Live data from Hacker News

How we uncovered the identity of popular spyware makers

medium.com

21–30 of 31 posts

Re: How we uncovered the identity of popular spyware makers

#21
I think what would be interesting is to ask Lenovo why they commissioned Lenovo Browser Guard from a known spyware distributor, Conduit (one of the biggest and for a time nastiest Malware programs was Search Protect, which they make).

Proof: here’s a press release from Perion from June 2014 which announced that they partnered with Lenovo to create Browser Guard:

http://www.businesswire.com/news/home/20140618005930/en/Peri...

And here is a January 2014 press release that shows that Perion acquired Conduit's ClientConnect Services in 2014

http://www.businesswire.com/news/home/20140102005313/en/Peri...

Re: How we uncovered the identity of popular spyware makers

#24
post #10

> After the first shock of seeing iCloud passwords stored in clear text(how hard would it be to encrypt them?) Not going to defend shady businesses, but I dislike this knee jerk reaction without understanding the actual issue. I've seen software that encrypts (encrypts, not hashes) passwords for security™, but stores the secret in the database, too. Sure, technically they didn't store plaintext passwords, but practic…

Even if you store the secret on the same server it shows some effort went into the protection of user credentials.

Re: How we uncovered the identity of popular spyware makers

#25
post #6

Great write-up, even though some enthusiastic conclusions are far from solid. >>>> the logo similarity convinced us beyond the shadow of a doubt that Mobisoft LTD is the development company behind mSpy >>>> Why would mSpy move their data from Amazon ... Incidentally, in September 2014, the FBI has arrested a CEO of another spyware company called Stealth Genie ... Could the ease with which the US authorities were able…

Even their graphic designer was in on it ;)

Re: How we uncovered the identity of popular spyware makers

#26
post #24
post #10

> After the first shock of seeing iCloud passwords stored in clear text(how hard would it be to encrypt them?) Not going to defend shady businesses, but I dislike this knee jerk reaction without understanding the actual issue. I've seen software that encrypts (encrypts, not hashes) passwords for security™, but stores the secret in the database, too. Sure, technically they didn't store plaintext passwords, but practic…

Even if you store the secret on the same server it shows some effort went into the protection of user credentials.

You aren't protecting anything, you're playing hide and seek. This isn't how security works.

Re: How we uncovered the identity of popular spyware makers

#27
post #26
post #24

Earlier quoted context omitted.

Even if you store the secret on the same server it shows some effort went into the protection of user credentials.

You aren't protecting anything, you're playing hide and seek. This isn't how security works.

It's called defense in depth. Get a clue.

Re: How we uncovered the identity of popular spyware makers

#28
> > After the first shock of seeing iCloud passwords stored in clear text(how hard would it be to encrypt them?), we have seen something very interesting in the file:

I don't understand why that particular developer account caught their eye while browsing through a 13GB data set.

Re: How we uncovered the identity of popular spyware makers

#29

> > After the first shock of seeing iCloud passwords stored in clear text(how hard would it be to encrypt them?), we have seen something very interesting in the file: I don't understand why that particular developer account caught their eye while browsing through a 13GB data set.

"This seemed like an obvious developers’ account, especially with this information being right at the beginning of the file."

Re: How we uncovered the identity of popular spyware makers

#30
post #24
post #10

> After the first shock of seeing iCloud passwords stored in clear text(how hard would it be to encrypt them?) Not going to defend shady businesses, but I dislike this knee jerk reaction without understanding the actual issue. I've seen software that encrypts (encrypts, not hashes) passwords for security™, but stores the secret in the database, too. Sure, technically they didn't store plaintext passwords, but practic…

Even if you store the secret on the same server it shows some effort went into the protection of user credentials.

FORD: Yeah, well, at least it’s better than, ooh, than er… ZAPHOD: It isn’t better than anything at all, is it?!
Post reply on HN