Live data from Hacker News

Targeted attack on our management with the Triangulation Trojan

usa.kaspersky.com

61–70 of 131 posts

Re: Targeted attack on our management with the Triangulation Trojan

#61
post #42

Earlier quoted context omitted.

I mean, unless you live in Middle East and one day they say you have WMD and they destroy your whole country. If you live in the EU or the US - then yes.

Or you live in Russia and you thought you had a deal that NATO wouldn't encroach further on your border... It was a trick question, none of them are good.

Unlike you, I actually lived in Russia and I can tell with 100% certainty that it's a bs narrative that was used to build up Putin support based on confrontation with the "west".

Re: Targeted attack on our management with the Triangulation Trojan

#62
post #10

From the article > We believe that the main reason for this incident is the proprietary nature of iOS. This operating system is a “black box”, in which spyware like Triangulation can hide for years. Detecting and analyzing such threats is made all the more difficult by Apple’s monopoly of research tools – making it a perfect haven for spyware. In other words, as I’ve often said, users are given the illusion of securi…

Does Kapersky release its products under open source license nowadays?

Re: Targeted attack on our management with the Triangulation Trojan

#63
post #14

Earlier quoted context omitted.

Shatters Apple's argument that all of these hurdles are better for security. I wonder if testimony like this could affect any of their antitrust lawsuits or right to repair lobbying.

Not "shatters", as while it is a valid counter, it doesn't tell you the relative strengths and weaknesses of the two approaches, only that Apple isn't perfect which should already have been assumed. A stronger counter to Apple's argument is the relative pricing of exploits… but the story I'm remembering is old enough that I don't want to just assume it's still true, even though it's near the top of my search results:…

You can see that it's still the case (for Android exploits to be priced higher than Apply).

https://zerodium.com/program.html

Re: Targeted attack on our management with the Triangulation Trojan

#64

tl;dr - malicious state and private threat actors can at any time completely take over your iphone (root access) with an invisible iMessage without you having a practical chance to detect it besides scanning your iphone backup

Should add that this can only occur if you haven't updated your phone in over a year.

Or if you were infected over a year ago by malware that blocks and doesn't notify you of updates.

Re: Targeted attack on our management with the Triangulation Trojan

#65
post #51

Earlier quoted context omitted.

Why are top management at Kaspersky using iPhones, presumably they knew iPhones were a “black box” and a security risk.

Why are they running iMessage? That’s the real vector here.

I don't think you can disable iMessage.

Re: Targeted attack on our management with the Triangulation Trojan

#67
post #50
post #42

Earlier quoted context omitted.

I mean, unless you live in Middle East and one day they say you have WMD and they destroy your whole country. If you live in the EU or the US - then yes.

Which middle eastern country have NATO attacked?

[dead]

Re: Targeted attack on our management with the Triangulation Trojan

#68
post #21
post #18

Earlier quoted context omitted.

Literally one google search gave me this.[1] You could have saved a lot of time writing "Kaspersky FSB GRU" in google than writing this comment to someone to cite their sources. [1] https://www.bloomberg.com/news/articles/2017-07-11/kaspersky...

Could you quote a paragraph from that article that supports the claim > Kaspersky was spying on international citizens for over a decade, providing data for both the FSB and GRU. I read it through twice and aside from implication the strongest assertion was that Bloomberg had seen emails that confirmed Kaspersky had worked with the FSB to supply anti-DDOS systems that included counter measures (the ability to hack an…

There's apparently an entire wiki on the subject and again it's mostly speculation, misunderstanding (ie, in the NSA case), or as you said misrepresenting what was essentially a pretty innocuous defensive gov contract by an infosec company.

https://en.wikipedia.org/wiki/Kaspersky_bans_and_allegations...

It makes sense for western governments to be wary of using it but going beyond that is just speculation at this point.

Re: Targeted attack on our management with the Triangulation Trojan

#69
post #65

Earlier quoted context omitted.

I don't think you can disable iMessage.

You can and this is trivially verifiable.

Right you can turn off getting any messages entirely and deregister your phone from their network. I believe what I was remembering was you can't swap out the primary SMS receiving app like you can on Android. Unless something changed. Not everyone like's to live in a security bubble w/o phone access, even the security minded.

Re: Targeted attack on our management with the Triangulation Trojan

#70
post #69

Earlier quoted context omitted.

You can and this is trivially verifiable.

Right you can turn off getting any messages entirely and deregister your phone from their network. I believe what I was remembering was you can't swap out the primary SMS receiving app like you can on Android. Unless something changed. Not everyone like's to live in a security bubble w/o phone access, even the security minded.

There is a switch in the Settings app to disable iMessage and just use SMS. This is an option for the built in messaging app, no need to “swap” or install another app.
Post reply on HN