Live data from Hacker News

FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

twitter.com

41–50 of 76 posts

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#41
post #40

Earlier quoted context omitted.

It's far smoother.

What protocol do you notice this with? In my experience, Microsoft RDP (the only protocol I know with configurable udp and tcp) with and without udp is imperceptible during typical use (eg. server administration).

With RDP. It's not imperceptible for me. I don't just use RDP for server administration.

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#42
post #39
post #18

Earlier quoted context omitted.

check out the *.pixel.archive.is lookups

Fascinating, they embed a tracking pixel of: http://onion.[SOME_NUMERIC_ID].pixel.archive.today/pixel.gif for Tor endpoint (archivecaslytosk.onion) connections but https:// [YOUR_IP].[COUNTRY_CODE].[SHORT_ALPHANUMERIC_ID].[SOME_NUMERIC_ID].pixel.archive.is/pixel.gif for regular (archive.is/archive.fo/archive.today/etc) connections. So at least this lets archive.is correlate your IP with your DNS server (which must pa…

There is something weird going on - both demanding the EDNS detail and then the extra tracking. I'm happy to avoid them using cloudflare's privacy stuff.

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#43
post #24
post #21

Speaking of TeamViewer, do you know a good open source alternative that I can self host (I mean self host the relay server for NAT traversal). That is as easy to use? Works on windows, mac and linux? It should also be installable in a few slick with no network configuration required.

I've been looking at a combination of SoftEther (for dynamic IPs) and Guacamole to replace TeamViewer, ConnectWise, etc.

I also use Guacamole for remote employee/vendor access (with public IPs hidden behind a proxy like an F5 or at least SSL+HTTP Simple Auth), but I haven't ever tried to configure it for remote support session sharing type stuff. Is that how you're using it? If so, how is it set up?

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#44

So I use TV for occasional family support. Were machines vulnerable with only Teamviewer: 1. Installed but not being used? 2. Only when being used (i.e. ask family member to fire it up and give the connection info)

If the software is not running when closed (system process) then it should mostly be fine.

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#45

Reposting what TheKnack said [0] as a top level comment, since this is important. > The Chief Security Architect of FireEye posted this Tweet last week clarifying that there isn't a new compromise of TeamViewer, and the social media posts suggesting there is are misinterpreting a slide from a conference presentation. > https://twitter.com/cglyer/status/1183210046093758464 [0]: https://news.ycombinator.com/item?id=213…

There is a more official statement from TV as well. https://community.teamviewer.com/t5/Announcements/FireEye-cl...

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#46
post #45

Reposting what TheKnack said [0] as a top level comment, since this is important. > The Chief Security Architect of FireEye posted this Tweet last week clarifying that there isn't a new compromise of TeamViewer, and the social media posts suggesting there is are misinterpreting a slide from a conference presentation. > https://twitter.com/cglyer/status/1183210046093758464 [0]: https://news.ycombinator.com/item?id=213…

There is a more official statement from TV as well. https://community.teamviewer.com/t5/Announcements/FireEye-cl...

> TeamViewer is safe to use

How often has that been true? TV has been hacked more than once AFAIK.

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#47
post #21

Speaking of TeamViewer, do you know a good open source alternative that I can self host (I mean self host the relay server for NAT traversal). That is as easy to use? Works on windows, mac and linux? It should also be installable in a few slick with no network configuration required.

[deleted]
Post reply on HN