Live data from Hacker News

CPU-Z and HWMonitor compromised

theregister.com

71–80 of 118 posts

Re: CPU-Z and HWMonitor compromised

#71
post #19

To our new generation of human shields willing to use software releases less than a month old, we salute your sacrifice.

Not fair take, cpuz and hwmonitor are often used on new installations of PCs (or at least for me) to verify hw specs and stuff. Or when I need to do some upgrade work for a desktop computer. I just go to the trusted site, download what's there and get going. This is not an npm package that a dev is updating on day 0 of its release for being a "human shield", it's literally the first version which comes up when DLing…

Seems like the kind of thing to just have on a bootable thumb drive, to inspect any machine without requiring installation on the fly.

In fact, I think I used to use memtest86+ this way as it is a baked in boot option on Fedora bootable ISO images. (Or at least was in the past, I haven't checked this recently.)

Re: CPU-Z and HWMonitor compromised

#72
One interesting thing about all this stuff is that we may see a big swing towards paid/trusted solutions for all these type of things.

Maybe the 5-10% of true nerds will go find the l33t open source solutions, but most people will just use some paid solution.

Maybe Steam could build. Or in Windows. Or some SaaS solution for registry.

In exchange you just share your HW info

Re: CPU-Z and HWMonitor compromised

#73
post #52

Earlier quoted context omitted.

I’m not one to chase the new and shiny, but how do you know a nominally months-old software package isn’t a newly compromised version at the time you download it?

Windows has this thing called digital signing with certificates that Linux users like to pretend doesn't exist or in the case of yesterday's Wireguard / VeraCrypt discussion, think it's an evil capitalist scheme to control the world. Digital signing on Windows predates Mac developer certificates by years but arguably wasn't widely used outside of security-paranoid organizations. Before someone says Linux offers GPG s…

> Windows has this thing called digital signing with certificates that Linux users like to pretend doesn't exist

...or, much more likely, any potential benefits are not worth the negatives.

Re: CPU-Z and HWMonitor compromised

#74

> after the download my Windows Defender instantly detecting a virus. > (because i am often working with programms which triggering the defender i just ignored that) This again shows the unfortunate corrosive effect of false-positives. Probably impossible to solve while aggressively detecting viruses though.

I think to an extent Microsoft is the guilty party here. For may cracks Windows Defender will trip saying "Win32/Keygen" even if there's no actual malware

https://www.microsoft.com/en-us/wdsi/threats/malware-encyclo...

This trains people that do a lot of piracy to be used to turning off their antivirus to let something through, which is fine until it's not. It's like drugs, if we know a subset of the population will do them no matter what, we should make it safe for them to the extent we can. False positives, causing people to ignore actual positives, creates a market for these things.

Re: CPU-Z and HWMonitor compromised

#75

some comments purportedly (i did not verify) from one of the maintainers: > Dear All, I'm Sam and in I'm working with Franck on CPU-Z (I'm doing the validator). Franck is unfortunately OOO for a couple weeks. I'm just out of bed after worked on Memtest86+ for most the night, so I'm doing my best to check everything. As very first checks, the file on our server looks fine ( https://www.virustotal.com/gui/file/6c8faba4…

It's the third time that I've read something about availability notifications on discord and other chats getting abused for timed attacks in the last few weeks.

Can you share what those other attacks were? It's helpful to study additional attacks to know what to look for.

Re: CPU-Z and HWMonitor compromised

#76

Earlier quoted context omitted.

Not fair take, cpuz and hwmonitor are often used on new installations of PCs (or at least for me) to verify hw specs and stuff. Or when I need to do some upgrade work for a desktop computer. I just go to the trusted site, download what's there and get going. This is not an npm package that a dev is updating on day 0 of its release for being a "human shield", it's literally the first version which comes up when DLing…

Seems like the kind of thing to just have on a bootable thumb drive, to inspect any machine without requiring installation on the fly. In fact, I think I used to use memtest86+ this way as it is a baked in boot option on Fedora bootable ISO images. (Or at least was in the past, I haven't checked this recently.)

CPU-Z gets updated to recognise new CPUs and memory configs and thus must be downloaded new to recognise the new hardware in a new machine (otherwise it can’t recognise it properly). With Memtest sure but CPU-Z is something you actually need the latest version of when you first fire up a new PC.

Re: CPU-Z and HWMonitor compromised

#77
post #52

Earlier quoted context omitted.

I’m not one to chase the new and shiny, but how do you know a nominally months-old software package isn’t a newly compromised version at the time you download it?

Windows has this thing called digital signing with certificates that Linux users like to pretend doesn't exist or in the case of yesterday's Wireguard / VeraCrypt discussion, think it's an evil capitalist scheme to control the world. Digital signing on Windows predates Mac developer certificates by years but arguably wasn't widely used outside of security-paranoid organizations. Before someone says Linux offers GPG s…

Linux package managers (the normal way to install software) use signed packages.

I don't know how easy/hard it would be to compromise that.

Re: CPU-Z and HWMonitor compromised

#78
post #58
post #19

To our new generation of human shields willing to use software releases less than a month old, we salute your sacrifice.

I hope you don't think that waiting a month will protect you. Malicious software can wait to be triggered months or years before anything malicious happens.

It helps. If I were a malware/backdoor author, I have the choice to make it lie idle for a couple months; this would help me get more victims, BUT it gives more time for someone to notice it BEFORE I get any victims at all.

Whereas if it is active immediately, I'm likely to get at least a few victims.

Re: CPU-Z and HWMonitor compromised

#79

some comments purportedly (i did not verify) from one of the maintainers: > Dear All, I'm Sam and in I'm working with Franck on CPU-Z (I'm doing the validator). Franck is unfortunately OOO for a couple weeks. I'm just out of bed after worked on Memtest86+ for most the night, so I'm doing my best to check everything. As very first checks, the file on our server looks fine ( https://www.virustotal.com/gui/file/6c8faba4…

Any idea how the compromise was achieved?
Post reply on HN