11 ms·
Targeted attack on our management with the Triangulation Trojan
- cookiengineer 3y agoKaspersky was spying on international citizens for over a decade, providing data for both the FSB and GRU. ...and now they're complaining about counter surveillance by the FBI?
- f6v 3y agoYou make it sound like big tech companies never cooperate with the law enforcement. I bet CIA and FBI have their hand so far up Zuck’s ass it’s almost like Minority Report at this point.
- cookiengineer 3y agoOf course it is like this. We live in the golden age of cyberwars. But you as a founder decide whose values of the surrounding society you align your company with. In an autocratic nation these controls are kind of absolutist in nature, whereas in democracies you have at least some sense of oversight. Given the mechanics of the game, where you reside your company tells a lot about who you're friends with. These days on a larger scale there's basically NATO, SCO, UAE, Israel and the African Union as alliances (setting aside (former) British colonies). Companies have to cooperate with either of those, otherwise they would not be allowed to exist.
- agentgumshoe 3y ago> These days on a larger scale there's basically NATO, SCO, UAE, Israel and the African Union as alliances (setting aside (former) British colonies). Which one's the good one?
- SenHeng 3y agoOnly Siths deal in absolutes. Among that list, NATO is by far the preferred option.
- ben_w 3y agoI'm not even sure which SCO is under discussion here, the unix one, Pakistan's "Special Communications Organization", the Shanghai Cooperation Organisation, or if Scotland is up to something surprising, or if it's one of several "State Controller's Office" and "Special Counsel's Office" in the USA…
- f6v 3y agoI mean, unless you live in Middle East and one day they say you have WMD and they destroy your whole country. If you live in the EU or the US - then yes.
- agentgumshoe 3y agoOr you live in Russia and you thought you had a deal that NATO wouldn't encroach further on your border... It was a trick question, none of them are good.
- ben_w 3y agoSoviet Union asked to join NATO but was rejected, and the post-Soviet Russian Federation started on the path to joining back in the day. It's not NATO's fault that all the small countries around Russia are so scared of Russian forces that they all ask to join a mutual defence pact.
- f6v 3y agoRussia wanting to join NATO is an anecdote.
- paulryanrogers 3y agoHas NATO crossed any Russian border? Now nearing borders appears motivated more by Russia's bullying of its neighbors than any desire within NATO to expand. Maybe you're forgetting the protection treaty Russia signed to respect Ukraine's borders in exchange for USSR nukes.
- enkid 3y agoNone of those things except NATO is an actual alliance.
- hulitu 3y ago> whereas in democracies you have at least some sense of oversight Can you give some examples of oversight ?
- Veen 3y agohttps://en.wikipedia.org/wiki/United_States_Intelligence_Community_Oversight https://en.wikipedia.org/wiki/United_States_Intelligence_Com...
- zamalek 3y agoHow is disclosing an Apple security issue "complaining"?
- brookst 3y agoIt’s the polemics. Complaining is a matter of presentation, not content. Plenty of security disclosures are matter of fact and not loaded with opinion and innuendo.
- crimsontech 3y agoDo you have any sources for this? I'm interested in reading more about it after seeing a lot of allegations. I don't recall ever seeing anything concrete.
- shmde 3y agoLiterally one google search gave me this.[1] You could have saved a lot of time writing "Kaspersky FSB GRU" in google than writing this comment to someone to cite their sources. [1]https://www.bloomberg.com/news/articles/2017-07-11/kaspersky-lab-has-been-working-with-russian-intelligence https://www.bloomberg.com/news/articles/2017-07-11/kaspersky...
- defrost 3y agoCould you quote a paragraph from that article that supports the claim > Kaspersky was spying on international citizens for over a decade, providing data for both the FSB and GRU. I read it through twice and aside from implication the strongest assertion was that Bloomberg had seen emails that confirmed Kaspersky had worked with the FSB to supply anti-DDOS systems that included counter measures (the ability to hack and disrupt hackers attacking systems) which wasn't denied by Kaspersky who maintained they do similar work with many governments and their 3-letter-agencies.
