Live data from Hacker News

Targeted attack on our management with the Triangulation Trojan

usa.kaspersky.com

101–110 of 131 posts

Re: Targeted attack on our management with the Triangulation Trojan

#101
post #93

Earlier quoted context omitted.

Because they were deceived by Apple's quality promises? If Apple really wanted to improve security (instead of just producing marketing claims about it) they would provide anyone with debugging symbols, root privileges and anything else needed for research and debugging.

> Because they were deceived by Apple's quality promises? The point being, with Kaspersky as security experts, it really does call into question their judgement and expertise.

It's entirely rational to have believed iPhone to be more secure in the past, now believe Android is more secure, and yet remain on iPhone:

  1. At some point, weigh probabilities of exploits
  2. Update Bayesian priors as new evidence arrives
  3. Even if the initial decision currently appears incorrect, there needs to be a high enough difference in probability to justify switching, because in switching, you're still exposed to any persistent exploitation via the old exploits plus new exploits on the new platform
Switching back and forth the instant your Bayesian prior swings over/under 50% for Android being more secure than iPhone is a terrible strategy. (Also, you need to risk-weight your various exploit probabilities... security is a multidimensional quantity, so collapsing to a scalar is at least context-/threat-model-dependent.)

Re: Targeted attack on our management with the Triangulation Trojan

#102
post #10

From the article > We believe that the main reason for this incident is the proprietary nature of iOS. This operating system is a “black box”, in which spyware like Triangulation can hide for years. Detecting and analyzing such threats is made all the more difficult by Apple’s monopoly of research tools – making it a perfect haven for spyware. In other words, as I’ve often said, users are given the illusion of securi…

Shatters Apple's argument that all of these hurdles are better for security. I wonder if testimony like this could affect any of their antitrust lawsuits or right to repair lobbying.

> Shatters Apple's argument that all of these hurdles are better for security.

Sorry I don't buy that this "shatters" anything besides peoples misguided assumptions that anything can be perfectly secure without being fully disconnected.

Apple's iOS 16 supports iphone 8 which was released in 2017, 5 years ago. Apple's iOs 15 supported iphone 6 which was released in 2015, 7 years ago.

> Samsung’s previous promise to provide three years of upgrades and ensures millions of Galaxy users have access to the latest features for security, productivity, visual experience and more, for as long as they own their device.

https://news.samsung.com/us/samsung-galaxy-os-upgrade-one-ui...

They only _just_ changed to 4 years, last year.

> Samsung will now provide up to five years of security updates to help protect select Galaxy devices

They do mention 5 years of updates but only for _select_ galaxy devices (presumably the top of the line).

---

I am assuming anyone rooting/flashing is taking way more risks and security concerns into their own hands. But in length of support/security updates alone apple is winning.

I also wonder how long it actually takes a vulnerability patch (let's say for a zero day) to get out on android and then through OEM security updates. (I haven't been android in too long to know this.) Apple actually just released a way for them to do this and have already used it once, they call it "Rapid Security Responses" (which you can switch off although idk why you would).

https://support.apple.com/en-us/HT204204

Re: Targeted attack on our management with the Triangulation Trojan

#103
post #14

Earlier quoted context omitted.

Not "shatters", as while it is a valid counter, it doesn't tell you the relative strengths and weaknesses of the two approaches, only that Apple isn't perfect which should already have been assumed. A stronger counter to Apple's argument is the relative pricing of exploits… but the story I'm remembering is old enough that I don't want to just assume it's still true, even though it's near the top of my search results:…

Pricing in the exploit market is value based, not cost based. You can sell an iOS exploit for more because the people you're targeting with it are generally wealthier.

> You can sell an iOS exploit for more

If you could sell it for more, but it seems you can't sell it for more.

This implies a large supply of zero-days competing with each other on price.

Re: Targeted attack on our management with the Triangulation Trojan

#104
post #101
post #93

Earlier quoted context omitted.

> Because they were deceived by Apple's quality promises? The point being, with Kaspersky as security experts, it really does call into question their judgement and expertise.

It's entirely rational to have believed iPhone to be more secure in the past, now believe Android is more secure, and yet remain on iPhone: 1. At some point, weigh probabilities of exploits 2. Update Bayesian priors as new evidence arrives 3. Even if the initial decision currently appears incorrect, there needs to be a high enough difference in probability to justify switching, because in switching, you're still expo…

This is irrelevant to the fact that they claim expertise as to why the iPhone is less secure.

They aren’t just claiming it’s because of this one exploit or some exploit stats - they are making the claim that it’s because it’s not open source.

Since they knew this all along, we can conclude that they have poor judgment.

Re: Targeted attack on our management with the Triangulation Trojan

#105
post #96

Earlier quoted context omitted.

