当前状态
相关研究
2- WhatsApp 以间谍软件滥用验证端点信任问责
WhatsApp 是一个风险与问责案例,因为这家以端到端加密闻名的消息服务必须面对另一个信任边界:端点、调用栈和平台基础设施——这些可能在消息被读取之前就被滥用。围绕 CVE-2019-3568、WhatsApp 对 NSO 集团的诉讼、后续法院裁决以及公共利益文献的公开记录表明,仅靠加密无法回答问责问题。问题在于谁掌握着漏洞修复、用户通知、基础设施滥用、商业间谍软件威慑的控制权,以及平台能否保护高风险用户免受针对性入侵的证据。
主文章发布时间 2026-07-15 - WhatsApp made spyware abuse an endpoint-trust accountability test
WhatsApp is a risk and accountability case because a messaging service known for end-to-end encryption had to confront a different trust boundary: the endpoint, the call stack, and the platform infrastructure that could be abused before a message was ever read. The public record around CVE-2019-3568, WhatsApp's litigation against NSO Group, later court rulings, and public-interest documentation shows that encryption alone cannot answer the accountability question. The question is who had control over exploit repair, user notice, infrastructure abuse, commercial spyware deterrence, and evidence that a platform can defend high-risk users against targeted intrusion.
主文章发布时间 2026-07-15
