Live data from Hacker News

Researchers crack open malware that hid for 5 years

arstechnica.com

221–230 of 232 posts

Re: Researchers crack open malware that hid for 5 years

#221

Earlier quoted context omitted.

Make it a button, so the customer can apply updates, but they need to press a button to make it happen. Add another button which, using only software stored in ROM, reloads the firmware from ROM. Then you have updates, but only when the customer knows and wants it, and if they ever screw it up then they can get back to a known good state.

The customer has no way of knowing whether they are installing genuine update, or MITM-modified malicious update. Public key cryptography solves that but then you have a problem how to protect the keys and crypto algorithms from tampering. Update buttons ain't a good replacement for TPM hardware.

It's an enormously harder problem to convince the customer to push the "update firmware" button on the front panel than it is to insert malware remotely without any action or knowledge on the customer's part.

Re: Researchers crack open malware that hid for 5 years

#222

Earlier quoted context omitted.

Are you including the capability to control it over a network? Burning potentially unfixable 0-day exploits into ROM would probably be a non-starter.

If you can update the firmware over a network, you have an uncloseable exploit vector. ROMs are not unfixable. They do require physical access, though, which eliminates nearly all of the risk.

Even if those updates require signature verification with a public key stored in ROM? I guess the signing key cold get out or you could patch the firmware to skip the signature check (the way the initial iPhone was jailbroken)

Re: Researchers crack open malware that hid for 5 years

#223

Earlier quoted context omitted.

What do you mean "attack"? Is there some specific harm being done that you want to protect against? Breach of defenses isn't itself an attack. A foreign agent inside your castle isn't an attacker until they start stabbing people, right? I'm not personally worried about what Chinese and Russian hackers know about me, because none of that information is particularly useful for taking valuables from me. I am curious wha…

How do you assume that the information isn't useful? That implies that all your valuables are fully isolated from the digital world - really? I really have trouble understanding the "I have nothing to hide" attitude. What's the difference to saying "there is this guy always standing in the corner of my living room, but I'll just assume he's benign..."

Well I would notice if something valuable to me is taken.

Re: Researchers crack open malware that hid for 5 years

#225

Earlier quoted context omitted.

And that's why you can still buy new i7 and Xeon motherboards with PS2 keyboard connectors--because some sites don't want there to be USB ports on the computers.

My computer is locked in a mesh cage anyway. Well, the thin client is.

That's another great idea! Like the cages around thermostats!

Re: Researchers crack open malware that hid for 5 years

#226
post #207

Earlier quoted context omitted.

SUSE is owned by Novell.

Not anymore, IIRC. When Novell was acquired by ... that company whose name I forgot (AttachMate?), SUSE was spun off as an independent company again. At least that is how I remember it.

Yeah it seems things have gotten a bit more complicated than i remembered.

Novell bought Suse, then Novell merged with Attachemate, in the process Suse became a business unit (wholly owned company?) under Attachemate, then there was a merger between Attachemate and Micro Focus in 2014.

Anyways, i suspect that as Suse is FOSS, and was initially Germany based, and now is UK based, both being NATO allies, that DOD has few issues with continued usage.

Re: Researchers crack open malware that hid for 5 years

#227

Earlier quoted context omitted.

There's also value in being able to visually inspect it and say "Yep, that USB port's disabled" versus digging through EFI settings. Every motherboard is going to have that option in a slightly different place, but if you can put epoxy in one USB port you're pretty well set for any piece of hardware.

This scales to ${number_of_devices_you_can_see}. A hundred or more? Easier to manage remotely. You're also likely to have a very limited number of models in that case.

One thing to keep in mind is that the kind of place which cares about things this much tends to be the kind of place which can hire staff — and it's a lot cheaper to hire technicians who can verify that epoxy plug than the security engineers who can confirm that you've done everything right in software.

Consider another instance of the problem: verifying that your webcam isn't being used to spy on you. Since a surprising number of hardware designers were negligent and made that software controllable it is orders of magnitude easier to simply deploy a piece of tape than try to prove that malware hasn't disabled the status LED:

http://security.stackexchange.com/questions/6758/can-webcams... http://blog.erratasec.com/2013/12/how-to-disable-webcam-ligh...

How much skill and diligence does it take to confirm that you have disabled the controller using each manufacturer's interface (if they even have one documented), that there isn't some way to re-enable it later (or that something like a sleep/resume cycle didn't reset the controller), and that all of that continues to be true for every subsequent configuration change or software/firmware update?

I would suggest that any organization with this level of risk would be better off paying someone $15/hour to check the ports along with the rest of their physical status checks and put the security engineers in charge of other improvements with a higher return.

Re: Researchers crack open malware that hid for 5 years

#228

Earlier quoted context omitted.

If you just leave away the USB mass storage kernel module when compiling the kernel, the mass storage device won't work anymore while the mouse still works. I wonder if this is a solution to this problem or not since it seems quite naive.

Any USB device gets to be a keyboard and mouse. If it comes down to it, the device could just "type" its payload.

And if that malware can't liberate USB access, and still needs to read data (rather than just writing it), it could exploit the capacity for various devices to emit detectable EM radiation. The fake keyboard/mouse, being inside the Faraday cage, would be able to sense that radiation and extract data that the malware in its payload sends back to it.

In fact, all of this would work equally well with a PS/2 port.

Re: Researchers crack open malware that hid for 5 years

#229

Earlier quoted context omitted.

The customer has no way of knowing whether they are installing genuine update, or MITM-modified malicious update. Public key cryptography solves that but then you have a problem how to protect the keys and crypto algorithms from tampering. Update buttons ain't a good replacement for TPM hardware.

It's an enormously harder problem to convince the customer to push the "update firmware" button on the front panel than it is to insert malware remotely without any action or knowledge on the customer's part.

It’s enormously easier problem to exploit a well-known remote code execution vulnerability, that’s unpatched because updates are too easy to ignore.

For the end user, it’s extremely easy to NOT push that button.

Re: Researchers crack open malware that hid for 5 years

#230
post #114
post #80

Earlier quoted context omitted.

Russia, Iran, Rwanda... Let's assume the latter is a vector, not the target. (The attacker is sophisticated enough that we can assume Rwanda itself is of little interest). Rwanda also has fairly close ties to Russia, which strengthens the vector hypothesis. Russia+Iran suggests a western actor. Their biggest shared interest is Syria, I'd think. And look, the Syrian conflict is on since March '11, and the activity acc…

> and also isn't friends with Iran or Russia Actually Israel is on very friendly terms with Russia. There are a ton of Russian immigrants in Israel to the point that Putin called them "Russian ambassadors". It didn't start that way - part of the history of the creation of the modern state of Israel is Russia vs US proxy conflict (of sorts) via Egypt. But it's not like that anymore, not for a long time. (The US and Ru…

While I'm not a proponent of the idea that Israel is behind this malware, I disagree with you. Israel is not on particularly good terms with Russia. Yes, the two governments have established a hotline to ensure that Russian military maneuvers in Syria are not misinterpreted, but the two countries are closer to foes with a mutually accepted cold peace. It's in the strategic interests of each country not to be outwardly hostile to one another, but they're definitely adversaries in many respects.
Post reply on HN