Comment by edm0nd

Comment by edm0nd 3 days ago

31 replies

These pagers were 100% a supply chain attack. Intercepted and modified with small explosives embedded in them or swapped the entire shipment out with ones with a small explosives in them.

There is no possibility these explosions are from battery overloads via an exploit or firmware hack.

spidersenses 3 days ago

>or firmware hack.

There's still the question of how the explosive capsule would have been triggered. It couldn't just explode at the first incoming call. There must be more to that.

  • ajsnigrutin 3 days ago

    The microcontrollers inside the pagers probably have a spare GPIO pin, so they'd just have to modify the software and attach the detonating electronics to that gpio pin.

    Since i'm supposedly "posting too fast", to answer the post below:

    > Just curious, is it possible to program the pins so that it triggers by wireless or satellite command? With that scale I don't think wireless is possible though.

    Technically it is, but requires additional electronics and antennas. It's much easier to just use the existing pager network and trigger when some specific message (or pager code) is detected. Paging networks are simple to implement.

    • tptacek 3 days ago

      It seems pretty plausible that the actual supply chain attack here would have been Israel subbing out whole shipping crates of pagers for sabotaged devices Israel manufactured itself, which would allow for arbitrary complex designs.

      • markus_zhang 3 days ago

        Maybe they bought a large quantity of pagers from the same supplier and modified beforehand? I think a few grams of high explosives is good enough.

    • markus_zhang 3 days ago

      Just curious, is it possible to program the pins so that it triggers by wireless or satellite command? With that scale I don't think wireless is possible though.

      • londons_explore 3 days ago

        the pager is already wireless. So adding functionality to trigger wirelessly (over the phone network) is trivial. And it can trigger only with a special message.

        • markus_zhang 3 days ago

          Yeah you are probably right. I'm an electronics newbie and don't know exactly how pagers work in wireless. I'm going to read some material on it.

    • markus_zhang 3 days ago

      Thanks, I wonder how does one do that. I'll probably need to read how pagers work.

  • svnt 3 days ago

    My best guess is explosively formed penetrator in the display.

    I don’t think wholesale replacement of the pagers was likely to work for a number of reasons.

    They had to go one step up the supply chain.

    The EFP display could be set to trigger on a certain message, or even the clearing of a certain message, which in devices without said display would do nothing.

    The display is most likely to be pointed at the user’s face, or opposed to their waistline (EFPs sort of fire both ways but in one axis.

    The battery, if it were a cylinder as would be likely, would fire tangentially, likely not hitting much.

    A prismatic battery would make a good place for an EFP but difficult to interface with and likely requires a second compromised component.

    • hinkley 3 days ago

      Theory: A prismatic battery with an explosive core and an electronic fuse swapped to trigger the explosive instead of disconnect the battery. Firmware change to short the battery. No visible signs of tampering even in iFixit like conditions.

      • svnt 3 days ago

        The best evidence we have now suggests that the devices used had removable (AAA) batteries, not built-in batteries.

        If I was buying pagers and had previously been hit by intelligence ops I would be buying batteries in random supermarkets.

      • rolux 3 days ago

        What would happen if you walked through airport security with such a device?

        • svnt 2 days ago

          Nothing, they aren’t looking for 2”x1” sheets of copper within electronic devices, and presumably the thin layer of explosives would be sealed and washed.

  • emiliobumachar 3 days ago

    Might be a hardcoded date and time. Does the legit pager messaging network give the time? If not, continually powered digital clocks drift slowly.

barbazoo 3 days ago

> These pagers were 100% a supply chain attack.

What did you base that on though, 100% is pretty confident

  • rdtsc 3 days ago

    Batteries are not magic unknown technology. People who understand their chemistry can confidently say things like that.

    • barbazoo 3 days ago

      Dunning-Kruger effect comes to mind again.

      • rdtsc 3 days ago

        How do you mean? I am trying to understand what you're saying, it seems you mean that people on HN only _think_ they understand how battery technology works saying this is impossible, but in reality they have no idea, and it's trivial to make an explosive device like out of pager batteries?

      • [removed] 2 days ago
        [deleted]
  • edm0nd 3 days ago

    Simple logic and science. Batteries do not cause forceful explosions like we've seen today. These pagers were intercepted and implanted with explosives (or entire load swapped with pre-made malicious ones) and then allowed to continue on to their destination. Thus I can say with 100% confidence that this was a supply chain attack.

sroussey 3 days ago

Likely, there are many many more of them out there, just did not fall into the dragnet of phone numbers that were set to activate.

  • s1artibartfast 3 days ago

    How do you judge that likely? It seems just as possible if not more that it was a single lot purchased by Hezbollah for Hezbollah.

  • meaydinli 3 days ago

    I'd guess anybody with a pager in that part of the world dumped theirs as soon as they heard what happened.

  • londons_explore 3 days ago

    I bet lots of people with that model of pager are now ripping them open to check for explosives. If we don't see pictures of unexploded ones, then I'd guess they were all triggered, and the only ones we might see are devices that were turned off at the time.

    • sroussey 3 days ago

      Agreed. Will be interesting if there is a teardown or not.