Inspectorgadget_1 wrote:
Let me make clear it wasn’t the company google that did it. Google had flaws that were exploited by very intelligent people that had a lot of time on their hands. I’ve been fighting with these hackers for almost two weeks now. I don’t know where it came from but check security certificates and see if there’s about 500 or so that don’t belong there and then hit me back.
That‘s still millions of dollars of tooling, which places your situation and your risks well outside of what can be addressed in a forum. You are reporting yourself as being a target of immensely well-funded adversaries.
The trusted certificate store is a fundamental part of modern network communications. The certificate store on Apple devices is protected similarly to the rest of the platform. Users can add certificates locally, but cannot add certificates to the trust store short of a separen security breach. And if there’s an existing breach that would allow it, there’s little reason to add some obvious and overt and easily-detected indication of compromise such as a new or changed certificate.
Again, you are reporting sophisticated exploits, well past the “reset and re-install” and “change your passwords” suggestions available around most forums, and what re-securing-related steps you’ve undoubtedly already tried.
That means collecting forensics, and mens working with folks that specialize in detecting exploits such as you’re reporting here. Also means reviewing your whole environment, expectations, and particular risks, and on what data you choose to maintain and where, and what data you purge. All of which gets into some personal details, ill-suited for discussions here.