Live data from Hacker News

Hezbollah pager explosions kill several people in Lebanon

reuters.com

401–410 of 1001 posts

Re: Hezbollah pager explosions kill several people in Lebanon

#401

From Israel's perspective, this supply chain attack was undoubtedly a clever move, but I can't help but wonder about its long-term consequences. Although it was aimed at harming Israel's adversaries, third-party countries may now hesitate to involve Israel in their supply chains. There's also the risk that other major producers could replicate this tactic, potentially leading to further escalation in the region or be…

IMO, this gives IL's enemies more excuses to execute more horrible attacks. Considering pagers are civilian products and some of them might actually be delivered to non-Hez civilians, the consequence is pretty dire. it basically says: we can do whatever we want because we can. Now imagine what the other side is going to reply.

The other side was already doing everything it could.

Re: Hezbollah pager explosions kill several people in Lebanon

#402
post #179

If we try to do what we are best at here at HN, let’s focus the discussion on the technical aspects of it. It immediately reminded me of Stuxnet, which also from a technical perspective was quite interesting. I already wonder if this was anything that was planted in the devices perviously, or if the ones responsible had similar devices, and managed reverse engineer them and craft a payload to them, that could be sent…

I wonder what Israel did to ensure that only legitimate targets were harmed by the sabotaged pagers.

[flagged]

Re: Hezbollah pager explosions kill several people in Lebanon

#403

Seems like a harbrining of war, if the pager network was compromised, thus burns the compromised network and also harms a lot of people. Most major newspapers in Israel are saying that Netanyahu wants an invasion of Southern Lebanon: https://www.ynetnews.com/article/bje3pjv60 https://www.jpost.com/arab-israeli-conflict/article-820399 https://www.timesofisrael.com/top-general-said-pushing-for-g...

Lebanon has been shooting rockets at Israel for a while now. They already are at war. It's just Israel is very strategic about its steps.

Re: Hezbollah pager explosions kill several people in Lebanon

#404
post #361

This almost reads like science fiction, what an incredible attack from a technical POV. A couple of thoughts: 1. The beepers were compromised and have been for a long time. I don't know how easy it is to exfiltrate data from them if they are receive-only devices. At any rate it shows that Israel is capable of intercepting and manipulating low-tech comms. What's left for Hezbollah to use? 2. The next step is to hack i…

> 1. The beepers were compromised and have been for a long time. Where did you see this? Sources are saying that Hezbollah recently upgraded their pagers with the American University of Beirut on August 29: https://x.com/gazanotice/status/1836082218805891360 Why would Israel have the ability to wipe out a good chunk of Hezbollah for years and just sat on it until now? They are claiming 2750 injuries: https://www.alja…

I wasn't thinking years, but months but I didn't know about the recent upgrade. At any rate, if the pagers allowed any data exfiltration they have been collecting that data since whenever the last upgrade was.

Re: Hezbollah pager explosions kill several people in Lebanon

#405
post #3

Why was this flagged? I vouched for it as it would make for an interesting discussion about the security of these devices and how this kind of cyberattack might have happened. Are smartphones, for example, also vulnerable to it?

Dupes also get flagged, like in this case. This submission got [dupe] added as a prefix to he title.

https://news.ycombinator.com/item?id=41567573

Re: Hezbollah pager explosions kill several people in Lebanon

#406
post #3

Why was this flagged? I vouched for it as it would make for an interesting discussion about the security of these devices and how this kind of cyberattack might have happened. Are smartphones, for example, also vulnerable to it?

> Why was this flagged? Anything any particularly motivated group dislikes here gets flagged; always been this way. Thanks for vouching. > Are smartphones, for example, also vulnerable to it? I also would love an answer to this question. Up until 12 minutes ago, I would never have thought _blowing up_ hundreds of pagers simultaneously was a realistic scenario. If anyone can make sense of how this actually worked I'd…

I am just out of the gate, but the videos show sharp percussive explosions and no lithium evidence. So C4 or RDX in the devices on a 'mod board' with the explosive disguised as a big capacitor or something. It had to be put into the devices. In order to justify an operation like this the explosions had to be near-simultaneous so the mod board had to have its own clock, which would be as accurate as the crystal in the clock circuit provides, maybe drift of +/- a few seconds since installation.

The broadcast pager network does not offer this level of time precision for a detonation message so as ugly as it sounds, I believe at the moment that 9/17/2024@3:30pm (or whatever) was preloaded into the 'mod boards'.

Perhaps the 'mod board' had the capability for the future time to be set with a broadcast message, but that introduces such complexity! It requires the page system itself to be compromised. The victims' paranoia served them badly in this case, a recent warning about cell devices and a lower tech 'solution' is rolled out and they would only trust one source, so all you'd have to do was get an explody batch into the supply chain with (reasonable) assurance that only Hezbollah members would get them.

In the coming days I'd look for clues in: The simultaneity of the explosions with times to the second // were any duds found and disassembled? // is there a separate radio receiver on the mod board (to set future detonation time) // when did the 'rollout' of the devices begin? // How many pager carrying non-members were injured and what were the circumstances ('medics' being one group) // Will suspicious broadcasts be discovered from logs or logged radio intercepts?

Given the people we are dealing with (I mean both sides) I am thinking that the operation avoided ANY covert channels at all and was a simple date-time bomb.

Re: Hezbollah pager explosions kill several people in Lebanon

#407
post #179

If we try to do what we are best at here at HN, let’s focus the discussion on the technical aspects of it. It immediately reminded me of Stuxnet, which also from a technical perspective was quite interesting. I already wonder if this was anything that was planted in the devices perviously, or if the ones responsible had similar devices, and managed reverse engineer them and craft a payload to them, that could be sent…

[flagged]

Understanding how the attack was carried out is the first step to identifying the vulnerability/risk/threat so it can be prevented. You don't have to be an expert or defer to experts in everything to be allowed to talk about it.

Re: Hezbollah pager explosions kill several people in Lebanon

#408
post #361

This almost reads like science fiction, what an incredible attack from a technical POV. A couple of thoughts: 1. The beepers were compromised and have been for a long time. I don't know how easy it is to exfiltrate data from them if they are receive-only devices. At any rate it shows that Israel is capable of intercepting and manipulating low-tech comms. What's left for Hezbollah to use? 2. The next step is to hack i…

Unfortunately innocent people were also harmed, don’t think a straight list will serve anyone Honestly I doubt Israel/Mossad doesn’t know who is in Hezbollah, i think this is more of a direct attack (obviously) mixed with scare/terror benefit

I think the value is in knowing the network and cross-reference against it. Innocent bystanders or people who happened to just go to the hospital today will probably fall off during this process. Not to mention that you can filter out by the type of injury to get a more accurate list.

Re: Hezbollah pager explosions kill several people in Lebanon

#409

This seems like it would have the potential for a lot of collateral damage due to the possibility that modified pagers might enter general distribution. That is to say, how do they insure that a given shipment of pagers are only going to Hezbollah as opposed to some of them going to people like aid workers?

I'm not sure why it's being assumed that they detonated all of the pagers. They presumably have unique device IDs / phone numbers that can be tied to individual people. For all we know, they may have just detonated the ones known to be in use by Hezbollah operatives.

[flagged]

Re: Hezbollah pager explosions kill several people in Lebanon

#410
Part of the context is that they use a different communication network which is probably why they were targeted in that specific way...

Overcharging batteries would be the hack....not suggesting someone do this but said strategy works with both acid based and lithium batteries...

Post reply on HN