Exploding Pagers & The Case for a Secure Supply Chain

Поділитися
Вставка
  • Опубліковано 23 вер 2024

КОМЕНТАРІ • 166

  • @bomberfish77
    @bomberfish77 6 днів тому +44

    this is something straight out of a bond film.

    • @John-wd5cb
      @John-wd5cb 6 днів тому +3

      Well Bond would take time to be identified. This event details now spilled wide open less than 12 hrs later. It's an American operation..

    • @JackDaniels-v6f
      @JackDaniels-v6f 6 днів тому +1

      New iPhone 16 free at Verizon! Ok, let me get my bomb sniffing dog to check it out first.

    • @jtjames79
      @jtjames79 6 днів тому

      Remember the USS Liberty.

    • @gustavomachado3488
      @gustavomachado3488 6 днів тому +2

      This is something straight out of the third reich.

    • @bobbysbits2575
      @bobbysbits2575 5 днів тому +1

      @@bomberfish77 I went for Grand Theft Auto 5

  • @ImperiumLibertas
    @ImperiumLibertas 6 днів тому +38

    My question is how did they know the pagers were only going to Hezbollah targets and not innocent civilians. Pretty interesting stuff.

    • @AdamDavisEE
      @AdamDavisEE 6 днів тому +1

      Some possibilities include: Hezbollah bought them in bulk, the attacker observed the messages sent using the pagers and only targeted those which met certain communications criteria (either messages received from certain phone numbers, or content in the messages), they developed a database over time of the users using other methods, or they didn't care and decided that 95% of pagers used today in certain regions are used by terrorists, and that the unintended casualties were acceptable. There are certainly other ways, but these are low cost ways to identify targets.
      I'm much more interested in the timeframe. They had to develop this plan, and produce the pagers, then sneak them into the supply chain in a way that won't allow them to be detected, the pagers had to work, and even as small as they were they had to carry enough explosive material to seriously harm anyone nearby. And they had to do this in a relatively short time, putting perhaps as many as 2,000 pagers into position. On top of that they had to either get all the numbers and send a special page, or attack the pager network and send a custom message, or the pagers had to have a built in additional trigger, perhaps based on timer, or received radio message from transmitters outside the country. Further, they either 1) had to look exactly like a regular pager when disassembled (battery pack was also explosive, perhaps), or they had to work so flawlessly that they wouldn't need repair between the time of distribution and the time of use.
      Identifying the targets and accurately targeting them is only a small part of a huge operation.
      And on top of that, they've sown the seeds of additional distrust. It will drive the communications further underground, but that will also slow and limit the communication, and any new technology brought in will have to be carefully examined, piece by piece.
      If China ever were to commit to a war with the US, they would need only modify perhaps 0.1% of their exports to the US to nefarious ends to cripple our economy or infrastructure.

    • @mythbuster6126
      @mythbuster6126 6 днів тому +46

      They don't care.

    • @justanothercomment416
      @justanothercomment416 6 днів тому +37

      They didn't and they don't care. They prefer it gets to everyone.

    • @garywatson
      @garywatson 6 днів тому

      The pagers were bought in bulk for Hezbollah militants and their support staff, from what they thought was a trusted source, because Israel was tracking them if they carried ordinary cell phones. They weren't sold on the open market. Someone installed about half an ounce of high explosive in each of them, with a remote trigger mechanism (Mossad, no doubt, did it).

    • @nezbrun872
      @nezbrun872 6 днів тому +15

      Why else would you order a pager in 2024, especially one that uses a proprietary encrypted messaging system.

  • @Winnetou17
    @Winnetou17 6 днів тому +6

    Was waiting for a mention of how right Richard Stallman is about freedom and security. Well, he's more on the software side, but the principles remain. We'll just have to start manufacturing locally chips. Which means they'll be decades away in performance and efficiency. But, hey, for something important, that might still be something better than nothing.

  • @sellicott
    @sellicott 6 днів тому +13

    "Reflections on Trusting Trust" is always apropos for software supply chain discussions.

  • @jashyotes
    @jashyotes 6 днів тому +29

    lol at the beginning of the video:
    Anti-defamation league ad pops up, "leeeeeeeeeeeeeeeeet's scroll down just a bit"

  • @typingcat
    @typingcat 5 днів тому +5

    The fact that both Intel and AMD have put some sort of secondary system into their CPU's that cannot be deactivated by the user convinces me that those companies did not do that on their own will, but some sort of US government agency forced them to.

