Live data from Hacker News

Proton.B: What this Mac malware does

cybereason.com

31–40 of 94 posts

Re: Proton.B: What this Mac malware does

#31

Earlier quoted context omitted.

And maybe dim the background, as wel as giving information about the creator of the application and if its codesigned. oh wait, that was too obtrusive and annoying

Not sure if you're being sarcastic about how users feel or about that kind of configuration for UAC, but personally it's one of the many things I dislike when I'm on a Windows computer. For power users it's annoying and disruptive. For users that might benefit the most from it they quickly learn to press ok always whenever they are prompted for something, no matter what it's asking. In my opinion, an ideal OS would h…

> For power users it's annoying and disruptive

Let me stop you right there. As a sysadmin, UAC is both effective as it is necessary. I absolutely don't want any application a user can launch with a mere YES/NO prompt but proper secondary credentials, interactively or by some nefarious app spawning other processes, to have the ability to gain an administrative level of access over the local machine. Unless it's absolutely necessary (which in most cases, it's not!).

"Power Users" are, in my experience, an annoyance at the corporate level and especially at home when they bomb their system so badly that it requires reinstalling the OS every few months.

However your other points raise a good standard and I'd like to specifically mention one I really want to see in Desktop OS's. That app sandboxing for every "feature" accessed should be a whitelisted (by asking for permission) endeavor. It should request access to the file system (only for those directories in its specific needs), calendar, contacts, network access, looking into other apps (themselves or their access to the file system), network access, etc.

Re: Proton.B: What this Mac malware does

#32
"Dialog boxes asking for passwords are a very popular social engineering tactic designed to trick users into giving attackers their passwords"

Apple is extremely guilty of normalizing the frequent entry of passwords. I recently reinstalled a Mac and an iPad, and for each device I must've entered my Apple ID password seven or eight times. in the normal course of getting things done I then enter either this, or my local login password, many times a week.

When your password is twenty characters of line noise or an extended passphrase this is thoroughly irksome, especially on virtual keyboards like the iPad. It is no surprise to me that less security conscious folks, faced with this onslaught of excessive credential demand, choose shorter i.e. easily cracked passwords; and no surprise that everyone becomes less suspicious of the sham password dialog.

So when reading of yet another photographic burglary from a cracked iCloud account, we should always lay part of the blame at Apple's feet, for systematically normalizing the frequent entry of credentials.

That is not the end of Apple's social engineering enablement shame. Another glaring blunder is in Apple Mail, where the "To:" field is shown with your real name, even when the sender did not include this. The humans respond positively to the use of their given name, so this heightens the verisimilitude of scam messages.

Re: Proton.B: What this Mac malware does

#33

"Dialog boxes asking for passwords are a very popular social engineering tactic designed to trick users into giving attackers their passwords" Apple is extremely guilty of normalizing the frequent entry of passwords. I recently reinstalled a Mac and an iPad, and for each device I must've entered my Apple ID password seven or eight times. in the normal course of getting things done I then enter either this, or my loca…

Yup. My Apple password is one of the very few remaining ones that isn't a random string generated by 1Password because Apple makes me enter it all the time. :(

Re: Proton.B: What this Mac malware does

#34

The standard macOS password prompt surely needs to change. It's become too familiar and I'm sure I've filled it in hastily before without wondering why or what for. It needs to be implemented in a way that is impossible for nefarious apps to replicate.

What I would love to see is a reason. Any program that requests elevated privileges should have to state to me why it wants those privileges. It's really frustrating to get this dialog pop up and have no idea what it's doing.

Re: Proton.B: What this Mac malware does

#35
post #33

"Dialog boxes asking for passwords are a very popular social engineering tactic designed to trick users into giving attackers their passwords" Apple is extremely guilty of normalizing the frequent entry of passwords. I recently reinstalled a Mac and an iPad, and for each device I must've entered my Apple ID password seven or eight times. in the normal course of getting things done I then enter either this, or my loca…

Yup. My Apple password is one of the very few remaining ones that isn't a random string generated by 1Password because Apple makes me enter it all the time. :(

"For your protection".

I agree, the number of times per week that I somehow end up entering my Apple ID password is egregious. Couple that with the abysmal iCloud/Apple ID/iPhone number conflicts that inevitably show up when you have more than one device. I've spent more hours than I care to remember working on my parents' devices fixing glitchy synchs.

Re: Proton.B: What this Mac malware does

#37
post #5

Does the Mac have any ability to warn when someone attempts to install malicious software, other than the usual warnings about unsigned software? Windows 10, for example, will scan every attachment before opening it, catching a lot of stuff before it can do any harm.

"scan everything before opening" is not always desirable as it exposes a large attack surface: https://bugs.chromium.org/p/project-zero/issues/detail?id=12...

"Avoid running your scan with elevated privileges" could have greatly mitigated this failure.

> NScript is the component of mpengine that evaluates any filesystem or network activity that looks like JavaScript. To be clear, this is an unsandboxed and highly privileged JavaScript interpreter that is used to evaluate untrusted code, by default on all modern Windows systems. This is as surprising as it sounds.

Re: Proton.B: What this Mac malware does

#38
Just a reminder when discussing any item with Mac in the title. Please make sure not to make any comments related to the content of the item. Please restrict yourself to noting how bad Apple and Mac are, and how you have spent the last 6 months working full time to build a Huckintosh that almost works except that you have to sacrifice a chicken on the keyboard to get WiFi to work. Extra points if you can reference irrelevant Steve Jobs references.

Re: Proton.B: What this Mac malware does

#39

"Dialog boxes asking for passwords are a very popular social engineering tactic designed to trick users into giving attackers their passwords" Apple is extremely guilty of normalizing the frequent entry of passwords. I recently reinstalled a Mac and an iPad, and for each device I must've entered my Apple ID password seven or eight times. in the normal course of getting things done I then enter either this, or my loca…

You people are doing something seriously wrong. About the only time I need to enter iCloud credentials is when I reboot my system, which is maybe once a month, or buy something. Complaining about credential entry on a new device install in this context is also kind of irrelevant, this malware doesn't strike during a new OS update.

Re: Proton.B: What this Mac malware does

#40

The standard macOS password prompt surely needs to change. It's become too familiar and I'm sure I've filled it in hastily before without wondering why or what for. It needs to be implemented in a way that is impossible for nefarious apps to replicate.

I think that's what TouchID is supposed to solve.
Post reply on HN