[HN Gopher] "Clickless" iOS exploits infect Kaspersky iPhones wi...
       ___________________________________________________________________
        
       "Clickless" iOS exploits infect Kaspersky iPhones with never-
       before-seen malware
        
       Author : samizdis
       Score  : 76 points
       Date   : 2023-06-01 17:27 UTC (5 hours ago)
        
 (HTM) web link (arstechnica.com)
 (TXT) w3m dump (arstechnica.com)
        
       | open-paren wrote:
       | https://securelist.com/operation-triangulation/109842/
        
       | ikekkdcjkfke wrote:
       | What an absolute joke that you can upload files on demand to
       | someones phone as long as you have a number or an email
        
         | TazeTSchnitzel wrote:
         | What is email if not a way to send files to other people's
         | computers? I don't understand your point.
        
       | gnicholas wrote:
       | Would this be prevented if an iPhone were in Lockdown Mode? [1]
       | 
       | 1: https://support.apple.com/en-us/HT212650
        
         | lcampbell wrote:
         | Given the exploit vector looks like yet another iMessage
         | attachment bug,
         | 
         | > The target iOS device receives a message via the iMessage
         | service, with an attachment containing an exploit.
         | 
         | and that one of the effects of Lockdown Mode is
         | 
         | > Messages - Most message attachment types are blocked, other
         | than certain images, video, and audio. Some features, such as
         | links and link previews, are unavailable.
         | 
         | It might be prevented. Pretty sure disabling iMessage
         | altogether sidesteps this class of bugs too. I've lost track of
         | how many times iMessage has been the root cause of "unattended
         | iOS RCE," at this point it's almost user negligence to have
         | left on.
        
           | miohtama wrote:
           | Likely another C-based media codec or other similar legacy
           | file reader bug.
        
           | gnicholas wrote:
           | I was surprised that the article didn't mention Lockdown Mode
           | considering the likely overlap in features. It's even
           | possible that Lockdown Mode was developed (at least in part)
           | to defeat these types of exploits, given the timeline.
        
           | metadat wrote:
           | Is there a way to disable only the iMessage attachments
           | functionality? (as an alternative to going full lockdown)
        
           | hospitalJail wrote:
           | Apple has chosen that it is more important to exploit in-
           | group bias with bubble colors than phone security.
           | 
           | I joke, but I can't tell you how annoying iMessage has been.
           | Its so bad with non-iphones, we basically switch to email or
           | teams when doing group communication.
        
             | dontlaugh wrote:
             | Generally everyone uses WhatsApp already anyway.
        
       | killingtime74 wrote:
       | Interesting that people in sensitive positions would use foreign
       | made smartphones. Surely they are Russian companies that
       | manufacture at least low end Android phones?
        
       | pseudo0 wrote:
       | > the fact of infection was detected by Kaspersky Unified
       | Monitoring and Analysis Platform (KUMA), a native SIEM solution
       | for information and event management; the system detected an
       | anomaly in our network coming from Apple devices.
       | 
       | Interesting. This demonstrates the big downside of iOS's security
       | model - it's basically impossible to run useful host-based IDS,
       | which likely would have flagged this much more quickly.
        
       | samspenc wrote:
       | My first question upon seeing the title was "What are Kaspersky
       | iPhones?"
       | 
       | Answered in the first paragraph: "Kaspersky has been hit by an
       | advanced cyberattack that used clickless exploits to infect the
       | iPhones of several dozen employees with malware ..."
       | 
       | So this was iPhones belonging to Kaspersky employees - though
       | sounds like the exploit could hit any iPhone.
        
       | amuletgrey wrote:
       | Looks like kaspersky just tries to blame iphones.
        
       | game_the0ry wrote:
       | Non-click exploits are freaky. I wish there was a way to detect
       | if my device is compromised.
        
         | hospitalJail wrote:
         | Treat all of your devices as compromised. Between the FBI
         | breaking the terrorist's iphone, Pegasus, etc... It might be
         | best to have a burner smart phone that you keep off 99.99% of
         | the time and get your secrets off it only.
        
           | boringuser2 wrote:
           | Or, you could just not have an iphone.
        
             | game_the0ry wrote:
             | Lame comment, but for what its worth - I assume my iphone
             | acts like a cia tacking device that sends all my info to
             | nsa, so I never put anything on there that could get me in
             | real trouble.
             | 
             | But it would suck if I got a text from a russian organized
             | hacking criminal org that got a hold or my banking
             | credentials.
        
               | boringuser2 wrote:
               | >Lame comment
               | 
               | Nice valley girl impression!
        
         | m463 wrote:
         | Blame apple for this.
         | 
         | I've always said you should be able to see what's on your own
         | device, but apple doesn't allow it, you can't access the entire
         | filesystem.
         | 
         | Also you can't see what processes are running, what they are
         | doing, or look at the network traffic being generated.
        
       ___________________________________________________________________
       (page generated 2023-06-01 23:02 UTC)