Researchers crack open malware that hid for 5 years
arstechnica.com
Researchers crack open malware that hid for 5 years
1–10 of 232 posts
Re: Researchers crack open malware that hid for 5 years
#2Re: Researchers crack open malware that hid for 5 years
#3Re: Researchers crack open malware that hid for 5 years
#4Some at the NSA is having a bad day reading this.
Re: Researchers crack open malware that hid for 5 years
#5That is a really impressive piece of software. USB exfiltration of data on air gapped machines is next level. I'm in awe of their skill.
"The library was masquerading as a Windows password filter, which is something administrators typically use to ensure passwords match specific requirements for length and complexity. The module started every time a network or local user logged in or changed a password, and it was able to view passcodes in plaintext."
Re: Researchers crack open malware that hid for 5 years
#6A more cynical view would be that many security firms sell both security and forensics/surveillance. One of those two product lines has to be fundamentally defective.
Is the position that hackable endpoints are a good compromise supportable any longer? Or has it bitten US entities in the ass enough that making truly secure computing a reality for computer users, even if it blinds the surveillance state, becomes the new goal.
Re: Researchers crack open malware that hid for 5 years
#7That is a really impressive piece of software. USB exfiltration of data on air gapped machines is next level. I'm in awe of their skill.
Re: Researchers crack open malware that hid for 5 years
#8Re: Researchers crack open malware that hid for 5 years
#9That is a really impressive piece of software. USB exfiltration of data on air gapped machines is next level. I'm in awe of their skill.
And they had every login for the network it was found on: "The library was masquerading as a Windows password filter, which is something administrators typically use to ensure passwords match specific requirements for length and complexity. The module started every time a network or local user logged in or changed a password, and it was able to view passcodes in plaintext."
Re: Researchers crack open malware that hid for 5 years
#10Some security professionals have expressed the view that insecure endpoints represent a good compromise. That is, without the US government being able to snoop on endpoint devices, encryption would have to be tightly controlled, so that the government could retain intelligence and investigatory capability. A more cynical view would be that many security firms sell both security and forensics/surveillance. One of thos…
1. endpoints are vulnerable because they are exceptionally hard to secure,
2. and attacking endpoints can be targeted and specific,
the governments case that weakening encryption is necessary for warranted search is weak. Even with strong encryption the government can exploit the targeted communicant's endpoint to learn either the plaintext or the encryption keys. This isn't a compromise so much as a statement of reality and what is likely to remain reality for some time to come. Weakening encryption, for the most part, provides benefits to the government in the form of mass surveillance, but for a variety of reasons doesn't offer much benefit in the form of limited, specific searches.
>making truly secure computing a reality for computer users,
We can make endpoints more secure, but I see no path to endpoint security that will keep out a determined well resourced adversary.