Skip to content

Commit

Permalink
Exploding hand-helds
Browse files Browse the repository at this point in the history
  • Loading branch information
ninabarzh committed Sep 25, 2024
1 parent 5f6446d commit 3849ec0
Show file tree
Hide file tree
Showing 7 changed files with 223 additions and 0 deletions.
1 change: 1 addition & 0 deletions project/blog/routes.py
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,7 @@
"data-retention-legislation-eu",
"gdpr",
"noble",
"pagers",
]


Expand Down
13 changes: 13 additions & 0 deletions project/blog/templates/blog/blog.html
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,19 @@
{% block content %}
<div class="blog-container">

<div class="blog-post-card card-overlay">
<img
src="{{ url_for('static', filename='img/exploding-pagers.png') }}"
alt="Exploding pagers"
class="blog-post-card__image" />
<div class="blog-post-card__body">
<a href="{{ url_for('blog.posts', blog_title='pagers') }}">
<h2 class="recipe-title-long">Exploding hand-helds</h2></a>
<p>Exploding hand-held devices such as pagers, radios and walkie-talkies to maim people was a targeted attack. It can not happen to us. It happened there, in Beirut, far from our beds.</p>
<p class="blog-post-card__date">Published on Sept 25, 2024</p>
</div>
</div>

<div class="blog-post-card card-overlay">
<img
src="{{ url_for('static', filename='img/noble-numbat.png') }}"
Expand Down
63 changes: 63 additions & 0 deletions project/blog/templates/blog/pagers.html
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
{% extends "blogpost.html" %}

{% block title %}
<h1>Exploding hand-helds</h1>
{% endblock %}

{% block date %}
<p class="blogpost__date">Published on Sept 25, 2024</p>
{% endblock %}

{% block image %}
<img
src="{{ url_for('static', filename='img/exploding-pagers.png') }}"
alt="Exploding hand-helds"
class="blogpost__image" />
{% endblock %}

{% block article %}
<p align="center"><a href="https://politicalcartoons.com/cartoon/288654">Cartoon by Joe Heller: Exploding pagers</a></p>

<h2>So what happened</h2>

The first round of blasts began in Lebanon's capital Beirut and several other areas of the country at about 15:30 local time on Tuesday 17 september 2024 involving pagers. Another round of blasts, now from walkie-talkies, happened on Wednesday the 18th, at around 17:00 local time.

Some of the pagers used by Hezbollah are models that run on <a href="https://www.bunniestudios.com/blog/2024/turning-everyday-gadgets-into-bombs-is-a-bad-idea/">lithium-ion batteries</a>, which can cause dangerous explosions. According to <a href="https://www.lbcgroup.tv/news/lebanon-news/796406/understanding-the-pager-and-how-it-can-explode/en">information obtained by LBCI</a>, the pager server can have been compromised, leading to the installation of a script that caused an overload. This then could have resulted in the overheating of the lithium battery, which then exploded. But it is unlikely that a regular pager battery alone can produce blasts that can injure multiple people (as was seen in some of the recorded attacks). It seems more likely the pagers were interdicted and modified with explosives.

<h2>Interdiction</h2>

<p>Using so-called "interdiction", the target hardware is intercepted while on route to a next supplier in the supply chain. The hardware must be unpackaged, modified, repackaged and put back in the chain without raising red flags. Using "Seeding" is probably even harder, because the manipulation happens on the factory floor. Access in both cases can be gained by social engineering, like posing as officials, bribery, threatening an insider, etcetera.</p>

<p>Hardware supply chain attacks <a href="https://www.bunniestudios.com/blog/2019/supply-chain-security-talk/">are extremely hard to defend from</a>.

<p>Once the hardware is successfully modified, adversaries can use the back door to gain further access or exfiltrate data, it is extremely difficult to detect and fix, and gives long-term access. It is entirely possible that explosives planted in the pagers were detonated using a remote command, perhaps hidden in a pager message. But erm? there is not much space in the devices. Which explosives were that then?</p>

<h2>Targeting costs</h2>

<p>To make it a targeted attack the attacker would need an operative to make sure he modified devices are delivered to the targets and not just anyone. This requires a mole, or a bribe. And time. How long does it take to infiltrate Hezbollah providers to the point of delivering hundreds of devices?</p>

<h2>Why this attack?</h2>

<p>Buying time? Replacing a large number of pagers will take time. Deterrence? The first round came just hours after Israel's security cabinet made the safe return of residents to the north of the country an official war goal. Showing the depth of Israel's intelligence pockets might deter Hezbollah. <a href="https://www.politico.com/news/magazine/2023/10/24/amos-yaldin-israeli-military-intelligence-netanyahu-qa-00123099">Amos Yadlin</a>, a former head of Israeli military intelligence, said the Israeli attack displayed "very impressive penetration capabilities, technology and intelligence." The deterrence factor however, does not seem to be working. </p>

<p>Did anyone else notice the use of the word "penetration"? What on Earth do they think they are doing?</p>

<p>And it is not a surprise either. <a href="https://www.independent.co.uk/news/world/how-the-phone-bomb-was-set-up-1323096.html">Similar capabilities were already shown.</a> Still, the scale of this attack seems "unprecedented". </p>

