Friday, September 20, 2024

weaponising the supply chain - thanks but no thanks, mossad

By intermediating the supply chain, Mossad appears to have been able to subvert safety in various mobile devices (so far, pagers, walkie talkies, possibly some phones) - one speculation is that they undermined the current limiter or other safety fature that stop the battery overheating and catching fire - and put in some interface to allow software (e.g. via specific messages to the device) to trigger this behaviour - rather than, say, just putting a few grams of semtex in the deveice and turning it into a small IED.

Because this was done at scale, and somewhat scattershot, the normal trust in the safety of devices bought through regular supply chains has been undermined. Imagine if Mossad had decided to do this via several made up intermediaries who sold through the Amazon Market place for example, especially with relatively low value items that aren't typically checked when being shipped internationally. Great. Now the idea is out of the box, it is another extreme example of asymmetric warfare - lots of organisations could re-implement it easily[*]. 

This instantly, a lot of organisations now have to worry about people who, having innocently bought such a device, (or indeed bought one off of someone else who got one of these exploted gadgets) want to travel

We currently ban e-bikes on trains in the UK because, even without state-sponsored terrorism, safety features on e-bikes are not terribly well checked (they don't have the equivalent of a regular MoT/roadworthiness/emissions check, which might help a bit). We also don't allow really large capacity power banks on planes. In these cases, the risks are higher even if the occurance of fire/explosion is rare, because the energy in the device is so much more.  Nevertheless, the explosions seen in Lebanon would be extremely dangerous on a plane, whether in the passenger cabin or the hold. 

Or we'll only allow devices where the battery can be removed and kept seperate from any trigger circuit. (useful for consumers who want to replace old, knackered batteries too).

So maybe we will see a ban on carrying any mobile/rechargeable device on planes for a while, until some certification (including tamper proof sealing of post-certified devices) is available.

Of course, Mossad will then subvert the certification labs next, no doubt.

Just to start with I think we need to stop people with Israeli passports traveling outside of their country as they represent a clear and present danger to everyone in the world, not just to innocent bystanders in market places in lebanon (or gaza). Until they can assure us that they are not going behave so irresponsibly, and regain any possible level of trust they might once have enjoyed. Of course, most their agents will also have other passports too.

Update - this Bunniestudios blog is a very useful detailed analysis of the howto....

* footnote - why the west didn't launch cyber attacks on Russia's infrastructure (e.g. taking down all their power and comms) when they invaded Ukraine was a) revealing the tools the west has and b) inviting a retaliation which would also have succeeded, were both v. bad ideas. Mossad has just revealed that it has no clue about this type of precautionary principle. Well done. guys.

No comments: