9 ms·
Transmission BitTorrent Client OSX/Keydnap Malware Incident Q+A
- SturgeonsLaw 10y agoThat's not the first time this has happened... http://gizmodo.com/yes-ransomware-can-affect-macs-too-1763239644 http://gizmodo.com/yes-ransomware-can-affect-macs-too-176323...
- king_phil 10y agoI would have thought that Mac users would be a good target in general because they might have better income than Windows users...
- rahimnathwani 10y agoMaybe per person, but probably not in aggregate.
- mkj 10y agoTorrent users might be a good target for better than average internet connections for ddos?
- arianvanp 10y agoAgain? :(
- devn0ll 10y agoThat's what I thought as well: http://news.softpedia.com/news/transmission-bittorrent-client-website-hacked-again-to-spread-mac-malware-507771.shtml http://news.softpedia.com/news/transmission-bittorrent-clien...
- davej 10y agoSecond time that this has happened to Transmission this year. Last time a ransomware got included. If you're a Transmission user then be very cautious when installing new versions.
- simcop2387 10y agoMain reason that I only install stuff like this from my distro's repositories. Anyone know if this would have affected homebrew and such on OSX?
- yAnonymous 10y agoWhen this happens regularly like with Transmission, is there a guarantee the version in official repos is not affected? The only way to be sure would be code checks and I doubt they do that.
- fdgdasfadsf 10y agoThat is why packages can be so slow to filter through from upstream.
- yAnonymous 10y agoFor Ubuntu, the universe repo (where Transmission is located) is community maintained and not even security upgrades are guaranteed. They do key checks only.
- jquast 10y agoHomebrew packages verify checksums, so very unlikely to be affected.
- cormacrelf 10y agoProbably a good idea to turn off auto-update from Transmission's preferences and only use brew update && brew cask install --force transmission to update. Even though they're also meant to be checksummed, I can't know whether an attacker also compromised the checksum mechanism.
- deep_attention 10y agoAre there any good alternatives to Transmission on OS X?
- beaker52 10y agouTorrent http://www.utorrent.com/ http://www.utorrent.com/
- temp 10y agoOnly if you want an interface filled with ads.
- taspeotis 10y agoPay for it then? Netflix scratches my entertainment itch now, but prior to it launching in Australia I almost went ahead and paid for uTorrent. It's a good, lightweight client. Software that works well deserves to be financially supported.
- iopq 10y agoqBittorrent is just as good and free, why pay for something that's maybe a few MB smaller? Do you really not have gigabytes of RAM on your machine? If you don't, I suggest spending that money on RAM.
- type0 10y ago> Pay for it then? Why? qBittorrent does a better job and it's open source in case you need to modify it.
- intoverflow2 10y agoSome peoples tastes are broader than the mainstream American TV on offer by Netflix
- SyneRyder 10y ago
- FatalLogic 10y agoI'm not a Transmission user, but this makes me wonder, as a sort of Ask HN question: How long do you wait before updating software? If you always update as soon as possible, then you risk getting hit by a compromise like this one, or you could suffer other unintentional bad effects of a botched update. But the longer you delay updating, the more you raise your risk of becoming a victim of a new vulnerability that's just been patched and is now in the wild.
- labster 10y agoI wait about a week, unless I've heard out of band talk about some terrible hack with a punny name and we all need to upgrade NAO!1! I suppose I should always look for a secondary source for release notes or such as soon as possible; I don't because I am a lazy human.
- FatalLogic 10y agoYes, totally, if you want to make the best decision, then you have to keep up with the news. That's why I'm interested in other opinions about this, because there's a lot of datapoints you need to factor into a decision. It's not a simple decision. That's work, and we are lazy humans, you're right. But, I don't wait a whole week if the update is from an organization which I think I can trust not to totally botch an update, because they're conscious of the enormous potential for costly legal liability. I'm thinking of organizations such as Microsoft, Apple, Nvidia, AMD, Google, as a few examples. I might wait 1 or 2 days in that case.
- labster 10y agoIt's more like a botched update from Microsoft, Apple, etc. will be noticed by lots of people within one or two days.
- FatalLogic 10y agoThe size of the user base is certainly an important factor. To maybe exaggerate a contrary opinion though, I'd say that users of, for example, Ubuntu Linux, are far more alert to security issues than Microsoft customers. I'm not totally disagreeing, I'm just trying to say that calculating a confidence score for software updates is not simple. Maybe it's clearer if I give you a real-world example: I use cryptocurrencies to move moderately large amounts of capital in my business, and so my paranoia-level for software installed on the single, air-gapped laptop that handles cryptocurrencies is sky high and crazy cautious. My other business is separated from that, and I can be much more relaxed about software updates for it, because the risks are much lower.
- Veen 10y agoI like Transmission, but this is the second serious security problem they've had this year. Once you can forgive, but twice and it's time to look for a new BitTorrent client.