<p>As mp wrote: "In other words, it seems to me, this action is only really possible
("easy") if you are already deeply invested in the dark arts of arms
trafficking and dealing, which is to say: embedded in the global,
criminal economy. It is statecraft."</p>

<h2>Western response</h2>

<p>There are UN accusations that this constitutes a war crime, as well as congratulations on the ingenuity of the attack, while it injured at least 2800 people and killed at least nine. But not really an outcry. I have not seen a real outcry on what is happening in Gaza either, by the way. Have we gone numb because of <a href="https://en.wikipedia.org/wiki/List_of_ongoing_armed_conflicts">all the war and killing</a>?</p>

<p>The best explanation I have seen is from Patrice: "In general, I think there is by now a weariness to address the
increasingly dystopian aspect of tech, wether it's corporate or military developed and deployed, since (i) it makes one very depressive
(ii) it won't help anyway"</p>

<p>Historically, technological advances are double-edged swords. Technology has been used against us, while claimed to have been designed to help us. Such opportunism rules mankind. What if our governments are taken over by less-democratic forces? If hand-held devices, such as walkie-talkies or pagers, can be implanted with explosives and can kill targets, how safe are any of us from this mode of attack?</p>

<p>Posting this is also unlikely to help, but I feel slightly better.</p>
{% endblock %}
13 changes: 13 additions & 0 deletions project/build/blog/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,19 @@ <h1><a href="https://tymyrddin.dev">Ty Myrddin Home</a></h1>

<div class="blog-container">

<div class="blog-post-card card-overlay">
<img
src="/static/img/exploding-pagers.png"
alt="Exploding pagers"
class="blog-post-card__image" />
<div class="blog-post-card__body">
<a href="/pagers/">
<h2 class="recipe-title-long">Exploding hand-helds</h2></a>
<p>Exploding hand-held devices such as pagers, radios and walkie-talkies to maim people was a targeted attack. It can not happen to us. It happened there, in Beirut, far from our beds.</p>
<p class="blog-post-card__date">Published on Sept 25, 2024</p>
</div>
</div>

<div class="blog-post-card card-overlay">
<img
src="/static/img/noble-numbat.png"
Expand Down
133 changes: 133 additions & 0 deletions project/build/pagers/index.html
Original file line number Diff line number Diff line change
@@ -0,0 +1,133 @@
<!DOCTYPE html>
<html lang="en">
<head>
<!-- Required meta tags -->
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">
<title>Unseen University</title>

<!-- Favicons -->
<link rel="apple-touch-icon" sizes="180x180" href="/static/favicons/apple-touch-icon.png">
<link rel="icon" type="image/png" sizes="32x32" href="/static/favicons/favicon-32x32.png">
<link rel="icon" type="image/png" sizes="16x16" href="/static/favicons/favicon-16x16.png">
<link rel="manifest" href="/static/favicons/site.webmanifest">
<link rel="mask-icon" href="/static/favicons/safari-pinned-tab.svg" color="#333333">
<link rel="shortcut icon" href="/static/favicons/favicon.ico" type="image/x-icon">
<meta name="msapplication-TileColor" content="#333333">
<meta name="theme-color" content="#000000">

<!-- Local CSS file for styling the application-->
<link rel="stylesheet" href="/static/css/base_style.css">

<!-- Additional Styling -->

<link rel="stylesheet" href="/static/css/blogpost_style.css">


</head>

<body>
<header>
<h1><a href="https://tymyrddin.dev">Ty Myrddin Home</a></h1>
<nav>
<ul>
<li class="nav__item"><a href="/" class="nav__link">Unseen University</a></li>
<li class="nav__item"><a href="/blog/" class="nav__link">Improbability Blog</a></li>
<li class="nav__item"><a href="/about/" class="nav__link">About</a></li>
<li class="nav__item"><a href="/registration/" class="nav__link">Register</a></li>
</ul>
</nav>
</header>

<main class="content">
<!-- child template -->

<div class="blogpost-container card-overlay">
<div class="blogpost__heading">

<h1>Exploding hand-helds</h1>


<h3>by Ty Myrddin</h3>


<p class="blogpost__date">Published on Sept 25, 2024</p>

</div>

<div class="blogpost__image">

<img
src="/static/img/exploding-pagers.png"
alt="Exploding hand-helds"
class="blogpost__image" />

</div>

<div class="blogpost__article">

<p align="center"><a href="https://politicalcartoons.com/cartoon/288654">Cartoon by Joe Heller: Exploding pagers</a></p>

<h2>So what happened</h2>

The first round of blasts began in Lebanon's capital Beirut and several other areas of the country at about 15:30 local time on Tuesday 17 september 2024 involving pagers. Another round of blasts, now from walkie-talkies, happened on Wednesday the 18th, at around 17:00 local time.

