Live data from Hacker News

Hezbollah pager explosions kill several people in Lebanon

reuters.com

631–640 of 1001 posts

Re: Hezbollah pager explosions kill several people in Lebanon

#632

That's an impressive supply-chain hack. Spend years showing how insecure modern telecom devices are and scare your enemy into going old-school, receive-only. Set up a shell company to sell pagers to your enemy's shell company. Give them devices implanted with a small explosive charge pointed inward, knowing they will be worn around the waist most of the time. Hack the backend server, send a coordinated page to all th…

Someone will eventually spill the beans on how it was done. They always do.

[flagged]

Re: Hezbollah pager explosions kill several people in Lebanon

#633

That's an impressive supply-chain hack. Spend years showing how insecure modern telecom devices are and scare your enemy into going old-school, receive-only. Set up a shell company to sell pagers to your enemy's shell company. Give them devices implanted with a small explosive charge pointed inward, knowing they will be worn around the waist most of the time. Hack the backend server, send a coordinated page to all th…

The shell company isn't a strict requirement, and I'd wager less likely. Infiltrating the delivery process would be easier and would instead require knowing about the pager purchase and being able to swap the actual package for an alternative package. Theoretically all of this is possible with some data interception to discover the pager order, a team to construct the exploding pagers, a person to deliver the exploding pagers, and a person to intercept the actual pagers (which could be the same person delivering the exploding pagers).

Re: Hezbollah pager explosions kill several people in Lebanon

#634
I find it hard to believe that people are seriously considering the cybersecurity angle in this situation. Yes, there may be some extremely rare and unlikely scenarios where you could hack into a device and cause the attached lithium-ion battery to overheat and combust. However, it’s important to understand that lithium-ion batteries don’t actually explode—they combust gradually over the span of a few seconds to minutes. Even if they did explode, which they don’t, we’re talking about something with the energy equivalent of a single AAA battery, not a large and powerful EV cell. Given these facts, it’s far more plausible that those pagers were intercepted and deliberately implanted with explosives, rather than being manipulated through hacking.

Re: Hezbollah pager explosions kill several people in Lebanon

#635
post #395

That's an impressive supply-chain hack. Spend years showing how insecure modern telecom devices are and scare your enemy into going old-school, receive-only. Set up a shell company to sell pagers to your enemy's shell company. Give them devices implanted with a small explosive charge pointed inward, knowing they will be worn around the waist most of the time. Hack the backend server, send a coordinated page to all th…

> Hack the backend server, send a coordinated page to all the pagers at the same time. You likely don’t even need to hack anything if you coordinate based on time. A built in clock would eliminate the need for any external signal and work in a, no pun intended, dead zone. If the pager itself is hacked, the software could also pretend to receive a page a moment before detonation to maximize the chance the device is he…

It most likely just received a code message that triggered the device.

Re: Hezbollah pager explosions kill several people in Lebanon

#636

From a legal perspective, are there any regulations on these kinds of attacks? Meaning, are they allowed? Are they considered a war crime or maybe this is still a gray area?

It's not that there is a list of approved ways to attack your enemy. Inventing new ways to take enemy by surprise is absolutely a part of warfare. What's important from legal perspective is the ratio between military effect and collateral damage. In this case so far it seems it was better than if conventional warfare was used.

Re: Hezbollah pager explosions kill several people in Lebanon

#637
post #361

This almost reads like science fiction, what an incredible attack from a technical POV. A couple of thoughts: 1. The beepers were compromised and have been for a long time. I don't know how easy it is to exfiltrate data from them if they are receive-only devices. At any rate it shows that Israel is capable of intercepting and manipulating low-tech comms. What's left for Hezbollah to use? 2. The next step is to hack i…

> 1. The beepers were compromised and have been for a long time. Where did you see this? Sources are saying that Hezbollah recently upgraded their pagers with the American University of Beirut on August 29: https://x.com/gazanotice/status/1836082218805891360 Why would Israel have the ability to wipe out a good chunk of Hezbollah for years and just sat on it until now? They are claiming 2750 injuries: https://www.alja…

> Hezbollah recently upgraded their pagers with the American University of Beirut

Please do not conflate Hezbollah and AUB.

The claim is that AUB medical school pagers were replaced a week or so ago. This is either pure coincidence, false or fake news to imply that AUB has Israeli operatives, or indeed that the pagers used were compromised and that the USA was aware of the impending attack and did not want to harm AUB medical staff - who probably are mostly not connected with Hezbollah.

Further reading: https://x.com/AUBMC_Official/status/1836086847153320148

Re: Hezbollah pager explosions kill several people in Lebanon

#638
post #112

This being a hack is improbable in my opinion. If you see the pictures of the aftermath, the damage is too big to be the result of a lithium battery explosion. Moreover the devices exploded at the same time in different locations (won’t happen if they made the battery overheat till explosion) HA probably bought a bad batch with implanted explosives and they set it off now.

> This being a hack is improbable

Your definition of hack differs from mine. This is hack in every sense of the word: supply chain hack, signals hack, and more...

Re: Hezbollah pager explosions kill several people in Lebanon

#639
post #361

This almost reads like science fiction, what an incredible attack from a technical POV. A couple of thoughts: 1. The beepers were compromised and have been for a long time. I don't know how easy it is to exfiltrate data from them if they are receive-only devices. At any rate it shows that Israel is capable of intercepting and manipulating low-tech comms. What's left for Hezbollah to use? 2. The next step is to hack i…

It’s hard to believe none of these beepers have failed before this and the explosives found by a beeper repair person

Re: Hezbollah pager explosions kill several people in Lebanon

#640
post #353

Another example of why outsourcing manufacturing is a national security concern, and how the absolute free market can lead "winners" to harm themselves by chasing "success" at all costs.

Do you think manufacturing pagers in Lebanon is a viable alternative?

The idea of the majority of manufacturing being external to a country is a little under 100 years old, yet people talk as if it is unthinkable.
Post reply on HN