Earlier quoted context omitted.
I just want to point out Candiru is a fish that supposedly wriggles up someone's ding-dong when they pee in Amazonian rivers while swimming? I'm... gravely... skeptical that it ever actually happens, if I were to guess it's one of those, "I fell on it while getting dressed" situations that are occasionally explained to amused ER doctors. Maybe even one of those, "they put a chemical in the pool that makes the water t…
Oh I don’t see humor in it at all. These guys picked the name of something that crawls up your urethra because that is how they saw themselves. These are Monsters, not people.
Hooking Candiru: Another mercenary spyware vendor comes into focus
21–30 of 33 posts
Re: Hooking Candiru: Another mercenary spyware vendor comes into focus
#22As a society, we absolutely have to start actively developing software (OS in the first place) and hardware with privacy as a topmost priority. Using Windows and common Windows apps leaves bizarrely many tracks on the computer. Just take a look at one of the many resources on "computer forensics" and you'll see. And I doubt this can be addressed without decreasing complexity.
I wonder if those supposedly secure Linux distros are actually secure. Anything from MS, Google, and Apple cannot be trusted.
Re: Hooking Candiru: Another mercenary spyware vendor comes into focus
#23I am curious as to how exactly the spyware got on the victims computers. In the Microsoft blog, they mention a chain of exploits. But it could be interesting to understand how they are able to target an individual system with such precision.
Re: Hooking Candiru: Another mercenary spyware vendor comes into focus
#24Funny thing is that they used zcombinator[.]co for one of their C2
Re: Hooking Candiru: Another mercenary spyware vendor comes into focus
#25As a society, we absolutely have to start actively developing software (OS in the first place) and hardware with privacy as a topmost priority. Using Windows and common Windows apps leaves bizarrely many tracks on the computer. Just take a look at one of the many resources on "computer forensics" and you'll see. And I doubt this can be addressed without decreasing complexity.
I wonder if those supposedly secure Linux distros are actually secure. Anything from MS, Google, and Apple cannot be trusted.
Open source has one really good benefit, Having more eyes on the code, which means less likely a bug goes undetected. It also means reduced effort for finding bugs. Though imo Linux is arguably more safer because if it's smaller surface area.
I think Linux (with additions like AppArmor/SELinux) is definitely more than enough for most high profile people. That coupled with Good Security practices (not running untrusted binaries, using end-to-end encrypted mediums for communication) imo should deter 99.9% of those surveillance attacks.
Re: Hooking Candiru: Another mercenary spyware vendor comes into focus
#26I am curious as to how exactly the spyware got on the victims computers. In the Microsoft blog, they mention a chain of exploits. But it could be interesting to understand how they are able to target an individual system with such precision.
This really gives you a perspective on how big this company is, having the resources and incentive to do these exploits instead of reporting it.
Re: Hooking Candiru: Another mercenary spyware vendor comes into focus
#27Earlier quoted context omitted.
>Microsoft doesn’t name Candiru but instead refers to an “Israel-based private sector offensive actor” it calls Sourgum. https://blogs.microsoft.com/on-the-issues/2021/07/15/cyberwe... >We believe Sourgum is an Israel-based private sector offensive actor or PSOA.
I just want to point out Candiru is a fish that supposedly wriggles up someone's ding-dong when they pee in Amazonian rivers while swimming? I'm... gravely... skeptical that it ever actually happens, if I were to guess it's one of those, "I fell on it while getting dressed" situations that are occasionally explained to amused ER doctors. Maybe even one of those, "they put a chemical in the pool that makes the water t…
Re: Hooking Candiru: Another mercenary spyware vendor comes into focus
#28I am curious as to how exactly the spyware got on the victims computers. In the Microsoft blog, they mention a chain of exploits. But it could be interesting to understand how they are able to target an individual system with such precision.
Article does mention Chrome 0-day Vulnerabilities (CVE-2021-21166 and CVE-2021-30551) and a Office Vulnerability (CVE-2021-33742). Knowing these were targeted attacks, It could have been as easy as sending a innocent looking email with a innocent looking link (something like blacklivesmatters[.]info). That combined with the Windows privilege acceleration attacks, could get the spyware insane amount of access. Conside…
Re: Hooking Candiru: Another mercenary spyware vendor comes into focus
#29Earlier quoted context omitted.
I wonder if those supposedly secure Linux distros are actually secure. Anything from MS, Google, and Apple cannot be trusted.
Well unless you are building everything from source (after auditing software), you end up trusting someone for the executable (packaged by distro maintainers). Distros like Gentoo solve this pretty well by giving a good suite of build tools, Nevertheless it's too bothersome for most users. Arch distributes it's package signing abilities to multiple maintainers who can revoke each other's keys. which imo is better tha…
This a million times.
The concept is so simple it doesn't even need proof or examples as solid arguments, but just in case, here's one: the famous Interbase backdoor.
Interbase was a database engine by Borland. In 1994 some developer added a hardcoded credential backdoor to ease development, but forgot to remove it in production. The backdoor wasn't malicious, yet still dangerous as it gave administrator privileges to anyone; it went unnoticed for about seven years and multiple versions of the product. In mid 2000, Borland released Interbase as Open Source, and within six months the vulnerability was discovered and fixed.
https://www.schneier.com/essays/archives/2001/03/back_door_s...
Re: Hooking Candiru: Another mercenary spyware vendor comes into focus
#30Earlier quoted context omitted.
I just want to point out Candiru is a fish that supposedly wriggles up someone's ding-dong when they pee in Amazonian rivers while swimming? I'm... gravely... skeptical that it ever actually happens, if I were to guess it's one of those, "I fell on it while getting dressed" situations that are occasionally explained to amused ER doctors. Maybe even one of those, "they put a chemical in the pool that makes the water t…
Oh I don’t see humor in it at all. These guys picked the name of something that crawls up your urethra because that is how they saw themselves. These are Monsters, not people.