Some of the pagers used by Hezbollah are models that run on <a href="https://www.bunniestudios.com/blog/2024/turning-everyday-gadgets-into-bombs-is-a-bad-idea/">lithium-ion batteries</a>, which can cause dangerous explosions. According to <a href="https://www.lbcgroup.tv/news/lebanon-news/796406/understanding-the-pager-and-how-it-can-explode/en">information obtained by LBCI</a>, the pager server can have been compromised, leading to the installation of a script that caused an overload. This then could have resulted in the overheating of the lithium battery, which then exploded. But it is unlikely that a regular pager battery alone can produce blasts that can injure multiple people (as was seen in some of the recorded attacks). It seems more likely the pagers were interdicted and modified with explosives.

<h2>Interdiction</h2>

<p>Using so-called "interdiction", the target hardware is intercepted while on route to a next supplier in the supply chain. The hardware must be unpackaged, modified, repackaged and put back in the chain without raising red flags. Using "Seeding" is probably even harder, because the manipulation happens on the factory floor. Access in both cases can be gained by social engineering, like posing as officials, bribery, threatening an insider, etcetera.</p>

<p>Hardware supply chain attacks <a href="https://www.bunniestudios.com/blog/2019/supply-chain-security-talk/">are extremely hard to defend from</a>.

<p>Once the hardware is successfully modified, adversaries can use the back door to gain further access or exfiltrate data, it is extremely difficult to detect and fix, and gives long-term access. It is entirely possible that explosives planted in the pagers were detonated using a remote command, perhaps hidden in a pager message. But erm? there is not much space in the devices. Which explosives were that then?</p>

<h2>Targeting costs</h2>

<p>To make it a targeted attack the attacker would need an operative to make sure he modified devices are delivered to the targets and not just anyone. This requires a mole, or a bribe. And time. How long does it take to infiltrate Hezbollah providers to the point of delivering hundreds of devices?</p>

<h2>Why this attack?</h2>

<p>Buying time? Replacing a large number of pagers will take time. Deterrence? The first round came just hours after Israel's security cabinet made the safe return of residents to the north of the country an official war goal. Showing the depth of Israel's intelligence pockets might deter Hezbollah. <a href="https://www.politico.com/news/magazine/2023/10/24/amos-yaldin-israeli-military-intelligence-netanyahu-qa-00123099">Amos Yadlin</a>, a former head of Israeli military intelligence, said the Israeli attack displayed "very impressive penetration capabilities, technology and intelligence." The deterrence factor however, does not seem to be working. </p>

<p>Did anyone else notice the use of the word "penetration"? What on Earth do they think they are doing?</p>

<p>And it is not a surprise either. <a href="https://www.independent.co.uk/news/world/how-the-phone-bomb-was-set-up-1323096.html">Similar capabilities were already shown.</a> Still, the scale of this attack seems "unprecedented". </p>

<p>As mp wrote: "In other words, it seems to me, this action is only really possible
("easy") if you are already deeply invested in the dark arts of arms
trafficking and dealing, which is to say: embedded in the global,
criminal economy. It is statecraft."</p>

<h2>Western response</h2>

<p>There are UN accusations that this constitutes a war crime, as well as congratulations on the ingenuity of the attack, while it injured at least 2800 people and killed at least nine. But not really an outcry. I have not seen a real outcry on what is happening in Gaza either, by the way. Have we gone numb because of <a href="https://en.wikipedia.org/wiki/List_of_ongoing_armed_conflicts">all the war and killing</a>?</p>

<p>The best explanation I have seen is from Patrice: "In general, I think there is by now a weariness to address the
increasingly dystopian aspect of tech, wether it's corporate or military developed and deployed, since (i) it makes one very depressive
(ii) it won't help anyway"</p>

<p>Historically, technological advances are double-edged swords. Technology has been used against us, while claimed to have been designed to help us. Such opportunism rules mankind. What if our governments are taken over by less-democratic forces? If hand-held devices, such as walkie-talkies or pagers, can be implanted with explosives and can kill targets, how safe are any of us from this mode of attack?</p>

<p>Posting this is also unlikely to help, but I feel slightly better.</p>

</div>

<div class="blogpost__article">
<hr>
<p>
Raw magic crackled from their spines, earthing itself harmlessly in the copper rails nailed to every shelf for
that very purpose. Faint traceries of blue fire crawled across the bookcases and there was a sound, a
papery whispering, such as might come from a colony of roosting starlings. In the silence of the night the
books talked to one another. <span style="float:right"> <strong>A student</strong></span></p>

</div>
</div>

</main>

<footer>
<p><a href="https://www.tymyrddin.dev/">Ty Myrddin</a> - <a rel="me" href="https://mastodon.social/@barzh">Mastodon</a> - <a rel="me" href="https://tube.spdns.org/a/barzh/video-channels">Move IT tube</a> - <a rel="me" href="https://github.com/tymyrddin">GitHub</a> - <a rel="me" href="https://gitlab.com/tymyrddin">Gitlab</a> - <a rel="me" href="https://bitbucket.org/tymyrddin/workspace/repositories/">Bitbucket</a></p>
</footer>
</body>
</html>
Binary file added project/build/static/img/exploding-pagers.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added project/static/img/exploding-pagers.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.

0 comments on commit 3849ec0

Please sign in to comment.