The internet in China is so bad developers at Tencent download Xcode from random links on Chinese Dropbox? Pathetic.
Popular Chinese iOS apps compromised in malware attack
81–89 of 89 posts
Re: Popular Chinese iOS apps compromised in malware attack
#82Earlier quoted context omitted.
What can Apple reliably do without exposing the source code and attribution (with signig) of every file used to generate the app, run inside a signed environment on a locked down computer? Please. This is the GFW.
I think that at least Apple could put the Xcode binary files onto a CDN inside China. I'm trying to download Xcode 7.0 from the App Store today, and it's still hanging after a few hours.
Re: Popular Chinese iOS apps compromised in malware attack
#83The internet in China is so bad developers at Tencent download Xcode from random links on Chinese Dropbox? Pathetic.
It's bad when crossing the border. Rumor says it's due to traffic analysis by the GFW. I cannot find any source to prove or disprove that though.
Re: Popular Chinese iOS apps compromised in malware attack
#84Earlier quoted context omitted.
It's bad when crossing the border. Rumor says it's due to traffic analysis by the GFW. I cannot find any source to prove or disprove that though.
I've been fortunate enough to have access to non-GFWed bandwidth to play with on several occasions, and my experience would seem to suggest this is accurate. I can easily sustain 60mbps to the US when not subject to the GFW, but when using normal non-exempt bandwidth from the same (domestic) provider, could only sustain 5-10mbps. China's network architecture in Tier-1 cities is largely fine, and it's really the GFW t…
Re: Popular Chinese iOS apps compromised in malware attack
#85Earlier quoted context omitted.
To give some practically implementable advice, what you should do is run anything that parses untrusted input in a virtual machine or physically separate machine. This means you should browse the web, read e-mail and read any Office/PDF/whatever files sent to you in a virtual machine that doesn't have access to anything more than strictly needed. The reason is that most desktop software and OS kernels are not written…
Congratulations, you just described a security compliance program that's smaller than DFARS 252.204-7012, COBIT, PCI-DSS, HIPAA/HITECH, CLOUD SECURITY MATRIX, SANS CRITICAL CONTROLS, SOX, FEDRAMP/FISMA, and ISO 27001. I keep reading (IMO nonsense) that best practices like those compliance frameworks aren't enough (mostly coming from Josh Corman). However, breaches are the on the rise and only 10% of the IT industry i…
The practical advice they give is in the form of obvious generalities ("setup your firewalls", "update your OS") without any concrete details on how to best do that or even a discussion on which attacks are prevented and which aren't
Threat model discussions, advice on choosing which threats you can realistically defend against, theoretical principles and talk about possible attacks also seem to be non-existent.
Re: Popular Chinese iOS apps compromised in malware attack
#86Earlier quoted context omitted.
Congratulations, you just described a security compliance program that's smaller than DFARS 252.204-7012, COBIT, PCI-DSS, HIPAA/HITECH, CLOUD SECURITY MATRIX, SANS CRITICAL CONTROLS, SOX, FEDRAMP/FISMA, and ISO 27001. I keep reading (IMO nonsense) that best practices like those compliance frameworks aren't enough (mostly coming from Josh Corman). However, breaches are the on the rise and only 10% of the IT industry i…
Well, for starters those standards don't seem to be targeted to individuals, and often the goal seems to be to just allow someone to say "I'm compliant with XXX" rather than telling them how to be secure. The practical advice they give is in the form of obvious generalities ("setup your firewalls", "update your OS") without any concrete details on how to best do that or even a discussion on which attacks are prevente…
I hope you're not suggesting that security compliance isn't necessary because of the time-consuming external research involved. Sure its a usability problem but does that mean we should throw it out and just stick with Penetration Testing, Intrusion Detection Systems, and Risk Assessments? A security guy actually told me that just doing Pentesting, Risk Assessments, and IDS was good enough.