- dmix 3y agoThere's apparently an entire wiki on the subject and again it's mostly speculation, misunderstanding (ie, in the NSA case), or as you said misrepresenting what was essentially a pretty innocuous defensive gov contract by an infosec company. https://en.wikipedia.org/wiki/Kaspersky_bans_and_allegations_of_Russian_government_ties https://en.wikipedia.org/wiki/Kaspersky_bans_and_allegations... It makes sense for western governments to be wary of using it but going beyond that is just speculation at this point.
- crimsontech 3y agoYeah sorry, I should have been more specific. I was looking for evidence that: > Kaspersky was spying on international citizens for over a decade, providing data for both the FSB and GRU. You linked a news article that states: > The U.S. government hasn’t identified any evidence connecting Kaspersky Lab to Russia’s spy agencies Maybe more evidence will be uncovered by the (alleged) targeted attack against Kaspersky though. I'm interested in the technology created to perform these activities more than the politics surrounding it. How they do it, not why.
- samwillis 3y agoThread from yesterday: https://news.ycombinator.com/item?id=36154455 https://news.ycombinator.com/item?id=36154455 “Clickless” iOS exploits infect Kaspersky iPhones with never-before-seen malware - 26 comments
- fortran77 3y agoSeveral people submitted this, but it gets swept off the HN front page by loyal Apple fans flagging it.
- gnicholas 3y agoI was surprised at how low it was on the front page, and how quickly it disappeared. But I never saw a "flagged" indicator on it. I thought that flagged posts typically had these indicators — is this not the case?
- ComodoHacker 3y agoFrom the linked technical report: The oldest traces of infection that we discovered happened in 2019. As of the time of writing in June 2023, the attack is ongoing, and the most recent version of the devices successfully targeted is iOS 15.7.
- vivegi 3y agoFrom the article > We believe that the main reason for this incident is the proprietary nature of iOS. This operating system is a “black box”, in which spyware like Triangulation can hide for years. Detecting and analyzing such threats is made all the more difficult by Apple’s monopoly of research tools – making it a perfect haven for spyware. In other words, as I’ve often said, users are given the illusion of security associated with the complete opacity of the system. What actually happens in iOS is unknown to cybersecurity experts, and the absence of news about attacks in no way indicates their being impossible – as we’ve just seen.
- deleted 3y ago[deleted]
- 2OEH8eoCRo0 3y agoShatters Apple's argument that all of these hurdles are better for security. I wonder if testimony like this could affect any of their antitrust lawsuits or right to repair lobbying.
- ben_w 3y agoNot "shatters", as while it is a valid counter, it doesn't tell you the relative strengths and weaknesses of the two approaches, only that Apple isn't perfect which should already have been assumed. A stronger counter to Apple's argument is the relative pricing of exploits… but the story I'm remembering is old enough that I don't want to just assume it's still true, even though it's near the top of my search results: https://www.wired.com/story/android-zero-day-more-than-ios-zerodium/ https://www.wired.com/story/android-zero-day-more-than-ios-z...
- kramerger 3y ago> users are given the illusion of security associated with the complete opacity of the system. What actually happens in iOS is unknown to cybersecurity experts, and the absence of news about attacks in no way indicates their being impossible For this to change the community needs to create the needed tools. I don't think Apple will ever help you with something that can potentially make them look bad.
- kossTKR 3y agoAdjacent topic but i have a friend who told me buying a refurbished iPhone from a local shop was a bad idea from a security perspective. Is this true? I thought a hard reset and secure enclave etc. was enough? Can you put "stuff" in it that survives to a new user?
- bollos 3y agoTheoretically yes. However, the chance of you encountering a second hand device with such an implant is relatively low I'd say. I guess if you buy it off journalists or activists the chance would be higher but still relatively unlikely. But as with anything, consider if it suits your threat model and act accordingly.
- saagarjha 3y agoExploits that survive a full wipe are almost unheard of on iOS.
