Live data from Hacker News

Operation Triangulation: What you get when attack iPhones of researchers

securelist.com

281–290 of 433 posts

Re: Operation Triangulation: What you get when attack iPhones of researchers

#281

That's pretty astonishing. The MMIO abuse implies either the attackers have truly phenomenal research capabilities, and/or that they hacked Apple and obtained internal hardware documentation (more likely). I was willing to believe that maybe it was just a massive NSA-scale research team up until the part with a custom hash function sbox. Apple appears to have known that the feature in question was dangerous and delib…

>also is indicative of a massive organization with truly abysmal levels of internal siloing. Or a joint project between several organizations.

Or, like, they have a root kit and it works so why reinvent the wheel? They have an attack payload so why reinvent the wheel? Just plug and play all the packages you need until you can compromise your target device.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#282
post #205
post #75

Earlier quoted context omitted.

Teenagers wanting blue bubbles and people looking to uninstall iMessage because it's a threat vector are two completely disjoint sets of people.

Blue bubbles bad syndrome. Gotta bring it up when ever humanly possible. Nvidia has a very similar green man bad syndrome going on too. As the amount of time a HN discussion on Nvidia increases, the probability of mentioning that Linus said “fuck you nvidia” approaches 1, even though it’s irrelevant to a topic, or that he's a mercurial asshole who's said a whole lot of things. The casual fanboyism disrupts all discou…

Can you explain how disliking Nvidia due to being systematically problematic at some point (maybe still being problematic) is a fanboyism or parasocial attachment?

Re: Operation Triangulation: What you get when attack iPhones of researchers

#283

Earlier quoted context omitted.

This chain isn’t delivered via an app, it is sent through iMessage. The checks for “only apps approved by Apple” are not relevant if you exploit your way past them.

Thanks I did see the researchers posted how the malware gets into memory, but I still feel like since Apple tightly controls the enviornment it ahould be able to detect anything running there that should not be.

Apple does not control what photo, video or PDF gets sent to you via iMessage.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#284

Earlier quoted context omitted.

Isn't it easier just to pay to one of hundreds employees having access to chip design? Or even get it without paying by appealing to patriotism?

How many ex-Apple employees work(ed) at NSA? It may just have been the right person doing their regular 9-5 job, with no subterfuge. The list of employers for Hardware security folks is likely a couple of dozen companies, and Apple and NSA are among the most prestigious of them. I expect some employees to move in both directions.

I know of two, one from my team. Don't know how long they stayed there, though.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#285
post #51

That's pretty astonishing. The MMIO abuse implies either the attackers have truly phenomenal research capabilities, and/or that they hacked Apple and obtained internal hardware documentation (more likely). I was willing to believe that maybe it was just a massive NSA-scale research team up until the part with a custom hash function sbox. Apple appears to have known that the feature in question was dangerous and delib…

or Apple just implemented this "API" for them, because they've asked nicely

I wouldn’t be surprised if one or two very senior people in large tech companies are agency agents, willingly or not.

I don’t really have any proof but considering the massive gain it shouldn’t surprise anyone. The agencies might not even need to pay large sum of $$$ if the said assets have vulnerabilities.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#286
post #92

Earlier quoted context omitted.

People use “green bubbles” to just mean “no guaranteed delivery or delivery receipts, no read receipts, very low quality image and videos, bad support for reactions, threaded replies, and group chats”. …the color isn’t the problem. It’s shorthand for the real underlying issues

The color is a big part of the problem, white on green is one of the hardest to read because of the distribution of color cone cells in our retinas. Only maybe white on yellow would be worse.

Dark mode is the way to go anyway.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#287
post #231

Earlier quoted context omitted.

the dollar as the reserve currency already has a serious impact on the US (ie. the big upside is that it allows the US to borrow for very cheap, but the nasty downside is keeping the purchasing power of the USD artificially high, which is not great for the non-finance sectors of the US, not great for people who work in those sectors, and double-plus-not-great for US exports [which are not the dollar itself]), basical…

A weak dollar is good if you own a company that relies on exports. For the rest of us who are paid in dollars and need to buy imports, a weaker dollar hurts. That is one opinion. We can already see China and Japan selling off their US bonds and the BRICS countries are working on solutions to get off the dollar with high priority.

> A weak dollar is good if you own a company that relies on exports.

It depends on your exports. If your exports have cheaper alternatives, then a weak dollar is good.

If your exports are high utility and have no cheaper alternative, then a strong dollar is better.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#288

iMessage can be disabled by local MDM for supervised devices, via free Apple Configurator in macOS app store, https://support.apple.com/guide/deployment/restrictions-for-... For Wi-Fi–only devices, the Messages app is hidden. For devices with Wi-Fi and cellular, the Messages app is still available, but only the SMS/MMS service can be used. SMS/MMS messages and non-emergency cellular radio traffic can be disabled by a…

We purchased an iPad with cellular, with the plan to put my home country's sim card in it so I can still receive SMS (as most of the banks there still requires SMS verification when you login), and it turns out that iPad with cellular does not really show you SMS's that's not from the carrier of the sim card.

I've never understood why iPads can't be used as phones with an ordinary cellphone SIM. Is it simply because Apple doesn't want to pay a Qualcomm licensing fee or some equivalent? Who is it in the chain/ecosystem that does not want tablets being used as full phones, the carriers? Apple?

Re: Operation Triangulation: What you get when attack iPhones of researchers

#289

Coresight is not some backdoor - it's a debug feature of all ARM CPU's. This looks like a necessary extension to coresight to work with Apples memory protection stuff. Even though no public documentation exists, I'm sure thousands of Apple engineers have access to a modded gdb or other tooling to make use of it.

That does not explain the weird hashing.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#290

Earlier quoted context omitted.

> leads Kaspersky [..] to the [..] rational conclusion: that Apple cooperated with the NSA on this exploit doesn't the article states precisely otherwise? that while the FSB accuses Apple of cooperation, Kaspersky does not have any reason to believe so, especially since it does not look like any known state actor.

Kaspersky only said they could not prove it. They did not make conclusion but laid out the evidence.

[deleted]
Post reply on HN