Live data from Hacker News

Symantec found evidence of Longhorn against 40 targets spread in 16 countries

symantec.com

31–40 of 49 posts

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#31

It's nice that Symantec has shared this info but their attempt at neutrality is frustrating. Based on their data they could easily state that Longhorn is a CIA group. They also didn't provide any links to WikiLeaks for people to learn more about what Vault 7 is.

How is this even neutrality at this point? And what is there even to attempt? It is ridiculous and serves no purpose that they do not write "CIA" once.

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#32
post #28

> [Longhorn] has used a range of back door Trojans in addition to zero-day vulnerabilities to compromise its targets. I genuinely don't see the added value of antivirus corporations in this or anywhere else. Better tactics are: - patch - educate wife and children

My wife has a PhD and ran up to date Firefox with noscript, Flash disabled, and ad-blockers, uses webmail, and doesn't install software or download executables in general. She still got hacked, due to a bug in Firefox that was exploited despite having noscript and Flash disabled. How, exactly, would you have educated her?

Real question: what kind of website she visited to get such infection? It's quite uncommon (even though theoretically an existing risk pretty much everywhere, and probably even not that hard to do if you control a website)

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#33
post #7

Earlier quoted context omitted.

- Don't run day to day with local admin

Many people say that the first thing they do is disable UAC. One person even told me that people who know what they are doing disable UAC. Not sure what to think of these people

UAC is arguably better than nothing but: it was designed to run at max level (the only available one in Vista, where it was introduced). Because the UX hindrance was too high MS added intermediate levels, but without evolving the whole design from a security model point of view. The result is so weak that MS simultaneously started to declare that UAC is not a security boundary, so they don't have to include comprehensive fixes in each security patch, only partial ones in system upgrades, when they feel like it.

https://github.com/hfiref0x/UACME currently references 8 unfixed bypasses. That's so high that I don't think this is reserved for targeted infection; it might very well happen in common malware.

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#34

Too bad it's not like Microsoft's Longhorn - then it would have been delivered years late as a shadow of it's promised self (Vista) ;)

Yeah, when I read the headline I was puzzled. "What has a canned MS project got to do with Symantec?"

God I'm so old.

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#35
post #28

Earlier quoted context omitted.

My wife has a PhD and ran up to date Firefox with noscript, Flash disabled, and ad-blockers, uses webmail, and doesn't install software or download executables in general. She still got hacked, due to a bug in Firefox that was exploited despite having noscript and Flash disabled. How, exactly, would you have educated her?

Real question: what kind of website she visited to get such infection? It's quite uncommon (even though theoretically an existing risk pretty much everywhere, and probably even not that hard to do if you control a website)

reddit, imgur, news sites. It was via an ad delivered over an ad network, so who knows really.

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#36
post #27

Symantec's board should be hung for treason for developing and distributing weapons that eliminate American warfare capabilities.

Let's please not go there, here.

https://news.ycombinator.com/newswelcome.html

https://news.ycombinator.com/newsguidelines.html

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#37

It's nice that Symantec has shared this info but their attempt at neutrality is frustrating. Based on their data they could easily state that Longhorn is a CIA group. They also didn't provide any links to WikiLeaks for people to learn more about what Vault 7 is.

Would they want to know for absolute certain the source of it, or if they did know, would they want to acknowledge that? Suppose it is from the CIA, they acknowledge it, and then add removal of it to their tools. They (NASDAQ-listed public company) would have then just knowingly acknowledged interfering with the activities of the intelligence agency in the country in which they operate.

I think it's smart for Symantec to remain completely neutral and unassuming.

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#38
post #28

> [Longhorn] has used a range of back door Trojans in addition to zero-day vulnerabilities to compromise its targets. I genuinely don't see the added value of antivirus corporations in this or anywhere else. Better tactics are: - patch - educate wife and children

My wife has a PhD and ran up to date Firefox with noscript, Flash disabled, and ad-blockers, uses webmail, and doesn't install software or download executables in general. She still got hacked, due to a bug in Firefox that was exploited despite having noscript and Flash disabled. How, exactly, would you have educated her?

By telling her to wait for the man to come home and fix the computer, if I'm reading that comment correctly. (I hope I'm not.)

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#39
post #35

Earlier quoted context omitted.

Real question: what kind of website she visited to get such infection? It's quite uncommon (even though theoretically an existing risk pretty much everywhere, and probably even not that hard to do if you control a website)

reddit, imgur, news sites. It was via an ad delivered over an ad network, so who knows really.

Sounds like the kind of thing that could get anybody, even a reasonably paranoid person.

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#40
post #35

Earlier quoted context omitted.

Real question: what kind of website she visited to get such infection? It's quite uncommon (even though theoretically an existing risk pretty much everywhere, and probably even not that hard to do if you control a website)

reddit, imgur, news sites. It was via an ad delivered over an ad network, so who knows really.

How come the adblocker didn't block the ad network?
Post reply on HN