My Authors
Read all threads
The story about Saudis hacking Jeff Bezos iPhone didn't find evidence, but unknowns, such as a suspicious encrypted video they couldn't decrypt.

So I wrote a blogpost with a detailed explanation how to decrypt it:
blog.erratasec.com/2020/01/how-to…
Steps:
1. backup the iPhone to desktop
2. grab the file 7c7fba66680ef796b916b067077cc246adacf01d (aka. ChatStorage.sqlite) from that backup
3. use sqlite, in the table ZWAMDIAITEM, grab ZMEDIAURL and ZMEDIAKEY
4. use those values to download the encrypted file and decrypt.
The FTI investigators found the encrypted version of the video suspicious because it was a few bytes longer than the unencrypted video.

That's just normal checksumming and padding, as you see in the code that decrypts the file.
The entire story hinges on this encrypted file containing exploits and/or malware. Once decrypted, this can either be confirmed or ruled out. It's almost certainly going to be ruled out, because the contents will just match the unencrypted video they already have.
Once ruled out, the entire story collapse, as there's no longer any tie to the Saudis. In other words, even if the phone were hacked, there wouldn't be any proof linking that hack to the Saudis.

As my other tweets discuss from a few days ago, there's not even evidence of a hack.
I wrote the code a few days ago but couldn't get it to work until @dinodaizovi showed me the problem, I was using the wrong string to salt the key expansion function, which changes depending on MP4 Video or JPEG Image.
@dinodaizovi In any case, YOU CAN DO THIS AT HOME. You can easily follow the steps to decrypt the WhatsApp videos on your own iPhone. You don't need fancy tools available only to law enforcement, but common, free tools, like iTunes to generate the backup.
Missing some Tweet in this thread? You can try to force a refresh.

Enjoying this thread?

Keep Current with Rob ☃️ Graham (not at Shmoocon this year)

Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Follow Us on Twitter!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!