Live data from Hacker News

Sophisticated OS X Backdoor Discovered

securelist.com

11–20 of 155 posts

Re: Sophisticated OS X Backdoor Discovered

#11
post #8
post #2

Are video captures actually possible? I could imagine video capture as part of a RAT, but what scares me is the idea of video capture that doesn't turn on the camera activity light. Are there any examples of that?

It was definitely possible a couple years back - https://jscholarship.library.jhu.edu/handle/1774.2/36569 We describe how to disable the LED on a class of Apple internal iSight webcams used in some versions of MacBook laptops and iMac desktops. This enables video to be captured without any visual indication to the user and can be accomplished entirely in user space by an unprivileged (non- root) application.

> It was definitely possible a couple years back

Yeah, a few years back studying MacBooks from 2008.

Re: Sophisticated OS X Backdoor Discovered

#12
I thought MacOS was "Secure By Design". This is what Apple states in their official product descriptions.

In fact, it says it on this current page:

http://www.apple.com/business/mac/

"Because OS X is secure by design, there’s no need for IT to install additional tools or lock down functionality for employees. And with an automated zero-touch deployment process, they don’t even have to open the box."

Re: Sophisticated OS X Backdoor Discovered

#13
post #4

Earlier quoted context omitted.

I don't know that it's possible on recent Apple hardware. I remember reading somewhere that the green LED is triggered by the camera power line, or something along those lines.

That's how it should be however that's not how it is for all web cameras. I don't know specifics about Apple.

Note to anyone developing a new webcam: if you want to be able to flash your LED to indicate something to the user, add another color, and keep the main LED tied to the power line (ideally with a hardware-implemented delayed shutoff on the power so a single-frame grab lights the LED for a long time).

Re: Sophisticated OS X Backdoor Discovered

#14

I thought MacOS was "Secure By Design". This is what Apple states in their official product descriptions. In fact, it says it on this current page: http://www.apple.com/business/mac/ "Because OS X is secure by design, there’s no need for IT to install additional tools or lock down functionality for employees. And with an automated zero-touch deployment process, they don’t even have to open the box."

I think that myth got shot down years ago. Along with magical and courageous marketing terms.

Re: Sophisticated OS X Backdoor Discovered

#15
post #2

Are video captures actually possible? I could imagine video capture as part of a RAT, but what scares me is the idea of video capture that doesn't turn on the camera activity light. Are there any examples of that?

IDK about current gen Apple hardware, but it was possible to do so on a 2008 MacBook, at least (academic paper and PoC app):

https://jscholarship.library.jhu.edu/bitstream/handle/1774.2...

Interestingly, on my battered, el cheapo Asus 12" netbook (2011 Intel Atom), this problem is solved very well: the on/off webcam switch physically blocks the webcam lens in the off state.

Re: Sophisticated OS X Backdoor Discovered

#16

I thought MacOS was "Secure By Design". This is what Apple states in their official product descriptions. In fact, it says it on this current page: http://www.apple.com/business/mac/ "Because OS X is secure by design, there’s no need for IT to install additional tools or lock down functionality for employees. And with an automated zero-touch deployment process, they don’t even have to open the box."

I think that myth got shot down years ago. Along with magical and courageous marketing terms.

They still say it! On a page on their website in 2016.

And their paid AstroTurfers are here on hn, with the downvotes.

Re: Sophisticated OS X Backdoor Discovered

#17
Can someone explain how the vicim gets infected?

As far as I can read from the article they discuss what happens if you are infected.

Also, isn't running binary files on OS X from let's say "Finder" automatically triggers Security alert ( like App-vendor lock )?

Re: Sophisticated OS X Backdoor Discovered

#19

I thought MacOS was "Secure By Design". This is what Apple states in their official product descriptions. In fact, it says it on this current page: http://www.apple.com/business/mac/ "Because OS X is secure by design, there’s no need for IT to install additional tools or lock down functionality for employees. And with an automated zero-touch deployment process, they don’t even have to open the box."

Everyone makes that claim.

https://channel9.msdn.com/Events/Ignite/2015/BRK3309

Post reply on HN