Live data from Hacker News

Operation Triangulation: What you get when attack iPhones of researchers

securelist.com

151–160 of 433 posts

Re: Operation Triangulation: What you get when attack iPhones of researchers

#151
post #79

Earlier quoted context omitted.

well of course nobody would have NSA_friendly_override() in the source plausible deniability is essential in such cases, hence the term bugdoor

This is the same conspiracy mindset of flat earthers, and you deserve your own netflix mockumentary over it. Because a bug is a bug, it's very nature means you cannot prove it isn't malicious, therefore you take it as positive proof of malice and sit pretty bc no one can prove a negative.

Are you posting from Eglin AFB? Which outfit are you with?

Re: Operation Triangulation: What you get when attack iPhones of researchers

#152
post #37

[flagged]

Based on past history, it would be more surprising if Apple wasn't actively cooperating with the NSA, that was the case with PRISM (wiki):

> "The documents identified several technology companies as participants in the PRISM program, including Microsoft in 2007, Yahoo! in 2008, Google in 2009, Facebook in 2009, Paltalk in 2009, YouTube in 2010, AOL in 2011, Skype in 2011 and Apple in 2012. The speaker's notes in the briefing document reviewed by The Washington Post indicated that '98 percent of PRISM production is based on Yahoo, Google, and Microsoft'"

With the rise of end-to-end encryption in the wake of the Snowden revelations, this put large tech corporations in a bind, given the conflict between consumer desire for secure snoop-proof devices, and government desire for backdoor access. Pressure might have been applies by government contracting decisions, so no cooperation == no big government contract. The general rise of end-to-end encryption also meant that things like deep packet inspection along the trunk no longer worked, putting a premium on breaking into devices to install keyloggers etc.

All the fear of China doing this with Huawei (probably well-justified fear) may have risen in part as projection by politicians and insiders who knew the US government was doing it already with Apple, Android, Intel, ARM, etc. The US government has certainly retained legalistic justification for such behavior, even though the Act expired in 2020[1]. Also, corporations have been given retroactive immunity for similar illegal activites before [2], so Apple has that precedent to go by.

[1] https://www.cjr.org/the_media_today/section_702_renewal_pres...

[2] https://www.aclu.org/news/national-security/retroactive-tele...

Re: Operation Triangulation: What you get when attack iPhones of researchers

#153

Earlier quoted context omitted.

I don't understand what you mean. They've always been making progress, driving the price up. They can just keep doing what they're doing, and there will be progress from today.

Is that actually true? Has the price of these exploits been going up year after year, or has it topped out at some level?

It’s been going up consistently. The number of groups that can field a full chain these days is dwindling.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#154

Earlier quoted context omitted.

I'd disagree with this. Apple execs surely know if this information gets leaked they're losing 30% market cap in a single day, why would they risk something like that when administrations change every 4-8 years?

Power is more important than profit. Those running the national security apparatus have been in power for 60 years. The fact that they still haven't released the documents on the JFK assassination evidences that they are still in power.

People will call you a crank or a conspiracy theorist but that is only because they are afraid to think about the answers to those questions themselves. Its easier to pretend it couldn't happen.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#155

Earlier quoted context omitted.

> iPad with cellular does not really show you SMS's that's not from the carrier of the sim card. Does iPad support SMS? The cellular line is usually only for data, https://www.howtogeek.com/710767/how-to-send-sms-text-messag... iPads can't send SMS text messages through Apple's Messages app. Even if you have an iPad with a cellular data plan for mobile internet on the go, you still can't send SMS text messages.

Apple's own user guide ( https://web.archive.org/web/20201223140550/https://support.a... ) suggests otherwise: >In the Messages app , you can send text messages as SMS/MMS messages through your cellular service, or ... Also my own experience is that it at least can receive SMS text messages, just it won't show you if it's not from your carrier (if it's from your carrier, it shows you via a popup window or something,…

No direct experience to share, but that sentence may be referencing Continuity via iCloud, which is optional:

  With Continuity, you can send and receive SMS/MMS messages on iPad using the cellular connection on your iPhone.
> if it's from your carrier, it shows you via a popup window

If it's not shown in Apple's Messages app, maybe it was a carrier-specific app?

Re: Operation Triangulation: What you get when attack iPhones of researchers

#156

Earlier quoted context omitted.

>It was complex because of all of the defenses put in place by Apple and others. I don't know jack about hardware but it would seem obvious that when one designs a chip, you make sure it does not have 'unknown hardware registers' or unknown anything when you get it back from the manufacture. This makes everything written on this page worthless... >Prevent anyone except you from using your devices and accessing your i…

> I don't know jack about hardware Could have stopped writing right there.

Agreed

Re: Operation Triangulation: What you get when attack iPhones of researchers

#157

Earlier quoted context omitted.

I'd disagree with this. Apple execs surely know if this information gets leaked they're losing 30% market cap in a single day, why would they risk something like that when administrations change every 4-8 years?

Power is more important than profit. Those running the national security apparatus have been in power for 60 years. The fact that they still haven't released the documents on the JFK assassination evidences that they are still in power.

Eh.

Let’s say your old boss was embezzling and got away with it. Now you are the boss, and if you go public with it, not only are they out of power and likely nothing will happen, but all the freedom and flexibility you have in the same position is gone, and you or your friends have an island-problem you would rather not get into.

Maybe it’s just better to not rile up the shareholders.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#158

Earlier quoted context omitted.

I don’t really see anything wrong with their security posture here.

Article says large data files were sent from device to servers. Perhaps they could have configured their networks to detect/block this part.

This would have a very high false positive rate.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#159
post #4

It’s quite unfortunate that Apple doesn’t allow users to uninstall iMessage, it seems to be the infection vector for advanced threats like this, NSO group, etc. Presumably it’s to avoid the support burden, but they could gate it behind having Lockdown Mode enabled for a week or something to shake out the vast majority of mistaken activations.

Can someone explain to me why we can load vast quantities of untrusted code and a wide variety of image formats in our browsers all day long and be mostly safe today, but somehow even first party messenger apps seem to be a relatively easily compromised? Why can't messenger apps be sandboxed as well as browsers?

Note that the second half of this exploit chain involves going around and exploiting the web browser.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#160
post #86

[flagged]

I'd disagree with this. Apple execs surely know if this information gets leaked they're losing 30% market cap in a single day, why would they risk something like that when administrations change every 4-8 years?

I think the charitable explanation here is that this was an undocumented debugging interface. Apple knew about it and did not disclose it in any publicly available material. The NSA almost certainly has access to Apple's source code and documentation. Just look at the Snowden leaks when it was disclosed that the NSA was mitming Google's DC to DC links. They already knew Google wasn't encrypting those links before they surreptitiously dug up the fiber and they already knew enough about the system architecture to make sense of that firehose of data. Clearly either through NSL or bribing some insiders, they already exfiltrated a bunch of internal documentation and source code. Why would Apple be any different?

I wouldn't expect them to have HSM keys or anything but a mirror of their VCS? Yeah the NSA probably has that.

Post reply on HN