Live data from Hacker News

Operation Triangulation What You Get When Attack iPhones of Researchers [video]

media.ccc.de

11–20 of 28 posts

Re: Operation Triangulation What You Get When Attack iPhones of Researchers [video]

#12

The lack of attribution on this organized and well-financed operation is the most concerning part of this attack, in my opinion. It seems unlikely that any APT would burn ALL of its 0-days for the iOS platform in one campaign, so they likely have more which they can pivot to. Of course there are 3 nation-states who are most likely to be behind this operation, but which one was it? If possible, we should be looking fo…

There are generally 4 major cyber powers that I consider when hearing about new advanced techniques / applications / threats: USA, Russia, Israel, China (in roughly that order). Israel is obviously complicated because historically a lot of their work has been in partnership with the USA, but that seems to be mildly less the case these days.

France and the UK are also world class. Anyone else?

Re: Operation Triangulation What You Get When Attack iPhones of Researchers [video]

#13

Earlier quoted context omitted.

There are generally 4 major cyber powers that I consider when hearing about new advanced techniques / applications / threats: USA, Russia, Israel, China (in roughly that order). Israel is obviously complicated because historically a lot of their work has been in partnership with the USA, but that seems to be mildly less the case these days.

I could be very wrong, but I feel Israel’s cybersecurity tech is more advanced than Russia (could be my western programming lol)

When you look at home media, every major development has been Russian.

Software for cracking Blu-rays? Russia was first.

Software for cracking 4K UHD Blu-rays? Russia was first.

Software for cracking Nintendo Switch games (DBI)? Russia was first.

The new flash-cart for the Switch, assuming it's legit? Russia.

The only hacker left who can crack Denuvo video games? Russian.

Re: Operation Triangulation What You Get When Attack iPhones of Researchers [video]

#14

The lack of attribution on this organized and well-financed operation is the most concerning part of this attack, in my opinion. It seems unlikely that any APT would burn ALL of its 0-days for the iOS platform in one campaign, so they likely have more which they can pivot to. Of course there are 3 nation-states who are most likely to be behind this operation, but which one was it? If possible, we should be looking fo…

If I were in charge, I would attack 90% Taiwanese and 10% of my real target. And I would leave Chinese comments everywhere. So I doubt you can point fingers so easily. These are some smart people.

Re: Operation Triangulation What You Get When Attack iPhones of Researchers [video]

#15

Earlier quoted context omitted.

There are generally 4 major cyber powers that I consider when hearing about new advanced techniques / applications / threats: USA, Russia, Israel, China (in roughly that order). Israel is obviously complicated because historically a lot of their work has been in partnership with the USA, but that seems to be mildly less the case these days.

France and the UK are also world class. Anyone else?

Imo the siloing / rehacking smacks of multiple contractors being coordinated by a government agency.

The contractors don't want to share 0days, so the hack boundary handoffs between contractors seems apparent to me.

That would suggest US or Israeli sourcing, or maybe Saudis who are eager buyers of Israeli hacking products

Re: Operation Triangulation What You Get When Attack iPhones of Researchers [video]

#16
post #14

The lack of attribution on this organized and well-financed operation is the most concerning part of this attack, in my opinion. It seems unlikely that any APT would burn ALL of its 0-days for the iOS platform in one campaign, so they likely have more which they can pivot to. Of course there are 3 nation-states who are most likely to be behind this operation, but which one was it? If possible, we should be looking fo…

If I were in charge, I would attack 90% Taiwanese and 10% of my real target. And I would leave Chinese comments everywhere. So I doubt you can point fingers so easily. These are some smart people.

CIA already had that, it's called Marble Framework, it's used to attribute their malware to other nations.

https://freedomhacker.net/vault-7-marble-framework-cia-evade...

Re: Operation Triangulation What You Get When Attack iPhones of Researchers [video]

#17

Earlier quoted context omitted.

There are generally 4 major cyber powers that I consider when hearing about new advanced techniques / applications / threats: USA, Russia, Israel, China (in roughly that order). Israel is obviously complicated because historically a lot of their work has been in partnership with the USA, but that seems to be mildly less the case these days.

France and the UK are also world class. Anyone else?

The Dutch have a few high profile hacks I’ve read about. Including literally watching the Russians hack the DNC.[1]

[1] https://www.washingtonpost.com/news/worldviews/wp/2018/01/26...

Re: Operation Triangulation What You Get When Attack iPhones of Researchers [video]

#18

Earlier quoted context omitted.

I could be very wrong, but I feel Israel’s cybersecurity tech is more advanced than Russia (could be my western programming lol)

When you look at home media, every major development has been Russian. Software for cracking Blu-rays? Russia was first. Software for cracking 4K UHD Blu-rays? Russia was first. Software for cracking Nintendo Switch games (DBI)? Russia was first. The new flash-cart for the Switch, assuming it's legit? Russia. The only hacker left who can crack Denuvo video games? Russian.

Necessity is the mother of all invention. This could just be related to socioeconomic factors.

Re: Operation Triangulation What You Get When Attack iPhones of Researchers [video]

#19

Earlier quoted context omitted.

There are generally 4 major cyber powers that I consider when hearing about new advanced techniques / applications / threats: USA, Russia, Israel, China (in roughly that order). Israel is obviously complicated because historically a lot of their work has been in partnership with the USA, but that seems to be mildly less the case these days.

> Israel is obviously complicated They also have a large and profitable industry selling state of the art tools to authoritarian regimes/dictators to target democracy activists and journalists.

So does every other industrialized country.

Re: Operation Triangulation What You Get When Attack iPhones of Researchers [video]

#20

The lack of attribution on this organized and well-financed operation is the most concerning part of this attack, in my opinion. It seems unlikely that any APT would burn ALL of its 0-days for the iOS platform in one campaign, so they likely have more which they can pivot to. Of course there are 3 nation-states who are most likely to be behind this operation, but which one was it? If possible, we should be looking fo…

Agree that its concerning regarding the lack of attribution especial given the complexity.

If I had to guess...and this is a wild guess and in no way based on hard evidence....but I think the true value would be using this as a vector to bypass 2fa or MFA for attacks on a supply chain. Chaining exploints isn't a new concept...hell I had a similar idea years ago regarding chaining cve's to create a better more fluid escalation of privileges. The concerning thing is these were 0days from the brief reading I did, and exploited hardware vulnerabilities.

IMO hardware is the best target because few people are going to rip apart the device to look at chips...and even if they did they would need a metrology or lithography lab to find a backdoor in a part of a CPU or other component. Just because the part was shipped from the factory and the factory made it correctly, if someone could compromise a basic part of the chip then its all over and you really have to spend your time looking for these things. Example would be the BMC on your dell server gets backdoored or editing a snippet of microcode that these chip makers do not publicly document.

Seems unlikely that they would blow so many 0days so recklessly just to infect the iPhone to get data....when it could be used for so much more.

If this is a nation state actor....chances are they can just buy the data via third party or could have forced apple to turn over the icloud data or just caught it via intercepting the undersea cables and the their 1 isp's

Unless I'm missing something.....and this was used go after a really critical target that was hard to compromise and as a result, once they got the Intel they wanted they might have just used it willy nilly or have considered the 0days as lost if they had compromised a foreign nation state or person of interest and figure since they used the exploit....their advisary will discover it sooner or later

Post reply on HN