Live data from Hacker News

Researchers crack open malware that hid for 5 years

arstechnica.com

1–10 of 232 posts

Re: Researchers crack open malware that hid for 5 years

#5

That is a really impressive piece of software. USB exfiltration of data on air gapped machines is next level. I'm in awe of their skill.

And they had every login for the network it was found on:

"The library was masquerading as a Windows password filter, which is something administrators typically use to ensure passwords match specific requirements for length and complexity. The module started every time a network or local user logged in or changed a password, and it was able to view passcodes in plaintext."

Re: Researchers crack open malware that hid for 5 years

#6
Some security professionals have expressed the view that insecure endpoints represent a good compromise. That is, without the US government being able to snoop on endpoint devices, encryption would have to be tightly controlled, so that the government could retain intelligence and investigatory capability.

A more cynical view would be that many security firms sell both security and forensics/surveillance. One of those two product lines has to be fundamentally defective.

Is the position that hackable endpoints are a good compromise supportable any longer? Or has it bitten US entities in the ass enough that making truly secure computing a reality for computer users, even if it blinds the surveillance state, becomes the new goal.

Re: Researchers crack open malware that hid for 5 years

#7

That is a really impressive piece of software. USB exfiltration of data on air gapped machines is next level. I'm in awe of their skill.

Can you clarify what exactly is so impressive about this software? I read the article, and I don't see it.

Re: Researchers crack open malware that hid for 5 years

#8
post #4
post #2

Some at the NSA is having a bad day reading this.

The article says it was first deployed in 2011. Five years is a pretty good run. I wonder what they're deploying right now?

Now they are in the SMC and the secure enclave.

Re: Researchers crack open malware that hid for 5 years

#9
post #5

That is a really impressive piece of software. USB exfiltration of data on air gapped machines is next level. I'm in awe of their skill.

And they had every login for the network it was found on: "The library was masquerading as a Windows password filter, which is something administrators typically use to ensure passwords match specific requirements for length and complexity. The module started every time a network or local user logged in or changed a password, and it was able to view passcodes in plaintext."

Perhaps time to move to 2FA.

Re: Researchers crack open malware that hid for 5 years

#10
post #6

Some security professionals have expressed the view that insecure endpoints represent a good compromise. That is, without the US government being able to snoop on endpoint devices, encryption would have to be tightly controlled, so that the government could retain intelligence and investigatory capability. A more cynical view would be that many security firms sell both security and forensics/surveillance. One of thos…

I've often heard not that "insecure endpoints represent a good compromise" but instead that since:

1. endpoints are vulnerable because they are exceptionally hard to secure,

2. and attacking endpoints can be targeted and specific,

the governments case that weakening encryption is necessary for warranted search is weak. Even with strong encryption the government can exploit the targeted communicant's endpoint to learn either the plaintext or the encryption keys. This isn't a compromise so much as a statement of reality and what is likely to remain reality for some time to come. Weakening encryption, for the most part, provides benefits to the government in the form of mass surveillance, but for a variety of reasons doesn't offer much benefit in the form of limited, specific searches.

>making truly secure computing a reality for computer users,

We can make endpoints more secure, but I see no path to endpoint security that will keep out a determined well resourced adversary.

Post reply on HN