Live data from Hacker News

Operation Triangulation: What you get when attack iPhones of researchers

securelist.com

81–90 of 433 posts

Re: Operation Triangulation: What you get when attack iPhones of researchers

#81

State actor attacks on another state actor. Incredible sophisticated and just goes to show you that it basically can’t be defended against

It can be defended against. The detail is that the only way to harden those defenses is to toss it out in the world and let folks poke holes in it. This was an extremely complex exploit. It was complex because of all of the defenses put in place by Apple and others. It required State level resources to pull it off. We also don't know what, if any, external skullduggery was involved in the exploit. Did someone penetra…

> Compromise an employee?

An official visits the headquarters, and informs that certain employees need to be hired at certain departments “to help with national security”. End of story.

What even makes people think that executives whose job is to deal with everyone in order to “do business” are their long distance friends, or some kind of punks who'd jump on the table and flip birdies into faces of people making such an offer?

Re: Operation Triangulation: What you get when attack iPhones of researchers

#82
post #4

It’s quite unfortunate that Apple doesn’t allow users to uninstall iMessage, it seems to be the infection vector for advanced threats like this, NSO group, etc. Presumably it’s to avoid the support burden, but they could gate it behind having Lockdown Mode enabled for a week or something to shake out the vast majority of mistaken activations.

> unfortunate that Apple doesn't allow users to uninstall iMessage

It can be disabled via Apple Configurator, https://news.ycombinator.com/item?id=38785311

Re: Operation Triangulation: What you get when attack iPhones of researchers

#83
post #32

Who had motive to target Russian government officials, knowledge of the attack vectors, history of doing so, and technical and logistical ability to perform it leads Kaspersky and myself to the only rational conclusion: that Apple cooperated with the NSA on this exploit. I assume they only use and potentially burn these valuable methods in rare and perhaps desperate instances. I expect the Russian and Chinese governm…

leads Kaspersky and myself to the only rational conclusion: that Apple cooperated with the NSA on this exploit. Kapersky reaches no such conclusion. That's from an FSB release.

[flagged]

Re: Operation Triangulation: What you get when attack iPhones of researchers

#85

Earlier quoted context omitted.

My adjacent conspiracy theory is that the NSA and other state agencies do both original research and pay hackers for exploits that Apple hasn’t yet discovered.

but why pay hackers to try to find a backdoor when you can just walk in the front door and use the carrot and stick to get what you want?

This happened at a company I worked at so it’s not out of the question. I figured it out by reverse engineering and quit on the spot. They tried to tell me I’d never work again if spying on users was a dealbreaker. They showed me a natsec slide deck that identified other collaborating companies as a way of making their point. Among them was Apple.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#87
post #3

[flagged]

There's a fundamental category error at play here: exploit chains like this one and the one behind FORCEDENTRY[1] cost millions, if not tens of millions, of dollars to discover and weaponize, even before operationalization. The people finding and building these chains are doing so as part of nation-state intelligence operations; they go well beyond what any reasonable civilian threat model contains. Put another way:…

There haven’t really been all that many hardware exploits for us to judge Apple on this, have there?

Re: Operation Triangulation: What you get when attack iPhones of researchers

#88

Earlier quoted context omitted.

> “Due to the closed nature of the iOS ecosystem, the discovery process was both challenging and time-consuming, requiring a comprehensive understanding of both hardware and software architectures... " -Kaspersky researcher Boris Larin supports your point but it's not an easy argument to win either way. It's "everyone can see it so the good guys will find it first" vs "bad guys have harder time discovering vulns but…

To be fair, that was just Kaspersky taking a jab at Apple, after being absolutely gutted by hackers because of their own poor security posture.

I don’t really see anything wrong with their security posture here.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#89
post #86

[flagged]

Yeah people keep talking about reverse engineering but it’s just as real a possibility that this was simply engineered to be there. Apple and the government made a big public show about the San Bernardino iPhone situation[1] but that could have easily been a cover to convince people the government can’t get in to iPhones - because eventually the government dropped the court case, got in anyway, and the whole thing was quickly forgotten.

We can imagine that the government either has ideological capture of apple - that the management of apple agree to install hard to exploit vulnerabilities tailored for US government use - or legal capture through FISA rulings.

I’d be curious if anyone can summarize the latest understanding of FISA court actions in this realm.

[1] https://www.theguardian.com/technology/2016/mar/28/apple-fbi...

Post reply on HN