Live data from Hacker News

Hezbollah pager explosions kill several people in Lebanon

reuters.com

781–790 of 1001 posts

Re: Hezbollah pager explosions kill several people in Lebanon

#781

From Israel's perspective, this supply chain attack was undoubtedly a clever move, but I can't help but wonder about its long-term consequences. Although it was aimed at harming Israel's adversaries, third-party countries may now hesitate to involve Israel in their supply chains. There's also the risk that other major producers could replicate this tactic, potentially leading to further escalation in the region or be…

There's also the hit to the reputation of the manufacturers of these devices to consider (even though they were almost certainly intercepted some time after manufacture and modified in transit, or replaced with a different batch that had been ordered by the perpetrator and modified ahead of time for a quick swap). The perpetrator may have been spying on the pager network for some time, and if so then their cover is blown and their information source is gone.

The larger issue is that if shipments of pagers can be intercepted and modified in this manner, then any electronic device can be subjected to other hardware-based attacks - eavesdropping devices, keystroke loggers, etc. What if large numbers of countries with developing tech markets start looking at the suppliers involved the way the USA looks at China's Huawei?

In general this boosts the open-soure model for both software and hardware, so the expected hardware configuration that can be checked visually and with other user-available tools. If any phone, pager, tablet or laptop can be physically hijacked and modified, the user should be allowed access to all the information and tools needed to detect it. This assumes the factory itself is not the bad actor.

Hardware security consultant firms probably have a bright future. Also robots for assistance with inspection.

Re: Hezbollah pager explosions kill several people in Lebanon

#782
post #264

From Israel's perspective, this supply chain attack was undoubtedly a clever move, but I can't help but wonder about its long-term consequences. Although it was aimed at harming Israel's adversaries, third-party countries may now hesitate to involve Israel in their supply chains. There's also the risk that other major producers could replicate this tactic, potentially leading to further escalation in the region or be…

Do you think Hezbollah was buying stuff from Israel, or otherwise using Israeli supply chains? I think it's far more likely that Mossad has infiltrated whatever foreign (non-Israeli) supply chain they were using. So this can happen regardless of whether you're using Israeli supply chains or not.

It was pointed out to me that you shouldn't overthink it: the most likely thing which happened is Israel had someone inside Hezbollah procurement and used them to take delivery (I'd put much lower odds on this guy being in on the plan, it's doubtful he even knew he was working for Israel directly).

You've got to remember that as internet people, we want everything to have a clever storyline to it. Intelligence services exploit that exact expectation though: the first thing you attack is trust within the organization itself, since it gives you more access, more easily and once people have talked themselves into "supply chain threat" there's a real danger they've ignored "actually the guy signing off on the paperwork is taking a payoff to ignore some delivery irregularities".

Re: Hezbollah pager explosions kill several people in Lebanon

#783
post #361

This almost reads like science fiction, what an incredible attack from a technical POV. A couple of thoughts: 1. The beepers were compromised and have been for a long time. I don't know how easy it is to exfiltrate data from them if they are receive-only devices. At any rate it shows that Israel is capable of intercepting and manipulating low-tech comms. What's left for Hezbollah to use? 2. The next step is to hack i…

Yikes the "list of patients" thing is scariest part of all of this: if they feed that into some monster AI that creates new targets... I can only imagine the diminishing accuracy of who is really deserving of being targets

But that is exactly what modern AI-era big data warfare would look like. By its nature, and by choice, less accuracy / more innocent targets, but oh well

Re: Hezbollah pager explosions kill several people in Lebanon

#784

There was a really dumb but also really entertaining Awkwafina/John Cena movie that I watched recently called Jackpot https://www.imdb.com/title/tt26940324/ . At one point in the middle of the movie one of the characters calls a 3 letter agency friend and asks them for a "Phone Strike on his location". There is a mob gathered outside of their room, and within 30 seconds everyone's phone blows up and the protagonists…

Wait for the "Tesla strike" in San Fran

Re: Hezbollah pager explosions kill several people in Lebanon

#785

From Israel's perspective, this supply chain attack was undoubtedly a clever move, but I can't help but wonder about its long-term consequences. Although it was aimed at harming Israel's adversaries, third-party countries may now hesitate to involve Israel in their supply chains. There's also the risk that other major producers could replicate this tactic, potentially leading to further escalation in the region or be…

it makes me think the Israeli decision-makers are trying to leave Hezbollah no choice but to escalate into a larger war. I think Hezbollah has been trying to avoid escalation into all out war, responding in limited proportionate ways despite Israel continuing to escalate. (Can you imagine if Hezbollah had detonated thousands of such devices in Israel? I'd be scared of a nuclear response). But Israeli leaders maybe de…

[flagged]

Re: Hezbollah pager explosions kill several people in Lebanon

#786
post #248

I am for some reason reminded of this classic scene from The Wire [1] where a detective sells a trove of preemptively wiretapped burner cell phones to a drug organization [1] https://www.youtube.com/watch?v=ZDalKxcLQC8

The Australian Federal Police and the US FBI launched a similar attack a few years ago where they sold a few thousand phones to underworld figures. The phones had an apparently encrypted and hidden chat app pre-installed on them which was feeding all the messages and data to the police.[0]

[0]: https://www.afp.gov.au/about-us/history/unique-stories/opera...

