Live data from Hacker News

Sophisticated OS X Backdoor Discovered

securelist.com

91–100 of 155 posts

Re: Sophisticated OS X Backdoor Discovered

#91
post #77

Earlier quoted context omitted.

No, Kaspersky Labs is using correct terminology. Some rootkits install a backdoor. Not all rootkits install a backdoor -- some merely conceal themselves and operate locally. The famous Sony Rootkit is one such example of a rootkit which did not add a backdoor. The defining characteristic of a rootkit is that it conceals its presence from the rest of the system. Backdoor.OSX.Mokes.a doesn't really do this -- it's only…

Whether the terminology is technically correct or not, I think it's obvious that it can easily be interpreted in different ways, some of which are incorrect. As such, while it may not be wrong, it is poorly chosen, and may be misleading. A better way to phrase it might have been "A sophisticated backdoor targeting OS X discovered".

> "A sophisticated backdoor targeting OS X discovered"

Unsure how this clears up the rootkit versus backdoor confusion...

Re: Sophisticated OS X Backdoor Discovered

#92

Earlier quoted context omitted.

I agree, the terminology Kaspersky Labs is using is incorrect and misleading. The further poster is right that this should be labeled as "rootkit."

No, Kaspersky Labs is using correct terminology. Some rootkits install a backdoor. Not all rootkits install a backdoor -- some merely conceal themselves and operate locally. The famous Sony Rootkit is one such example of a rootkit which did not add a backdoor. The defining characteristic of a rootkit is that it conceals its presence from the rest of the system. Backdoor.OSX.Mokes.a doesn't really do this -- it's only…

Backdoor is a politically loaded term at this point. Backdoors (in privacy-related discourse) are vulnerabilities inserted intentionally by the manufacturer or government with supply-chain cooperation. The claim "Backdoor found in X's product" is roughly equivalent to the claim "Evidence found that X is a collaborator with the surveillance state" to many people, so we might want to be careful about throwing it around when we don't mean that.

Re: Sophisticated OS X Backdoor Discovered

#93

Earlier quoted context omitted.

No, Kaspersky Labs is using correct terminology. Some rootkits install a backdoor. Not all rootkits install a backdoor -- some merely conceal themselves and operate locally. The famous Sony Rootkit is one such example of a rootkit which did not add a backdoor. The defining characteristic of a rootkit is that it conceals its presence from the rest of the system. Backdoor.OSX.Mokes.a doesn't really do this -- it's only…

Calling it a backdoor may be correct, but calling it an "OS X backdoor", particularly with no other context in the title, is not. It's merely clickbait.

Yes, I concluded from the title it's backdoor in OS X itself (which would be huge news), not merely a backdoor kit running on OS X (which is not really all that notable, absolutely no surprise that backdoor kits exist for OS X and this one is nothing special among them as it seems).

Re: Sophisticated OS X Backdoor Discovered

#95
post #21

Earlier quoted context omitted.

Backdoors can be installed after the fact. The vendor putting in a back door is only one way for it to be present. This would be malware inserting a back door for further exploitation.

If you previously establish that the vulnerability was introduced by a third party, then "backdoor" might be an OK term afterward - after the context has been introuced. In an example without context (like, a headline), "backdoor" strongly implies that it was built by the vendor. I have to disagree with you and concur with the other commenters saying this was a very misleading choice of words by Kaspersky. They shoul…

I make the same association. A door is part of a building, and is put there during construction (initial release) or in owner-planned renovations (software updates).

I've never heard of someone breaking into a building by cutting a hole into a wall to install their own entry door that they have a key to, but that's the scenario this "OS X backdoor" is describing.

Re: Sophisticated OS X Backdoor Discovered

#96
post #87

Please clarify the title. It sounds like Apple put a backdoor into OSX.

I suggest "sophisticated malware backdoor payload for OSX discovered." Then it's clear it's not a part of the OSX itself and that it's something that has to be somehow installed by some third party (e.g. using any malware installation method or a real spy).

Re: Sophisticated OS X Backdoor Discovered

#97
post #77

Earlier quoted context omitted.

Whether the terminology is technically correct or not, I think it's obvious that it can easily be interpreted in different ways, some of which are incorrect. As such, while it may not be wrong, it is poorly chosen, and may be misleading. A better way to phrase it might have been "A sophisticated backdoor targeting OS X discovered".

> "A sophisticated backdoor targeting OS X discovered" Unsure how this clears up the rootkit versus backdoor confusion...

It doesn't, it clears up the 'this was put in by Apple' confusion.

Re: Sophisticated OS X Backdoor Discovered

#98
post #66

Earlier quoted context omitted.

No, that's wrong. Wikipedia has definitions that match my own knowledge, so i'll link and quote those. https://en.wikipedia.org/wiki/Rootkit "A rootkit is a collection of computer software, typically malicious, designed to enable access to a computer or areas of its software that would not otherwise be allowed (for example, to an unauthorized user) while at the same time masking its existence or the existence of othe…

No, that is really wrong. Rootkits aren't for privilege escalation, see the paragraph immediately following your quote: "... an attacker can install it once they've obtained root or Administrator access." Calling BO a backdoor is a major corruption of the word, as you loose the only word for describing intentionally weakened security - so that you may describe a thing which already has several more explicitly definin…

The installation of the rootkit is different from its purpose. A rootkit may require a root permission to install, perhaps piggybacking on another legitimate install such as in the famous Sony BMG rootkit. Or it may use an exploit to gain root access and install.

However, once installed, the purpose is the same: To provide the attacker with root permissions. It will also typically use its access to root permissions to hide itself from detection.

Re: Sophisticated OS X Backdoor Discovered

#99
post #2

Are video captures actually possible? I could imagine video capture as part of a RAT, but what scares me is the idea of video capture that doesn't turn on the camera activity light. Are there any examples of that?

I'm going to dig into this and find out, I've wanted to know for ages.

If the LED == LED_TORCH, then it looks like it may be possible:

https://github.com/patjak/bcwc_pcie/blob/8cc44d67f3c924f30a8...

Either way, I'm planning on buying some spare parts to actually test and possibly PoC this.

Re: Sophisticated OS X Backdoor Discovered

#100

Earlier quoted context omitted.

> "A sophisticated backdoor targeting OS X discovered" Unsure how this clears up the rootkit versus backdoor confusion...

It doesn't, it clears up the 'this was put in by Apple' confusion.

Yes, that's exactly what I was trying to address. I should have quoted the first sentence of the parent to make that obvious, since there were a few assertions in that comment.
Post reply on HN