Live data from Hacker News

Operation Triangulation: What you get when attack iPhones of researchers

securelist.com

61–70 of 433 posts

Re: Operation Triangulation: What you get when attack iPhones of researchers

#61
post #51

That's pretty astonishing. The MMIO abuse implies either the attackers have truly phenomenal research capabilities, and/or that they hacked Apple and obtained internal hardware documentation (more likely). I was willing to believe that maybe it was just a massive NSA-scale research team up until the part with a custom hash function sbox. Apple appears to have known that the feature in question was dangerous and delib…

or Apple just implemented this "API" for them, because they've asked nicely

Or they have assets working at Apple... or they hired an ex-Apple employee... etc.

That's the problem with this sort of security through obscurity; it's only secure as long as the people who know about it can keep it secret.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#62

Earlier quoted context omitted.

what does "uninstall iMessage" mean? you can disable iMessage right in the settings so you only receive SMSs

Which is what lockdown mode already does

Actually lockdown is better. It leaves E2E encryption alone, but restricts attachment types, which should be enough to block the initial exploit in the chain.

Disabling iMessage would fall back to SMS, allowing messages to be snooped / modified in transit.

Hopefully they’ll also have a way to disable RCS, since it allows attackers to modify messages, and also has a larger implementation attack surface than SMS.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#63

Who had motive to target Russian government officials, knowledge of the attack vectors, history of doing so, and technical and logistical ability to perform it leads Kaspersky and myself to the only rational conclusion: that Apple cooperated with the NSA on this exploit. I assume they only use and potentially burn these valuable methods in rare and perhaps desperate instances. I expect the Russian and Chinese governm…

My adjacent conspiracy theory is that the NSA and other state agencies do both original research and pay hackers for exploits that Apple hasn’t yet discovered.

The Darknet Diaries episode "Zero Day Brokers" goes into this. Apparently Argentina hosts a lot of outsourced exploit development. Here's the transcript: https://darknetdiaries.com/transcript/98/

Re: Operation Triangulation: What you get when attack iPhones of researchers

#64
post #30
post #5

Earlier quoted context omitted.

They gotta, gotta , have those blue bubbles. Some teenagers fight to get an overpriced phone solely to avoid the deep deep shame of having a green bubble when chatting. If apple is forced to shut down iMessage being the exclusive option and have some pure SMS application they might see a sudden noticeable drop in market share.

They knew exactly what they were doing when they chose that nice blue and that cheap looking green.

No they didn't, because the green was first in 2007, when iPhone only supported SMS. It was 4 years later that iMessage launched. The conversation probably went like:

"Okay well, now that we're launching an alternative to SMS, how will we distinguish iMessage messages from regular SMS messages?"

"Hm, well, SMS messages are green, so what if we picked another color?"

"Yeah okay, blue? ¯\_(ツ)_/¯"

"Sounds good, mock it up and send it to the engineers"

edit: The reason for picking green originally was probably because all the "communication"-related apps had a green color scheme, including Messages. This persists today — the app icons for Phone, Messages, and FaceTime are all green.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#65
post #53

Earlier quoted context omitted.

>It was complex because of all of the defenses put in place by Apple and others. I don't know jack about hardware but it would seem obvious that when one designs a chip, you make sure it does not have 'unknown hardware registers' or unknown anything when you get it back from the manufacture. This makes everything written on this page worthless... >Prevent anyone except you from using your devices and accessing your i…

You’re assuming the registers are unknown to the chip designer. The article doesn’t state that. It says it’s undocumented for the security researchers.

good point

Re: Operation Triangulation: What you get when attack iPhones of researchers

#66
post #13

Earlier quoted context omitted.

They've already announced that they will be adding RCS support.

... And they've already announced[1] that they will be retaining the exclusive blue bubble for iMessage messages for... reasons? The green/blue bubble distinction will continue even when there is no technical difference between messages. 1. https://mashable.com/article/apple-rcs-support

People use “green bubbles” to just mean “no guaranteed delivery or delivery receipts, no read receipts, very low quality image and videos, bad support for reactions, threaded replies, and group chats”.

…the color isn’t the problem. It’s shorthand for the real underlying issues

Re: Operation Triangulation: What you get when attack iPhones of researchers

#67

>The resulting shellcode, in turn, went on to once again exploit CVE-2023-32434 and CVE-2023-38606 to finally achieve the root access required to install the last spyware payload. Why isn't Apple detecting the spyware\malware payload? If only Apps approved by Apple are allowed on an iPhone, detection should be trivial. And why has no one bothered to ask Apple or ARM about this 'unknown hardware'? >If we try to descri…

I think Lockdown would help here since it doesn’t decode message attachments. So the original link in the chain (decoding a PDF) would be impossible.

As for detecting unauthorized apps, I would imagine that once you’ve taken over control of the OS kernel, it’s game over for such software-based restrictions. The Halting theorem guarantees such limitations to any software-based restriction. And as long as you can form a Turing complete mechanism from pieces of the computer, such software limitations will apply.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#68

Earlier quoted context omitted.

My adjacent conspiracy theory is that the NSA and other state agencies do both original research and pay hackers for exploits that Apple hasn’t yet discovered.

but why pay hackers to try to find a backdoor when you can just walk in the front door and use the carrot and stick to get what you want?

Here's my serious answer that still works if you hate Apple.

Your question assumes two things: (1) That Apple intentionally leaves vulnerabilities in the stack, and (2) that Tim Apple is occasionally willing to share this candy with governments.

Having worked at Apple, I don't believe (1) can be true. Not only is it extremely unlikely that it could be kept a secret, but Apple's thing is "obsessive control", a mindset borne of organizational PTSD which originated with its near-death experience in the mid-to-late 90s. The Apple I know would not risk intentionally leaving back doors unlocked for enemies to find and leverage.

As for (2), the existence of a "Binder of Vulns" by nation-states would expose Apple to existential risk. It's possible that it could be kept secret within Apple's walls if it were never used, but once shared with a government it could not be contained. The splash damage of such a discovery could easily kill Apple.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#69
post #13

Earlier quoted context omitted.

... And they've already announced[1] that they will be retaining the exclusive blue bubble for iMessage messages for... reasons? The green/blue bubble distinction will continue even when there is no technical difference between messages. 1. https://mashable.com/article/apple-rcs-support

Yep, why would they drop it? It’s especially egregious as Apple disregards its own human interface guidelines to make green bubbles excessively low-contrast. Very intentional.

[deleted]

Re: Operation Triangulation: What you get when attack iPhones of researchers

#70

https://streaming.media.ccc.de/37c3/relive/11859

Begins @ 27:21 In addition contents of the presentation, in terms of timeline... 2018 (September): First undocumented MMIO-present CPU launched, Apple A12 Bionic SOC. 2021 (December): Early exploit chain infrastructure backuprabbit.com created 2021-12-15T18:33:19Z, cloudsponcer.com created 2021-12-17T16:33:50Z. 2022 (April): Later exploit chain infrastructure snoweeanalytics.com created 2022-04-20T15:09:17Z suggestin…

It's really a pity they explain all the mistakes that helped the malware be detected.
Post reply on HN