Hacker News new | ask | show | jobs
by veave 1113 days ago
Why are they using iOS if they feel that way about it?

Also: iOS 16 is not vulnerable and it was released on September 12, 2022 - why are those phones out of date for so long?

3 comments

That one of the bigger security companies seemingly didn't have MDM screaming bloody murder or outright blocking authentication for an endpoint this out of date is more than a little concerning.

Props to their SIEM for detecting it in the end, but this seems like it could've been detected and remediated a few weeks in (assuming it didn't also have the ability to spoof the iOS version).

That's why I believe this is a made up article for selling their security product.
From the comments section on Securelist page on Operation Triangulation https://securelist.com/operation-triangulation/109842/

<extract>

> SECURELIST

> Posted on June 2, 2023. 11:10 am

> Hi Bil!

> We identified that the latest version of iOS that was targeted by Triangulation is 15.7. However, given the sophistication of the cyberespionage campaign and the complexity of analysis of iOS platform, we can’t guarantee that other versions of iOS are not affected.

</extract>

Does an OS upgrade remove this malware though? Maybe it doesn't and it's why so many phones were infected.
The article says:

>An indirect indication of the presence of Triangulation on the device is the disabling of the ability to update iOS.

So I assume that the malware stops working when iOS is updated. This highlights the tremendous importance of keeping software up to date.

> the disabling of the ability to update iOS.

This is done by the malware.

Indeed, the identified fix involves a factory reset and upgrading iOS to prevent the malware from taking over again.

That provides a simple explanation for why the phones are running such an old version: because they've been infected and unable to be updated for that entire time.

I guess execs at security firms are no better than average people when it comes to noticing that their phones never got the various new features (end emojis!) from the last year of OS updates.
Latest update from Kaspersky.

> June 02 2023 Update: triangle_check utility

> We have developed and made freely available the triangle_check utility, that can detect indicators of compromise in an Apple device backup. Detailed instructions on how to use it under different OSs (Windows, Linux and macOS), as well as how to create a device backup can be found in a post on Securelist. [1]

[1]: https://securelist.com/find-the-triangulation-utility/109867...