Live data from Hacker News

Symantec found evidence of Longhorn against 40 targets spread in 16 countries

symantec.com

21–30 of 49 posts

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#21

Too bad it's not like Microsoft's Longhorn - then it would have been delivered years late as a shadow of it's promised self (Vista) ;)

And it would be deprecated tomorrow [1] [1] https://support.microsoft.com/en-ca/help/22882

Nice catch :)

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#22
post #11

> [Longhorn] has used a range of back door Trojans in addition to zero-day vulnerabilities to compromise its targets. I genuinely don't see the added value of antivirus corporations in this or anywhere else. Better tactics are: - patch - educate wife and children

> educate wife and children I'm guessing you don't have teens who have to have the latest mod for every game they play. Giving up a very real download for the slight chance of a virus is a risk they are very willing to make.

This is why abstinence education results in teen pregnancies. Teenagers require birth control and supervision.

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#23
post #7

Earlier quoted context omitted.

- Don't run day to day with local admin

Many people say that the first thing they do is disable UAC. One person even told me that people who know what they are doing disable UAC. Not sure what to think of these people

https://blogs.msdn.microsoft.com/oldnewthing/20160816-00/?p=...

I'm in the "meh" camp here.

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#24

Earlier quoted context omitted.

Many people say that the first thing they do is disable UAC. One person even told me that people who know what they are doing disable UAC. Not sure what to think of these people

UAC is merely a prompt that desensitizes users to more prompts. Whenever UAC shows up, for most people, the default reflex is just make the annoying prompt go away. Yes it to death. Users simply should not log in as Administrators for day-to-day use. Anything requiring Administrator permissions should force a full log out, and change of identity. UAC doesn't educate users. Users should either be locked out of dangero…

I recall at least one instance where my mom stopped at a UAC prompt wondering what it meant. Her calling me to verify what it was doing saved her from installing some malware. So anecdotally those prompts are not completely useless. She is not a tech literate person either, not much beyond referring to the browser as "the internet."

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#26
It's nice that Symantec has shared this info but their attempt at neutrality is frustrating.

Based on their data they could easily state that Longhorn is a CIA group. They also didn't provide any links to WikiLeaks for people to learn more about what Vault 7 is.

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#28

> [Longhorn] has used a range of back door Trojans in addition to zero-day vulnerabilities to compromise its targets. I genuinely don't see the added value of antivirus corporations in this or anywhere else. Better tactics are: - patch - educate wife and children

My wife has a PhD and ran up to date Firefox with noscript, Flash disabled, and ad-blockers, uses webmail, and doesn't install software or download executables in general. She still got hacked, due to a bug in Firefox that was exploited despite having noscript and Flash disabled.

How, exactly, would you have educated her?

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#29

Earlier quoted context omitted.

UAC is merely a prompt that desensitizes users to more prompts. Whenever UAC shows up, for most people, the default reflex is just make the annoying prompt go away. Yes it to death. Users simply should not log in as Administrators for day-to-day use. Anything requiring Administrator permissions should force a full log out, and change of identity. UAC doesn't educate users. Users should either be locked out of dangero…

I recall at least one instance where my mom stopped at a UAC prompt wondering what it meant. Her calling me to verify what it was doing saved her from installing some malware. So anecdotally those prompts are not completely useless. She is not a tech literate person either, not much beyond referring to the browser as "the internet."

But, did she have Administrator permissions?

Re: Symantec found evidence of Longhorn against 40 targets spread in 16 countries

#30
post #28

> [Longhorn] has used a range of back door Trojans in addition to zero-day vulnerabilities to compromise its targets. I genuinely don't see the added value of antivirus corporations in this or anywhere else. Better tactics are: - patch - educate wife and children

My wife has a PhD and ran up to date Firefox with noscript, Flash disabled, and ad-blockers, uses webmail, and doesn't install software or download executables in general. She still got hacked, due to a bug in Firefox that was exploited despite having noscript and Flash disabled. How, exactly, would you have educated her?

It's hard to be "invulnerable" these days. I guess you could avoid the majority of infections by using some "weird" software configuration: such as linux with some nightly built of chromium. I heard that Macs are also quite resistant (still). But these things are very dynamic and change fast. What was good yesterday ("educate" users), may not be relevant any more today.
Post reply on HN