- infthi 3y agohardware modifications definitely can. A few years ago I've read ([0] - the article is in russian but google translate does its job) about hardware bugs installed in iphones - with a mic and an own SIM card, everything is powered from the phone's battery. [0] https://service-iphone.ru/blog/proslushka-v-iphone-teper-bez-uchastija-specsluzhb/ https://service-iphone.ru/blog/proslushka-v-iphone-teper-bez...
- tbossanova 3y agoDidn’t read the article, because on my oldish phone the cookie options defaulted to disallowing necessary cookies and allowing all others. I’m fairly confident this is a bug
- tbossanova 3y agoAand I just reloaded and it bounced around between cookie modal and nothing before letting me in without further interaction
- Traubenfuchs 3y agotl;dr - malicious state and private threat actors can at any time completely take over your iphone (root access) with an invisible iMessage without you having a practical chance to detect it besides scanning your iphone backup
- bboygravity 3y agoIt still blows my mind that this is not a known fact by most people for as long as phones have existed? Or maybe it is?
- diydsp 3y agohow is this generally possible? In my simplified understanding, a text message is a hunk of data, but I know it's more complex than that.... it must be able to connect to all kinds of services and trigger all kinds of code running, right? Can't it be sanity checked sufficiently?
- mrandish 3y agoApparently, it uses iMessage's proprietary messaging format, not standard text messages. I don't use iOS but my understanding is users can't replace iMessage with another messaging app.
- Traubenfuchs 3y ago> my understanding is users can't replace iMessage with another messaging app. To be precise there is one "Messaging" app, that automagically uses iMessage (blue bubbles) instead of SMS (green bubbles) whenever possible. One can turn off iMessage in the settings, which will probably lead to your iPhone rejecting iMessages, making other iPhones only send SMS to you and also make your iPhone only send SMS. Whether that toggle prevents receiving and processing of malicious, invisible iMessages is an entirely different question.
- saiya-jin 3y agoEven if it would be a simple text message (which its not for iphone), it triggers a text parser at minimum. That parser can have carious bugs in it, ie if parser checks phone contacts to highlight phone number in text as a known contact, identifies some weblink etc. To sum it up to have it as fancy as possible to users it checks various things and needs permissions for that. Enough 0days in the chain and you can do whatever you need. This is the problem of closed systems, you have to trust manufacturer 100%, there is no independent audit possible. And if you ever did any serious code before, you know by heart that any code has bugs, in the code, in platform/VM it runs, apis etc.
- saagarjha 3y ago> What actually happens in iOS is unknown to cybersecurity experts Sounds like a skill issue to me. I'll eat my words if they were genuinely infected with something that lingered in such a way that it persisted past a reboot and completely broke all updates, but I would be very surprised if this was the case.
- pseudo0 3y agoWhy would an actor with a reliable zero-click need to persist past a reboot? That appears to be the claim in the article, update blocking plus on-demand reinfection.
- rho4 3y ago"An indirect indication of the presence of Triangulation on the device is the disabling of the ability to update iOS" My guess would be that they didn't find out thanks to their monitoring solution, but because some senior manager shouted pretty loudly at someone to get their iPhone to update, asap! :)
- dist-epoch 3y agoOr maybe the monitoring solution noticed the LACK of update checks from iOS devices.
- seanhunter 3y agoNoticed a lack of updates after 6 months. The whole thing doesn't exactly speak to extreme infosec competence at Kaspersky labs in my opinion.
- mango7283 3y ago/Overworked blue teamer rant We're just bloody tired okay?!? Every fing weekend every fking day it's a new 0day and exploit and attack surface. And then the new patch breaks production or the new edr throws up a storm because someone had the audacity to run psexec or some other bullcrap /Overworked blue teamer rant
- j16sdiz 3y agoIs this an AD for their SIEM product?
- m3kw9 3y agoHow does one “ draws a yellow triangle in the device’s memory.”?
- sounds 3y agoThe phrase "in the device's memory" refers to off-screen rendering: https://www.quora.com/What-is-the-use-of-offscreen-rendering https://www.quora.com/What-is-the-use-of-offscreen-rendering