Live data from Hacker News

Researchers crack open malware that hid for 5 years

arstechnica.com

101–110 of 232 posts

Re: Researchers crack open malware that hid for 5 years

#101
post #40

Interesting regarding USB devices. When US DoD systems were infected with a virus someone brought from home on a USB stick, I remember hearing there were going around filling USB ports with epoxy. There was some method behind the madness I guess. There is also a market for routers and other devices which are produced as much as possible in US (are they rolling their own capacitors I am wondering...). I saw some of th…

>filling USB ports with epoxy This seems apocryphal. Its trivial to disable USB for a mass storage (or all devices) via things like group policy or other security controls. Or disable the controller. Those USB ports aren't perfect boxes, the epoxy would just run out all over the place. More than likely you'd have an OS-level security policy and bios block, which is trivial to do in a managed environment. I hear this…

> This seems apocryphal. Its trivial to disable USB for a mass storage (or all devices) via things like group policy or other security controls. Or disable the controller.

The question is - where do you stop? The controller could be re-enabled from a lower level, etc. The rabbit hole goes very deep. Sometimes it's best to just take control of the physical layer and call it a day.

> Those USB ports aren't perfect boxes, the epoxy would just run out all over the place.

Epoxy putty would work pretty well, and it's widely available.

Re: Researchers crack open malware that hid for 5 years

#102

Earlier quoted context omitted.

>filling USB ports with epoxy This seems apocryphal. Its trivial to disable USB for a mass storage (or all devices) via things like group policy or other security controls. Or disable the controller. Those USB ports aren't perfect boxes, the epoxy would just run out all over the place. More than likely you'd have an OS-level security policy and bios block, which is trivial to do in a managed environment. I hear this…

> This seems apocryphal. Its trivial to disable USB for a mass storage (or all devices) via things like group policy or other security controls. Or disable the controller. The question is - where do you stop? The controller could be re-enabled from a lower level, etc. The rabbit hole goes very deep. Sometimes it's best to just take control of the physical layer and call it a day. > Those USB ports aren't perfect boxe…

There's also value in being able to visually inspect it and say "Yep, that USB port's disabled" versus digging through EFI settings.

Every motherboard is going to have that option in a slightly different place, but if you can put epoxy in one USB port you're pretty well set for any piece of hardware.

Re: Researchers crack open malware that hid for 5 years

#103

Earlier quoted context omitted.

>filling USB ports with epoxy This seems apocryphal. Its trivial to disable USB for a mass storage (or all devices) via things like group policy or other security controls. Or disable the controller. Those USB ports aren't perfect boxes, the epoxy would just run out all over the place. More than likely you'd have an OS-level security policy and bios block, which is trivial to do in a managed environment. I hear this…

> This seems apocryphal. Its trivial to disable USB for a mass storage (or all devices) via things like group policy or other security controls. Or disable the controller. The question is - where do you stop? The controller could be re-enabled from a lower level, etc. The rabbit hole goes very deep. Sometimes it's best to just take control of the physical layer and call it a day. > Those USB ports aren't perfect boxe…

Or to put it another way: "ensuring you've secured all hardware and software exploits in your stack from top to bottom" vs "epoxy and focus on network exploits". Don't knock physical security.

Re: Researchers crack open malware that hid for 5 years

#104
post #60

Apple's walled garden has been subjected to criticism from open source advocates. And Windows 10's telemetry triggers a lot of privacy concerns, too. But in our current security environment, what if these walls become necessary for secure computing? By analogy, there's a reason that many ancient cities were circled by a wall.

> By analogy, there's a reason that many ancient cities were circled by a wall. Walls around cities were likely very poor at stopping small, stealthy groups of infiltrators. They were designed for much more brute force attacks. Apple's walled garden helps quite a bit with the deluge of crap that would be available without it. Without it there would be an order of magnitude more crap (in quantity and quality). That sa…

Devil's advocate, walls and the enablement of taxation also centralized capital and enabled cities to spend it on public works that might not have been built otherwise (and before I get the "then they shouldn't!" retort, I think we can all agree there are shared infrastructure resources that w/couldn't be built by private actors).

In a world where all phones are loosely controlled Android derivates competing on slim profit margins, is anyone going to make the drive for hard hardware-enabled crypto? And even if they wanted to, could they afford it?

