Live data from Hacker News

How to catch a wild triangle

securelist.com

31–40 of 46 posts

Re: How to catch a wild triangle

#31

Earlier quoted context omitted.

It wasn't clear to me from reading the blogpost that persistence _wasn't_ achieved?

They mentioned that the suspicious traffic stopped after a restart.

I'm not seeing that mentioned in this blogpost, was it mentioned in one of the other ones?

Re: How to catch a wild triangle

#32
post #22

> Unfortunately, this method did not allow us to intercept HTTPS traffic of Apple services (including iMessage), as iOS implements SSL pinning for this. Thus, we were not able to decrypt iMessage traffic that came through the VPN. When security helps attackers... that's a bit ironic. Anyway, this article is exactly why I don't want to work in computer security, you constantly have to look behind you, and government A…

I don't know. It sounds like you liked the article.

Re: How to catch a wild triangle

#33

Earlier quoted context omitted.

They mentioned that the suspicious traffic stopped after a restart.

I'm not seeing that mentioned in this blogpost, was it mentioned in one of the other ones?

https://securelist.com/operation-triangulation/109842/

They talk about it here, under "what we know so far"

Re: How to catch a wild triangle

#34

I've always felt that security/exploit devs are just different. This kind of constant striving and failing until finally succeeding would be such an incredibly frustrating experience for me. Kudos to them though, it's serious perseverance.

It's not failing. I know that's a trope (1000 filaments that don't work)...but it really is the difference in you and them. Their mindset is not that they have failed, at any point. They are poking and probing and analyzing and incrementally finding things out. At no point were they failing. They probably didn't consider that they could fail.

It's a mindset/perspective difference.

Re: How to catch a wild triangle

#36
post #25

Earlier quoted context omitted.

Persistence on iOS is really, really hard.

I agree with you on that, but the USA (and probably China) is the nation state least likely to skimp on iOS persistence when targeting Russian AV analysts :D

I can only guess at motivations but I would think that when targeting security researchers you’d aim to not have persistence since that would make require leaving evidence of infection on the device.

Re: How to catch a wild triangle

#37
post #22

> Unfortunately, this method did not allow us to intercept HTTPS traffic of Apple services (including iMessage), as iOS implements SSL pinning for this. Thus, we were not able to decrypt iMessage traffic that came through the VPN. When security helps attackers... that's a bit ironic. Anyway, this article is exactly why I don't want to work in computer security, you constantly have to look behind you, and government A…

Computer security person here! I have yet to be assassinated :)

Survivorship bias

Re: How to catch a wild triangle

#38
post #26
post #11

> Despite many ups and downs, we eventually managed to obtain all the stages used in this attack, including four zero-day exploits reported to Apple, two validators, an implant and its modules. Looks like NSA still hasn't forgiven Kaspersky for exposing STUXNET [1]. It seems that this latest attack on Kaspersky was expensive. Losing 4 zerodays must have been painful. It's also possible that Israel and Unit 8200 [2] w…

> but my money's on the NSA Why is your money on the NSA?

because it is the only boogeyman he knows how to blame with no evidence

Re: How to catch a wild triangle

#39

Earlier quoted context omitted.

It wasn't clear to me from reading the blogpost that persistence _wasn't_ achieved?

They mentioned that the suspicious traffic stopped after a restart.

FTA: "Once the device rebooted, all the suspicious activity stopped."
Post reply on HN