  • @MrMoto655
    @MrMoto655 6 днів тому +9

    Supply chain attacks have been a thing for a long time. The CIA would leave exploding ammunition to be found by the Viet Cong in Vietnam and the Soviets in Afghanistan would trade boiled ammo(won’t fire) to locals for supplies, knowing it would go to the Mujahideen. It can be incredibly effective when implemented correctly

  • @tactics40
    @tactics40 5 днів тому +5

    "Let's not talk about who did this."
    I wonder why we wouldn't try to name the people who did this.

    • @tyrgoossens
      @tyrgoossens 5 днів тому +3

      It's not the point of the video, that's another conversation entirely. The method applies just as much to government officials, or mobsters, or just rival companies, etc. If you have enemies, you need information about your supply chain.

    • @Rom2Serge
      @Rom2Serge 2 дні тому

      It was done on EU territory , coz Taiwan said they stopped producing this pages like decade ago.
      And as i read they were stored in EU.
      Tho i might be wrong , i read only a handful of articles.

  • @bobbysbits2575
    @bobbysbits2575 6 днів тому +2

    Root certification authority sounds like a good challenge for a public blockchain.

  • @beskamir5977
    @beskamir5977 6 днів тому +1

    I considered if something like this could be possible when Samsung Note 7's turned out to be accidental bombs, but these pagers had actual explosives implanted in them, so that would suggest weaponizing batteries is thankfully harder than simply installing explosives in target devices. Still a concern, but not as bad as if it was just the battery that got blown up.

  • @markedwinwebb
    @markedwinwebb 6 днів тому +1

    What if these pagers were tampered with after manufacture? That seems more likely. A small amount of plastic explosive goes a long way.

  • @ahvideplaneet
    @ahvideplaneet 6 днів тому +4

    "Why do they hate us so?"

  • @sambo3975
    @sambo3975 6 днів тому +5

    This gets worrying when you think about how China, one of the USA's greatest adversaries, makes most of the stuff we use here.

  • @MerrimanDevonshire
    @MerrimanDevonshire 6 днів тому +7

    Amateurs talk tactics, Professionals study logistics... 😂😮😢

    • @beskamir5977
      @beskamir5977 6 днів тому +1

      Yeah logistics are everything.

  • @dava00007
    @dava00007 6 днів тому +5

    I thought they had figured how to blow the lithium batteries remotely.

    • @fontenbleau
      @fontenbleau 6 днів тому +4

      they can't, only ignite max, chemistry of that batteries wasn't ordinary

  • @ChiefBridgeFuser
    @ChiefBridgeFuser 5 днів тому +1

    Precise control of supply chain would do wonders for thwarting repair!

  • @radornkeldam
    @radornkeldam 2 дні тому

    Intel ME is not only present in i7s. there are features that are only available on high end cpus, such as the intel vPro feature that are implemented through the ME, but the ME itself, hardware and firmware, are available in all Intel CPUs regardles of the feature set available through it.

  • @act.13.41
    @act.13.41 6 днів тому +1

    Thanks Bryan. I have been watching this for hours now.

  • @neilpatrickhairless
    @neilpatrickhairless 6 днів тому +2

    Nokia owners be like: "Perkele!"

  • @ValenceFlux
    @ValenceFlux 6 днів тому +1

    Kind of reminds me of the time our phones got hacked and data was deleted during and electrical applications course of all places.
    One of the apprentices said 'Hey my phones messed up and I lost all my contacts'. Which prompted all of us to check our phones. All of us with HTC Verizon phones had the same problem and they would overheat. I believe it was a few months later those phones got banned.
    And the next course was supposed to be logic functions in security...
    I was looking forward to that course but unforeseen turn of events put me in the hospital.

  • @aakasoto
    @aakasoto 6 днів тому +13

    ✡did it.

  • @cinemint
    @cinemint 6 днів тому +2

    Time to only use old devices

  • @mdean3801
    @mdean3801 6 днів тому +2

    what's more difficult?, thousands of points in a supply chain to reach an individual; or one malware deposited to thousands of known individuals? Ever wonder about the chip makers in Israel if they are compromised?

    • @robinsutcliffe-video_art
      @robinsutcliffe-video_art 5 днів тому

      lots of methods being used to inspect inside silicon for this reason. It seems like those detonations are powerful, perhaps too large even for a lithium fire.

  • @happygomonkey
    @happygomonkey 6 днів тому +3

    start with RISCV

  • @stam_ehad
    @stam_ehad 6 днів тому +1

    This is nuts nuts i tell you

  • @1rez378
    @1rez378 6 днів тому +4

    Wtf, PDA bombs are real

  • @autohmae
    @autohmae 6 днів тому +1

    What I don't understand why didn't Purism work with Fairphone, their ideas should align better.