Re: Researchers crack open malware that hid for 5 years

#105
What's with all this nonsense about could have "been developed only with the active support of a nation-state"? Do nations suddenly have access to some sort of advanced, alien software development teams?

Feels more like political sabre-rattling to get the public to eventually condone a future attack from our homeland shores of Oceania against the evil Eastasia or Eurasia.

Re: Researchers crack open malware that hid for 5 years

#106
post #40

Interesting regarding USB devices. When US DoD systems were infected with a virus someone brought from home on a USB stick, I remember hearing there were going around filling USB ports with epoxy. There was some method behind the madness I guess. There is also a market for routers and other devices which are produced as much as possible in US (are they rolling their own capacitors I am wondering...). I saw some of th…

Too many people without security clearance can access and modify Linux. In any real security environment, open-source is poison. Period, end of story.

Re: Researchers crack open malware that hid for 5 years

#107
post #105

What's with all this nonsense about could have "been developed only with the active support of a nation-state"? Do nations suddenly have access to some sort of advanced, alien software development teams? Feels more like political sabre-rattling to get the public to eventually condone a future attack from our homeland shores of Oceania against the evil Eastasia or Eurasia.

I believe it's less about fear mongering and more about understanding the level of sophistication of the software. Talk to anti malware analyst and they'll tell you how commoditized the malware game is nowadays. There's an endless stream of malware and ransomware which can be linked back to just a handful of frameworks. These types of malware families also fall under the spray-n-pray mentality for distribution. Spam, drive-by-downloads, infected torrents, etc.

Compare the mass of malware that is out there with the level of technical sophistication, OPSEC to prevent detection, and precise targeting of its victims. Along with other big name malwares (i.e. Stuxnet, Flame, etc.), this class of malware is very precise in its objective. It isn't trying to make money for its owners. It isn't trying to replicate itself across the internet endlessly. Rather it has a key objective of infecting a specific set of networks. So when researchers call out the fact that it is likely to be "state sponsored", they are saying the purpose of the malware is very different than your average piece of malware.

Re: Researchers crack open malware that hid for 5 years

#108
post #106
post #40

Interesting regarding USB devices. When US DoD systems were infected with a virus someone brought from home on a USB stick, I remember hearing there were going around filling USB ports with epoxy. There was some method behind the madness I guess. There is also a market for routers and other devices which are produced as much as possible in US (are they rolling their own capacitors I am wondering...). I saw some of th…

Too many people without security clearance can access and modify Linux. In any real security environment, open-source is poison. Period, end of story.

^ As if any amount of security clearance can erase human fallibility.

In any real security environment, humans are poison. Period, end of story. This is not an issue exclusive to open-source.

Re: Researchers crack open malware that hid for 5 years

#109
post #105

What's with all this nonsense about could have "been developed only with the active support of a nation-state"? Do nations suddenly have access to some sort of advanced, alien software development teams? Feels more like political sabre-rattling to get the public to eventually condone a future attack from our homeland shores of Oceania against the evil Eastasia or Eurasia.

I believe it's less about fear mongering and more about understanding the level of sophistication of the software. Talk to anti malware analyst and they'll tell you how commoditized the malware game is nowadays. There's an endless stream of malware and ransomware which can be linked back to just a handful of frameworks. These types of malware families also fall under the spray-n-pray mentality for distribution. Spam,…

Essentially depending on what malware does we can easily identify government software because criminal software has a different set of objectives. Is it possible though that corporate software could have similar objectives? I'm thinking corporate espionage type behaviour.

Re: Researchers crack open malware that hid for 5 years

#110
post #105

What's with all this nonsense about could have "been developed only with the active support of a nation-state"? Do nations suddenly have access to some sort of advanced, alien software development teams? Feels more like political sabre-rattling to get the public to eventually condone a future attack from our homeland shores of Oceania against the evil Eastasia or Eurasia.

I believe it's less about fear mongering and more about understanding the level of sophistication of the software. Talk to anti malware analyst and they'll tell you how commoditized the malware game is nowadays. There's an endless stream of malware and ransomware which can be linked back to just a handful of frameworks. These types of malware families also fall under the spray-n-pray mentality for distribution. Spam,…

[deleted]
Post reply on HN