Live data from Hacker News

Targeted attack on our management with the Triangulation Trojan

usa.kaspersky.com

81–90 of 131 posts

Re: Targeted attack on our management with the Triangulation Trojan

#81
post #10

From the article > We believe that the main reason for this incident is the proprietary nature of iOS. This operating system is a “black box”, in which spyware like Triangulation can hide for years. Detecting and analyzing such threats is made all the more difficult by Apple’s monopoly of research tools – making it a perfect haven for spyware. In other words, as I’ve often said, users are given the illusion of securi…

Shatters Apple's argument that all of these hurdles are better for security. I wonder if testimony like this could affect any of their antitrust lawsuits or right to repair lobbying.

It doesn't really shatter anything does it? People here are going to understand that there are trade-offs to every decision made.

I suspect iOS is not worse than the more open Android simply because senior management at Kaspersky are using iPhones. If anybody is choosing their platform with security in mind, it has to be them and they are going with iOS.

Re: Targeted attack on our management with the Triangulation Trojan

#82
post #61

Earlier quoted context omitted.

Unlike you, I actually lived in Russia and I can tell with 100% certainty that it's a bs narrative that was used to build up Putin support based on confrontation with the "west".

So no agreements had previously been made then? https://nsarchive.gwu.edu/briefing-book/russia-programs/2017... I mean, I'm not supporting Russia's actions here, I'm saying the US (mainly) are just a bad an actor. They're essentially fighting a war with Russia (as their warmongers and military complex love to tell their shareholders about), Ukraine is just the pawn in the middle. I should have said 'towards' the bord…

>> So no agreements had previously been made then?

Not according to direct participants like the foreign minister of the USSR. https://www.spiegel.de/international/europe/interview-with-e...

Moreover, NATO and Russia signed a treaty greenlighting NATO enlargement before any official talks with former Warsaw Pact countries started, so whatever was allegedly said or heard prior to that is irrelevant anyway.

>> I'm not supporting Russia's actions here

You are, whether you recognize it or not. Your contrarian take is a made up narrative to justify the war. Makes you feel smarter than the rest while advancing Russian interests and blaming victims for crimes against them.

Re: Targeted attack on our management with the Triangulation Trojan

#83
post #10

From the article > We believe that the main reason for this incident is the proprietary nature of iOS. This operating system is a “black box”, in which spyware like Triangulation can hide for years. Detecting and analyzing such threats is made all the more difficult by Apple’s monopoly of research tools – making it a perfect haven for spyware. In other words, as I’ve often said, users are given the illusion of securi…

Shatters Apple's argument that all of these hurdles are better for security. I wonder if testimony like this could affect any of their antitrust lawsuits or right to repair lobbying.

Is Apple making that argument?

Re: Targeted attack on our management with the Triangulation Trojan

#84
post #73

Earlier quoted context omitted.

It still blows my mind that this is not a known fact by most people for as long as phones have existed? Or maybe it is?

how is this generally possible? In my simplified understanding, a text message is a hunk of data, but I know it's more complex than that.... it must be able to connect to all kinds of services and trigger all kinds of code running, right? Can't it be sanity checked sufficiently?

Apparently, it uses iMessage's proprietary messaging format, not standard text messages. I don't use iOS but my understanding is users can't replace iMessage with another messaging app.

Re: Targeted attack on our management with the Triangulation Trojan

#85
post #14

Earlier quoted context omitted.

Shatters Apple's argument that all of these hurdles are better for security. I wonder if testimony like this could affect any of their antitrust lawsuits or right to repair lobbying.

Not "shatters", as while it is a valid counter, it doesn't tell you the relative strengths and weaknesses of the two approaches, only that Apple isn't perfect which should already have been assumed. A stronger counter to Apple's argument is the relative pricing of exploits… but the story I'm remembering is old enough that I don't want to just assume it's still true, even though it's near the top of my search results:…

Pricing in the exploit market is value based, not cost based.

You can sell an iOS exploit for more because the people you're targeting with it are generally wealthier.

Re: Targeted attack on our management with the Triangulation Trojan

#86
post #10

From the article > We believe that the main reason for this incident is the proprietary nature of iOS. This operating system is a “black box”, in which spyware like Triangulation can hide for years. Detecting and analyzing such threats is made all the more difficult by Apple’s monopoly of research tools – making it a perfect haven for spyware. In other words, as I’ve often said, users are given the illusion of securi…

Shatters Apple's argument that all of these hurdles are better for security. I wonder if testimony like this could affect any of their antitrust lawsuits or right to repair lobbying.

It doesn't shatter anything except Kaspersky's good judgement. If this is true the real question is:

Why are Kaspersky's management using iPhones?

Re: Targeted attack on our management with the Triangulation Trojan

#88

Earlier quoted context omitted.

Shatters Apple's argument that all of these hurdles are better for security. I wonder if testimony like this could affect any of their antitrust lawsuits or right to repair lobbying.

It doesn't shatter anything except Kaspersky's good judgement. If this is true the real question is: Why are Kaspersky's management using iPhones?

Because they were deceived by Apple's quality promises?

If Apple really wanted to improve security (instead of just producing marketing claims about it) they would provide anyone with debugging symbols, root privileges and anything else needed for research and debugging.

Re: Targeted attack on our management with the Triangulation Trojan

#89
post #73

Earlier quoted context omitted.

It still blows my mind that this is not a known fact by most people for as long as phones have existed? Or maybe it is?

how is this generally possible? In my simplified understanding, a text message is a hunk of data, but I know it's more complex than that.... it must be able to connect to all kinds of services and trigger all kinds of code running, right? Can't it be sanity checked sufficiently?

Even if it would be a simple text message (which its not for iphone), it triggers a text parser at minimum. That parser can have carious bugs in it, ie if parser checks phone contacts to highlight phone number in text as a known contact, identifies some weblink etc.

To sum it up to have it as fancy as possible to users it checks various things and needs permissions for that. Enough 0days in the chain and you can do whatever you need.

This is the problem of closed systems, you have to trust manufacturer 100%, there is no independent audit possible. And if you ever did any serious code before, you know by heart that any code has bugs, in the code, in platform/VM it runs, apis etc.

Re: Targeted attack on our management with the Triangulation Trojan

#90

Earlier quoted context omitted.

Shatters Apple's argument that all of these hurdles are better for security. I wonder if testimony like this could affect any of their antitrust lawsuits or right to repair lobbying.

It reads more like an excuse than the actual reason. Endpoint protection solutions can be installed in iOS devices. The device could also be wiped clean, eliminating the malware. The latter should not be much of an issue in any serious organization. If any executive keeps critical data in a phone, that is already an issue. The former is a hassle, but I have had to use locked down iPhones before, and the tradeoffs are…

> Endpoint protection solutions can be installed in iOS devices.

How does "endpoint protection solution" protect from 0-day exploits? I guess it can do that only in marketing materials, not in reality.

Post reply on HN