[HN Gopher] "Clickless" iOS exploits infect Kaspersky iPhones wi...
___________________________________________________________________
"Clickless" iOS exploits infect Kaspersky iPhones with never-
before-seen malware
Author : samizdis
Score : 76 points
Date : 2023-06-01 17:27 UTC (5 hours ago)
(HTM) web link (arstechnica.com)
(TXT) w3m dump (arstechnica.com)
| open-paren wrote:
| https://securelist.com/operation-triangulation/109842/
| ikekkdcjkfke wrote:
| What an absolute joke that you can upload files on demand to
| someones phone as long as you have a number or an email
| TazeTSchnitzel wrote:
| What is email if not a way to send files to other people's
| computers? I don't understand your point.
| gnicholas wrote:
| Would this be prevented if an iPhone were in Lockdown Mode? [1]
|
| 1: https://support.apple.com/en-us/HT212650
| lcampbell wrote:
| Given the exploit vector looks like yet another iMessage
| attachment bug,
|
| > The target iOS device receives a message via the iMessage
| service, with an attachment containing an exploit.
|
| and that one of the effects of Lockdown Mode is
|
| > Messages - Most message attachment types are blocked, other
| than certain images, video, and audio. Some features, such as
| links and link previews, are unavailable.
|
| It might be prevented. Pretty sure disabling iMessage
| altogether sidesteps this class of bugs too. I've lost track of
| how many times iMessage has been the root cause of "unattended
| iOS RCE," at this point it's almost user negligence to have
| left on.
| miohtama wrote:
| Likely another C-based media codec or other similar legacy
| file reader bug.
| gnicholas wrote:
| I was surprised that the article didn't mention Lockdown Mode
| considering the likely overlap in features. It's even
| possible that Lockdown Mode was developed (at least in part)
| to defeat these types of exploits, given the timeline.
| metadat wrote:
| Is there a way to disable only the iMessage attachments
| functionality? (as an alternative to going full lockdown)
| hospitalJail wrote:
| Apple has chosen that it is more important to exploit in-
| group bias with bubble colors than phone security.
|
| I joke, but I can't tell you how annoying iMessage has been.
| Its so bad with non-iphones, we basically switch to email or
| teams when doing group communication.
| dontlaugh wrote:
| Generally everyone uses WhatsApp already anyway.
| killingtime74 wrote:
| Interesting that people in sensitive positions would use foreign
| made smartphones. Surely they are Russian companies that
| manufacture at least low end Android phones?
| pseudo0 wrote:
| > the fact of infection was detected by Kaspersky Unified
| Monitoring and Analysis Platform (KUMA), a native SIEM solution
| for information and event management; the system detected an
| anomaly in our network coming from Apple devices.
|
| Interesting. This demonstrates the big downside of iOS's security
| model - it's basically impossible to run useful host-based IDS,
| which likely would have flagged this much more quickly.
| samspenc wrote:
| My first question upon seeing the title was "What are Kaspersky
| iPhones?"
|
| Answered in the first paragraph: "Kaspersky has been hit by an
| advanced cyberattack that used clickless exploits to infect the
| iPhones of several dozen employees with malware ..."
|
| So this was iPhones belonging to Kaspersky employees - though
| sounds like the exploit could hit any iPhone.
| amuletgrey wrote:
| Looks like kaspersky just tries to blame iphones.
| game_the0ry wrote:
| Non-click exploits are freaky. I wish there was a way to detect
| if my device is compromised.
| hospitalJail wrote:
| Treat all of your devices as compromised. Between the FBI
| breaking the terrorist's iphone, Pegasus, etc... It might be
| best to have a burner smart phone that you keep off 99.99% of
| the time and get your secrets off it only.
| boringuser2 wrote:
| Or, you could just not have an iphone.
| game_the0ry wrote:
| Lame comment, but for what its worth - I assume my iphone
| acts like a cia tacking device that sends all my info to
| nsa, so I never put anything on there that could get me in
| real trouble.
|
| But it would suck if I got a text from a russian organized
| hacking criminal org that got a hold or my banking
| credentials.
| boringuser2 wrote:
| >Lame comment
|
| Nice valley girl impression!
| m463 wrote:
| Blame apple for this.
|
| I've always said you should be able to see what's on your own
| device, but apple doesn't allow it, you can't access the entire
| filesystem.
|
| Also you can't see what processes are running, what they are
| doing, or look at the network traffic being generated.
___________________________________________________________________
(page generated 2023-06-01 23:02 UTC)