Live data from Hacker News

Operation Triangulation: What you get when attack iPhones of researchers

securelist.com

171–180 of 433 posts

Re: Operation Triangulation: What you get when attack iPhones of researchers

#171
post #4

It’s quite unfortunate that Apple doesn’t allow users to uninstall iMessage, it seems to be the infection vector for advanced threats like this, NSO group, etc. Presumably it’s to avoid the support burden, but they could gate it behind having Lockdown Mode enabled for a week or something to shake out the vast majority of mistaken activations.

In the face of this kind of threat, it's pretty obvious why Apple treated Beeper as a security risk and took appropriate measures to secure iMessage.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#173

Earlier quoted context omitted.

Yeah people keep talking about reverse engineering but it’s just as real a possibility that this was simply engineered to be there. Apple and the government made a big public show about the San Bernardino iPhone situation[1] but that could have easily been a cover to convince people the government can’t get in to iPhones - because eventually the government dropped the court case, got in anyway, and the whole thing wa…

> that could have easily been a cover The problem with conspiracies is everyone involved knows it’s a secret. If you’re the CIA, it’s much less risky to compromise a chip design engineer than have everyone from the CEO down at Apple in on the plant.

Maybe but then again what’s another secret when at a high level these firms are already very secretive.

It’s not apple but I think a lot about how Eric Schmidt of google was directly meeting with US military officials and talking about how important US defense was.

You can end up with a situation where the chip designer and some higher up both know what is happening and the higher up is there as a check to provide cover in case the chip designer is caught up in suspicion. (“No we asked for this for the manufacturing team.” Kind of thing.)

Of course this is all conjecture with no evidence and I understand why we don’t want to spend much energy on discussions we can’t confirm, but at the same time it is frustrating when the default assumption is that apple had no knowledge about this. The truth is that we don’t know and likely will never know.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#176

Isn't the most obvious answer that Apple, like other US tech firms such as Google, simply creates these wild backdoors for the NSA/GCHQ directly? Every time one's patched, three more pop up. We already know Apple and Google cooperate with the spy agencies very eagerly.

> We already know Apple and Google cooperate with the spy agencies very eagerly.

The evidence clearly indicates otherwise…

Re: Operation Triangulation: What you get when attack iPhones of researchers

#177

Earlier quoted context omitted.

Your “threat model analysis” takes for granted that a “civilian” is a billion times less important than a “nation-state”. It makes no sense to waste any time analyzing anything after such a conclusion. Therefore, something is wrong here.

I think you've misunderstood. The point was that there are (to simplify) two different threat models at play here: one where your most powerful adversary is somewhere between your family and domestic law enforcement, and another where you are worth $10+ million to a nation state. 99.99% of the world lives in threat model 1; our goal as security minded people is to protect these people. These people want general purpo…

I'm trying to paint a bigger, better picture.

From the inside of the status quo, those threat models, well-informed reasoning, the descriptions of hierarchy, and what “should” and “should not” be possible, “millions will react like this, millions will react like that” are valid and respected. From the outside, there's a tiny bit of a problem: ordinary human has no value apart from that of a cog in the machine, there is really nothing to protect, an empty place, so all those powerful words crumble like a card house in situations like these.

What I'm hinting at is that that assumption is wrong, it's a dead end from the start. Just like tribes sitting around the bonfire, and discussing legendary totem animals and gods making their life reasonable and orderly, people today are charmed by the images of events “above”. It's just a belief in the workings of “modern world”. One needs a better base to live one's own life, not an axiom that one, for all intents and purposes, doesn't matter.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#178

Attack by CIA/NSA? They have the best possible insight into the hardware and software at all stages I should think.

It targeted Russian embassy officials, and with this level of sophistication, so it’s quite obviously NSA/etc.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#179

What are the chances this MMIO register could have been discovered by brute force probing every register address? Mere differences in timing could have indicated the address was a valid address, and then the hash could perhaps have been brute forced too since it is effectively a 20 bit hash.

Looking at that sbox implementation, I can't believe it was implemented as a lookup table in the hardware of the chip - there must be some condensed Boolean expression that gives the same result.

The fact the attackers didn't know that Boolean expression suggests they reverse engineered it rather than had documentation.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#180
post #80

Who had motive to target Russian government officials, knowledge of the attack vectors, history of doing so, and technical and logistical ability to perform it leads Kaspersky and myself to the only rational conclusion: that Apple cooperated with the NSA on this exploit. I assume they only use and potentially burn these valuable methods in rare and perhaps desperate instances. I expect the Russian and Chinese governm…

This looks like a typical modern security hole. There’s a giant stack of layers of unnecessary complexity, and all of them are garbage. The composition is also garbage. All the NSA needs to launch attacks like this is to get a bunch of mediocre engineers to layer complexity atop complexity. They don’t need Apple to know about the attack. Honestly, they probably didn’t actually have to do anything to get Apple (or any…

You make a good point that a team of mediocre engineers could be responsible for the vulnerabilities. Those doing code review and change control would also need to be mediocre. It could be a combination of compromised and mediocre coordinated by a manager who is in service of the apparatus. Knowledge of the operation would better not go all the way up the ranks to keep it quiet.
Post reply on HN