Live data from Hacker News

Operation Triangulation: What you get when attack iPhones of researchers

securelist.com

31–40 of 433 posts

Re: Operation Triangulation: What you get when attack iPhones of researchers

#31

The extra hardware registers might have been discovered by examining the chip itself. One could find where the registers were on it, and notice some extra registers, then do some experimenting to see what they did.

Maybe, but chips already have vast, vast, quantities of physical registers in a big blob.

Assuming it wasn't a lucky guess, timing attacks are often used to find this stuff.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#32

Who had motive to target Russian government officials, knowledge of the attack vectors, history of doing so, and technical and logistical ability to perform it leads Kaspersky and myself to the only rational conclusion: that Apple cooperated with the NSA on this exploit. I assume they only use and potentially burn these valuable methods in rare and perhaps desperate instances. I expect the Russian and Chinese governm…

leads Kaspersky and myself to the only rational conclusion: that Apple cooperated with the NSA on this exploit.

Kapersky reaches no such conclusion. That's from an FSB release.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#33

Who had motive to target Russian government officials, knowledge of the attack vectors, history of doing so, and technical and logistical ability to perform it leads Kaspersky and myself to the only rational conclusion: that Apple cooperated with the NSA on this exploit. I assume they only use and potentially burn these valuable methods in rare and perhaps desperate instances. I expect the Russian and Chinese governm…

That’s only “rational” for kaspersky bc in their world they can’t function without having actual intelligence operatives on staff. I seriously doubt nsa needed help here

Re: Operation Triangulation: What you get when attack iPhones of researchers

#34

The extra hardware registers might have been discovered by examining the chip itself. One could find where the registers were on it, and notice some extra registers, then do some experimenting to see what they did.

Do you know how this is possible? Would decapping the SoC or taking an xray of it provide a physical map of the registers?

You can find the register file relatively easily because it's a block of memory that's the same on each core but isn't cache, but it isn't a 1:1 map from architectural registers that we would recognize: the chip is designed to find an optimal allocation of slots in the register file to runtime values.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#36

State actor attacks on another state actor. Incredible sophisticated and just goes to show you that it basically can’t be defended against

It can be defended against. The detail is that the only way to harden those defenses is to toss it out in the world and let folks poke holes in it. This was an extremely complex exploit. It was complex because of all of the defenses put in place by Apple and others. It required State level resources to pull it off. We also don't know what, if any, external skullduggery was involved in the exploit. Did someone penetra…

>It was complex because of all of the defenses put in place by Apple and others.

I don't know jack about hardware but it would seem obvious that when one designs a chip, you make sure it does not have 'unknown hardware registers' or unknown anything when you get it back from the manufacture.

This makes everything written on this page worthless...

>Prevent anyone except you from using your devices and accessing your information. https://www.apple.com/privacy/control/

Re: Operation Triangulation: What you get when attack iPhones of researchers

#38
It’s kind of simple imo. Apple is an American company and after Jobs died, Apple quickly signed up to working with the NSA and enrolled in the Prism programme.

Apple, like any other USA company, has to abide by the laws and doing what they are told to do. If that means hardware backdoors, software backdoors, or giving NSA a heads up over a vulnerability during the time it takes to fix said vulnerability (to give time for NSA to make good use of it) then they will.

Only someone with great sway (like Jobs) could have resisted something like this without fear of the US Govt coming after him. His successor either didn’t have that passion for privacy or the courage to resist working with the NSA.

Anyone, anywhere with an iPhone will be vulnerable to NSA being able to break into their phone anytime they please, thanks to Apple. And with Apple now making their own silicon, the hardware itself will be even more of a backdoor.

Almost every single staff member at Apple will be none the wiser about this obv and unable to do anything about it even if they did - and their phones will be just as fair game to tap whenever the spies want.

I am speculating. But in my mind, it’s really quite obvious. Just like how Prism made me win an argument I had with someone who was a die hard Apple fan and thought they would protect privacy at all costs… 6 months later, Snowden came along and won me that argument.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#40
post #30
post #5

Earlier quoted context omitted.

They gotta, gotta , have those blue bubbles. Some teenagers fight to get an overpriced phone solely to avoid the deep deep shame of having a green bubble when chatting. If apple is forced to shut down iMessage being the exclusive option and have some pure SMS application they might see a sudden noticeable drop in market share.

They knew exactly what they were doing when they chose that nice blue and that cheap looking green.

Never forget the icon they used for Windows servers: https://i.stack.imgur.com/5rYVr.png
Post reply on HN