Live data from Hacker News

Sophisticated OS X Backdoor Discovered

securelist.com

131–140 of 155 posts

Re: Sophisticated OS X Backdoor Discovered

#131
post #20

Is 'backdoor' the correct term if the vulnerability does not originate from Apple?

I don't like the use of backdoor for malicious cracks, as it confuses the argument between malware and bad security practices. Though technically, backdoor is the correct term.

Cracks are for defeating copy protection, so this comment is all kinds of problematic!

Re: Sophisticated OS X Backdoor Discovered

#132

I feel the use of 'backdoor' here is misleading. The software described would usually be classified as an Advanced Persistent Threat [1] or Rootkit [2] Backdoor [3] usually refers to methods to sidestep authentication added by the vendor. 1: https://en.wikipedia.org/wiki/Advanced_persistent_threat 2: https://en.wikipedia.org/wiki/Rootkit 3: https://en.wikipedia.org/wiki/Backdoor_(computing)

Nope, wrong. Backdoor has been in use for this since long before the silly "APT" acronym was coined.

Re: Sophisticated OS X Backdoor Discovered

#133

Earlier quoted context omitted.

I agree, the terminology Kaspersky Labs is using is incorrect and misleading. The further poster is right that this should be labeled as "rootkit."

No, Kaspersky Labs is using correct terminology. Some rootkits install a backdoor. Not all rootkits install a backdoor -- some merely conceal themselves and operate locally. The famous Sony Rootkit is one such example of a rootkit which did not add a backdoor. The defining characteristic of a rootkit is that it conceals its presence from the rest of the system. Backdoor.OSX.Mokes.a doesn't really do this -- it's only…

Let's call it "a window with a shitty lock" instead of a "back door", if it's an unintentional vulnerability. Then we can just use "back door [left open]" to mean something intentional. Or, you know "key under a rock in the garden" because only certain people know where it is. Actually, I think that's where "Window( with a )S(hitty lock)" 95 first got it's name.

Re: Sophisticated OS X Backdoor Discovered

#135
post #6
post #5

Earlier quoted context omitted.

A lot of cross platform software that attempts audio/video (e.g. Skype etc) would be considered malware by some. Usually people who've had to use it at least once.

Serious question: Is this snark, or does the software in question do sketchy things with privilege escalation that might be leveraged into attacks? I agree that much software has terrible UI, but it's good to distinguish surface stuff from objectively terrible security decisions.

I don't know whether this is still the case but Skype used to use some of the most advanced anti-debugging, runtime code obfuscation, etc etc methods of its time for no obvious reason. See http://www.secdev.org/conf/skype_BHEU06.handout.pdf for details. It certainly made people pause and think about what kind of shady stuff they were up to.

Re: Sophisticated OS X Backdoor Discovered

#136

Not sure whether to be amused, vindicated, or concerned that the most prominent conversation here on HN is terminology: "Is 'backdoor' the correct term?" Malware, trojan, virus, rootkit, backdoor, squirglebunny (OK, I may have made that last one up). There's not a lot of talk about the threat vector though - does anyone know how this infects systems?

did you see last weeks post about bikeshedding? this is exactly what bikeshedding is.

Re: Sophisticated OS X Backdoor Discovered

#137
post #136

Not sure whether to be amused, vindicated, or concerned that the most prominent conversation here on HN is terminology: "Is 'backdoor' the correct term?" Malware, trojan, virus, rootkit, backdoor, squirglebunny (OK, I may have made that last one up). There's not a lot of talk about the threat vector though - does anyone know how this infects systems?

did you see last weeks post about bikeshedding? this is exactly what bikeshedding is.

What colour is the Rootkit?

Re: Sophisticated OS X Backdoor Discovered

#139

Okay, but no information on what to do about it, or how to protect against it.

Install Kaspersky Endpoint Protection, friend! ;) In all seriousness, when a company releases a malware write-up, they typically imply that their software would have prevented it or will prevent it.

http://blog.talosintel.com/2016/08/vulnerability-spotlight-m...
Post reply on HN