Live data from Hacker News

Operation Triangulation: What you get when attack iPhones of researchers

securelist.com

11–20 of 433 posts

Re: Operation Triangulation: What you get when attack iPhones of researchers

#11
post #4

It’s quite unfortunate that Apple doesn’t allow users to uninstall iMessage, it seems to be the infection vector for advanced threats like this, NSO group, etc. Presumably it’s to avoid the support burden, but they could gate it behind having Lockdown Mode enabled for a week or something to shake out the vast majority of mistaken activations.

what does "uninstall iMessage" mean? you can disable iMessage right in the settings so you only receive SMSs

Re: Operation Triangulation: What you get when attack iPhones of researchers

#12
post #4

It’s quite unfortunate that Apple doesn’t allow users to uninstall iMessage, it seems to be the infection vector for advanced threats like this, NSO group, etc. Presumably it’s to avoid the support burden, but they could gate it behind having Lockdown Mode enabled for a week or something to shake out the vast majority of mistaken activations.

Do you believe your other messaging apps lack vulnerabilities? What is most popular will always be most picked on.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#13
post #5

Earlier quoted context omitted.

They gotta, gotta , have those blue bubbles. Some teenagers fight to get an overpriced phone solely to avoid the deep deep shame of having a green bubble when chatting. If apple is forced to shut down iMessage being the exclusive option and have some pure SMS application they might see a sudden noticeable drop in market share.

They've already announced that they will be adding RCS support.

... And they've already announced[1] that they will be retaining the exclusive blue bubble for iMessage messages for... reasons? The green/blue bubble distinction will continue even when there is no technical difference between messages.

1. https://mashable.com/article/apple-rcs-support

Re: Operation Triangulation: What you get when attack iPhones of researchers

#14
Who had motive to target Russian government officials, knowledge of the attack vectors, history of doing so, and technical and logistical ability to perform it leads Kaspersky and myself to the only rational conclusion: that Apple cooperated with the NSA on this exploit. I assume they only use and potentially burn these valuable methods in rare and perhaps desperate instances. I expect the Russian and Chinese governments' ban on use of Iphones will not be lifted and expand to other governments. Similarly to how the sanctions have backfired, this tactic will also backfire by reducing trust in Apple which is the core of their value proposition.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#17

>The resulting shellcode, in turn, went on to once again exploit CVE-2023-32434 and CVE-2023-38606 to finally achieve the root access required to install the last spyware payload. Why isn't Apple detecting the spyware\malware payload? If only Apps approved by Apple are allowed on an iPhone, detection should be trivial. And why has no one bothered to ask Apple or ARM about this 'unknown hardware'? >If we try to descri…

> Why isn't Apple detecting the spyware\malware payload? If only Apps approved by Apple are allowed on an iPhone, detection should be trivial.

Because Apple is busy fixing exploits discovered by Citizenlab. /s

But hey, Apple is secure.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#18
post #4

It’s quite unfortunate that Apple doesn’t allow users to uninstall iMessage, it seems to be the infection vector for advanced threats like this, NSO group, etc. Presumably it’s to avoid the support burden, but they could gate it behind having Lockdown Mode enabled for a week or something to shake out the vast majority of mistaken activations.

I remember people were very passionately arguing iMessage can only be secure if the only client is the Apple sanctioned one

> the unknown attackers kept their campaign alive simply by sending devices a new malicious iMessage text shortly after devices were restarted.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#19

State actor attacks on another state actor. Incredible sophisticated and just goes to show you that it basically can’t be defended against

It can be defended against. The detail is that the only way to harden those defenses is to toss it out in the world and let folks poke holes in it.

This was an extremely complex exploit. It was complex because of all of the defenses put in place by Apple and others. It required State level resources to pull it off.

We also don't know what, if any, external skullduggery was involved in the exploit. Did someone penetrate Apple/ARM and get internal documentation? Compromise an employee? Did Apple/ARM participate? Maybe they just dissolved a CPU cover, and reverse engineered it.

But, that cat is not out of the bag, and it's been patched.

Progress.

As many folks say, when it comes to dealing with security, consider the threat model. Being under the lens of an advanced State is different from keeping your young brother out of your WoW account.

This exploit wasn't done by a bunch of scammers selling "PC Support". That's the good news.

When stuff like this happens, I always go back to Stuxnet, where not only did they breach an air gap, they went in and did a sneak and peek into some other company to get the private signing keys so that their corrupted payload was trusted. There's a difference between an intelligence operation and a "hack".

Making stuff like this very expensive is part of the defensive posture of the platform.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#20
post #4

It’s quite unfortunate that Apple doesn’t allow users to uninstall iMessage, it seems to be the infection vector for advanced threats like this, NSO group, etc. Presumably it’s to avoid the support burden, but they could gate it behind having Lockdown Mode enabled for a week or something to shake out the vast majority of mistaken activations.

what does "uninstall iMessage" mean? you can disable iMessage right in the settings so you only receive SMSs

Which is what lockdown mode already does
Post reply on HN