Live data from Hacker News

Sophisticated OS X Backdoor Discovered

securelist.com

151–155 of 155 posts

Re: Sophisticated OS X Backdoor Discovered

#151

Earlier quoted context omitted.

I think you are spot on for rootkit, but you are absolutely wrong on backdoor. You say "This conversation is the best possible example of why we can't allow the corruption of previously well defined words - it causes confusion for no good reason." when YOU(and others like you) are the one corrupting the meaning of backdoor. Backdoor has meant for ages to be a way to access a computer/program while bypassing the norma…

> ... whether added by the designer or by someone else. Your exception seems to hing on the word designer. I'd describe the individual responsible placing the backdoor as the designer. So if you place a modified version of /usr/sbin/sshd, then you've designed the backdoor for that system. I see no redefinition.

Your post further up in the thread:

> Calling BO a backdoor is a major corruption of the word, as you loose the only word for describing intentionally weakened security - so that you may describe a thing which already has several more explicitly defining names: malware, trojan, dropper, etc.

Thinking in that context, it sounded like you were arguing further for the fact that backdoors should only be describing intentionally weakened security. Have you changed your mind about that?

Re: Sophisticated OS X Backdoor Discovered

#152

Earlier quoted context omitted.

> It was definitely possible a couple years back Yeah, a few years back studying MacBooks from 2008 .

Have they been updated since then?

Assuming this is a serious question, yes, the camera and MacBooks both have changed a lot since 2008. This is probably why they did the study on 2008 MacBooks as opposed to later models. They wouldn't get the results they wanted otherwise.

Re: Sophisticated OS X Backdoor Discovered

#153

Earlier quoted context omitted.

> ... whether added by the designer or by someone else. Your exception seems to hing on the word designer. I'd describe the individual responsible placing the backdoor as the designer. So if you place a modified version of /usr/sbin/sshd, then you've designed the backdoor for that system. I see no redefinition.

Your post further up in the thread: > Calling BO a backdoor is a major corruption of the word, as you loose the only word for describing intentionally weakened security - so that you may describe a thing which already has several more explicitly defining names: malware, trojan, dropper, etc. Thinking in that context, it sounded like you were arguing further for the fact that backdoors should only be describing intent…

> Have you changed your mind about that?

No. Unlike a rootkit, context really matters in the case of a backdoor - not so much the implementation means. BO is no more a backdoor than vnc or sshd. Now if Dell decides to secretly package BO in their product line, then it is a backdoor.

> ...backdoors should only be describing intentionally weakened security.

I can't think of a backdoor that does not meet that description, do you have anything in mind?

Re: Sophisticated OS X Backdoor Discovered

#155
post #56

Earlier quoted context omitted.

rootkit comes from unix, it was a tool helping to restore admin privileges even after the admin found that the host was hacked (that's where the name comes from root = admin on unix). Its goal was to be invisible. The sony rootkit was named somewhat incorrectly, because it also tried to hide itself and no other existing malware names fit it.

rootkit comes from unix, it was a tool helping to restore admin privileges even after the admin found that the host was hacked (that's where the name comes from root = admin on unix). Its goal was to be invisible. Are you sure? It also commonly referred to such kits being used by hostile parties. I've personally interrupted an attempt at installing the "Hungarian Rootkit" in the 90's. (I put unpatched Red Hat 6 onlin…

I see my response was ambiguous. Of course I meant rootkit was always malicious. It was used by intruder to gain root back after admin though he restored the host after being hacked.

Rootkits are the reason why it is recommended to wipe the whole system after being hacked, because you can't be sure there there wasn't anything installed.

Post reply on HN