email, saying that, “It only comes to life when you open it.” That’s not entirely accurate, by the way, given that nowadays, in general, your device can’t get infected by simply opening an email (unless your email client allows scripting.) Email hacks often involve clicking on malicious links or downloading infected attachments.

Of course, Clegg could have meant that your device can get compromised when you click on a file, but that’s not clear given his answer.

Facebook’s policy chief added that “something” must have affected the phone’s operating system. According to a technical report on the hack, Bezos’ was using an iPhone X when he received a suspicious video file from the Saudi prince on WhatsApp, which investigators later determined was the source of the malware.

Advertisement

When asked how he could be sure of his statements, Clegg fumbled again but managed to get out that it’s because end-to-end encryption is unhackable.

Advertisement

“As sure as you can be that the technology of end-to-end encryption cannot, other than unless you have handset, or you have the message at either end, cannot be hacked into,” he said.

Some members of the technology community have criticized Clegg’s response to the Bezos hack. According to the BBC, cybersecurity researchers pointed to two WhatsApp security flaws in 2019 to demonstrate that the messaging app wasn’t infallible. In one case, hackers developed malware that was activated when attackers called another person via WhatsApp. Facebook later sued the Israeli-based NSO Group, which is accused of making the malware.

Advertisement

In another case, hackers found a security flaw that could have let them access people’s messages by sending a malicious video file.

This isn’t the first time Facebook has blamed operating systems for the hack this week. During an interview with Bloomberg, Nicola Mendelsohn, Facebook’s vice president for Europe, the Middle East, and Africa, said that the Bezos hack highlights one of the “potential underlying vulnerabilities that exist on the actual operating systems on phones.”

Advertisement

Apple declined to comment on Facebook’s statements.

Advertisement

Although Facebook has not named Apple specifically in the comments made by Clegg and Mendelsohn, the report revealing that Bezos was using an iPhone X was published by news outlets before both made their comments.

The role of WhatsApp in the Bezos hack is the latest chapter of a story that can sometimes resemble an alarming and tragic TV drama. Experts believe that Bezos was targeted by Saudi Arabia because he is the owner of the Washington Post, which published critical articles about the crown prince. The author of those articles was Jamal Khashoggi, who was killed by the Saudi government in 2018.

Advertisement

Saudi Arabia has denied claims that bin Salman was behind the Bezos hack. It has called for an investigation concerning the accusations.