Live data from Hacker News

FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

twitter.com

71–76 of 76 posts

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#71

Earlier quoted context omitted.

> TeamViewer is safe to use How often has that been true? TV has been hacked more than once AFAIK.

TV gives full access to computers through passwords and it seems it's not brute-force resistant. Think about how long an SSH server with password enabled and no autoban would last in the open... Edit: nevermind, the attack is apparently through some malware.

> Think about how long an SSH server with password enabled and no autoban would last in the open

quite long? unless you're using a bad password I don't really see any risk other than filling logs from password attempts.

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#72
post #68
post #66

Earlier quoted context omitted.

But for remote control, it stops after every few minutes, asking the "controlled" user to click on a button to continue. Not so practical in a few situations.

What do you mean? I've never had it do that.

It always happens for me when accessing a Linux machine remotely. I can't find a screenshot now, so the next time I do it, I'll take one. It seems to be a security measure, to prevent someone from sharing remote access and then forgetting about it afterwards, but it makes for terrible usability.

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#73
post #48

MeshCentral is open source, runs on Linux and works with Windows, Mac and Linux clients for one-off support and unattended remote control...

For a less sophisticated option for home users there's also DWService that is open source.

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#74
post #70
post #53

Earlier quoted context omitted.

Ok, we changed the URL to that from https://www.securitynewspaper.com/2019/10/14/fireeye-confirm... . Thanks!

The title could still be a bit better, the story is about the ability to access billions of devices. There is zero indication that billions of devices were actually accessed.

Sorry for the belated reply; I just saw this. I suppose "may have accessed" was intended to communicate that in the title?

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#75

So I use TV for occasional family support. Were machines vulnerable with only Teamviewer: 1. Installed but not being used? 2. Only when being used (i.e. ask family member to fire it up and give the connection info)

If the software is not running when closed (system process) then it should mostly be fine.

Yeah, you never obviously know these days if there are background services running.

Re: FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

#76
post #74
post #70

Earlier quoted context omitted.

The title could still be a bit better, the story is about the ability to access billions of devices. There is zero indication that billions of devices were actually accessed.

Sorry for the belated reply; I just saw this. I suppose "may have accessed" was intended to communicate that in the title?

I'm sure it was, I'm just not so sure that it does a very good job at that.

I feel like the most obvious interpretation of this is "APT41 possibly accessed billions of devices" which is incorrect, they had the ability but it is known that they only accessed a rather limited set of devices.

I'm not sure what would've been a better title though, especially given the length restrictions" ¯\_(ツ)_/¯

Post reply on HN