Earlier quoted context omitted.
Maybe but then again what’s another secret when at a high level these firms are already very secretive. It’s not apple but I think a lot about how Eric Schmidt of google was directly meeting with US military officials and talking about how important US defense was. You can end up with a situation where the chip designer and some higher up both know what is happening and the higher up is there as a check to provide co…
There are different levels of secret. I would never leak a normal company secret. But a national security secret is a different story.
Operation Triangulation: What you get when attack iPhones of researchers
271–280 of 433 posts
Re: Operation Triangulation: What you get when attack iPhones of researchers
#272>This attachment exploits vulnerability CVE-2023-41990 in the undocumented, Apple-only TrueType font instruction ADJUST for a remote code execution. This instruction existed since the early 90’s and the patch removed it. This is getting ridiculous. How many iMessage exploits have there now been via attachments? Why aren't Apple locking down the available codecs? Why isn't BlastDoor doing its job? This is really disap…
iOS has a reputation for having the best security, but how many times have Android/WhatsApp had these sorts of silent-instant-root exploits via invisible messages? I don't remember it happening. Maybe the strategy of writing lots of stuff in Java is paying off there.
And even better, there are plenty of old Android phones out which will be vulnerable to various exploits because of weak OTA update support policies.
Re: Operation Triangulation: What you get when attack iPhones of researchers
#273That's pretty astonishing. The MMIO abuse implies either the attackers have truly phenomenal research capabilities, and/or that they hacked Apple and obtained internal hardware documentation (more likely). I was willing to believe that maybe it was just a massive NSA-scale research team up until the part with a custom hash function sbox. Apple appears to have known that the feature in question was dangerous and delib…
Or a joint project between several organizations.
Re: Operation Triangulation: What you get when attack iPhones of researchers
#274>This attachment exploits vulnerability CVE-2023-41990 in the undocumented, Apple-only TrueType font instruction ADJUST for a remote code execution. This instruction existed since the early 90’s and the patch removed it. This is getting ridiculous. How many iMessage exploits have there now been via attachments? Why aren't Apple locking down the available codecs? Why isn't BlastDoor doing its job? This is really disap…
Re: Operation Triangulation: What you get when attack iPhones of researchers
#275Earlier quoted context omitted.
> reboot your iPhone at least weekly with the Hard Reset key sequence, https://www.wikihow.com/Hard-Reset-an-iPhone
Sorry for the lay question but what’s the benefit of the hard reset over a general restart?
Re: Operation Triangulation: What you get when attack iPhones of researchers
#276Earlier quoted context omitted.
One could argue the same about alternatives to Safari, and yet Chrome has proven to be more secure than Safari (based on Pwn2Own results).
I would not argue that about web browsers, because there’s plenty others out there. I don’t think Google would make a iMessage client for iOS.
Browsers are not the only thing concerned here, there are many sectors impacted by this philosophy. Qubes-OS for Linux Distributions, replacing containers (and especially Docker) with daemon-less or even MicroVM (Firecracker, Podman, ...). I'm sure there are also heavily sandboxed clients for Matrix, SMS or Emails.
Re: Operation Triangulation: What you get when attack iPhones of researchers
#277>The resulting shellcode, in turn, went on to once again exploit CVE-2023-32434 and CVE-2023-38606 to finally achieve the root access required to install the last spyware payload. Why isn't Apple detecting the spyware\malware payload? If only Apps approved by Apple are allowed on an iPhone, detection should be trivial. And why has no one bothered to ask Apple or ARM about this 'unknown hardware'? >If we try to descri…
Re: Operation Triangulation: What you get when attack iPhones of researchers
#278I see that one of the steps in exploit was to use GPU registers to bypass kernel memory protection. Does it mean that the vulnerability cannot be fixed by an update and existing devices will stay vulnerable?
Re: Operation Triangulation: What you get when attack iPhones of researchers
#279Earlier quoted context omitted.
This happened at a company I worked at so it’s not out of the question. I figured it out by reverse engineering and quit on the spot. They tried to tell me I’d never work again if spying on users was a dealbreaker. They showed me a natsec slide deck that identified other collaborating companies as a way of making their point. Among them was Apple.
You are telling me that natsec people give every rando the full list of participants in the conspiracy? That just doesn't make sense for any (semi)competent security agency to disclose.
Re: Operation Triangulation: What you get when attack iPhones of researchers
#280This wouldn't be zero click if iMessage didn't parse attachments without user consent.