From the article > We believe that the main reason for this incident is the proprietary nature of iOS. This operating system is a “black box”, in which spyware like Triangulation can hide for years. Detecting and analyzing such threats is made all the more difficult by Apple’s monopoly of research tools – making it a perfect haven for spyware. In other words, as I’ve often said, users are given the illusion of securi…
Does Kapersky release its products under open source license nowadays?
Targeted attack on our management with the Triangulation Trojan
91–100 of 131 posts
Re: Targeted attack on our management with the Triangulation Trojan
#92Earlier quoted context omitted.
I mean, unless you live in Middle East and one day they say you have WMD and they destroy your whole country. If you live in the EU or the US - then yes.
Which middle eastern country have NATO attacked?
https://www.nato.int/cps/en/natohq/topics_8189.htm
Not sure why the downvotes, this is literally the one and only time in NATO's history that Article 5 has been invoked https://en.wikipedia.org/wiki/North_Atlantic_Treaty#Septembe...
Re: Targeted attack on our management with the Triangulation Trojan
#93Earlier quoted context omitted.
It doesn't shatter anything except Kaspersky's good judgement. If this is true the real question is: Why are Kaspersky's management using iPhones?
Because they were deceived by Apple's quality promises? If Apple really wanted to improve security (instead of just producing marketing claims about it) they would provide anyone with debugging symbols, root privileges and anything else needed for research and debugging.
The point being, with Kaspersky as security experts, it really does call into question their judgement and expertise.
Re: Targeted attack on our management with the Triangulation Trojan
#94Earlier quoted context omitted.
how is this generally possible? In my simplified understanding, a text message is a hunk of data, but I know it's more complex than that.... it must be able to connect to all kinds of services and trigger all kinds of code running, right? Can't it be sanity checked sufficiently?
Apparently, it uses iMessage's proprietary messaging format, not standard text messages. I don't use iOS but my understanding is users can't replace iMessage with another messaging app.
To be precise there is one "Messaging" app, that automagically uses iMessage (blue bubbles) instead of SMS (green bubbles) whenever possible. One can turn off iMessage in the settings, which will probably lead to your iPhone rejecting iMessages, making other iPhones only send SMS to you and also make your iPhone only send SMS. Whether that toggle prevents receiving and processing of malicious, invisible iMessages is an entirely different question.
Re: Targeted attack on our management with the Triangulation Trojan
#95Earlier quoted context omitted.
You can and this is trivially verifiable.
Right you can turn off getting any messages entirely and deregister your phone from their network. I believe what I was remembering was you can't swap out the primary SMS receiving app like you can on Android. Unless something changed. Not everyone like's to live in a security bubble w/o phone access, even the security minded.
But you are correct that you cannot switch to a different SMS/MMS app.
Re: Targeted attack on our management with the Triangulation Trojan
#96Earlier quoted context omitted.
Shatters Apple's argument that all of these hurdles are better for security. I wonder if testimony like this could affect any of their antitrust lawsuits or right to repair lobbying.
It doesn't really shatter anything does it? People here are going to understand that there are trade-offs to every decision made. I suspect iOS is not worse than the more open Android simply because senior management at Kaspersky are using iPhones. If anybody is choosing their platform with security in mind, it has to be them and they are going with iOS.
Re: Targeted attack on our management with the Triangulation Trojan
#97Thread from yesterday: https://news.ycombinator.com/item?id=36154455 “Clickless” iOS exploits infect Kaspersky iPhones with never-before-seen malware - 26 comments
Re: Targeted attack on our management with the Triangulation Trojan
#98Thread from yesterday: https://news.ycombinator.com/item?id=36154455 “Clickless” iOS exploits infect Kaspersky iPhones with never-before-seen malware - 26 comments
Several people submitted this, but it gets swept off the HN front page by loyal Apple fans flagging it.
Re: Targeted attack on our management with the Triangulation Trojan
#99Earlier quoted context omitted.
Not "shatters", as while it is a valid counter, it doesn't tell you the relative strengths and weaknesses of the two approaches, only that Apple isn't perfect which should already have been assumed. A stronger counter to Apple's argument is the relative pricing of exploits… but the story I'm remembering is old enough that I don't want to just assume it's still true, even though it's near the top of my search results:…
Pricing in the exploit market is value based, not cost based. You can sell an iOS exploit for more because the people you're targeting with it are generally wealthier.
Re: Targeted attack on our management with the Triangulation Trojan
#100Earlier quoted context omitted.
Which middle eastern country have NATO attacked?
When the US invoked Article 5 after 9/11 and NATO invaded Afghanistan? https://www.nato.int/cps/en/natohq/topics_8189.htm Not sure why the downvotes, this is literally the one and only time in NATO's history that Article 5 has been invoked https://en.wikipedia.org/wiki/North_Atlantic_Treaty#Septembe...