God, the number of techbros here who are confident in their ability to resist targeted attacks from sophisticated national intelligence agencies is terrifying, but also explains a lot about why Silicon Valley is the way it is.
Posts
-
God, the number of techbros here who are confident in their ability to resist targeted attacks from sophisticated national intelligence agencies is terrifying, but also explains a lot about why Silicon Valley is the way it is. -
What can we do to defend ourselves against threats like the Israeli pager supply chain attack?What can we do to defend ourselves against threats like the Israeli pager supply chain attack?
Well, for starters, if your threat model includes state actors using shell companies to sell you custom made exploding electronics in bulk, you should stop getting your security advice from social media.
-
Current reporting from NYT and others (gift link: https://www.nytimes.com/live/2024/09/17/world/israel-hamas-war-news?unlocked_article_code=1.LU4.yQNN.lrxL0ef79K2O&smid=url-share) essentially confirms the speculation: Supply chain tampering with a new ...Current reporting says at least 20 deaths and 450 injuries from today’s walkie-talkie explosions (this is on top of yesterday’s pagers). The pagers seem to have injured (roughly) a single individual each. The apparently more powerful explosions from the walkie-talkies may have each claimed more victims. So it’s less clear from this how many compromised devices were actually involved today.
-
Current reporting from NYT and others (gift link: https://www.nytimes.com/live/2024/09/17/world/israel-hamas-war-news?unlocked_article_code=1.LU4.yQNN.lrxL0ef79K2O&smid=url-share) essentially confirms the speculation: Supply chain tampering with a new ...In any case, the V82 battery does not have a data connection to the host radio, so that means that (assuming it was the battery pack that exploded) any triggering mechanism was likely self-contained in the battery pack and did not make use of the communications capability of the radio itself. That would mean it was trigged by either an offline timer or a separate receiver/antenna inside the battery pack. If the latter, it would have to be in range of a signal sent by the attacker.
-
Current reporting from NYT and others (gift link: https://www.nytimes.com/live/2024/09/17/world/israel-hamas-war-news?unlocked_article_code=1.LU4.yQNN.lrxL0ef79K2O&smid=url-share) essentially confirms the speculation: Supply chain tampering with a new ...Icom may not be a household name (well, it is in my household, but I'm a nerd). They're a major manufacturer of two-way and related radio gear for commercial, industrial, public safety, marine, aviation, and amateur markets, based in Japan and marketed around the world. The V82 radio that was apparently exploding is an older, discontinued model, but counterfeit versions of it from various Chinese sources are widely available.
-
Current reporting from NYT and others (gift link: https://www.nytimes.com/live/2024/09/17/world/israel-hamas-war-news?unlocked_article_code=1.LU4.yQNN.lrxL0ef79K2O&smid=url-share) essentially confirms the speculation: Supply chain tampering with a new ...Walkie-talkie radios differ from pagers in several relevant ways here. First, they're larger, and so have room to hide more explosive material; some of the images I've seen show damaged buildings, suggesting larger explosions than we saw with the pagers.
Second, walkie-talkies aren't generally carried around all the time the way pagers are. They typically spend a lot of time off and sitting in a charger, possibly near other radios. This is also consistent with the images of damaged buildings.
-
Current reporting from NYT and others (gift link: https://www.nytimes.com/live/2024/09/17/world/israel-hamas-war-news?unlocked_article_code=1.LU4.yQNN.lrxL0ef79K2O&smid=url-share) essentially confirms the speculation: Supply chain tampering with a new ...So I've now seen video and stills of several different exploded radios. All appear to be Icom V82s (or something that looks similar). In all but one case, the battery was missing, and the damage to the radio itself was relatively small, adding credence to the hypothesis that the explosion came from the battery pack. I believe the battery form factor is common to a number of Icom models, including the current ones. So possibly what was compromised was a shipment of replacement batteries.
-
Current reporting from NYT and others (gift link: https://www.nytimes.com/live/2024/09/17/world/israel-hamas-war-news?unlocked_article_code=1.LU4.yQNN.lrxL0ef79K2O&smid=url-share) essentially confirms the speculation: Supply chain tampering with a new ...At this point, everyone in Lebanon and Hezbollah has to be wondering what's going to be exploding tomorrow.
-
Current reporting from NYT and others (gift link: https://www.nytimes.com/live/2024/09/17/world/israel-hamas-war-news?unlocked_article_code=1.LU4.yQNN.lrxL0ef79K2O&smid=url-share) essentially confirms the speculation: Supply chain tampering with a new ...On the latest round of explosions, so far I've found a couple photos of a mangled Icom model V82 walkie-talkie, a discontinued (but still widely available around the world in counterfeited form) commercial analog two-way radio.
But it's unclear if that's the only type of device that exploded today, and it's also possible that the various photos I've seen are all of the same individual radio. Still haven't seen good authoritative reports of the scope and scale of todays wave of explosions.
-
Current reporting from NYT and others (gift link: https://www.nytimes.com/live/2024/09/17/world/israel-hamas-war-news?unlocked_article_code=1.LU4.yQNN.lrxL0ef79K2O&smid=url-share) essentially confirms the speculation: Supply chain tampering with a new ...Note that there are obviously a large number of moral, ethical, and legal questions about this whole operation. I'm focused on the technical, strategic, and logistical issues in this thread, which should not be taken to suggest in any way that I don't think those questions are important or worth probing. It's just not what I'm exploring here.