    • @autohmae
      @autohmae 6 днів тому

      HTTPS known backdoors, you'll have to explain what you mean, I assume you meant they might generate a genuine looking certificate because you assume they have access to the CAs.

    • @autohmae
      @autohmae 6 днів тому

      If you can find it and want to know how we can pretty much not trust high-end chips at all at the moment:
      Bunnie Huang Keynote Address Impedance Matching Expectations Between RISC V

  • @John-wd5cb
    @John-wd5cb 6 днів тому +7

    Taiwan manufacturing company and a CIA supply chain Man In the Middle operation. USAF deployment and assistance Tailored Operation Access with possible NSA airborne teams and Israel giving the green light of the Op. Mostly an American operation. Two E C130 airborne BACONs were used modified since 2016 as MIM access and listening platforms. The BACONs arrived non stop from US remained airborne for 15 hours over Lebanon/Syria then landed at Souda bay Greece.

    • @neilpatrickhairless
      @neilpatrickhairless 6 днів тому +5

      They should send in paratroopers to teach you punctuation.

    • @linuxforpunks
      @linuxforpunks 6 днів тому +2

      @@neilpatrickhairless Apostrotroopers

    • @John-wd5cb
      @John-wd5cb 6 днів тому

      Israel has crossed the Rubicon.
      400 in critical condition.
      11 dead
      4000 injured. Non combatants, women snd children.
      This is a weapon of mass destruction.
      To any non digital entities reading yhi (non bits, ie humans)
      Your lives have changed for ever.
      You just don't know it yet.
      Chemical biological war is next?
      You just don't target unsuspected populace with mass casualty events.
      Yesterday was the date THAT EVERYTHING CHANGED.

  • @SirBapkins
    @SirBapkins 6 днів тому +1

    Watched on Locals

  • @DavidConnerCodeaholic
    @DavidConnerCodeaholic 6 днів тому

    So you gonna need Nix or Guix to really be able to account for firmware builds and build components

  • @Alexander_Sannikov
    @Alexander_Sannikov 6 днів тому

    honestly it does not matter if none of the chips had any labels of them, if the boards were potted and all the software was proprietary: it should have been pretty obvious that there was some hardware component that contained explosives in those devices. it's pretty shocking it was never spotted.

    • @Badspot
      @Badspot 6 днів тому +5

      How often do you disassemble your brand new devices? Do you cut open the batteries to make sure it's not half battery and half semtex?

    • @Alexander_Sannikov
      @Alexander_Sannikov 6 днів тому

      @@Badspot if i was a terrorist i'd be taking my devices apart before even turning them on for the first time

  • @von_nobody
    @von_nobody 5 днів тому

    I recall hard disk that have pre-installed viruses :)

  • @walterhartman
    @walterhartman 6 днів тому

    This won't happen to me, Still using my AN0M phone.

  • @anon_y_mousse
    @anon_y_mousse 5 днів тому

    I'm not so sure that a secure supply chain is really possible no matter how local the manufacturing unless you manufacture things yourself in your basement. Even then, if a state actor sets their sights on you, then secure may be impossible. Of course, in the future, we may all need to do something like that using homebrew electronics just to get privacy and security. If our society doesn't increase its overall intelligence level, this can't possibly happen, and I fear it never will.

  • @rptube16
    @rptube16 2 дні тому

    Pagers are still a thing?

  • @maxrobe
    @maxrobe 6 днів тому +1

    Xbox 360 used to get a bit toasty.

  • @fontenbleau
    @fontenbleau 6 днів тому +1

    something fishy in this story and it's hard to believe that such small li-ion batteries doing like that. For ordinary people-do we need to wait for full mobile devices ban on airplanes?

  • @ZE_TRVTH_NVKE
    @ZE_TRVTH_NVKE 5 днів тому +1

    0:38 Ehh... At least we know that you are one of them, since you didn't name the juice.

  • @algramic195
    @algramic195 4 дні тому +2

    Think I'll just not buy anything that has been through Israel.

  • @odirex
    @odirex 6 днів тому +9

    hilarious planned obsolescence.

    • @ivancho5854
      @ivancho5854 6 днів тому +1

      Excellent comment. 🤣👍

  • @bobanmilisavljevic7857
    @bobanmilisavljevic7857 6 днів тому +4

    Gottem!

  • @Acetyl53
    @Acetyl53 6 днів тому +1

    1200. 12.

  • @Lestibournes
    @Lestibournes 6 днів тому +12

    It was a much needed dose of good cheer in dark times.

  • @mikescholz6429
    @mikescholz6429 6 днів тому +2

    Not even explosives, they caused thermal runaway in the li-poly cells remotely.

