Pavel Durov criticized WhatsApp, once again announcing the vulnerability of the most popular messenger in the world. The Bell figured out the origins of this dispute and learned from the experts, which is more reliable - WhatsApp or Telegram.

This note was originally written for the weekly technology building The Bell. You can subscribe to it here .
At the end of November, Pavel Durov was not the first time for the first time that WhatsApp does not just contain vulnerabilities. In his opinion, the company specifically leaves the "backdors", that is, the holes in defense, for the authorities and special services. Durov claims that Facebook even before the purchase of WhatsApp was part of government surveillance programs and it would be naive to assume that this has changed later. He also refers to one of the founders of whatsApp Brian Eckon, who also called on to remove Facebook and stated that Mark Zuckerberg users sold the company with the messenger.
Over the past few months, WhatsApp has been in the center of two high -profile scandals associated with hacking smartphones. Both are tied to really serious leaks, explains Sergey Nikitin, deputy head of the Group-IB computer forensic laboratory. The first leak, detected in May, made it possible to access the device using a call via WhatsApp. The second, which served as the reason for the attack of Durov, gives the attackers the opportunity to establish spy software, simply sending the video.
The first scandal happened in May. Then it turned out that the big vulnerability in WhatsApp allowed to establish a spy on the Israeli NSO Group called PEGASUS using just one call through WhatsApp. Employees of the Israeli company denied that they themselves chose the victim, but did not refute their involvement in the attack. And at the end of October, the head of WhatsApp in the column at The Washington Post accused NSO Group of involvement in hacking devices at least 100 human rights activists and activists around the world.
In order to evaluate the scale of the problem, you need to tell the story of the NSO Group. The company was founded in 2010, but for the first time its name sounded loudly only in the summer of 2016. Then Lookout, engaged in cybersecurity, announced that the Israeli NSO was able to hack the then iOS and establish a program that intercepts all the user actions.
This very concerned the whole industry. Firstly, the NSO software complex involved three unknown holes in the Apple platform before that time (because of this, the vulnerability was called Trident, “Trident”). Secondly, the American Francisco Partners bought 70% of the company, specializing in technological investments and managing $ 12 billion by assets for 2019.
NSO Group offers a luxury class, then wrote The New York Times. The installation of spy software costs $ 500,000, and surveillance for the first 10 iPhones will cost another $ 650,000. The business was successful. In 2018, the company's revenue amounted to $ 250 million, dozens of customers used its services, but Francisco Partners chose to quickly get rid of the asset.
In early 2019, according to The Times of Israel, the founders of the NSO Group bought a control package back. For the transaction, the company was estimated at about $ 1 billion, which made it a “unicorn”. Money for ransom to the founders helped to find the European Private Capital Fund Novpina Capital.
This fund occupies a unique market position. Its founder, the former British Olympic athlete, Steven Pil turned out to be such a versatile person that he was specially created to work with the NSO Group. Saw at the same time created the SMP Policy Innovation Limited Non -Profit Consulting, and managed the Russian and Eastern European cases of the TPG Capital investment, and also participated in the activities of the School of State Council in Oxford, which bears the name of its sponsor Leonard Blavatnik.
Having invested in NSO, Pali immediately took on communication with Amnesty International and other human rights organizations. And although the NSO Group was still called the “Cyber weapon merchants” and the “Spy Poe Personal Manager”, the message managed to deliver the addressee-Novalpina Capital promised to “significantly improve the company's attitude to human rights”. And later The Guardian found out that the NSO Group also became the new co -owner of the NSO Group, Yana Pal, the wife of Stephen and at the same time a British human rights activist. This caused a scandal in those circles that are significant for Novalpina Capital, and not just technological companies. Of course, the NSO Group is unlikely to be able to change its nuclear business model, but now she will have to seriously take into account the possible reputation damage associated with the choice of the authorities of the wrong goals for hacking.
The vulnerability in WhatsApp, which allowed to install by the NSO Group in the messenger, using the call, was found at about the same when all these events occurred. Such visible simplicity is very characteristic of good vulnerabilities - before the installation occurred when the user, for example, crossed the link to the SMS sent by SMS (November vulnerability, which became the reason for Durov’s statement, also facilitates the infection - it is enough to send the victim the video file in the MP4 format). The result was Facebook and NSO Group to each other: Facebook claims are understandable, and the employees of the Israeli company complained about blocking in the ecosystem of Mark Zuckerberg.