Re: Hezbollah pager explosions kill several people in Lebanon

#787
post #179

If we try to do what we are best at here at HN, let’s focus the discussion on the technical aspects of it. It immediately reminded me of Stuxnet, which also from a technical perspective was quite interesting. I already wonder if this was anything that was planted in the devices perviously, or if the ones responsible had similar devices, and managed reverse engineer them and craft a payload to them, that could be sent…

My other thought is that these probably came from the Iranian military, and it’s quite possible the Iranian military puts explosives in them so they can remotely detonate one that falls into enemy hands. And that Isreal simply found out about this and managed to figure out how to activate that.

This is reaching. How would this mechanism even work? If the enemy has control of a communications device then (1) they've had it and you didn't know for some time and (2) they already know how it works. There's no benefit to putting a self-destruct mechanism into such a thing, since if you know it's compromised then you just stop messaging it.

The self-destruct is pointless, because you can't even verify that it was successful and you have no actual technology to protect (unlike say, US military drones which self-destruct to protect technological details of their construction - and the US would still prefer to commit a mission to bombing a crash site to be sure if they can).

Basically you answer your own problem: the most likely outcome of a self-destruct mechanism is that it goes off accidentally against your own forces, or gets exploited - while it would deliver no actual benefit to you.

Which is to say: when analyzing an adversaries likely actions you don't start by assuming they're stupid or irrational (which is different from whether or not their overall goals might be stupid or irrational).

Re: Hezbollah pager explosions kill several people in Lebanon

#788

From Israel's perspective, this supply chain attack was undoubtedly a clever move, but I can't help but wonder about its long-term consequences. Although it was aimed at harming Israel's adversaries, third-party countries may now hesitate to involve Israel in their supply chains. There's also the risk that other major producers could replicate this tactic, potentially leading to further escalation in the region or be…

That's a real issue. Especially if this escalates to smartphones.

Technical questions:

- Was the explosive in the pager detectable by the normal tests used at airports?

- Who gets to skip those tests? Are all devices carried by airline pilots examined with explosive tests?

- This is selective. Only the addressed devices blow up. That has implications for devices which know too much about their owners.

Re: Hezbollah pager explosions kill several people in Lebanon

#789

Honestly, at this point, I see absolutely zero difference, from a moral perspective, between the Israeli government and their enemies. Both are as bad as each other and have been implicated in many war crimes and human rights abuses, however Israel has more firepower and can inflict much more damage (E.g. demolish an entire apartment block, killing hundreds of innocent people from the air). The last thing any country…

[flagged]

This is objectively false.

Israel is objectively an apartheid state [1][2], no different to apartheid South Africa. South Africa was also a "democracy" (for white people). You cannot be both a democracy and an apartheid state, by definition.

There are ~2M Palestinians in Gaza and ~3M in the West Bank, both areas that Israel lays claim to and are within its borders. These 5M people do not have the rights of the Jewish citizens of Israel. Even for the few who are Israeli Arabs, they don't have the same rights as Jewish Israeli citizens (eg [3]). Most settlements prohibit Israeli Arabs from living their under 2018 segregation laws [4].

Anyone with a passing knowledge of American history will immediately recognize Israel for what it is. Jim Crowe laws, sundown towns and so on.

And this segregation permeates every aspect of daily life. Checkpoints, residency permit segregation, Palestinians falling under military rather than civil jurisdiction, many Palestinians being held indefinitely without charge, water restrictions, building roads to divide up the West Bank and separate Palestinian communities, destroying Palestinian food sources, randomly bulldozing Palestinian homes, never premitting construction, settler terrorism, honestly the list goes on and on.

And in 11 months, ~75,000 tons of munitions have been dropped on an open air prison, also one of the most densely packed and most populous refugee camps in the world.

Democracy? I think not.

[1]: https://www.amnesty.org/en/latest/campaigns/2022/02/israels-...

[2]: https://www.vox.com/23924319/israel-palestine-apartheid-mean...

[3]: https://www.hrw.org/news/2011/03/30/israel-new-laws-marginal...

[4]: https://www.vox.com/world/2018/7/31/17623978/israel-jewish-n...

Re: Hezbollah pager explosions kill several people in Lebanon

#790
post #179

If we try to do what we are best at here at HN, let’s focus the discussion on the technical aspects of it. It immediately reminded me of Stuxnet, which also from a technical perspective was quite interesting. I already wonder if this was anything that was planted in the devices perviously, or if the ones responsible had similar devices, and managed reverse engineer them and craft a payload to them, that could be sent…

I find it extremely unlikely that this was done with the native capabilities and equipment in the devices. It would be extremely interesting if it were. A far simpler explanation would be explosives implanted en-route.

The more interesting question is whether any sort of remote-detonate capability was involved, or this was just timed explosives.

If you look at something like this [1], then the obvious way to do this is to replace one of the NiMH batteries with a lithium cell providing the full output voltage, and replace the other cell with the explosive payload.

A basic timer set them off, and installation would be straightforward. You could probably even arrange this to not be distinguishable on X-Ray by playing with the structure of the explosive device so it would look like a battery.

Getting a little fancier, setting your timer up so the pager "waits for a page" by current draw (from say, the buzzer motor) would be a way to try and ensure the user was holding it near their face before it went off.

What's missing in the current reporting is whether this was simultaneous, keyed to a page, or what have you.

[1] https://store.jtech.com/jtech-guestcall-pager-nimh-battery-5...

Post reply on HN