It doesn't really shatter anything does it? People here are going to understand that there are trade-offs to every decision made. I suspect iOS is not worse than the more open Android simply because senior management at Kaspersky are using iPhones. If anybody is choosing their platform with security in mind, it has to be them and they are going with iOS.

Previous nation-state level hacking on iPhones used exploits available on the (grey?) market. https://blog.google/threat-analysis-group/italian-spyware-ve...

And on that same page it says the Android version didn’t even require an exploit. The sneakiest thing that was required on Android was to write the word “Samsung” on the app icon so that users would click it.

Near the end, they say:

> This campaign is a good reminder that attackers do not always use exploits to achieve the permissions they need.

Re: Targeted attack on our management with the Triangulation Trojan

#106
post #101

Earlier quoted context omitted.

It's entirely rational to have believed iPhone to be more secure in the past, now believe Android is more secure, and yet remain on iPhone: 1. At some point, weigh probabilities of exploits 2. Update Bayesian priors as new evidence arrives 3. Even if the initial decision currently appears incorrect, there needs to be a high enough difference in probability to justify switching, because in switching, you're still expo…

This is irrelevant to the fact that they claim expertise as to why the iPhone is less secure. They aren’t just claiming it’s because of this one exploit or some exploit stats - they are making the claim that it’s because it’s not open source. Since they knew this all along, we can conclude that they have poor judgment.

They knew all along it was closed source, but that doesn't mean they believed all along (or at least were confident enough in their belief) that closed source resulted in higher risk of extant exploitable flaws.

Re: Targeted attack on our management with the Triangulation Trojan

#107

tl;dr - malicious state and private threat actors can at any time completely take over your iphone (root access) with an invisible iMessage without you having a practical chance to detect it besides scanning your iphone backup

Should add that this can only occur if you haven't updated your phone in over a year.

God knows what other government spywayre us already available and in use and that can do more than this.

Only the top of the iceberg is being visible to public if not less.

Re: Targeted attack on our management with the Triangulation Trojan

#108
post #106

Earlier quoted context omitted.

This is irrelevant to the fact that they claim expertise as to why the iPhone is less secure. They aren’t just claiming it’s because of this one exploit or some exploit stats - they are making the claim that it’s because it’s not open source. Since they knew this all along, we can conclude that they have poor judgment.

They knew all along it was closed source, but that doesn't mean they believed all along (or at least were confident enough in their belief) that closed source resulted in higher risk of extant exploitable flaws.

Sure, I think a lot of people would think about it this way - but that just means they don’t have any real expertise.

Kaspersky says:

“We believe that the main reason for this incident is the proprietary nature of iOS.”

If the proprietary nature is the main reason for the incident, then Android should have been overwhelmingly more secure all along, and they should know this.

If they are only just figuring this out now, then they have been ludicrously ignorant for people who claim to be experts.

Occam’s razor says they really aren’t as expert as their marketing claims and they are trying to save face by blaming Apple.

Given that the Kremlin is blaming Apple and the NSA, perhaps Kaspersky is trying to deflect blame for not having warned Russian diplomats about the issue.

Re: Targeted attack on our management with the Triangulation Trojan

#109
post #101

Earlier quoted context omitted.

It's entirely rational to have believed iPhone to be more secure in the past, now believe Android is more secure, and yet remain on iPhone: 1. At some point, weigh probabilities of exploits 2. Update Bayesian priors as new evidence arrives 3. Even if the initial decision currently appears incorrect, there needs to be a high enough difference in probability to justify switching, because in switching, you're still expo…

This is irrelevant to the fact that they claim expertise as to why the iPhone is less secure. They aren’t just claiming it’s because of this one exploit or some exploit stats - they are making the claim that it’s because it’s not open source. Since they knew this all along, we can conclude that they have poor judgment.

So, they discover a vulnerability in ios and publish the details of the symptoms of the exploit -- something that Apple themselves were unaware --, release a tool to detect indicators of compromise in iphone backups and yet, somehow they have poor judgment?

What should they be doing? Keep the discovery to themselves so those who claim iPhone is secure can continue living obliviously with their worldview unchanged? Wouldn't we accuse them of poor judgment if they did that?

It is quite reasonable for them to say the ecosystem being closed is making analysis and detection difficult. It is up to Apple to do what they want with that information.

Re: Targeted attack on our management with the Triangulation Trojan

#110
post #51

Earlier quoted context omitted.

Why are top management at Kaspersky using iPhones, presumably they knew iPhones were a “black box” and a security risk.

Why are they running iMessage? That’s the real vector here.

Actually, Apple should consider making iMessage open source.

Given it is such a popular attack vector, it probably benefits the ios ecosystem to take the benefit of open source scrutiny. There are other messaging apps like Signal, WhatsApp, Telegram etc., So, it is not like a copycat would suddenly emerge and threaten Apple's position. Apple hold the keys to the app store anyway and can review any potential copycat (supposedly malicious one) and prevent it from being released.

Post reply on HN