Personally, I believe the rest of the world doesn't have a reasonable alternative except for going through a thorough cleansing process of security compliance. That's why its been my mission to take out the guesswork from security compliance frameworks like DFARS 252.204-7012, COBIT, PCI-DSS, HIPAA, FEDRAMP/FISMA, ISO 27001/2.
However, I understand that these Compliance Frameworks might not be for you. It seems like you're already self-compliant with your security processes and you're so security-competent that you're doing things right the first time around.
Re: Popular Chinese iOS apps compromised in malware attack
#87Earlier quoted context omitted.
Well, for starters those standards don't seem to be targeted to individuals, and often the goal seems to be to just allow someone to say "I'm compliant with XXX" rather than telling them how to be secure. The practical advice they give is in the form of obvious generalities ("setup your firewalls", "update your OS") without any concrete details on how to best do that or even a discussion on which attacks are prevente…
>The practical advice they give is in the form of obvious generalities ("setup your firewalls", "update your OS") without any concrete details on how to best do that I hope you're not suggesting that security compliance isn't necessary because of the time-consuming external research involved. Sure its a usability problem but does that mean we should throw it out and just stick with Penetration Testing, Intrusion Dete…
Some of those processes are a fucking joke. The HIPAA technical safeguards include nothing particularly interesting; the hard part is the paperwork and legal ass-covering. Some PCI-DSS "auditors" are nothing more than salespeople who bought Nessus or similar and charge $10k/pop to run it, slap a logo on its report, and email it to you. Security regulations that businesses at large actually seem to care about have nothing at all to do with secure software engineering, just checking boxes like "have a firewall" and "have a password policy" and "have a network security policy" as if producing an endless trail of Word documents will make you less vulnerable.
Re: Popular Chinese iOS apps compromised in malware attack
#88Earlier quoted context omitted.
>The practical advice they give is in the form of obvious generalities ("setup your firewalls", "update your OS") without any concrete details on how to best do that I hope you're not suggesting that security compliance isn't necessary because of the time-consuming external research involved. Sure its a usability problem but does that mean we should throw it out and just stick with Penetration Testing, Intrusion Dete…
It seems that organizations where security is a compliance-driven process are barely concerned or not concerned at all about security breaches, only regulators. Some of those processes are a fucking joke. The HIPAA technical safeguards include nothing particularly interesting; the hard part is the paperwork and legal ass-covering. Some PCI-DSS "auditors" are nothing more than salespeople who bought Nessus or similar…
superuser2: you're telling me that having a process for firewall changes or rotating your keys is a joke? What other process is a fucking joke? System Hardening? Log review? Source code analysis? Updating your network diagrams? Physical access monitoring? These are all processes (and more) that compliance says you should do.
You bitch about word documents when I bet you've never even gone through a thorough compliance process.
Re: Popular Chinese iOS apps compromised in malware attack
#89Remember the NSA's infamous "I hunt sysadmins" [1]. Software engineers, ops people, and sysadmins at big tech companies with interesting data are high-value targets. If you can can run code on production infrastructure or a large install base, you should assume you are being actively, personally targeted by multiple advanced persistent threats, including at least one state intelligence agency, and adjust your OPSEC a…
Not even that -- there are tech firms that have teams that span multiple geographic boundaries and spoken languages, and they have varying degrees of opsec (from none to excellent, with your typical bellcurve). These firms receive contracts from Fortune 500 companies that have no interest in hiring/maintaining technical staff but have a need for apps that reach their userbase (of which numbers from hundreds of thousa…
Even more reason to enforce a compliance program (e.g. ISO 27001) to clean your systems and your code.
In fact, you're talking about growing cracks appearing everywhere, and when I look at your code right now, I see even you don't follow secure coding practices for Software Development. Not using the Pull Request Model? Just pushing commits directly into master? These (and more) are all bad security processes that I've identified in your github account.
https://github.com/ihsw/toxiproxy-php-client/commits/master
And you're the same people that talk about security compliance as if its a burden when you're not even doing basic hygiene with your own code.