Live data from Hacker News

Proton.B: What this Mac malware does

cybereason.com

51–60 of 94 posts

Re: Proton.B: What this Mac malware does

#51
post #8

Does the Mac have any ability to warn when someone attempts to install malicious software, other than the usual warnings about unsigned software? Windows 10, for example, will scan every attachment before opening it, catching a lot of stuff before it can do any harm.

Mac OS X Snow Leopard and malware detection https://support.apple.com/en-us/HT202234 Surprised I hadn't heard if this kicked in for Handbrake, but Apple maintains a list of malware (I assume by file hash?). I remember when this went into the OS because there were concerns about legit software being blacklisted.

Yes Apple has blacklisted the new malware in XProtect.

Re: Proton.B: What this Mac malware does

#53

Earlier quoted context omitted.

And maybe dim the background, as wel as giving information about the creator of the application and if its codesigned. oh wait, that was too obtrusive and annoying

Not sure if you're being sarcastic about how users feel or about that kind of configuration for UAC, but personally it's one of the many things I dislike when I'm on a Windows computer. For power users it's annoying and disruptive. For users that might benefit the most from it they quickly learn to press ok always whenever they are prompted for something, no matter what it's asking. In my opinion, an ideal OS would h…

There is no undo when you're giving access to information.

This malware reads your passwords and sends them to a remote server. How would you block it?

Re: Proton.B: What this Mac malware does

#54

I have been using homebrew to install handbrake. What's nice is that homebrew checks SHA256 before installing. $ brew cask install handbrake ==> Satisfying dependencies complete ==> Downloading https://download.handbrake.fr/handbrake/releases/1.0.7/HandBrake-1.0.7.dmg Already downloaded: /Users/wolf/Library/Caches/Homebrew/Cask/handbrake--1.0.7.dmg ==> Verifying checksum for Cask handbrake ==> Installing Cask handbra…

Homebrew added new policy https://github.com/caskroom/homebrew-cask/pull/33538/files

> When updating the `sha256` stanza of an existing Cask, the `version` also has to have changed. Otherwise, the new checksum has to be confirmed by the developer.

Re: Proton.B: What this Mac malware does

#55
post #38

Just a reminder when discussing any item with Mac in the title. Please make sure not to make any comments related to the content of the item. Please restrict yourself to noting how bad Apple and Mac are, and how you have spent the last 6 months working full time to build a Huckintosh that almost works except that you have to sacrifice a chicken on the keyboard to get WiFi to work. Extra points if you can reference ir…

Please don't. It only makes things worse.

Re: Proton.B: What this Mac malware does

#56

Earlier quoted context omitted.

Not sure if you're being sarcastic about how users feel or about that kind of configuration for UAC, but personally it's one of the many things I dislike when I'm on a Windows computer. For power users it's annoying and disruptive. For users that might benefit the most from it they quickly learn to press ok always whenever they are prompted for something, no matter what it's asking. In my opinion, an ideal OS would h…

There is no undo when you're giving access to information. This malware reads your passwords and sends them to a remote server. How would you block it?

Because since the only way that a program can have access to information is by explicitly handing that info to the program from another program the only place you enter a password is on your login screen.

Re: Proton.B: What this Mac malware does

#57
Mobile OS security models are bound to land on the desktop soon-ish. What does any random App have to do with anything in ~/Library that is not its own Application Support or .plist preferences?

To be honest I don't mind if all Apps are sandboxed with the exception of a couple "user super-user"; I don't really care if my machine's root account is secure if all my horses sitting in $HOME are let loose on the net.

Re: Proton.B: What this Mac malware does

#58
> Note: The domains in red were not registered at the time of my research, although they were registered last night by an unknown entity. They seem to be back up domains in case one of the first two stops working.

Or they could be domains for checking if you're in a sandbox like WanaCrypt. Why wouldn't you just use 20 well known domains otherwise?

Re: Proton.B: What this Mac malware does

#59

Why were they going after 1password filevaults? I assume 1password is like keypass, where all your passwords are in an encrypted file? How could they decrypt all those files? Or do they assume people use weak passwords?

According to the article this malware also does keylogging. So, presumably, they'll have the vault password as well.

Re: Proton.B: What this Mac malware does

#60
post #34

The standard macOS password prompt surely needs to change. It's become too familiar and I'm sure I've filled it in hastily before without wondering why or what for. It needs to be implemented in a way that is impossible for nefarious apps to replicate.

What I would love to see is a reason . Any program that requests elevated privileges should have to state to me why it wants those privileges. It's really frustrating to get this dialog pop up and have no idea what it's doing.

Many programs actually do, to a varying degree. Some programs are very vague but others can be specific. In the article, the virus even explains it: to install additional codecs. It might have even tricked me into thinking that it might need those (maybe they are integrated into quicktime and thus needs those privliages).

Almost any program that does something more advanced stuff then emails needs a helped application which often requires a root password. This is unfortunately true and apple is not very interested in fixing it (because their AppStore is safe and you ought to only use the AppStore because it will be sufficient for all your needs -- at least that's what the geniuses at Apple told me, which is actually good advice for most people but from time to time they need to enter the root/admin password and you can't really educate "normal users" when to enter it and when not to).

Post reply on HN