-
Current reporting from NYT and others (gift link: https://www.nytimes.com/live/2024/09/17/world/israel-hamas-war-news?unlocked_article_code=1.LU4.yQNN.lrxL0ef79K2O&smid=url-share) essentially confirms the speculation: Supply chain tampering with a new ...The plot continues to thicken, with another wave of exploding devices reported among Hezbollah members around Lebanon today. This time, it appears to include walkie-talkie-type radios. I've not yet found reliable reports of specific models of radios, so it's hard to even speculate yet on how these might have been triggered - possibly over the air, but also possibly with a pre-set timer.
What's clear is that Hezbollah's supply chain problem is even worse than it seemed yesterday.
-
Current reporting from NYT and others (gift link: https://www.nytimes.com/live/2024/09/17/world/israel-hamas-war-news?unlocked_article_code=1.LU4.yQNN.lrxL0ef79K2O&smid=url-share) essentially confirms the speculation: Supply chain tampering with a new ...Another note: a supply chain compromise is a very powerful capability, and by using it this way they effectively completely burned it, foreclosing the possibility of future exploitation. Hezbollah (and anyone else who considers Israel an adversary) is going to be *very* careful about how it sources its gear for the foreseeable future. (What else might you do if you could control comms gear of your adversary?) This was likely VERY carefully considered, likely at the highest levels of government.
-
Current reporting from NYT and others (gift link: https://www.nytimes.com/live/2024/09/17/world/israel-hamas-war-news?unlocked_article_code=1.LU4.yQNN.lrxL0ef79K2O&smid=url-share) essentially confirms the speculation: Supply chain tampering with a new ...As I've noted elsewhere, one-way pagers (at least the kind that don't explode) are actually a pretty good way for a covert organization to communicate with its members. Unlike cellphones, which are constantly registering with a local tower, pagers don't expose the locations of recipients to the infrastructure or to eavesdroppers. They work by "flooding" - broadcasting all messages over the entire service area, leaving it to the devices to filter out the messages addressed to them.
-
Current reporting from NYT and others (gift link: https://www.nytimes.com/live/2024/09/17/world/israel-hamas-war-news?unlocked_article_code=1.LU4.yQNN.lrxL0ef79K2O&smid=url-share) essentially confirms the speculation: Supply chain tampering with a new ...@EricFielding Very unclear. It says "the pagers received a message..." but it seems to be actually describing merely the pagers *displaying* a message.
-
Current reporting from NYT and others (gift link: https://www.nytimes.com/live/2024/09/17/world/israel-hamas-war-news?unlocked_article_code=1.LU4.yQNN.lrxL0ef79K2O&smid=url-share) essentially confirms the speculation: Supply chain tampering with a new ...Notably, the NYT reporting isn't hedging even slightly on identifying Israel as the source of the attack, though does note that they haven't officially commented.
-
Current reporting from NYT and others (gift link: https://www.nytimes.com/live/2024/09/17/world/israel-hamas-war-news?unlocked_article_code=1.LU4.yQNN.lrxL0ef79K2O&smid=url-share) essentially confirms the speculation: Supply chain tampering with a new ...... The disadvantage (to the attacker) of offline pre-scheduled triggering is that it becomes essentially impossible to scrub or reschedule the attack if something goes wrong or there's reason for delay. So I wouldn't rule out a broadcast signal entirely. Assuming some of the devices survived (duds, etc), I'd imagine there's a lot of reverse-engineering being attempted right now.
-
Current reporting from NYT and others (gift link: https://www.nytimes.com/live/2024/09/17/world/israel-hamas-war-news?unlocked_article_code=1.LU4.yQNN.lrxL0ef79K2O&smid=url-share) essentially confirms the speculation: Supply chain tampering with a new ...Unclear from reporting how they were triggered. Some possibilities include:
- completely offline (all the compromised pagers were pre-programmed to beep and explode at a particular time)
- a broadcast signal (possibly sent by a high power transmitter controlled by Israel) that all the devices were programed to respond to
- individually addressed messages to each of the pagers (less likely, since that would take a while to go through).
My guess is the first.
-
Current reporting from NYT and others (gift link: https://www.nytimes.com/live/2024/09/17/world/israel-hamas-war-news?unlocked_article_code=1.LU4.yQNN.lrxL0ef79K2O&smid=url-share) essentially confirms the speculation: Supply chain tampering with a new ...... The pagers apparently were programmed to beep and then display a message ostensibly from Hezbollah leadership, and then explode, behavior that would encourage users to be in close proximity to the device as it exploded.
... -
Current reporting from NYT and others (gift link: https://www.nytimes.com/live/2024/09/17/world/israel-hamas-war-news?unlocked_article_code=1.LU4.yQNN.lrxL0ef79K2O&smid=url-share) essentially confirms the speculation: Supply chain tampering with a new ...Current reporting from NYT and others (gift link: https://www.nytimes.com/live/2024/09/17/world/israel-hamas-war-news?unlocked_article_code=1.LU4.yQNN.lrxL0ef79K2O&smid=url-share) essentially confirms the speculation: Supply chain tampering with a new batch of 3000 pagers from Taiwan ordered by Hezbollah, involving adding 2oz of explosive material near the battery. Reports of 2800 injured, implying that essentially all of them went off, apparently nearly simultaneously, suggesting this was not targeting particular individuals (just anyone with a pager in the batch). At least nine deaths so far.
-
One of the jarring things about working in DC is being invited to meetings with policymakers to discuss some highly technical thing and realizing that *everyone* else in the room is a lobbyist for some tech company rather than an actual tech expert. An...One of the jarring things about working in DC is being invited to meetings with policymakers to discuss some highly technical thing and realizing that *everyone* else in the room is a lobbyist for some tech company rather than an actual tech expert. And they're all wondering what *you're* doing there.