Live data from Hacker News

The Microsoft Update mechanism has been used to spread malware

f-secure.com

41–50 of 64 posts

Re: The Microsoft Update mechanism has been used to spread malware

#43
post #28

Earlier quoted context omitted.

What happened with France?

I suspect it's a reference to 'the Maginot Line': http://en.wikipedia.org/wiki/Maginot_Line

Oh yeah, sure, blame it on the Belgians!

Re: The Microsoft Update mechanism has been used to spread malware

#44
post #21

Earlier quoted context omitted.

A very similar thing happened with France during WW2. I always remind myself I'm not as smart as I think I am.

What happened with France?

I was thinking of http://en.wikipedia.org/wiki/Funkspiel .

Re: The Microsoft Update mechanism has been used to spread malware

#45
post #40

> I guess the good news is that this wasn't done by cyber criminals interested in financial benefit. They could have infected millions of computers. Instead, this technique has been used in targeted attacks, most likely launched by a Western intelligence agency. You mean the bad news.

They apparently were only thinking of monetary losses, but a government malware on my computer is alot worse than credit card malware. At least we know what credit card malware can do at best (or worst).

Re: The Microsoft Update mechanism has been used to spread malware

#46
post #4

This is like finding out the zombies have made it into the compound. I wonder how big this hole is to fix. I also wonder, as many have, if this was written by an Intelligence agency and, if so, if they had access to Windows' source code.

The idea of Microsoft willingly giving windows source code access to government does not make alot of sense.

What could have however happened is that the said "Intelligence agency" first created a malware to infect MSFT engineers' computers and get access info of the code repository and then spoofing themselves as MSFT employees to download the source code. This is alot more plausible considering what stuxnet and flame can already do. (Assuming they were made by same "Intelligence agency")

MSFT should really check the systems of their employees first.

Re: The Microsoft Update mechanism has been used to spread malware

#47

Earlier quoted context omitted.

The same would happen on ubuntu if someone steals the repository keys. This has nothing to do with copy protection.

But my point is that more teams needed access to signing keys because some of those teams were dedicated only to licensing issues. If they didn't need signing keys, those keys wouldn't have been compromised. I suppose I can break it down another way. Complexity introduces vulnerabilities. Some complexity is necessary for the software to accomplish what the customer wants. Some complexity is arguably necessary to prot…

> But my point is that more teams needed access to signing keys because some of those teams were dedicated only to licensing issues. If they didn't need signing keys, those keys wouldn't have been compromised.

Cryptographically signed binaries are not used to manage licensing issues, they are used to make sure that no-one intercepts your download and replaces it with a malicious binary. It is absolutely essential that computer programs are signed or delivered through a secure connection.

Losing your signing keys will make the entire system jeopardized and new keys must be generated and securely transmitted (this is hard).

> To me, it is upsetting when the code to protect the vendor's interests is where a critical security vulnerability exists.

Yes, that would be upsetting if it were true. But it isn't. The whole system is in place to protect you, the customer.

Re: The Microsoft Update mechanism has been used to spread malware

#48
post #15

Earlier quoted context omitted.

The same would happen on ubuntu if someone steals the repository keys. This has nothing to do with copy protection.

Let's not forget that kernel.org itself was hacked. Nor that Firefox et al update themselves. People who live in glass houses...

This is why Linux kernel source code is also signed cryptographically and so is their git repository (all tags are signed). They also employ a PGP-style web of trust instead of an SSL-style centralized certificate management.

The chances of someone slipping in a backdoor in kernel releases are very slim.

Re: The Microsoft Update mechanism has been used to spread malware

#49
post #18
post #4

This is like finding out the zombies have made it into the compound. I wonder how big this hole is to fix. I also wonder, as many have, if this was written by an Intelligence agency and, if so, if they had access to Windows' source code.

My Windows already fixed it. http://support.microsoft.com/kb/2718704

How can you tell whether the fix was genuine? What if you were already infected by the Flame virus or similar that intercepts your Windows update traffic?

I hope Microsoft can deliver the revoked certificates in a trustworthy manner.

Re: The Microsoft Update mechanism has been used to spread malware

#50
post #28

Earlier quoted context omitted.

I suspect it's a reference to 'the Maginot Line': http://en.wikipedia.org/wiki/Maginot_Line

Oh yeah, sure, blame it on the Belgians!

Fellow Belgian here, our ancestors had been naive...

Our main line of defense, the fort d'Ében-Émael, had been built by German workers. The German army had their plans, and knew the weak point of the fort: its vast, undefended roof (it was used as a football field by the soldiers).

During a dark night, they landed with gliders on the roof, and manually set up shaped charges[1] to destroy the turrets, which were resistant to conventional bombs.

Game over.

[1] http://en.wikipedia.org/wiki/Shaped_charge , damages seen from the outside: http://upload.wikimedia.org/wikipedia/commons/thumb/f/f6/Ebe...

--

Edited to reconcile my foggy memory with the historic truth...

Post reply on HN