Live data from Hacker News

Operation Triangulation: What you get when attack iPhones of researchers

securelist.com

421–430 of 433 posts

Re: Operation Triangulation: What you get when attack iPhones of researchers

#421

Earlier quoted context omitted.

I don't think hiring an ex-Apple dev would let you get the needed sbox unless they stole technical documentation as they left. So it either has to be stolen technical docs, or a feature that was put there specifically for their usage. The fact that the ranges didn't appear in the DeviceTree is indeed a bit suspicious, the fact that the description after being added is just 'DENY' is also suspicious. Why is it OK to d…

> It makes you wonder what is on these guy's iPhones that's considered so valuable. Presumably, they were after emails describing more zero days in other programs. My theory is that defensive cyber security is so hard that it's literally easier to hack the entire world(with a focus on security people) to see if anyone has breached your systems.

Honeypots? Honeypots seem to be consistently under exploited.

A good honeypots is a counterattack on intruder psychology in a host of ways.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#422
post #380

Earlier quoted context omitted.

> truly phenomenal research capabilities Maybe a nation state, e.g., APT?

Being able to put together tooling with these capabilities makes the attacker an APT by definition. These are generally assumed to be national intelligence services, though that is an assumption. (Among other things, there are multiple countries where the lines between intelligence agencies and their contractors are... fuzzy.) And while Kaspersky is refusing to speculate at all about attribution, the Russian governme…

I thought there were Israeli private services/ contractors providing APT as a service to, for example, Saudi Arabia or other despotic regimes.

I think that was in the news back in the sochi Olympics. The value of cyber capabilities is only going up with time

The siloing may be due to multiple contractors. I imagine these exploit vendors are protective of their arsenal of attacks.

Because as has been said many times, the three letter agencies aren't exempt from the curse of government employee mediocrity.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#425

Earlier quoted context omitted.

Seems likely a compromise at the GPU or ARM side as equally possible routes.

What do you mean? Both the GPU and CPU design are proprietary to Apple. They used to use regular ARM designed cores but the last one of those before switching to their own core design was something like the A5 days (from memory). It uses the ARM instruction set but isn’t actually designed by ARM at all. Similar for the GPU too. They may have started with HDL licensed from others (like I think their GPU might actually…

CoreSight is not Apple proprietary, it’s part of ARM’s offering. This vulnerability appears to be part of CoreSight.

> but I believe the ARM one is basically from-scratch

You are wrongly believing then. There’s still a bunch of ARM IP in their CPU.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#426

Earlier quoted context omitted.

No, I won’t agree to context free blanket statements which are specifically worded to imply something which is simply not provably true, especially given evidence to the opposite. If you knew anything about PRISM at all, even the technical details publicly available with the minimalist of effort on your part, you wouldn’t be asking.

The struggle itself is a clue, nobody takes time out of their day to defend Apple and PRISM on the Internet. Opsec needs enhancement.

> nobody takes time out of their day to defend Apple and PRISM on the Internet

I’m definitely not defending Apple to be clear. I just believe facts matter, especially when it involves security topics. Parroting around misleading and/or straight false statements related to security topics does nobody any good.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#428

Now I am thinking Kaspersky should not have published this information. What a wrong decision. Instead they should have sold it to Russian government which I am sure could find lot of interesting uses for these "debugging features" and offer a good reward.

Kaspersky are already firmly under the full control of the state, selling anything is redundant. The whole video comes off as a massive flex, giving off the same vibes as athletes representing the country at the Olympics.

I was disappointed that nobody in the audience dared to ask the obvious question of how much time has passed between disclosing the vulnerability to the state agencies and Apple. I very much doubt the state didn't seize the opportunity to use the exploit against its enemies first and tactically disclose it later. If anything, the talk demonstrates that if they opted to disclose such a valuable exploit, they could afford to because they have the capability to discover more and have other exploits that did yet not outlive their use. I bet there is an interesting story behind the talk, hopefully, the details will eventually surface up.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#429

Earlier quoted context omitted.

Yep, why would they drop it? It’s especially egregious as Apple disregards its own human interface guidelines to make green bubbles excessively low-contrast. Very intentional.

I bought the very first iPhone the day after its release. Long before iMessage was introduced, it only supported SMS at the time. People forget, but those bubbles, the original SMS ones, were green. Blue bubbles showed up only when iMessage debuted three years later.

I wonder if those had different contrast or not? I switched just a few years ago.

Re: Operation Triangulation: What you get when attack iPhones of researchers

#430
post #246

Earlier quoted context omitted.

It should be very easy to add one without somebody noticing. This is the same Apple which shipped a version of macOS for months that added the ability to login to root with any password only a few years ago. Their review processes are so incompetent even one of the most security critical components, root login, let a totally basic “fail your security 101 class” bug through. It is absolutely inexcusable to have a proc…

Mistakes happen but Apple's reputation for strong security is well deserved. They invest heavily and the complexity of this exploit chain is evidence of that. Linux has had its fair share of trivial root login exploits that somehow got through code review.

Where do Apple have a reputation for strong security?

Compared to other mainstream operating system, they seem to constantly be the last to introduce things like stack canaries, non executable memory segments, and all that which is considered best practice now.

Post reply on HN