It’s quite unfortunate that Apple doesn’t allow users to uninstall iMessage, it seems to be the infection vector for advanced threats like this, NSO group, etc. Presumably it’s to avoid the support burden, but they could gate it behind having Lockdown Mode enabled for a week or something to shake out the vast majority of mistaken activations.
Operation Triangulation: What you get when attack iPhones of researchers
11–20 of 433 posts
Re: Operation Triangulation: What you get when attack iPhones of researchers
#12It’s quite unfortunate that Apple doesn’t allow users to uninstall iMessage, it seems to be the infection vector for advanced threats like this, NSO group, etc. Presumably it’s to avoid the support burden, but they could gate it behind having Lockdown Mode enabled for a week or something to shake out the vast majority of mistaken activations.
Re: Operation Triangulation: What you get when attack iPhones of researchers
#13Earlier quoted context omitted.
They gotta, gotta , have those blue bubbles. Some teenagers fight to get an overpriced phone solely to avoid the deep deep shame of having a green bubble when chatting. If apple is forced to shut down iMessage being the exclusive option and have some pure SMS application they might see a sudden noticeable drop in market share.
They've already announced that they will be adding RCS support.
Re: Operation Triangulation: What you get when attack iPhones of researchers
#14Re: Operation Triangulation: What you get when attack iPhones of researchers
#15Re: Operation Triangulation: What you get when attack iPhones of researchers
#16Re: Operation Triangulation: What you get when attack iPhones of researchers
#17>The resulting shellcode, in turn, went on to once again exploit CVE-2023-32434 and CVE-2023-38606 to finally achieve the root access required to install the last spyware payload. Why isn't Apple detecting the spyware\malware payload? If only Apps approved by Apple are allowed on an iPhone, detection should be trivial. And why has no one bothered to ask Apple or ARM about this 'unknown hardware'? >If we try to descri…
Because Apple is busy fixing exploits discovered by Citizenlab. /s
But hey, Apple is secure.
Re: Operation Triangulation: What you get when attack iPhones of researchers
#18It’s quite unfortunate that Apple doesn’t allow users to uninstall iMessage, it seems to be the infection vector for advanced threats like this, NSO group, etc. Presumably it’s to avoid the support burden, but they could gate it behind having Lockdown Mode enabled for a week or something to shake out the vast majority of mistaken activations.
> the unknown attackers kept their campaign alive simply by sending devices a new malicious iMessage text shortly after devices were restarted.
Re: Operation Triangulation: What you get when attack iPhones of researchers
#19State actor attacks on another state actor. Incredible sophisticated and just goes to show you that it basically can’t be defended against
This was an extremely complex exploit. It was complex because of all of the defenses put in place by Apple and others. It required State level resources to pull it off.
We also don't know what, if any, external skullduggery was involved in the exploit. Did someone penetrate Apple/ARM and get internal documentation? Compromise an employee? Did Apple/ARM participate? Maybe they just dissolved a CPU cover, and reverse engineered it.
But, that cat is not out of the bag, and it's been patched.
Progress.
As many folks say, when it comes to dealing with security, consider the threat model. Being under the lens of an advanced State is different from keeping your young brother out of your WoW account.
This exploit wasn't done by a bunch of scammers selling "PC Support". That's the good news.
When stuff like this happens, I always go back to Stuxnet, where not only did they breach an air gap, they went in and did a sneak and peek into some other company to get the private signing keys so that their corrupted payload was trusted. There's a difference between an intelligence operation and a "hack".
Making stuff like this very expensive is part of the defensive posture of the platform.
Re: Operation Triangulation: What you get when attack iPhones of researchers
#20It’s quite unfortunate that Apple doesn’t allow users to uninstall iMessage, it seems to be the infection vector for advanced threats like this, NSO group, etc. Presumably it’s to avoid the support burden, but they could gate it behind having Lockdown Mode enabled for a week or something to shake out the vast majority of mistaken activations.
what does "uninstall iMessage" mean? you can disable iMessage right in the settings so you only receive SMSs