4 ms·
I'm guessing they're leaving out the "sophisticated" details of the compromise. Using encryption to hide your malware from virus scanners and using some compute
by datums 17y ago
I'm guessing they're leaving out the "sophisticated" details of the compromise. Using encryption to hide your malware from virus scanners and using some computer "social engineering" (ssl connection) is not very sophisticated. I don't understand why it needs to be sophisticated ? because it's google ? It's known that some of the largest viruses have spread to government comuputers (sobig).
- joe_the_user 17y agoPerhaps is was custom encryption not previously seen? I would imagine that while using encryption doesn't imply massive resources, developing custom encryption does.
- DanielBMarkham 17y agoI don't know a lot about security -- certainly not as much as some here (although I can follow along with their banter easily enough) But I know enough not to feel comfortable commenting on this in a public forum. (Not trying to pass a value judgment on you, just suggesting a reason you guys might not be getting an answer to your question.)
- mariorz 17y ago>But I know enough not to feel comfortable commenting on this in a public forum. why?
- DanielBMarkham 17y agoBecause it's a lose-lose proposition. If I get it right, I'm helping some other schmuck break into people's systems. If I get it wrong then I'm the schmuck. And yes, people will learn to break into systems without my help, and yes, openness is the best defense we have against these things. I've just decided I'm just not going to put anything out there that could possibly be used like that. I tell you one of the reasons why: about twelve years ago, back in the Windows 3/95 days, I got a call from some stock brokers in New York. They wanted to know basically how to spy on their employees. So I sketched out a system where software would take pictures of their desktops every few seconds -- this was a long time before such software ever existed. I also sketched out several ways you could keep the software from being detected. I never knew if they wrote the system or what happened to my design, but it never sat well with me. I always wished I could have went back and not provided them with the information. So now I don't do that anymore.
- ErrantX 17y ago> I never knew if they wrote the system or what happened to my design, but it never sat well with me. I always wished I could have went back and not provided them with the information. This is the least favourite part of my job too. I have a couple of uncomfortable memories from university days when I ran my mouth about some little ideas.
- datums 17y agoNo clue. I'm guilty of reading the article “The encryption was highly successful in obfuscating the attack and avoiding common detection methods,” One of the malicious programs opened a remote backdoor to the computer, establishing an encrypted covert channel that masqueraded as an SSL connection to avoid detection
- joe_the_user 17y agoSheesh, I'm pretty sure the bad guys aren't going to gain much by any vagues sketches of an approach that apparently requires a whole modern state to execute... The original is specific in points... And there are zillions of reasons for people not to reply to my post. I know I'm not always that interesting...
- swolchok 17y agoPacking is already fairly effective. http://polypack.eecs.umich.edu/ http://polypack.eecs.umich.edu/
- datums 17y agoThere's no requirement for it to be custom. It's encryption.