Hacker News new | ask | show | jobs
by hammock 1789 days ago
Wait... This happened in 2017.

Facebook bought WhatsApp in 2014.

Pegasus is built on a WhatsApp vulnerability.

Should Facebook have patched this 4 years ago, rather than try to pay a third party to exploit it?

1 comments

It's a funny thought that FB would hire another company to exploit their own software. Because you'd think the dev wouldn't need that. But it actually makes sense, since building in an exploitable flaw (intentionally or not) is NOT the same as making real-world use of it.

Plus even soliciting a 3rd party gives you plausible deniability if someone comes asking you if you exploited the flaw yourself. Oh, to be a capitalist in the 21st century is to feel ALIVE!