Live data from Hacker News

Transmission BitTorrent app contained malware

forum.transmissionbt.com

201–210 of 355 posts

Re: Transmission BitTorrent app contained malware

#201

It's not. Condoms aren't used against a hostile opponent. If your partner is intent on exposing you, a condom won't provide any protection.

Perhaps a better analogy is "everyone knows locks can be picked", but people don't leave all their doors unlocked...

Maybe closer to "everyone knows safes can be cracked". Compared to lockpicking, or the other, more brute force ways to get past doors, the skill needed to find and exploit a new (0day) vulnerability is relatively specialized, albeit abundant enough for worry.

Re: Transmission BitTorrent app contained malware

#203
If they indeed used a legit code signing certificate, what is the fix? It seems very difficult to just blindly trust signed binaries anymore. Short of setting up a registry of vetted code signing certificates, it seems that signed code is just as easily manipulated as unsigned code. And even then, the keys to the certificate could be mishandled.

Re: Transmission BitTorrent app contained malware

#204

It looks like they've since changed the upgrade to 2.92 (it was previously 2.91 this morning), wonder why that happened?

The update dialog says: "Everyone running 2.90 on OS X should immediately upgrade to and run 2.92, as they may have downloaded a malware-infected file. This new version will make sure that the “OSX.KeRanger.A” ransomware (more information available here) is correctly removed from you're computer. Users of 2.91 should also immediately upgrade to and run 2.92. Even though 2.91 was never infected, it did not automatical…

Thanks, I dug out the diff and found that too :)

https://trac.transmissionbt.com/changeset?old_path=%2F&old=1...

Re: Transmission BitTorrent app contained malware

#205
post #186
post #144

Earlier quoted context omitted.

I think the point is that viruses can exploit properties of their hosts regardless of how they came to do so.

But humans and viruses aren't competing in the same game. A better metaphor for the adversary in that situation is the person you're having sex with poking a hole in your condom.

These metaphors are hard to follow. Does anyone have a car analogy to phrase this better? Seems like that's all we're missing in this thread.

Re: Transmission BitTorrent app contained malware

#207

Earlier quoted context omitted.

I am not following your comment here. Most Jenkins setup use global credentials or use the server-side config file like .ssh/config, .gitconfig link.

But ideally there are no credentials because Jenkins doesn't need to push code to the repo (and can clone the pubically available code).

But it might need to push new (binary) updates if the master/deploy branches gets updated or a commit contains a specific tag.

As far as I know, only the binary was updated.

I'd be interested to hear, though, how it got compromised after all.

Re: Transmission BitTorrent app contained malware

#208
post #86

Earlier quoted context omitted.

Here's an analysis of the malware - http://researchcenter.paloaltonetworks.com/2016/03/new-os-x-...

"It will then sleep for three days. Note that, in a different sample of KeRanger we discovered, the malware also sleeps for three days, but also makes requests to the C2 server every five minutes." It's fascinating!

Isn't it possible to fire a takedown notice to that server? I mean KeRanger committed a felony and Amazon (assuming you mean Amazon's EC2 server) might react quickly if they realize what has happened. It might save a lot of computers from getting destroyed. As long as the server is somewhere in the Western world, it should not be a problem.

Re: Transmission BitTorrent app contained malware

#209
post #129
post #78

Earlier quoted context omitted.

(reply to noondip): if anyones got a better suggestion I'd love to hear it :)

Back when Apple still made Mac OS X Server as a separate operating system, they included ClamAV¹ to scan for malware in mail. They don’t include it anymore, but ClamXav² (been around since 2004³) is a nice GUI for ClamAV that I’ve been using for a while now. ―――――― ¹ — https://en.wikipedia.org/wiki/Clam_AntiVirus#Mac_OS_X ² — http://clamxav.com/index.html ³ — http://clamxav.com/birthday.html

I run a private mail server and swear by ClamAV to help reduce noise and pollution that accumulates and spreads through my server, but I don't think I've ever had any luck with it being a good front line defense against up-and-coming malware, whether it targets Windows or Mac. I don't think I would recommend it as a primary malware scanner for a Mac, or Windows.

Re: Transmission BitTorrent app contained malware

#210

It's not. Condoms aren't used against a hostile opponent. If your partner is intent on exposing you, a condom won't provide any protection.

This is what happens when you start using analogy instead of logic.

What do you think the logy in analogy stands for?
Post reply on HN