Live data from Hacker News

Researchers crack open malware that hid for 5 years

arstechnica.com

151–160 of 232 posts

Re: Researchers crack open malware that hid for 5 years

#151
post #40

Interesting regarding USB devices. When US DoD systems were infected with a virus someone brought from home on a USB stick, I remember hearing there were going around filling USB ports with epoxy. There was some method behind the madness I guess. There is also a market for routers and other devices which are produced as much as possible in US (are they rolling their own capacitors I am wondering...). I saw some of th…

Part of the reason that Windows is an approved OS is enterprise support. When you pay for hundreds of thousands of licenses for a product you can demand features. If the DoD went with Debian they would need an entire corps of developers to maintain government specific patches. Ubuntu offers enterprise support but it's from an African country and that is undesirable as you mentioned above. I've seen government systems…

Like Germany isn't an extension of the USA. Only Russians got kicked out of there...

Re: Researchers crack open malware that hid for 5 years

#152
post #40

Interesting regarding USB devices. When US DoD systems were infected with a virus someone brought from home on a USB stick, I remember hearing there were going around filling USB ports with epoxy. There was some method behind the madness I guess. There is also a market for routers and other devices which are produced as much as possible in US (are they rolling their own capacitors I am wondering...). I saw some of th…

>filling USB ports with epoxy This seems apocryphal. Its trivial to disable USB for a mass storage (or all devices) via things like group policy or other security controls. Or disable the controller. Those USB ports aren't perfect boxes, the epoxy would just run out all over the place. More than likely you'd have an OS-level security policy and bios block, which is trivial to do in a managed environment. I hear this…

well the thing is i dont know if you know it foxconn builds your ciscos i only know cause i worked installing fiber in the plant they have in houston its one of a number in the US. in there i saw lots of chinese ladies putting together made-to-order cisco switches of all sizes with boards i assume were made in china. oh dont get me wrong the americans worked in sales out front. :)

Re: Researchers crack open malware that hid for 5 years

#153
post #104
post #60

Earlier quoted context omitted.

> By analogy, there's a reason that many ancient cities were circled by a wall. Walls around cities were likely very poor at stopping small, stealthy groups of infiltrators. They were designed for much more brute force attacks. Apple's walled garden helps quite a bit with the deluge of crap that would be available without it. Without it there would be an order of magnitude more crap (in quantity and quality). That sa…

Devil's advocate, walls and the enablement of taxation also centralized capital and enabled cities to spend it on public works that might not have been built otherwise (and before I get the "then they shouldn't!" retort, I think we can all agree there are shared infrastructure resources that w/couldn't be built by private actors). In a world where all phones are loosely controlled Android derivates competing on slim…

> Devil's advocate, walls and the enablement of taxation

Sure. I wasn't making a case that taxation at the wall is bad, but that it has the capability to be bad. We use regulation in (mostly) free markets to greater or lesser success to steer the markets in some manner. If you accept that pure capitalism doesn't necessarily yield an optimally performing system when people are involved, then that ability to influence the market is a useful capability, especially when applied judiciously. A blanket rate isn't necessarily the most efficient form of that, but it is a way to raise revenue.

> In a world where all phones are loosely controlled Android derivates

I think you've already stacked the starting conditions to the point where it's not really worthwhile to consider. That situation would be ripe for disruption in some manner, because I think it's inherently unstable. All it takes is a small niche market for alternatives that do make choices based on privacy, or security, and events that spur interest in those topics, and the larger population of providers will need to respond appropriately or risk ceding a increasingly large portion of the market to those that do.

Re: Researchers crack open malware that hid for 5 years

#154
post #106

Earlier quoted context omitted.

Too many people without security clearance can access and modify Linux. In any real security environment, open-source is poison. Period, end of story.

So you trust the black boxes someone sold you?

The opposite of “open source” isn't “black box”.

Re: Researchers crack open malware that hid for 5 years

#155
post #40

Interesting regarding USB devices. When US DoD systems were infected with a virus someone brought from home on a USB stick, I remember hearing there were going around filling USB ports with epoxy. There was some method behind the madness I guess. There is also a market for routers and other devices which are produced as much as possible in US (are they rolling their own capacitors I am wondering...). I saw some of th…

Part of the reason that Windows is an approved OS is enterprise support. When you pay for hundreds of thousands of licenses for a product you can demand features. If the DoD went with Debian they would need an entire corps of developers to maintain government specific patches. Ubuntu offers enterprise support but it's from an African country and that is undesirable as you mentioned above. I've seen government systems…

SUSE is owned by Novell.