    • @neilpatrickhairless
      @neilpatrickhairless 6 днів тому

      Hot Poking the Chibson

    • @brulsmurf
      @brulsmurf 6 днів тому +6

      It was confirmed they contained explosives. You don't kill someone with a 800mah lithium battery 😂

    • @ivancho5854
      @ivancho5854 6 днів тому +3

      ​@@brulsmurf C4 battery! 🤣

    • @mikescholz6429
      @mikescholz6429 5 днів тому

      @@brulsmurf idk I’ve seen a 650mah explode in someones back pocket… it wouldn’t surprise me if they could be lethal.

    • @mikescholz6429
      @mikescholz6429 5 днів тому

      @@brulsmurf I wonder if they used runaway to trigger the explosives then because there were reports of some people discarding their devices earlier in the day because the batteries felt hot.

  • @engineeranonymous
    @engineeranonymous 6 днів тому +3

    This do not needs to be a secure supply issue. If you know the charger IC and how to bypass overcharge security then you will have a device you can use as an explosive any time you want. Remember Galaxy Note 7.

    • @bloepje
      @bloepje 6 днів тому

      The note 7 was a mechanical issue.

    • @arlobubble3748
      @arlobubble3748 6 днів тому +1

      Best case scenario on a non defective battery you'll be able to start a fire, and even then only when the device is actively being charged

    • @neilpatrickhairless
      @neilpatrickhairless 6 днів тому

      Which is wild because lithium ion batteries don't extinguish easily when on fire and everyone's phone stays on charge because UA-cam eats charge like it's feeding a golem

    • @AlchemyCat
      @AlchemyCat 6 днів тому

      @@bloepje Exactly that was by accident, now imagine a terrorist state using that battery energy in a designed attack and you have something that looks like this.

    • @engineeranonymous
      @engineeranonymous 5 днів тому

      @@bloepje Let!s assume you know if you push battery too much too fast you might trigger a mechanical failure. Since when overcharged lithium batteries tend to swell. Like you know if you push a centrifuge speed low too high for days it will fail. Won't you use it for your advantage ?

  • @rahulramteke3338
    @rahulramteke3338 День тому

    Free 🇵🇸

  • @ZappyOh
    @ZappyOh 6 днів тому +4

    Dirty trick.

  • @wikwayer
    @wikwayer 6 днів тому +4

    You are playing a dangerous game

    • @freedustin
      @freedustin 6 днів тому +10

      We all are, its called "Existing."

    • @neilpatrickhairless
      @neilpatrickhairless 6 днів тому +4

      Shoutout to survivors of existence! They're really becoming a dying breed

  • @eliasmai6170
    @eliasmai6170 6 днів тому +1

    were all those pagers made in China?

  • @draoi99
    @draoi99 6 днів тому +2

    Can't imagine who would have done this but it was clever and amusing.

    • @act.13.41
      @act.13.41 6 днів тому +6

      One of the most inventive things I have ever seen.

    • @ImperiumLibertas
      @ImperiumLibertas 6 днів тому +14

      Why can't we just say Mosad? Is that not allowed to be said or something?

    • @williambuckley5601
      @williambuckley5601 6 днів тому +7

      Amusing? How so?

    • @John-wd5cb
      @John-wd5cb 6 днів тому +4

      USAF and CIA.

    • @j_shelby_damnwird
      @j_shelby_damnwird 6 днів тому +9

      Oh sure, getting your spleen blown off by the exploding pager of the guy next in line at the supermarket sounds like a barrel of laughs. High comedy.

  • @mohamedelhaddade6371
    @mohamedelhaddade6371 6 днів тому +16

    don't say Hezbollah terrorist's ... don't be political here

    • @guillermogongorafigoli4542
      @guillermogongorafigoli4542 6 днів тому

      Violent political group It IS the very definition of a terrorist group. But I will not get political.

    • @masonwheeler6536
      @masonwheeler6536 6 днів тому +23

      What's "political" about telling the simple truth?

    • @cavalieroutdoors6036
      @cavalieroutdoors6036 6 днів тому +21

      It's just calling a spade a spade. That ain't political, it is what it is.

    • @fontenbleau
      @fontenbleau 6 днів тому +3

      fighting crime by crime never paid off anywhere

    • @John-wd5cb
      @John-wd5cb 6 днів тому

      For 5 billion people on this Earth USA/Britain/Israel are the terrorists. Nobody can do anything about it.

  • @jttech44
    @jttech44 5 днів тому

    Supply chain wouldn't have helped the terrorists. This happened while they were hung up in customs, ie, in transit to destination.
    What would have saved them is a checksum, ie, "this device weighs X.XX grams +/- 0.X grams.
    Glad it didn't =]