- okket 10y agoFYI: Transmission binaries are now hosted on GitHub, so it is very unlikely that anything like this can happen in the future without compromising developer machines.
- Mahn 10y agoMore info on the malware: > The OSX/Keydnap backdoor is equipped with a mechanism to gather and exfiltrate passwords and keys stored in OS X’s keychain. The author simply took a proof-of-concept example available on Github called Keychaindump. It reads securityd’s memory and searches for the decryption key for the user’s keychain. This process is described in a paper by K. Lee and H. Koo. One of the reasons we think the source was taken directly from Github is that the function names in the source code are the same in the Keydnap malware. Source: http://www.welivesecurity.com/2016/07/06/new-osxkeydnap-malware-hungry-credentials/ http://www.welivesecurity.com/2016/07/06/new-osxkeydnap-malw...
- GirlsCanCode 10y agoB..b..bbut! I thought Macs were _secure by design_ and didn't get infected! Did they lie?
- danieldk 10y agoThis is why applications should use app sandboxing on OS X. And Apple should provide an option to reject (by default) any application that is not signed + sandboxed, rather than: anything, signed, or app store.
- aparadja 10y agoWow. I'm the author of keychaindump. Didn't expect to become a malware co-author.
- robk 10y agoSeemed pretty likely though don't you think?
- aparadja 10y agoI guess any security tools and scripts are bound to be used for naughty stuff at some point, but I thought "real" malware writers would put more effort (at least obfuscation) into their products. Keychaindump is a crude hacky PoC, and I honestly didn't expect it to get directly copy-pasted into "serious" malware.
- deleted 10y ago[deleted]
- okket 10y agoService announcement: You were only at risk when you downloaded fresh copies from the website. As with the previous incident, updates within the app were safe and checked.
- xnyhps 10y agoIt's pretty scary that they still haven't fixed the Sparkle RCE vulnerability from a few months back. Attackers with access to their servers could've installed malware for every user, even if they didn't install the update.
- thesimon 10y agoAre Transmission releases usually codesigned?
- okket 10y agoYes. And updates are checked within the Transmission app.
- thesimon 10y agoLooks like it was signed by a different developer: https://news.ycombinator.com/item?id=12403906 https://news.ycombinator.com/item?id=12403906 In comparison to Windows, macOS doesn't really seem to show the developer in the normal user flow.
- arm 10y agoYep. That’s at least one advantage for macOS apps that use Installer.app¹ to install; Installer.app makes it really easy to see the certificate². ―――――― ¹ — https://en.wikipedia.org/wiki/Installer_(OS_X) https://en.wikipedia.org/wiki/Installer_(OS_X) ² — http://f.cl.ly/items/1s1E3n19273M1l3i3S2X/developer_id_installer.png http://f.cl.ly/items/1s1E3n19273M1l3i3S2X/developer_id_insta...
- kalleboo 10y agoSo what happened with the codesigning? That's pretty much the only viable line of defense for the average user (nobody is going to be verifying SHA signatures, or the site is going to be compromised along with the download) Was the malware version also signed with an official Apple Developer ID? The same ID? Is a change of ID verified with the auto-updater? If there was a malicious Developer ID, has it been revoked by Apple?
- tajen 10y agoInteresting question. According to https://developer.apple.com/support/certificates/ https://developer.apple.com/support/certificates/: >> If your membership expires, users can still download, install, and run your Developer ID–signed applications. However, once your Developer ID certificate expires, you must be an Apple Developer Program member to get new Developer ID certificates to sign updates and new applications. What I understand is that codesigning costs $99 a year, which open-source projects may want to skip, but this harms their credibility if their downloads are compromised.
- SyneRyder 10y agoI really thought Apple had added a free option (maybe even specifically for open source projects?), but I can't find it anywhere. Can anyone else find that info, or am I misremembering?
- Mtinie 10y agoI believe you are misremembering the details. There is a free account option, but code signing isn't available. https://developer.apple.com/support/compare-memberships/ https://developer.apple.com/support/compare-memberships/ What's not clear to me, however, is if the educational option allows for free developer-level memberships.
- SyneRyder 10y agoThank you! I'd confused it with recent changes to the iOS program allowing people to self-sign so they can test on their own iOS devices. It looks like Educational memberships are Sign-In With Apple ID only, which doesn't provide a Developer ID (which is required for code signing, as far as I can tell).
- rahiel 10y agoIt's nasty that a free software project has to deal with this, given their limited resources. This shows the importance of reproducible builds and using package managers with verification like APT or homebrew.
