Live data from Hacker News

Operation Triangulation: What you get when attack iPhones of researchers

securelist.com

201–210 of 433 posts

Re: Operation Triangulation: What you get when attack iPhones of researchers

#202
post #37

[flagged]

Reading between the lines of TFA, it seems the researchers may also suspect that to be the case: > Our guess is that this unknown hardware feature was most likely intended to be used for debugging or testing purposes by Apple engineers or the factory, or that it was included by mistake. Because this feature is not used by the firmware, we have no idea how attackers would know how to use it. However, keep in mind that…

Since they've gone to the trouble of protecting it with an insecure hash, couldn't they also have designed this hardware feature so that it could be completely disabled until the device is rebooted? This vulnerability doesn't persist through reboots, so it would be sufficient to have the firmware lock the feature out during startup outside of development or manufacturing contexts.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#203
post #79

Earlier quoted context omitted.

well of course nobody would have NSA_friendly_override() in the source plausible deniability is essential in such cases, hence the term bugdoor

This is the same conspiracy mindset of flat earthers, and you deserve your own netflix mockumentary over it. Because a bug is a bug, it's very nature means you cannot prove it isn't malicious, therefore you take it as positive proof of malice and sit pretty bc no one can prove a negative.

We had backdoors, then PRISM revealed. We have bugdoors now. No reason to think three letter glowies would like to give up any amount of control. They have the 'power' to straight up lie to the congress under oath, see Clapper.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#204

I'm curious to know from experts if there's anything Apple can do to create a step-change in terms of security of iPhones? Like if the going rate for a zero day is $1 million, is there anything Apple can do that can drive that up to $2 or $3 million? Or is it just going to be a perpetual cat and mouse game with no real "progress"?

Sure. Rewrite sensitive parts of their stack in memory safe languages. They have Swift after all. A lot of the iOS security improvements over time have really been more like mitigations that try to contain the damage when the giant of pile of decades old C gets exploited.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#205
post #75
post #5

Earlier quoted context omitted.

They gotta, gotta , have those blue bubbles. Some teenagers fight to get an overpriced phone solely to avoid the deep deep shame of having a green bubble when chatting. If apple is forced to shut down iMessage being the exclusive option and have some pure SMS application they might see a sudden noticeable drop in market share.

Teenagers wanting blue bubbles and people looking to uninstall iMessage because it's a threat vector are two completely disjoint sets of people.

Blue bubbles bad syndrome. Gotta bring it up when ever humanly possible.

Nvidia has a very similar green man bad syndrome going on too. As the amount of time a HN discussion on Nvidia increases, the probability of mentioning that Linus said “fuck you nvidia” approaches 1, even though it’s irrelevant to a topic, or that he's a mercurial asshole who's said a whole lot of things.

The casual fanboyism disrupts all discourse on these topics because there’s a large minority of users who have adopted what PG describes as “hater-ism” and allowed it to dominate their thinking on a topic. Negative parasocial attachment is the same process as positive parasocial attachment and just as problematic, but largely never called out.

http://www.paulgraham.com/fh.html

In short: lotta fanboys on these topics who don't even realize they're fanboys/adopting fanboy frames, because they don't realize that anti-fanboys are still parasocially attached too. And we've casually accepted the low level of discourse on these topics, and it pollutes the whole discussion of a lot of interesting topics because of who's doing them.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#206
post #4

It’s quite unfortunate that Apple doesn’t allow users to uninstall iMessage, it seems to be the infection vector for advanced threats like this, NSO group, etc. Presumably it’s to avoid the support burden, but they could gate it behind having Lockdown Mode enabled for a week or something to shake out the vast majority of mistaken activations.

Can someone explain to me why we can load vast quantities of untrusted code and a wide variety of image formats in our browsers all day long and be mostly safe today, but somehow even first party messenger apps seem to be a relatively easily compromised? Why can't messenger apps be sandboxed as well as browsers?

Sending these through messaging apps is appealing because that usually requires zero user action - you just send a message and the device runs the exploit as it generates preview thumbnails.

But browser exploits require the user to visit an infected website, which is much tougher. If I recieve an email or sms with "visit applesupport.info" I'm not going to click it.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#207

>Although infections didn’t survive a reboot Reminder to reboot your iPhone at least weekly if you are concerned about this kind of attack.

> reboot your iPhone at least weekly with the Hard Reset key sequence, https://www.wikihow.com/Hard-Reset-an-iPhone

Sorry for the lay question but what’s the benefit of the hard reset over a general restart?

Re: Operation Triangulation: What you get when attack iPhones of researchers

#208
post #32

Earlier quoted context omitted.

leads Kaspersky and myself to the only rational conclusion: that Apple cooperated with the NSA on this exploit. Kapersky reaches no such conclusion. That's from an FSB release.

It is true that Kaspersky by policy does not make attribution without concrete proof. It is the responsibility of intelligence agencies to make the call based on preponderance of evidence. The video linked above leads suspicion to a very few options. The attacker left a list of Apple ID's in the code in one place to check against. Kaspersky provided them to Apple, and Apple did not respond with any details about the…

What is more true is that the article posted explicitly says the exact opposite of what you suggested upthread - a fact you should acknowledge.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#209

That's pretty astonishing. The MMIO abuse implies either the attackers have truly phenomenal research capabilities, and/or that they hacked Apple and obtained internal hardware documentation (more likely). I was willing to believe that maybe it was just a massive NSA-scale research team up until the part with a custom hash function sbox. Apple appears to have known that the feature in question was dangerous and delib…

> If the hardware feature was openly documented it'd have been found much, much sooner.

Well, the point of kerckhoff's principle is that it should have been openly documented and then anyone lookindg at the docs even pre-publication would have said "we can't ship it like that, that feature needs to go."

Re: Operation Triangulation: What you get when attack iPhones of researchers

#210

Isn't the most obvious answer that Apple, like other US tech firms such as Google, simply creates these wild backdoors for the NSA/GCHQ directly? Every time one's patched, three more pop up. We already know Apple and Google cooperate with the spy agencies very eagerly.

> We already know Apple and Google cooperate with the spy agencies very eagerly. The evidence clearly indicates otherwise…

Ahem, Snowden, PRISM anyone?
Post reply on HN