Live data from Hacker News

How to catch a wild triangle

securelist.com

41–46 of 46 posts

Re: How to catch a wild triangle

#42
post #22

> Unfortunately, this method did not allow us to intercept HTTPS traffic of Apple services (including iMessage), as iOS implements SSL pinning for this. Thus, we were not able to decrypt iMessage traffic that came through the VPN. When security helps attackers... that's a bit ironic. Anyway, this article is exactly why I don't want to work in computer security, you constantly have to look behind you, and government A…

Computer security person here! I have yet to be assassinated :)

And that was the last time anybody ever heard from the real saagarjha.

Re: How to catch a wild triangle

#43
post #13

> Unfortunately for us, all the communications with the servers in question happened over HTTPS, so we could not recover any additional details from the traffic. This is why your corporate network should MitM all TLS connections by default.

The risk of getting your MitM box compromised is too high IMO

Is this risk analysis real? I don't believe in companies that think this is a risk at all if their box is implemented properly. If it's even possible to compromise then you have bigger problems (like your intranet not being properly secured, or the MitM setup not being sandboxed properly, or .....)

Re: How to catch a wild triangle

#44
post #22

> Unfortunately, this method did not allow us to intercept HTTPS traffic of Apple services (including iMessage), as iOS implements SSL pinning for this. Thus, we were not able to decrypt iMessage traffic that came through the VPN. When security helps attackers... that's a bit ironic. Anyway, this article is exactly why I don't want to work in computer security, you constantly have to look behind you, and government A…

Computer security person here! I have yet to be assassinated :)

Depends on what sort of security you work, but companies who work for state or military related security might be easy targets.

Security means money and can mean violence.

There are computer security people who work for intel agencies, those are the people I am talking about.

Even people who work for securing data of companies, those people might also be targets.

Re: How to catch a wild triangle

#45
post #14
post #11

> Despite many ups and downs, we eventually managed to obtain all the stages used in this attack, including four zero-day exploits reported to Apple, two validators, an implant and its modules. Looks like NSA still hasn't forgiven Kaspersky for exposing STUXNET [1]. It seems that this latest attack on Kaspersky was expensive. Losing 4 zerodays must have been painful. It's also possible that Israel and Unit 8200 [2] w…

no way in hell the NSA forcibly tries to reinfect targets over and over, that's not their modus operandi. Instead they would have spend money to find a persistence on the infected device. The fact that the attacker has almost a full-chain but no persistence screams to me "second fiddle", probably a nation state that have access to 0-days brokers but no in-house engineering.

This is not the first time the NSA infiltrated Kaspersky. Avoiding persistence was one of the desired requirements of the attack.

Re: How to catch a wild triangle

#46
post #2

Ooh, I really enjoyed this devlog. I'd have liked to see where they pointed the finger in terms of who they think sent these off, but in case you're too lazy to read: a .watchface file sent over iMessage was used to hoist up enough power to delete all records of the iMessage and open two-way encrypted communications with a local binary. Figuring that out led to (I think?) four zero-day reports to Apple, and a substan…

Really wish everyone would stop using iMessage forever and Appl would just drop it. It really is garbage and its so clearly multitasking in its true actual purpose that its starting to get ridiculous. I nominally feel the same about forcing WebKit and various other similar internal standards that constantly result in zero-days and that also happen to be enforced as defaults upon sign in
Post reply on HN