- okket 10y agoSimple file check if you are infected: if [ -f "/Applications/Transmission.app/Contents/Resources/License.rtf" ] || [ -f "/Volumes/Transmission/Transmission.app/Contents/Resources/License.rtf" ] || [ -f "$HOME/Library/Application Support/com.apple.iCloud.sync.daemon/icloudsyncd" ] || [ -f "$HOME/Library/Application Support/com.apple.iCloud.sync.daemon/process.id" ] || [ -f "$HOME/Library/LaunchAgents/com.apple.iCloud.sync.daemon.plist" ] || [ -d "/Library/Application Support/com.apple.iCloud.sync.daemon/" ] || [ -f "$HOME/Library/LaunchAgents/com.geticloud.icloud.photo.plist" ]; then echo "OSX/Keydnap detected."; else echo "You're good."; fi Source: https://gist.github.com/kaizensoze/ca96d039b295db220951d42ca7c83d89 https://gist.github.com/kaizensoze/ca96d039b295db220951d42ca...
- toxik 10y agoAnd to run it from the clipboard: pbpaste | sh -
- labster 10y agoWhy not this? curl https://gist.githubusercontent.com/kaizensoze/ca96d039b295db220951d42ca7c83d89/raw/ | bash
- okket 10y agoYour line downloads and executes the latest version of the gist, it could have changed from a file check to a virus installer by the author (unlikely, but I have to point it out). To be a bit more safe (while trusting that GitHub is not compromised) pin a known, verified version: curl https://gist.githubusercontent.com/kaizensoze/ca96d039b295db220951d42ca7c83d89/raw/a26e5a025ea21d3a0af536eeca49619272d0068f/quick-osx-keydnap-check | bash (sorry for the overlong line)
- heeen2 10y agothis pattern is just as dangerous (maybe less for github if you trust them) because you can detect curl and deliver malicious code: https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b...
- yladiz 10y agoKinda sucks, and I haven't followed Transmission for a while, but them transitioning more to Github is a good thing -- I trust Github more than a self hosted solution, in general. It sucks they've been compromised twice in a year, but hopefully this will help mitigate some of that.
- GirlsCanCode 10y agoFool Me a Twice, Shame On Me
- dantiberian 10y agoThey never responded with details of what they were doing to improve security after the last incident: https://forum.transmissionbt.com/viewtopic.php?f=1&t=17938 https://forum.transmissionbt.com/viewtopic.php?f=1&t=17938. The outside appearance is that they didn't address the problem seriously enough.
- jrochkind1 10y agoYeah, I was thinking, didn't this happen before?
- lqdc13 10y agoOne of their servers or dev machines might have a rootkit. At this point, wiping basically everything is required.
- Shank 10y agoLooks to me like the developers don't actively participate in their forum. Seems like this would be way too big to go unreplied to for months.
- stevenh 10y agoIs there any evidence the developers aren't doing this themselves as a false flag attack on their own product to profit off of the malware?
- huhtenberg 10y ago> Am I at risk? Instead of "Blah-blah, less than a day, go check yourself", they could grep the logs for IPs (and session cookies if they log that) of lucky winners and explicitly inform them, when they hit any page on their site. Then show generic version to everyone else. This takes all but 5 minutes to set up.
- jmiserez 10y agoNice idea with a major problem: If they did this, the absence of such a message could suggest that you were not affected, when in fact you could be (changed IP, cleared browser, etc). False negatives are pretty bad in this case, better for users to check themselves.
- deleted 10y ago[deleted]
- wepple 10y agoplus everyone behind a single NAT IP will get the message and freak out.
- huhtenberg 10y agoNo, you are missing the point. It will all remain exactly as it is now, except for the case when they recognize a visitor that is likely to have downloaded the malware. In this case they should throw an extra warning.
- jmiserez 10y agoYou would be right if nobody besides the affected people would ever know that they are doing this. But as soon as other people know or hear of it, they will go check the website to "see if they are affected". Even if the website has a huge disclaimer telling people that they could still be affected, the absence of the warning would still suggest that they are not affected, even when they could be.
- rem1313 10y ago
- mirap 10y agoThis is happening too often... so, what other BitTorrent clients are you using on Mac OS?
- menzoic 10y agoAccording to the article, the title is wrong "The infected file was available for download somewhere between a few hours and less than a day."
- tomasandrle 10y agoThanks for the correction. I wrote the original title based on the warning on their homepage: "Critical security notice to users who downloaded Transmission 2.92 for Mac on August 28th or 29th".
- mikegerwitz 10y agoI notice that they don't sign their releases.
- aorth 10y agoYou might want to install Objective-See's free BlockBlock tool to block these type of things: https://twitter.com/objective_see/status/771189100355264512 https://twitter.com/objective_see/status/771189100355264512 Also, their other (free, open source) tools are very good too, like KnockKnock and RansomWhere: https://objective-see.com/ https://objective-see.com/
- zyxley 10y agoTime to switch to qBittorrent.
- varcharlie 10y agoThey say that the infected file was only there for a day, but maybe it would behoove them to do some bash-fu w/ their logs and get an approximation of the number of users affected!
- fastball 10y agoWow, I downloaded a binary from the website in that exact timeframe. Luckily, it was only the CLI version, which I was putting on an Ubuntu system...
- cjbramble 10y agoI will be using Deluge now.