Live data from Hacker News

Operation Triangulation: What you get when attack iPhones of researchers

securelist.com

91–100 of 433 posts

Re: Operation Triangulation: What you get when attack iPhones of researchers

#91
post #3

[flagged]

There's a fundamental category error at play here: exploit chains like this one and the one behind FORCEDENTRY[1] cost millions, if not tens of millions, of dollars to discover and weaponize, even before operationalization. The people finding and building these chains are doing so as part of nation-state intelligence operations; they go well beyond what any reasonable civilian threat model contains. Put another way:…

Why is it that everyone balks at including these shadowy government agencies in threat models? It feels like people just don't want the heat. Would people just give up if it was some corrupt narcostate instead?

They've proven numerous times they couldn't care less about the rights of their own citizens. The US agencies in particular can't even muster any respect for their own allies. I don't even want to imagine what they feel justified in doing to foreigners. They're basically a threat to everyone on earth at this point and we all need the ability to defend against people like them.

So it costs millions to compromise someone? We need to find ways to make it cost billions then. Then we make it cost trillions. They should have to commit crimes against humanity in order to get anyone at all.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#92
post #13

Earlier quoted context omitted.

... And they've already announced[1] that they will be retaining the exclusive blue bubble for iMessage messages for... reasons? The green/blue bubble distinction will continue even when there is no technical difference between messages. 1. https://mashable.com/article/apple-rcs-support

People use “green bubbles” to just mean “no guaranteed delivery or delivery receipts, no read receipts, very low quality image and videos, bad support for reactions, threaded replies, and group chats”. …the color isn’t the problem. It’s shorthand for the real underlying issues

The color is a big part of the problem, white on green is one of the hardest to read because of the distribution of color cone cells in our retinas. Only maybe white on yellow would be worse.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#93
post #37

[flagged]

Reading between the lines of TFA, it seems the researchers may also suspect that to be the case: > Our guess is that this unknown hardware feature was most likely intended to be used for debugging or testing purposes by Apple engineers or the factory, or that it was included by mistake. Because this feature is not used by the firmware, we have no idea how attackers would know how to use it. However, keep in mind that…

I always get weird consultants reaching out to me on LinkedIn asking for deets on my org's layout and - curiously - our tech stack. They offer something like $500+ an hour but I don't want to be complicit in some compromise. Private intelligence is such a fascinating industry.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#94

iMessage can be disabled by local MDM for supervised devices, via free Apple Configurator in macOS app store, https://support.apple.com/guide/deployment/restrictions-for-... For Wi-Fi–only devices, the Messages app is hidden. For devices with Wi-Fi and cellular, the Messages app is still available, but only the SMS/MMS service can be used. SMS/MMS messages and non-emergency cellular radio traffic can be disabled by a…

We purchased an iPad with cellular, with the plan to put my home country's sim card in it so I can still receive SMS (as most of the banks there still requires SMS verification when you login), and it turns out that iPad with cellular does not really show you SMS's that's not from the carrier of the sim card.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#95

Earlier quoted context omitted.

but why pay hackers to try to find a backdoor when you can just walk in the front door and use the carrot and stick to get what you want?

Here's my serious answer that still works if you hate Apple. Your question assumes two things: (1) That Apple intentionally leaves vulnerabilities in the stack, and (2) that Tim Apple is occasionally willing to share this candy with governments. Having worked at Apple, I don't believe (1) can be true. Not only is it extremely unlikely that it could be kept a secret, but Apple's thing is "obsessive control", a mindset…

We already know Apple has participated to the PRISM program, it's not speculation anymore.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#96
post #51

That's pretty astonishing. The MMIO abuse implies either the attackers have truly phenomenal research capabilities, and/or that they hacked Apple and obtained internal hardware documentation (more likely). I was willing to believe that maybe it was just a massive NSA-scale research team up until the part with a custom hash function sbox. Apple appears to have known that the feature in question was dangerous and delib…

or Apple just implemented this "API" for them, because they've asked nicely

I think the way it’s done is that the code is presented to them to use, Apple probably don’t even code those parts themselves.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#97

>The resulting shellcode, in turn, went on to once again exploit CVE-2023-32434 and CVE-2023-38606 to finally achieve the root access required to install the last spyware payload. Why isn't Apple detecting the spyware\malware payload? If only Apps approved by Apple are allowed on an iPhone, detection should be trivial. And why has no one bothered to ask Apple or ARM about this 'unknown hardware'? >If we try to descri…

This chain isn’t delivered via an app, it is sent through iMessage. The checks for “only apps approved by Apple” are not relevant if you exploit your way past them.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#98
post #34

Earlier quoted context omitted.

Do you know how this is possible? Would decapping the SoC or taking an xray of it provide a physical map of the registers?

You can find the register file relatively easily because it's a block of memory that's the same on each core but isn't cache, but it isn't a 1:1 map from architectural registers that we would recognize: the chip is designed to find an optimal allocation of slots in the register file to runtime values.

That’s where the GPRs would live. There’s no reason you have to put weird MMIO there too.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#99

Earlier quoted context omitted.

but why pay hackers to try to find a backdoor when you can just walk in the front door and use the carrot and stick to get what you want?

Here's my serious answer that still works if you hate Apple. Your question assumes two things: (1) That Apple intentionally leaves vulnerabilities in the stack, and (2) that Tim Apple is occasionally willing to share this candy with governments. Having worked at Apple, I don't believe (1) can be true. Not only is it extremely unlikely that it could be kept a secret, but Apple's thing is "obsessive control", a mindset…

I am assuming or knowing that the national security apparatus can both coerce and incentivize companies and individuals to give it what it wants. Their power is great and relatively unchecked to do both. Coercion tactics include releasing compromising information on a company, person or family member and more directly injuring person or company. Incentives include favorable regulation, taxation, and deals with other companies they control.

Knowledge of a binder of vulnerabilities is perhaps one of the greatest secrets that must be protected. Wikileaks releasing the Vault 7 leak was the death knell of Julian Assange. It proved such a binder exists in great detail.

I don't hate Apple, but assuming they can't be reached, seems naïve.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#100
post #40
post #30

Earlier quoted context omitted.

They knew exactly what they were doing when they chose that nice blue and that cheap looking green.

Never forget the icon they used for Windows servers: https://i.stack.imgur.com/5rYVr.png

That’s hilarious
Post reply on HN