Live data from Hacker News

Transmission BitTorrent app contained malware

forum.transmissionbt.com

261–270 of 355 posts

Re: Transmission BitTorrent app contained malware

#261
post #134

Transmission put up a new version - 2.92 that supposedly checks for and removes the malware.

Threw away Transmission as soon as I read this (even though I was running a old version), my trust is pretty much gone now, never installing it again. Shame because it really was a nice app.

flying the day after 9/11 was the safest time, I really doubt this sort of thing will happen again to the same software

Re: Transmission BitTorrent app contained malware

#262
post #179
post #168

Earlier quoted context omitted.

I think it's a poor illustration. You could install and run this app as a regular user (and never escalate to administrator) and the app's bundled malware would still absolutely destroy anything of value on your computer. It's the stuff inside $HOME (and $HOME/Documents) that's valuable. Not system binaries in {/bin,/sbin,/Applications} that can be re-downloaded in a second. The problem is that any non-sandboxed app…

First, obviously you can make an account for running the untrusted software, like Bittorrent clients (which are known to carry malware frequently). Second, most malware requires and counts on having admin privileges on target machine. The task of auditing, cleaning and finding out that malware is present is significantly easier if malware is limited to a non-privileged account. With malware running as a non-privilege…

> most malware requires and counts on having admin privileges on target machine.

If you really believe this, run rm -rf ~ on your computer right now. Also rm -rf /Volumes/* (on OS X) or wherever your network/external drives are mounted on your OS. Since you don't have admin privileges, nothing bad happened right? Because that is the primary goal of ransomware.

Anyway, this specific malware doesn't even attempt to acquire root; it operates entirely as your local user. And there's no installer package, so why are you complaining about them?

Re: Transmission BitTorrent app contained malware

#265

Earlier quoted context omitted.

so, what do you think where logic comes from? I'll spare you the effort: > [...] from properly feminine of λογικός ‎(logikós, “of or pertaining to speech or reason or reasoning, rational, reasonable”), from λόγος ‎(lógos, “speech, reason”). https://en.wiktionary.org/wiki/logic There is no analogy without logic. I even fail to recognize a difference between speech and logic, speech without logic, by analogy, would be…

Your extremely ignorant argument immediately implies that the clubs used to hit baseballs are necessarily related to flying mammals. The facts that the english word analogy descends in a complicated manner from a greek word referring to mathematical proprotions, and the english word logic descends in a somewhat less complicated manner from a greek word referring to speech, and that those greek words shared their pron…

The similarity between according to" + "ratio," and “of or pertaining to speech or reason or reasoning, rational, reasonable” is just too simple and striking to be missed and forgotten.

No linguistic reasoning is needed however, to see that an analogy essentially needs logic to work in any language. It helps however. EG in English tongue still language in an idiomatic metaphorical sense, analog to the original meaning of logos, tongue, metaphorically referring to speech.

My argument is not ignorant, anyway, it's arrogant.

Re: Transmission BitTorrent app contained malware

#266
post #2

Along with the recent Linux Mint hijack, this really illustrates the need for people to verify programs they download. Though I think most people can't be bothered to verify the checksum on a file every time they download it. On the other hand, the Windows and OS X App Stores are awful. Linux package managers are looking like one of the only straightforward ways to distribute applications securely.

Linux package managers are looking like one of the only straightforward ways to distribute applications securely. Unless you are a small independent app developer. Virtually no distribution wants to take proprietary software. And you have to package for a wide variety of different distributions. On the other hand, the Windows and OS X App Stores are awful. The Mac App store works pretty much effortless for me. It's s…

The question is whether we should trust proprietary software even if it is downloaded securely. I consider "hard to get proprietary software into the official repos" as a feature. Unfortunately it's not as hard as you make it sound in most distributions.

Re: Transmission BitTorrent app contained malware

#267

Earlier quoted context omitted.

"It will then sleep for three days. Note that, in a different sample of KeRanger we discovered, the malware also sleeps for three days, but also makes requests to the C2 server every five minutes." It's fascinating!

Isn't it possible to fire a takedown notice to that server? I mean KeRanger committed a felony and Amazon (assuming you mean Amazon's EC2 server) might react quickly if they realize what has happened. It might save a lot of computers from getting destroyed. As long as the server is somewhere in the Western world, it should not be a problem.

Amazon's abuse teamight help, but the DMCA would not relevant unless you can show copyright infringement in this.

Re: Transmission BitTorrent app contained malware

#268

I've become increasingly paranoid lately, given that things like these happen and major bugs are uncovered in software that I use almost every day. It's good that the Transmission developer reacted quickly and made waves so that people can at least be aware that they might have been exposed.. But I wonder how many more applications from the hundreds that I have installed on my machines contain weird stuff - either in…

> Open source software is especially vulnerable to this kind > of stuff. Give it 2 or 3 years and stories will come trickling out about how most OS apps have had commits from hackers, governments etc. So far most source checking - to the extent that it happens at all - is all about buffer overruns and the like; micro stuff that's easily catchable. Well, you say that, but, you know, heartbleed etc. But what about whol…

> > Open source software is especially vulnerable to this kind > of stuff.

> Give it 2 or 3 years and stories will come trickling out about how most OS apps have had commits from hackers, governments etc. So far most source checking - to the extent that it happens at all - is all about buffer overruns and the like; micro stuff that's easily catchable. Well, you say that, but, you know, heartbleed etc. But what about whole modules designed with two purposes in mind?

Free Software has existed for over 20 years. Not to mention the fact that the same problem you describe is far more trivial for proprietary software. There's no straightforward way to find out if it's backdoored (although, luckily quite a few backdoors are done badly so we can find out). The point is that if you assume that all free software is compromised, you have to assume all proprietary software is compromised. I'd prefer to have some free software be compromised because then I'm not at the mercy of the vendor to fix it.

Re: Transmission BitTorrent app contained malware

#269
post #76

Earlier quoted context omitted.

Side topic: probably not a good idea to expose Jenkins externally, especially if you don't keep Jenkins up-to-date all the time (for transmission bt it is up-to-date right now). This Jenkins probably contain the key to the svn server, so if someone finds a hole...

>Side topic: probably not a good idea to expose Jenkins externally Jenkins (and CI in general) can be a very weak point. This was posted on Hacker News a while back https://github.com/samratashok/ContinuousIntrusion

Very useful demonstration. thanks for sharing.

Re: Transmission BitTorrent app contained malware

#270
post #134

Transmission put up a new version - 2.92 that supposedly checks for and removes the malware.

Threw away Transmission as soon as I read this (even though I was running a old version), my trust is pretty much gone now, never installing it again. Shame because it really was a nice app.

I don't understand this attitude, the Transmission team responded immediately to the problem. There's no indication that this was the result of some problem specific to the application or its developers.

Transmission was and remains my favorite torrent client on OS X, although I still like the torrent information presentation uTorrent had, and I still will run my old pre-adware 1.6.4 if I want more detail on a swarm.

Given that older versions still work, it seems exceptionally silly to delete an old version because of a site compromise.

Post reply on HN