That's pretty astonishing. The MMIO abuse implies either the attackers have truly phenomenal research capabilities, and/or that they hacked Apple and obtained internal hardware documentation (more likely). I was willing to believe that maybe it was just a massive NSA-scale research team up until the part with a custom hash function sbox. Apple appears to have known that the feature in question was dangerous and delib…
Operation Triangulation: What you get when attack iPhones of researchers
51–60 of 433 posts
Re: Operation Triangulation: What you get when attack iPhones of researchers
#52Earlier quoted context omitted.
... And they've already announced[1] that they will be retaining the exclusive blue bubble for iMessage messages for... reasons? The green/blue bubble distinction will continue even when there is no technical difference between messages. 1. https://mashable.com/article/apple-rcs-support
Yep, why would they drop it? It’s especially egregious as Apple disregards its own human interface guidelines to make green bubbles excessively low-contrast. Very intentional.
Re: Operation Triangulation: What you get when attack iPhones of researchers
#53Earlier quoted context omitted.
It can be defended against. The detail is that the only way to harden those defenses is to toss it out in the world and let folks poke holes in it. This was an extremely complex exploit. It was complex because of all of the defenses put in place by Apple and others. It required State level resources to pull it off. We also don't know what, if any, external skullduggery was involved in the exploit. Did someone penetra…
>It was complex because of all of the defenses put in place by Apple and others. I don't know jack about hardware but it would seem obvious that when one designs a chip, you make sure it does not have 'unknown hardware registers' or unknown anything when you get it back from the manufacture. This makes everything written on this page worthless... >Prevent anyone except you from using your devices and accessing your i…
The article doesn’t state that. It says it’s undocumented for the security researchers.
Re: Operation Triangulation: What you get when attack iPhones of researchers
#54Re: Operation Triangulation: What you get when attack iPhones of researchers
#55https://streaming.media.ccc.de/37c3/relive/11859
In addition contents of the presentation, in terms of timeline...
2018 (September): First undocumented MMIO-present CPU launched, Apple A12 Bionic SOC.
2021 (December): Early exploit chain infrastructure backuprabbit.com created 2021-12-15T18:33:19Z, cloudsponcer.com created 2021-12-17T16:33:50Z.
2022 (April): Later exploit chain infrastructure snoweeanalytics.com created 2022-04-20T15:09:17Z suggesting exploit weaponized by this date.
2023 (December): Approximate date of capture (working back from "half year" quoted analysis period + mid-2023 Apple reports.
The presenters also state that signs within the code reportedly suggested the origin APT group has used the same attack codebase for "10 years" (ie. since ~2013) and also uses it to attack MacOS laptops (with antivirus circumvention). The presenters note that the very "backdoor-like" signed debug functionality may have been included in the chips without Apple's knowledge, eg. by the GPU developer.
So... in less than 3.5 years since the first vulnerable chip hit the market, a series of undocumented debug MMIOs in the Apple CoreSight GPU requiring knowledge of a lengthy secret were successfully weaponized and exploited by an established APT group with a 10+ year history. Kaspersky are "not speculating" but IMHO this is unlikely to be anything but a major state actor.
Theory: I guess since Apple was handed ample evidence of ~40 self-doxxed APT-related AppleIDs, we can judge the identity using any follow-up national security type announcements from the US. If all is quiet it's probably the NSA.
Re: Operation Triangulation: What you get when attack iPhones of researchers
#56Earlier quoted context omitted.
It can be defended against. The detail is that the only way to harden those defenses is to toss it out in the world and let folks poke holes in it. This was an extremely complex exploit. It was complex because of all of the defenses put in place by Apple and others. It required State level resources to pull it off. We also don't know what, if any, external skullduggery was involved in the exploit. Did someone penetra…
>It was complex because of all of the defenses put in place by Apple and others. I don't know jack about hardware but it would seem obvious that when one designs a chip, you make sure it does not have 'unknown hardware registers' or unknown anything when you get it back from the manufacture. This makes everything written on this page worthless... >Prevent anyone except you from using your devices and accessing your i…
well you are in trouble then. all of modern hardware have such hidden parts in them, and are most of the time referenced as "undocumented" instead of "unknown". I know this seems pedantic, but from a public eye, anything undocumented is unknown. what makes those special however, is those are not used at all by public software, thus truly unknown as one can only guess their use or even their mere existence.
Re: Operation Triangulation: What you get when attack iPhones of researchers
#57[flagged]
Re: Operation Triangulation: What you get when attack iPhones of researchers
#58It’s quite unfortunate that Apple doesn’t allow users to uninstall iMessage, it seems to be the infection vector for advanced threats like this, NSO group, etc. Presumably it’s to avoid the support burden, but they could gate it behind having Lockdown Mode enabled for a week or something to shake out the vast majority of mistaken activations.
Re: Operation Triangulation: What you get when attack iPhones of researchers
#59Who had motive to target Russian government officials, knowledge of the attack vectors, history of doing so, and technical and logistical ability to perform it leads Kaspersky and myself to the only rational conclusion: that Apple cooperated with the NSA on this exploit. I assume they only use and potentially burn these valuable methods in rare and perhaps desperate instances. I expect the Russian and Chinese governm…
My adjacent conspiracy theory is that the NSA and other state agencies do both original research and pay hackers for exploits that Apple hasn’t yet discovered.
Like how the NRO used to design and launch satellites that cost more than aircraft carriers but are now working closely with private companies like Maxar to find more economical solutions.
https://www.maxar.com/press-releases/nro-awards-maxar-a-10-y...
Re: Operation Triangulation: What you get when attack iPhones of researchers
#60Who had motive to target Russian government officials, knowledge of the attack vectors, history of doing so, and technical and logistical ability to perform it leads Kaspersky and myself to the only rational conclusion: that Apple cooperated with the NSA on this exploit. I assume they only use and potentially burn these valuable methods in rare and perhaps desperate instances. I expect the Russian and Chinese governm…
doesn't the article states precisely otherwise? that while the FSB accuses Apple of cooperation, Kaspersky does not have any reason to believe so, especially since it does not look like any known state actor.