Live data from Hacker News

Targeted attack on our management with the Triangulation Trojan

usa.kaspersky.com

41–50 of 131 posts

Re: Targeted attack on our management with the Triangulation Trojan

#41
post #10

From the article > We believe that the main reason for this incident is the proprietary nature of iOS. This operating system is a “black box”, in which spyware like Triangulation can hide for years. Detecting and analyzing such threats is made all the more difficult by Apple’s monopoly of research tools – making it a perfect haven for spyware. In other words, as I’ve often said, users are given the illusion of securi…

Why are top management at Kaspersky using iPhones, presumably they knew iPhones were a “black box” and a security risk.

Re: Targeted attack on our management with the Triangulation Trojan

#42
post #9

Earlier quoted context omitted.

> These days on a larger scale there's basically NATO, SCO, UAE, Israel and the African Union as alliances (setting aside (former) British colonies). Which one's the good one?

Only Siths deal in absolutes. Among that list, NATO is by far the preferred option.

I mean, unless you live in Middle East and one day they say you have WMD and they destroy your whole country. If you live in the EU or the US - then yes.

Re: Targeted attack on our management with the Triangulation Trojan

#43
post #10

From the article > We believe that the main reason for this incident is the proprietary nature of iOS. This operating system is a “black box”, in which spyware like Triangulation can hide for years. Detecting and analyzing such threats is made all the more difficult by Apple’s monopoly of research tools – making it a perfect haven for spyware. In other words, as I’ve often said, users are given the illusion of securi…

Why are top management at Kaspersky using iPhones, presumably they knew iPhones were a “black box” and a security risk.

I guess everyone at Kaspersky knew the risk of an attack was non-zero given their industry profile. Their SIEM finally caught it, albeit it is arguable if the detection was timely and as others in the thread have pointed out, their MDM should have detected the upgrade failures or version issues. We will probably hear about it in the detailed paper/presentation later.

Their rant on the closed nature of the ios ecosystem is more around Apple's hold on the research tools. That is what I took from the statement, among other things.

Re: Targeted attack on our management with the Triangulation Trojan

#44
"An indirect indication of the presence of Triangulation on the device is the disabling of the ability to update iOS"

My guess would be that they didn't find out thanks to their monitoring solution, but because some senior manager shouted pretty loudly at someone to get their iPhone to update, asap! :)

Re: Targeted attack on our management with the Triangulation Trojan

#46
post #37
post #17

Earlier quoted context omitted.

Why are they using iOS if they feel that way about it? Also: iOS 16 is not vulnerable and it was released on September 12, 2022 - why are those phones out of date for so long?

That one of the bigger security companies seemingly didn't have MDM screaming bloody murder or outright blocking authentication for an endpoint this out of date is more than a little concerning. Props to their SIEM for detecting it in the end, but this seems like it could've been detected and remediated a few weeks in (assuming it didn't also have the ability to spoof the iOS version).

That's why I believe this is a made up article for selling their security product.

Re: Targeted attack on our management with the Triangulation Trojan

#47
post #42
post #9

Earlier quoted context omitted.

Only Siths deal in absolutes. Among that list, NATO is by far the preferred option.

I mean, unless you live in Middle East and one day they say you have WMD and they destroy your whole country. If you live in the EU or the US - then yes.

Or you live in Russia and you thought you had a deal that NATO wouldn't encroach further on your border...

It was a trick question, none of them are good.

Re: Targeted attack on our management with the Triangulation Trojan

#48
post #24

Adjacent topic but i have a friend who told me buying a refurbished iPhone from a local shop was a bad idea from a security perspective. Is this true? I thought a hard reset and secure enclave etc. was enough? Can you put "stuff" in it that survives to a new user?

Exploits that survive a full wipe are almost unheard of on iOS.

hardware modifications definitely can. A few years ago I've read ([0] - the article is in russian but google translate does its job) about hardware bugs installed in iphones - with a mic and an own SIM card, everything is powered from the phone's battery.

[0] https://service-iphone.ru/blog/proslushka-v-iphone-teper-bez...

Re: Targeted attack on our management with the Triangulation Trojan

#49
post #10

From the article > We believe that the main reason for this incident is the proprietary nature of iOS. This operating system is a “black box”, in which spyware like Triangulation can hide for years. Detecting and analyzing such threats is made all the more difficult by Apple’s monopoly of research tools – making it a perfect haven for spyware. In other words, as I’ve often said, users are given the illusion of securi…

Shatters Apple's argument that all of these hurdles are better for security. I wonder if testimony like this could affect any of their antitrust lawsuits or right to repair lobbying.

It reads more like an excuse than the actual reason.

Endpoint protection solutions can be installed in iOS devices. The device could also be wiped clean, eliminating the malware.

The latter should not be much of an issue in any serious organization. If any executive keeps critical data in a phone, that is already an issue.

The former is a hassle, but I have had to use locked down iPhones before, and the tradeoffs are still better than facing an intrusion.

The vulnerability and the vector could also have been present in a different form in Android devices.

All in all, I don't think this is the response Kaspersky should have come forward with.

Re: Targeted attack on our management with the Triangulation Trojan

#50
post #42
post #9

Earlier quoted context omitted.

Only Siths deal in absolutes. Among that list, NATO is by far the preferred option.

I mean, unless you live in Middle East and one day they say you have WMD and they destroy your whole country. If you live in the EU or the US - then yes.

Which middle eastern country have NATO attacked?
Post reply on HN