Kaspersky finds hardware backdoor in 5 generations of Apple Silicon (2024)
xstore.co.za
xstore.co.za
Does anyone know why it reads so apologetic?
1. Complete separation of work and personal computers and cellphones.
2. Company cellphones only stay in the facility and are checked for vulnerabilities from time to time.
3. No bragging in public about your project or messing with other women/men other than one's own partner, so one does not expose personal vulnerabilities.
There's never been any real and substantial evidence for this and much to the contrary. They've moved a lot of their infra out of Russia and have for ages been early on malware that originated from Russia and allies.
It's one of those things that if American media writes about it long enough people somehow just assume its true.
This has been done many times before by other companies. Huawei used to do a lot of closed door development -- every one of the team lives in a hotel for a few months without phones and cannot get out. If your adversary burnt so many zero days and maybe also pulled some strings to hack you, you absolutely should do this.
Or it's possible you are using your development processes more like a honeypot to trap the attackers. I suspect that was the case here - it's awfully hard to analyze a modern exploit unless you manage to get it to install on a phone you are already monitoring.
(all new exploits are 'single install' - ie. the exploit will retrieve most of its code from a server which will only send the data once, and then immediately after use the exploit code will be deleted. That makes recording the exploit hard).
Posting this in a thread about a HW backdoor in iPhone seems strange. And there are also a lot of noclick exploits in the Apple ecosystem: NSO comes to mind.
My main issue with Apple is that they, internally, do not do any security research. They just close the holes, if, and after, they are discovered.
If it is some device sitting on the memory bus, how did they disable it in a way it couldn't be reenabled by the OS kernel? Most hardware that sits on a CPU bus doesn't have such an ability.
Yet platforms with apparently secure e2e messaging (ie. WhatsApp) never seem to be used by criminals.
I wonder if this is just selection bias in the criminals caught, or if there is some forcing factor persuading criminals to make poor security choices.
Do you have the keys to your WhatsApp messages ? Are you sure that they only reach their intended recipient ?
It's always possible there is some secret command which makes the closed source client leak the keys, but I imagine an audit of the disassembly of the client side app would discover that.