Live data from Hacker News

Transmission BitTorrent Client OSX/Keydnap Malware Incident Q+A

transmissionbt.com

21–30 of 146 posts

Re: Transmission BitTorrent Client OSX/Keydnap Malware Incident Q+A

#21
post #5

Second time that this has happened to Transmission this year. Last time a ransomware got included. If you're a Transmission user then be very cautious when installing new versions.

It was the .dmg file hosted on their own server, so any version could be compromised. I guess the safest route to take is to build the app from source.

Re: Transmission BitTorrent Client OSX/Keydnap Malware Incident Q+A

#22
post #9
post #7

Earlier quoted context omitted.

uTorrent http://www.utorrent.com/

Only if you want an interface filled with ads.

Pay for it then? Netflix scratches my entertainment itch now, but prior to it launching in Australia I almost went ahead and paid for uTorrent. It's a good, lightweight client. Software that works well deserves to be financially supported.

Re: Transmission BitTorrent Client OSX/Keydnap Malware Incident Q+A

#25

Are there any good alternatives to Transmission on OS X?

This may be overkill for some people, but if you have a VPN and use docker somewhere at home you can check out this container: https://github.com/haugene/docker-transmission-openvpn

I run it on a really old low-power PC and it's been very nice...I can even access it remotely wherever I am.

Re: Transmission BitTorrent Client OSX/Keydnap Malware Incident Q+A

#26
post #18

I'm not a Transmission user, but this makes me wonder, as a sort of Ask HN question: How long do you wait before updating software? If you always update as soon as possible, then you risk getting hit by a compromise like this one, or you could suffer other unintentional bad effects of a botched update. But the longer you delay updating, the more you raise your risk of becoming a victim of a new vulnerability that's j…

Neither during this or the previous incidence the updates were compromised (they were checked by the installed binary). Only fresh downloads from the website.

I haven't read much about this, so perhaps I'm not understanding clearly, but if the downloaded binary from Transmission's "website server" was replaced, then how is that not a compromise?

I genuinely feel for the developers, and I personally would not blame them if I was affected, but unless the data was intercepted enroute from their server, then I think they have to accept some degree of responsibility for the whole delivery chain to the end user.

Re: Transmission BitTorrent Client OSX/Keydnap Malware Incident Q+A

#27
post #5

Second time that this has happened to Transmission this year. Last time a ransomware got included. If you're a Transmission user then be very cautious when installing new versions.

Main reason that I only install stuff like this from my distro's repositories. Anyone know if this would have affected homebrew and such on OSX?

Homebrew packages verify checksums, so very unlikely to be affected.

Re: Transmission BitTorrent Client OSX/Keydnap Malware Incident Q+A

#28
So what happened with the codesigning? That's pretty much the only viable line of defense for the average user (nobody is going to be verifying SHA signatures, or the site is going to be compromised along with the download)

Was the malware version also signed with an official Apple Developer ID? The same ID? Is a change of ID verified with the auto-updater?

If there was a malicious Developer ID, has it been revoked by Apple?

Re: Transmission BitTorrent Client OSX/Keydnap Malware Incident Q+A

#29
post #11

I like Transmission, but this is the second serious security problem they've had this year. Once you can forgive, but twice and it's time to look for a new BitTorrent client.

FYI: Transmission binaries are now hosted on GitHub, so it is very unlikely that anything like this can happen in the future without compromising developer machines.
Post reply on HN