It's not. Condoms aren't used against a hostile opponent. If your partner is intent on exposing you, a condom won't provide any protection.
Perhaps a better analogy is "everyone knows locks can be picked", but people don't leave all their doors unlocked...
Transmission BitTorrent app contained malware
201–210 of 355 posts
Re: Transmission BitTorrent app contained malware
#202Re: Transmission BitTorrent app contained malware
#203Re: Transmission BitTorrent app contained malware
#204It looks like they've since changed the upgrade to 2.92 (it was previously 2.91 this morning), wonder why that happened?
The update dialog says: "Everyone running 2.90 on OS X should immediately upgrade to and run 2.92, as they may have downloaded a malware-infected file. This new version will make sure that the “OSX.KeRanger.A” ransomware (more information available here) is correctly removed from you're computer. Users of 2.91 should also immediately upgrade to and run 2.92. Even though 2.91 was never infected, it did not automatical…
https://trac.transmissionbt.com/changeset?old_path=%2F&old=1...
Re: Transmission BitTorrent app contained malware
#205Earlier quoted context omitted.
I think the point is that viruses can exploit properties of their hosts regardless of how they came to do so.
But humans and viruses aren't competing in the same game. A better metaphor for the adversary in that situation is the person you're having sex with poking a hole in your condom.
Re: Transmission BitTorrent app contained malware
#206Re: Transmission BitTorrent app contained malware
#207Earlier quoted context omitted.
I am not following your comment here. Most Jenkins setup use global credentials or use the server-side config file like .ssh/config, .gitconfig link.
But ideally there are no credentials because Jenkins doesn't need to push code to the repo (and can clone the pubically available code).
As far as I know, only the binary was updated.
I'd be interested to hear, though, how it got compromised after all.
Re: Transmission BitTorrent app contained malware
#208Earlier quoted context omitted.
Here's an analysis of the malware - http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-...
"It will then sleep for three days. Note that, in a different sample of KeRanger we discovered, the malware also sleeps for three days, but also makes requests to the C2 server every five minutes." It's fascinating!
Re: Transmission BitTorrent app contained malware
#209Earlier quoted context omitted.
(reply to noondip): if anyones got a better suggestion I'd love to hear it :)
Back when Apple still made Mac OS X Server as a separate operating system, they included ClamAV¹ to scan for malware in mail. They don’t include it anymore, but ClamXav² (been around since 2004³) is a nice GUI for ClamAV that I’ve been using for a while now. ―――――― ¹ — https://en.wikipedia.org/wiki/Clam_AntiVirus#Mac_OS_X ² — http://clamxav.com/index.html ³ — http://clamxav.com/birthday.html