Live data from Hacker News

Transmission BitTorrent Client OSX/Keydnap Malware Incident Q+A

transmissionbt.com

11–20 of 146 posts

Re: Transmission BitTorrent Client OSX/Keydnap Malware Incident Q+A

#14
More info on the malware:

> The OSX/Keydnap backdoor is equipped with a mechanism to gather and exfiltrate passwords and keys stored in OS X’s keychain. The author simply took a proof-of-concept example available on Github called Keychaindump. It reads securityd’s memory and searches for the decryption key for the user’s keychain. This process is described in a paper by K. Lee and H. Koo. One of the reasons we think the source was taken directly from Github is that the function names in the source code are the same in the Keydnap malware.

Source: http://www.welivesecurity.com/2016/07/06/new-osxkeydnap-malw...

Re: Transmission BitTorrent Client OSX/Keydnap Malware Incident Q+A

#15
post #5

Second time that this has happened to Transmission this year. Last time a ransomware got included. If you're a Transmission user then be very cautious when installing new versions.

Main reason that I only install stuff like this from my distro's repositories. Anyone know if this would have affected homebrew and such on OSX?

Re: Transmission BitTorrent Client OSX/Keydnap Malware Incident Q+A

#17

I'm not a Transmission user, but this makes me wonder, as a sort of Ask HN question: How long do you wait before updating software? If you always update as soon as possible, then you risk getting hit by a compromise like this one, or you could suffer other unintentional bad effects of a botched update. But the longer you delay updating, the more you raise your risk of becoming a victim of a new vulnerability that's j…

I wait about a week, unless I've heard out of band talk about some terrible hack with a punny name and we all need to upgrade NAO!1! I suppose I should always look for a secondary source for release notes or such as soon as possible; I don't because I am a lazy human.

Re: Transmission BitTorrent Client OSX/Keydnap Malware Incident Q+A

#18

I'm not a Transmission user, but this makes me wonder, as a sort of Ask HN question: How long do you wait before updating software? If you always update as soon as possible, then you risk getting hit by a compromise like this one, or you could suffer other unintentional bad effects of a botched update. But the longer you delay updating, the more you raise your risk of becoming a victim of a new vulnerability that's j…

Neither during this or the previous incidence the updates were compromised (they were checked by the installed binary). Only fresh downloads from the website.

Re: Transmission BitTorrent Client OSX/Keydnap Malware Incident Q+A

#19
post #5

Second time that this has happened to Transmission this year. Last time a ransomware got included. If you're a Transmission user then be very cautious when installing new versions.

You were only at risk when downloaded fresh copies from the website. Updates were checked by the already installed Transmission.
Post reply on HN