To say, like Pavel Durov, that there is a lot of vulnerabilities in WhatsApp - this is suspicious, will be an exaggeration, the senior pentor (tests for penetration) Digital Security Alexander Bagov believes. “In recent years, Facebook and its services have been under the sight of not only ordinary hackers, but also entire states that were ready to finish the company for any non -compliance with the safety of users. It must be understood that completely invulnerable systems do not exist, there are only better or worse protected, ”he explains.
Market mechanisms confront security requirements. “You can, of course, conduct a very tough audit of the code, but then it will be almost unrealistic to write such a large project as a messenger with a bunch of functions: you can do any new chip with safe development only a year after your competitors,” Bagov believes. It is important how many users managed to suffer from vulnerability. In the end, by the time Durov wrote a post, WhatsApp released the update and eliminated the hole.
There were no such large scandals around Telegram. But Sergey Nikitin from Group-Ib associates this with the fact that the messenger is much less popular (300 million Telegram people against more than 1.5 billion WhatsApp). “Moreover, we do not know for sure whether there is vulnerability there or not. Perhaps they are found, eliminated, and this goes unnoticed, ”he argues. - At the same time, whatsApp is now very closely monitored. But there are vulnerabilities in all messengers. ” Durov himself Nikitin connects with the "competition".
Digital Security believes that any messenger can be hacked, but WhatsApp does not have “fairly simple vulnerabilities”. Bugs adds that Durov is “a little cunning” when he speaks of Telegram security. The messenger found a vulnerability that allowed to read the contents of secret chats in case of access to the device, he recalls.
“Telegram client applications are found in vulnerabilities similar to found in WhatsApp,” the expert says. “However, it is worthwhile to understand that the development systems of developers about these attacks leave a rather narrow window for an attack - before the system is made to the system.” The question is how long the attackers who have found vulnerability will be able to keep it secret.
State bodies may be more profitable to demand encryption keys to the owners; It was Telegram's refusal to convey the keys to the locks. Interestingly, the keys were requested not only by the messenger Durov. The FSB came to whatsApp and Viber, but as a result no one handed them over, Sergei Nikitin recalls. The fact that the Telegram as a result applied sanctions, but there are no other instant messengers, he calls the "purely political history."
Partially, Nikitin’s statements are confirmed by the fact that if the special services had access to the backdor provided by Facebook, the authorities of various countries would not have to turn to companies like NSO Group. The one to gain access to the phones of those whom the authorities considered extremists, it involves not yet closed vulnerabilities. The development of each vulnerability can cost the company in millions of dollars, and the attack is carried out not only to instant messengers.
Facebook, buying WhatsApp, gave $ 19 billion. This money is still unable to repel, since the messenger, due to his corporate culture, has long resisted any method of advertising monetization. A few years later, both founders left the company, who did not want to put up with the approach to the user as a product. This, on the one hand, unleashed Facebook hands, and on the other, led to the search for new approaches; WhatsApp in its markets began to be associated with the spread of fakes, election manipulation and many other things that make the development of media services.
In addition, Facebook itself began to notice the ceiling in the advertising income of its ecosystem. Any tape - messages, posts, records - has a limited advertising capacity.
The company decided to develop other directions in its products - from exotic virtual reality, which will not “shoot” to more traditional payment infrastructure and the development of electronic trade.
At the beginning of the year, Facebook decided to combine messengers platforms, simplifying and increasing the handling of the product, as well as reducing the attack area - to find vulnerability in one of three messengers is easier than one.
All summer the company tried to advance its cryptocurrency, which could give financial instruments to residents of developing countries. When this did not work , I launched the more familiar payment service Facebook Pay, working in Messenger, WhatsApp and Instagram.
The company also moved to online trade. In March, shopping appeared on Instagram. In November, mobile catalogs of goods were launched in WhatsApp, combining 1.5 billion users.
As a result of Durov, rightfully proud of the technological advantage and made fun of WhatsApp, adopting innovative functions, now acts as a catch -up:
A separate threat to Telegram is the Facebook media strategy. The new product, the News tab, allows the company to capture the tidbit of the news aggregation market. At the same time, Mark Zuckerberg is ready to pay publishers.
In the long run, this can lead to the fact that Facebook will become the point of entry for consumption of news from authoritative sources, and even with access to the minds of half of humanity.
The news infrastructure of many countries of Telegram (Iran, Russia, Uzbekistan) generally needs to be repaired and alternative sources of information. In June, Telegram began a set of people on a block of news recommendations, offering to go to the company to the developers of Yandex.No -Novosti and other aggregators. At the end of November, the task of clustering news content was put up for a competition with a prize fund of $ 100 thousand.
In such an arms race, the lack of vulnerabilities, perhaps, is far from the main thing.