Live data from Hacker News

Operation Triangulation: What you get when attack iPhones of researchers

securelist.com

251–260 of 433 posts

Re: Operation Triangulation: What you get when attack iPhones of researchers

#251

Earlier quoted context omitted.

If you read a better article with technical details [1], you'll see that Apple SOCs contain a "feature" (that resembles a debugging tool) that allows to bypass memory protection by writing into undocumented and unused GPU registers. Apple locks down kernel memory to stop exploits, but these registers allow to bypass the lock. This vulnerability is they key vulnerability without which all the exploit chain would be us…

[flagged]

The original article doesn't have as many technical details as the article I linked to. That is why I added a link to another article which is better in my opinion and it is difficult to understand the vulnerability from original article. Original article also doesn't say anything about how Apple tried to fix it.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#252

The extra hardware registers might have been discovered by examining the chip itself. One could find where the registers were on it, and notice some extra registers, then do some experimenting to see what they did.

Isn't it easier just to pay to one of hundreds employees having access to chip design? Or even get it without paying by appealing to patriotism?

Or just covertly tell Apple to hand over its documentation / to knowingly leave gaps in the defenses for NSA to exploit.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#253
post #207

Earlier quoted context omitted.

> reboot your iPhone at least weekly with the Hard Reset key sequence, https://www.wikihow.com/Hard-Reset-an-iPhone

Sorry for the lay question but what’s the benefit of the hard reset over a general restart?

[dead]

Re: Operation Triangulation: What you get when attack iPhones of researchers

#255
post #4

It’s quite unfortunate that Apple doesn’t allow users to uninstall iMessage, it seems to be the infection vector for advanced threats like this, NSO group, etc. Presumably it’s to avoid the support burden, but they could gate it behind having Lockdown Mode enabled for a week or something to shake out the vast majority of mistaken activations.

In the face of this kind of threat, it's pretty obvious why Apple treated Beeper as a security risk and took appropriate measures to secure iMessage.

I don’t think that’s clear at all. I imagine it’s still trivial for attackers to still send specially crafted one-off payloads.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#256

Earlier quoted context omitted.

How did sanctions backfire?

Germany's economy shrunk last year while Russia's grew. Dedollarization has accelerated which will impact the US not immediately but in near future.

You are talking about an unsustainable war economy that is overheating. Soaring inflation, brain drain and a falling ruble are only just the short term phenomena.

--> https://www.reuters.com/breakingviews/russian-war-economy-is...

If you would truly believe what you say, you should convert all your savings from dollar to rubles. No serious economist would think that doing so would be a masterstroke though.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#257

Earlier quoted context omitted.

In the face of this kind of threat, it's pretty obvious why Apple treated Beeper as a security risk and took appropriate measures to secure iMessage.

I don’t think that’s clear at all. I imagine it’s still trivial for attackers to still send specially crafted one-off payloads.

The attack vector is still smaller if Apple restricts iMessage to official devices only compared to any rooted Android phone being able to spam iMessage payloads.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#258
post #147

>This attachment exploits vulnerability CVE-2023-41990 in the undocumented, Apple-only TrueType font instruction ADJUST for a remote code execution. This instruction existed since the early 90’s and the patch removed it. This is getting ridiculous. How many iMessage exploits have there now been via attachments? Why aren't Apple locking down the available codecs? Why isn't BlastDoor doing its job? This is really disap…

If I've read the rest of the documentation correctly, the exploit is actually triggered from an attached ".watchface" file, which of course, has the font vulnerability in it.

I'd like to meet the person who suggested even sending .watchface files as iMessage attachments in the first place. What were you thinking? Did you not have a large enough attack surface already?

Re: Operation Triangulation: What you get when attack iPhones of researchers

#259
post #48
post #3

[flagged]

> it turns out that more people having access to the source code makes it more secure. The OpenSSL debacle kinda disproved that point, didn’t it?

How so? You need to quantify it; e.g., something like number of bugs found per year per LOC.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#260
post #231

Earlier quoted context omitted.

Germany's economy shrunk last year while Russia's grew. Dedollarization has accelerated which will impact the US not immediately but in near future.

the dollar as the reserve currency already has a serious impact on the US (ie. the big upside is that it allows the US to borrow for very cheap, but the nasty downside is keeping the purchasing power of the USD artificially high, which is not great for the non-finance sectors of the US, not great for people who work in those sectors, and double-plus-not-great for US exports [which are not the dollar itself]), basical…

A weak dollar is good if you own a company that relies on exports. For the rest of us who are paid in dollars and need to buy imports, a weaker dollar hurts.

That is one opinion. We can already see China and Japan selling off their US bonds and the BRICS countries are working on solutions to get off the dollar with high priority.

Post reply on HN