Earlier quoted context omitted.
They knew all along it was closed source, but that doesn't mean they believed all along (or at least were confident enough in their belief) that closed source resulted in higher risk of extant exploitable flaws.
Sure, I think a lot of people would think about it this way - but that just means they don’t have any real expertise. Kaspersky says: “We believe that the main reason for this incident is the proprietary nature of iOS.” If the proprietary nature is the main reason for the incident , then Android should have been overwhelmingly more secure all along, and they should know this. If they are only just figuring this out n…
Targeted attack on our management with the Triangulation Trojan
111–120 of 131 posts
Re: Targeted attack on our management with the Triangulation Trojan
#112Earlier quoted context omitted.
This is irrelevant to the fact that they claim expertise as to why the iPhone is less secure. They aren’t just claiming it’s because of this one exploit or some exploit stats - they are making the claim that it’s because it’s not open source. Since they knew this all along, we can conclude that they have poor judgment.
So, they discover a vulnerability in ios and publish the details of the symptoms of the exploit -- something that Apple themselves were unaware --, release a tool to detect indicators of compromise in iphone backups and yet, somehow they have poor judgment? What should they be doing? Keep the discovery to themselves so those who claim iPhone is secure can continue living obliviously with their worldview unchanged? Wo…
I can see this point of view, but I feel expertise is more about skill in acquiring information and updating beliefs. In my view, real experts can be blatantly wrong, even about foundational facts, if they have an exceptional ability to update those beliefs.
Re: Targeted attack on our management with the Triangulation Trojan
#113Earlier quoted context omitted.
I mean, unless you live in Middle East and one day they say you have WMD and they destroy your whole country. If you live in the EU or the US - then yes.
Which middle eastern country have NATO attacked?
Re: Targeted attack on our management with the Triangulation Trojan
#114Earlier quoted context omitted.
Or you live in Russia and you thought you had a deal that NATO wouldn't encroach further on your border... It was a trick question, none of them are good.
Soviet Union asked to join NATO but was rejected, and the post-Soviet Russian Federation started on the path to joining back in the day. It's not NATO's fault that all the small countries around Russia are so scared of Russian forces that they all ask to join a mutual defence pact.
Re: Targeted attack on our management with the Triangulation Trojan
#115Earlier quoted context omitted.
Or you live in Russia and you thought you had a deal that NATO wouldn't encroach further on your border... It was a trick question, none of them are good.
Has NATO crossed any Russian border? Now nearing borders appears motivated more by Russia's bullying of its neighbors than any desire within NATO to expand. Maybe you're forgetting the protection treaty Russia signed to respect Ukraine's borders in exchange for USSR nukes.
Does NATO even have a border with the counties member states invaded in the past three or so decades? Except Yugoslavia.
Re: Targeted attack on our management with the Triangulation Trojan
#116Earlier quoted context omitted.
Or you live in Russia and you thought you had a deal that NATO wouldn't encroach further on your border... It was a trick question, none of them are good.
Unlike you, I actually lived in Russia and I can tell with 100% certainty that it's a bs narrative that was used to build up Putin support based on confrontation with the "west".
Re: Targeted attack on our management with the Triangulation Trojan
#117Earlier quoted context omitted.
Sure, I think a lot of people would think about it this way - but that just means they don’t have any real expertise. Kaspersky says: “We believe that the main reason for this incident is the proprietary nature of iOS.” If the proprietary nature is the main reason for the incident , then Android should have been overwhelmingly more secure all along, and they should know this. If they are only just figuring this out n…
I feel this is likely going to devolve into a semantic argument over the true definition of real expertise. A key sticking point will likely be volume of a priori knowledge vs. skill in acquiring and synthesizing knowledge.
This is inconsistent with their claims of expertise.
That’s the issue. I believe the claim isn’t being made because they are experts or because it is true, but rather to deflect blame for marketing and political reasons.
Re: Targeted attack on our management with the Triangulation Trojan
#118Earlier quoted context omitted.
So, they discover a vulnerability in ios and publish the details of the symptoms of the exploit -- something that Apple themselves were unaware --, release a tool to detect indicators of compromise in iphone backups and yet, somehow they have poor judgment? What should they be doing? Keep the discovery to themselves so those who claim iPhone is secure can continue living obliviously with their worldview unchanged? Wo…
If I'm understanding the GP correctly, they're asserting that any "real expert" would have anticipated being exploited on iPhone and would never have used iPhone. I can see this point of view, but I feel expertise is more about skill in acquiring information and updating beliefs. In my view, real experts can be blatantly wrong, even about foundational facts, if they have an exceptional ability to update those beliefs…
It’s entirely possible that they are experts, but are making making a claim that is not based on their expertise, for reasons of political and marketing expediency.
Re: Targeted attack on our management with the Triangulation Trojan
#119Earlier quoted context omitted.
Or maybe the monitoring solution noticed the LACK of update checks from iOS devices.
Noticed a lack of updates after 6 months . The whole thing doesn't exactly speak to extreme infosec competence at Kaspersky labs in my opinion.
We're just bloody tired okay?!? Every fing weekend every fking day it's a new 0day and exploit and attack surface.
And then the new patch breaks production or the new edr throws up a storm because someone had the audacity to run psexec or some other bullcrap
/Overworked blue teamer rant
Re: Targeted attack on our management with the Triangulation Trojan
#120Earlier quoted context omitted.
So no agreements had previously been made then? https://nsarchive.gwu.edu/briefing-book/russia-programs/2017... I mean, I'm not supporting Russia's actions here, I'm saying the US (mainly) are just a bad an actor. They're essentially fighting a war with Russia (as their warmongers and military complex love to tell their shareholders about), Ukraine is just the pawn in the middle. I should have said 'towards' the bord…
>> So no agreements had previously been made then? Not according to direct participants like the foreign minister of the USSR. https://www.spiegel.de/international/europe/interview-with-e... Moreover, NATO and Russia signed a treaty greenlighting NATO enlargement before any official talks with former Warsaw Pact countries started, so whatever was allegedly said or heard prior to that is irrelevant anyway. >> I'm not…
No I'm not supporting Russia here, I'm saying they were not just acting "out of nowhere," they are playing the same geopolitical war games (and now actual war), as the US is, but the US are pretending they're absolutely the good guys (i.e. pretending they want peace) while shovelling coal into the fire top speed.
It's a war between Russia and NATO/US, Ukraine just happens to hold shared interests and is now sadly in the middle of this disaster of big boys beating chests.
Hence my comment, who's the good guy...