It's not. Condoms aren't used against a hostile opponent. If your partner is intent on exposing you, a condom won't provide any protection.
I can't think of a more hostile opponent than an HIV virus. And we're still not sure if Transmission was spreading the virii intentionally, making the condom analogy even more fitting.
Transmission BitTorrent app contained malware
121–130 of 355 posts
Re: Transmission BitTorrent app contained malware
#122I uninstalled the app, but is there a way I can check if i've been affected?
Re: Transmission BitTorrent app contained malware
#123While we're here, can anyone recommend a good antivirus for OSX? I've just been looking at BitDefender, which looks promising, but would rather get this right than faff around with potentially crappy AV tools.
> can anyone recommend a good antivirus for OSX? Common Sense 2016, see https://github.com/drduh/OS-X-Security-and-Privacy-Guide
Re: Transmission BitTorrent app contained malware
#124Along with the recent Linux Mint hijack, this really illustrates the need for people to verify programs they download. Though I think most people can't be bothered to verify the checksum on a file every time they download it. On the other hand, the Windows and OS X App Stores are awful. Linux package managers are looking like one of the only straightforward ways to distribute applications securely.
The app made it onto the OSX App Store and the author's certs were revoked. This isn't a case of verify source, verify application. This is a case of anything can be infected and it's damn near impossible to check everything.
As such, checking the source is still very much relevant here since this wasn't a compromised app in the Mac App Store, it's an app distributed outside it.
Re: Transmission BitTorrent app contained malware
#125Re: Transmission BitTorrent app contained malware
#126Along with the recent Linux Mint hijack, this really illustrates the need for people to verify programs they download. Though I think most people can't be bothered to verify the checksum on a file every time they download it. On the other hand, the Windows and OS X App Stores are awful. Linux package managers are looking like one of the only straightforward ways to distribute applications securely.
The app made it onto the OSX App Store and the author's certs were revoked. This isn't a case of verify source, verify application. This is a case of anything can be infected and it's damn near impossible to check everything.
Re: Transmission BitTorrent app contained malware
#127Earlier quoted context omitted.
Anyone can sign up for the Apple Developer Program to become an "identified developer", so there's nothing that stops an attacker from signing their malware.
And according to the analysis [0], this is exactly what they did. They used a different cert to sign their malware. I have to admit that Windows' UAC is better in that regard, as it shows the signees name. But of course this is only useful if you know the "right" name. [0] http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-...
(There is third party tool named RB App Checker which does make these tasks a bit easier, though)
Re: Transmission BitTorrent app contained malware
#128It's not. Condoms aren't used against a hostile opponent. If your partner is intent on exposing you, a condom won't provide any protection.
I can't think of a more hostile opponent than an HIV virus. And we're still not sure if Transmission was spreading the virii intentionally, making the condom analogy even more fitting.
Re: Transmission BitTorrent app contained malware
#129Earlier quoted context omitted.
Noted: I've gone with BitDefender from the Map App Store. Will report back results. EDIT: welp, BitDefender found nothing, all clear.
(reply to noondip): if anyones got a better suggestion I'd love to hear it :)
――――――
¹ — https://en.wikipedia.org/wiki/Clam_AntiVirus#Mac_OS_X
Re: Transmission BitTorrent app contained malware
#130It's not. Condoms aren't used against a hostile opponent. If your partner is intent on exposing you, a condom won't provide any protection.
Just because attackers can break out of VMs, doesn't mean that they always do. I wager most malware out there isn't set up to do that.
Locking your car door won't keep a dedicated attacker out of your car. Simple ceramic shards from a sparkplug will get them through the window with barely any effort at all. Nevertheless, locking your car doors is an effective way to reduce your risk, as it dissuades more opportunistic attackers.