Live data from Hacker News

FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

twitter.com

61–70 of 76 posts

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#61
post #45

Reposting what TheKnack said [0] as a top level comment, since this is important. > The Chief Security Architect of FireEye posted this Tweet last week clarifying that there isn't a new compromise of TeamViewer, and the social media posts suggesting there is are misinterpreting a slide from a conference presentation. > https://twitter.com/cglyer/status/1183210046093758464 [0]: https://news.ycombinator.com/item?id=213…

There is a more official statement from TV as well. https://community.teamviewer.com/t5/Announcements/FireEye-cl...

Most useless statement in the history of mankind.

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#62
post #48

MeshCentral is open source, runs on Linux and works with Windows, Mac and Linux clients for one-off support and unattended remote control...

Thank you for the hint, I used AnyDesk (think it was built by people who worked at TV) but I'd enjoy an open source solution even more if it does what it should.

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#63
post #60
post #21

Speaking of TeamViewer, do you know a good open source alternative that I can self host (I mean self host the relay server for NAT traversal). That is as easy to use? Works on windows, mac and linux? It should also be installable in a few slick with no network configuration required.

In case when remote control capabilities are not required, one could use jitsi ( https://jitsi.org ) video conferencing service which provides screen sharing capabilities (implementation depends on the web browser). The main advantage is that there is no need to install any software neither on the remote machine nor on the local one. There is a cloud hosted free version https://meet.jit.si which does not even require…

For those of you who need to try it out real quick : Jitsi Docker : https://github.com/jitsi/docker-jitsi-meet

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#64
post #21

Speaking of TeamViewer, do you know a good open source alternative that I can self host (I mean self host the relay server for NAT traversal). That is as easy to use? Works on windows, mac and linux? It should also be installable in a few slick with no network configuration required.

I use nomachine behind vpn and it works much smoother than teamviewer. It's multiplatform and free for personal use.

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#65
post #62
post #48

MeshCentral is open source, runs on Linux and works with Windows, Mac and Linux clients for one-off support and unattended remote control...

Thank you for the hint, I used AnyDesk (think it was built by people who worked at TV) but I'd enjoy an open source solution even more if it does what it should.

I've been using MeshCommander/MeshCentral (and their older tools like Open MDTK) since the first public versions, both for vPro/AMT related management tasks, and remote control. I'm very happy with them but I certainly won't rely on the assumption that they can't be hacked. With enough "motivation" an attacker has plenty of targets on the logistics chain where a vulnerability can be introduced (in the code, in the installer, etc.).

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#66
post #28

Earlier quoted context omitted.

Yes technically it could work, but I cannot ask the users to use SSH and configure VNC. The force of team viewer is that you download it, open it, and give number over the phone and it works.

Chrome remote desktop works pretty well

But for remote control, it stops after every few minutes, asking the "controlled" user to click on a button to continue. Not so practical in a few situations.

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#67
post #38

TeamViewer devs are especially to blame for this. You can’t install it without admin permissions even if you just want to control another desktop. Unless you manually extract the .app from the .pkg, in which case it works fine. Anyways, this isn’t the first time TeamViewer has been hacked. Wonder what their beef is against E2EE between connected computers.

On Windows it can be used by a standard user without being installed. It's much more difficult to do this on macos. Even on Windows there are dark patterns that make this difficult, but it can be done.

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#68
post #66

Earlier quoted context omitted.

Chrome remote desktop works pretty well

But for remote control, it stops after every few minutes, asking the "controlled" user to click on a button to continue. Not so practical in a few situations.

What do you mean? I've never had it do that.

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#69
post #21

Speaking of TeamViewer, do you know a good open source alternative that I can self host (I mean self host the relay server for NAT traversal). That is as easy to use? Works on windows, mac and linux? It should also be installable in a few slick with no network configuration required.

https://github.com/OpenIndex/RemoteSupportTool

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#70
post #53
post #7

The article should've linked to this tweet[0] by the same researcher instead: > "APT41 compromised company behind TeamViewer - which enabled them to access any system with TeamViewer installed" [0] https://twitter.com/cglyer/status/1182413194360508419

Ok, we changed the URL to that from https://www.securitynewspaper.com/2019/10/14/fireeye-confirm... . Thanks!

The title could still be a bit better, the story is about the ability to access billions of devices. There is zero indication that billions of devices were actually accessed.
Post reply on HN