Re: Researchers crack open malware that hid for 5 years

#156
post #106

Earlier quoted context omitted.

Too many people without security clearance can access and modify Linux. In any real security environment, open-source is poison. Period, end of story.

So security through obscurity?

Or maybe security through, you know, actual security.

Closed source does not mean obscurity–– and open source does not mean clarity (see OpenSSL, that one Linux 2.6 thing¹, etc).

It's not like being proprietary suddenly means the only security is through obscurity. Why do you think that? Are you just a zealot? Did you not consider that closed source software could be well-engineered and secure? You're welcome to read about some of the security features in Windows NT² (that article is a bit old but still relevant), which are considerably more thorough than (non-SE)Linux (I think SELinux has auditing now, so it's at least comparable to NT).

Now, don't get me wrong, I generally prefer open-source tools (for a variety of reasons) and tend to trust them more, but saying stupid stuff like you are just gives open source a bad name.

On top of that, obscurity is a perfectly valid layer of security. To use a mediocre analogy, of course you want your safe to be strong enough that nobody could break in even if it's in plain sight—but it's certainly not a bad idea to hide the safe as well.

¹ https://lwn.net/Articles/341773/

² https://www.microsoft.com/resources/documentation/windowsnt/...

Re: Researchers crack open malware that hid for 5 years

#157

Earlier quoted context omitted.

> This seems apocryphal. Its trivial to disable USB for a mass storage (or all devices) via things like group policy or other security controls. Or disable the controller. The question is - where do you stop? The controller could be re-enabled from a lower level, etc. The rabbit hole goes very deep. Sometimes it's best to just take control of the physical layer and call it a day. > Those USB ports aren't perfect boxe…

> Sometimes it's best to just take control of the physical layer and call it a day. If you want to stop your every day user from plugging in USB drives then this is probably all you need to do. In a scenario where you're concerned about insider threats with even a minimal level of computing knowledge, you have to lock down the BIOS and the OS layer as well. "Oh the IT guy put epoxy in the USB ports, guess I'll just t…

Case intrusion sensors are a thing. And i swear i have seen cases with loops for padlocks.

Re: Researchers crack open malware that hid for 5 years

#158

Earlier quoted context omitted.

I'm definitely an advocate of open source myself, and I never thought I'd be considering the other side's arguments. It's just that I see major data/security breaches increasing in the news, along with stories (like this one) about cyber-offensive capabilities growing more and more powerful. In the InfoSec world, it seems like anything is hackable, and the balance of power firmly lies with offensive tools. I'm just s…

What do you mean "attack"? Is there some specific harm being done that you want to protect against? Breach of defenses isn't itself an attack. A foreign agent inside your castle isn't an attacker until they start stabbing people, right? I'm not personally worried about what Chinese and Russian hackers know about me, because none of that information is particularly useful for taking valuables from me. I am curious wha…

I'm concerned about industrial espionage: http://www.cnbc.com/2015/10/19/china-hacking-us-companies-fo...

Also at personal risk is anyone with a US security clearance: https://www.washingtonpost.com/news/federal-eye/wp/2015/07/0...

Re: Researchers crack open malware that hid for 5 years

#159
post #154

Earlier quoted context omitted.

So you trust the black boxes someone sold you?

The opposite of “open source” isn't “black box”.

Not the person you're replying to but opposite of open source is closed source, and isn't that basically a black box to you since you don't know what it's doing?

Is there something more subtle I'm missing?

Re: Researchers crack open malware that hid for 5 years

#160
post #41

> The researchers went on to speculate that the project was funded by a nation-state, but they stopped short of saying which one. So ... does anyone, perhaps who doesn't have Kaspersky's business interests to protect, care to actually speculate? In other cases it's been seemingly well-known in the security community which APT attacks trace back to which countries, it's just apparently impolite to say it in public.

Kaspersky has significant ties to the Russian government, so presumably some nation-state who Russia opposes.

This likely means the USA, a US ally like Israel, or a growing power such as China or India.

But the USA is the most likely candidate.

Post reply on HN