Live data from Hacker News

Operation Triangulation: What you get when attack iPhones of researchers

securelist.com

341–350 of 433 posts

Re: Operation Triangulation: What you get when attack iPhones of researchers

#341

As its about a 37c3 presentation here a comment from Fefe¹ in German https://blog.fefe.de/?ts=9b729398 According to him the exploit chain was likely worth in the region of a 8-digit dollar value. ¹ https://en.wikipedia.org/wiki/Felix_von_Leitner I guess somebody is going to get fired.

Why? Having exploits “burned” is part of the business.

Exploit yes

Decade old Backdoors no

Re: Operation Triangulation: What you get when attack iPhones of researchers

#342
post #295

Earlier quoted context omitted.

I do wonder if the people earning millions of dollars a year think the same way however. Considering how compartmentalized Apple is it would not take many people to be in on this.

Yes, the famously compartmentalized Apple, whose roadmap regularly leaks out to the press years (cars, AirTags, Vision Pro) and months in advance (leaks about every iPhone), absolutely a great target for subterfuge.

“Undocumented registers” is uninteresting to the general public and only needs to be known to a handful of people.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#343
post #4

It’s quite unfortunate that Apple doesn’t allow users to uninstall iMessage, it seems to be the infection vector for advanced threats like this, NSO group, etc. Presumably it’s to avoid the support burden, but they could gate it behind having Lockdown Mode enabled for a week or something to shake out the vast majority of mistaken activations.

In the face of this kind of threat, it's pretty obvious why Apple treated Beeper as a security risk and took appropriate measures to secure iMessage.

The security model is basically orthogonal.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#344

Earlier quoted context omitted.

I don't think hiring an ex-Apple dev would let you get the needed sbox unless they stole technical documentation as they left. So it either has to be stolen technical docs, or a feature that was put there specifically for their usage. The fact that the ranges didn't appear in the DeviceTree is indeed a bit suspicious, the fact that the description after being added is just 'DENY' is also suspicious. Why is it OK to d…

APTs probably routinely identify and target such developers. With multi-million dollar payouts for single bugs and high state level actor attention, employee profiling is clearly a known attack vector and internal security teams probably now brief on relevant opsec. FWIW the only Apple kernel developer I knew has somewhat recently totally removed themselves from LinkedIn.

People who work on the kernel are not hard to find.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#345

Earlier quoted context omitted.

Why? Having exploits “burned” is part of the business.

Exploit yes Decade old Backdoors no

> Decade old Backdoors no

I really doubt it's a backdoor after reading the blog post and this thread chain from a prolific M1 MacBook hacker (macran) I think it was just an unused or very rarely used feature that was left enabled by accident.

https://social.treehouse.systems/@marcan/111655847458820583

Some choice quotes.

First, yeah, the dbgwrap stuff makes perfect sense. I knew about it for the main CPUs, makes perfect sense it'd exist for the ASCs too. Someone had a lightbulb moment. We might even be able to use some of those tricks for debugging stuff ourselves :)

Second, that "hash" is almost certainly not a hash. It's an ECC code*. I bet this is a cache RAM debug register, and it's writing directly to the raw cache memory array, including the ECC bits, so it has to manually calculate them (yes, caches in Apple SoCs have ECC, I know at least AMCC does and there's no reason to think GPU/ASC caches wouldn't too). The "sbox" is just the order of the input bits to the ECC generator, and the algorithm is a textbook ECC code. I don't know why it's somewhat interestingly shuffled like that, but I bet there's a hardware reason (I think for some of these things they'll even let the hardware synthesis shuffle the bits to whatever happens to be physically optimal, and that's why you won't find the same table anywhere else).

Re: Operation Triangulation: What you get when attack iPhones of researchers

#346

Earlier quoted context omitted.

Perhaps Apple should provide research devices directly to the US's and China's intelligence agencies and pit them against each other to help close more vulnerabilities. The agencies can decide on their own where to strike the balance between offense and defense, but I suspect it would lead to more closed vulnerabilities over time.

Intelligence agencies unfortunately seem to have a bad track record when it comes to disclosing vulnerabilities, they’re very offensive-focused.

I think that would be the case if they were given to the US and other Western intelligence agencies. My scenario requires competition between geopolitical opponents to create an incentive to worry about defense as well.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#347
post #42

For those interested in the talk by the Kaspersky researches, the cleaned video isn't uploaded yet but you can find a stream replay here: https://streaming.media.ccc.de/37c3/relive/a91c6e01-49cf-422... (talk starts at minute 26:20)

...and its online: https://media.ccc.de/v/37c3-11859-operation_triangulation_wh...

Re: Operation Triangulation: What you get when attack iPhones of researchers

#348

Earlier quoted context omitted.

Unfortunately, Lockdown Mode disables Live Photos from being received via iMessage... That's a pretty big iPhone feature to not work under Lockdown Mode!

Not received at all or received as a still photo?

Still photo.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#349
post #250

Earlier quoted context omitted.

2-3 million dollars is not “amazing”. That is less than the cost to open a McDonalds. You can get a small business loan in the US for more than that. There are literally tens of millions of people in the world who can afford that. That is 1/5 the cost of a tank. 2-3 million dollars is pocket lint to people conducting serious business, let alone governments. It is at best okay if you are conducting minor personal busi…

> 2-3 million dollars is not “amazing”. I don't know. $2-3m for reading code in Ghidra and throwing stuff at a wall until something sticks? Maybe some fuzzing, etc. I get that you theoretically could find an exploit that for example, you send to 100 known wealthy people, and with it you steal saved cookies + device IDs from financial apps and then try to transfer their funds/assets to an account you control but... Co…

this has the (un)fortunate consequence of being illegal. Writing exploits and selling them to a friendly government, on the other hand, is totally legal. Plus, then you can sell support contracts for that sweet recurring revenue!
Post reply on HN