4 ms·
Second time that this has happened to Transmission this year. Last time a ransomware got included. If you're a Transmission user then be very cautious when inst
by davej 10y ago
Second time that this has happened to Transmission this year. Last time a ransomware got included. If you're a Transmission user then be very cautious when installing new versions.
- simcop2387 10y agoMain reason that I only install stuff like this from my distro's repositories. Anyone know if this would have affected homebrew and such on OSX?
- yAnonymous 10y agoWhen this happens regularly like with Transmission, is there a guarantee the version in official repos is not affected? The only way to be sure would be code checks and I doubt they do that.
- fdgdasfadsf 10y agoThat is why packages can be so slow to filter through from upstream.
- yAnonymous 10y agoFor Ubuntu, the universe repo (where Transmission is located) is community maintained and not even security upgrades are guaranteed. They do key checks only.
- jquast 10y agoHomebrew packages verify checksums, so very unlikely to be affected.
- cormacrelf 10y agoProbably a good idea to turn off auto-update from Transmission's preferences and only use brew update && brew cask install --force transmission to update. Even though they're also meant to be checksummed, I can't know whether an attacker also compromised the checksum mechanism.
- minhoryang 10y agoDo we need to --force just for updating?
- millak 10y agoYep, brew cask will just tell you that Transmission is already installed without --force.
- Kudos 10y agoDepending on where they get their checksums. Anyone can submit an app update, so long as the official download link matches the provided checksum then it will get merged. The only benefit here is the delay introduced in receiving the update.
- jrochkind1 10y agoAnd where do the checksums come from?
- jquast 10y agoChanges made by GitHub pull requests. I'm sure an anonymous contributor who submits only a checksum change, without version bump, would most certainly fail review.
- jrochkind1 10y agoI don't believe that's true. I'm googling to try to find how Homebrew uses checksums and where it gets them. But not everything homebrew installs comes from GitHub, so I don't see how checksums for all of it could come from 'Changes made by GitHub pull requests'. And it looks like homebrew checksums both source packages and pre-compiled binaries. There's no way an upstream dependency would be providing their own checksum for a homebrew compiled binary. Homebrew also switched from using MD5 to using SHA1 recently (https://github.com/Homebrew/brew/blob/master/share/doc/homebrew/Checksum_Deprecation.md https://github.com/Homebrew/brew/blob/master/share/doc/homeb...), obviously all of their dependencies didn't switch in unison too, which suggests the checksums do not come from the dependencies themselves. Looking for more info about this, having trouble finding it. To have confidence in homebrew's checksum system, one needs to know how it works and where they come from, but having trouble finding it. Or did you mean the checksum is made in a PR to homebrew's own repo? Right, but the question is still where it comes from. If it was generated from bad source obtained from upstream, it will of course be bad. It's just verifying that the package as installed matches what homebrew maintainers meant to install; but that's no guarantee that what homebrew maintainers meant to install wasn't bad in the first place. Since transmission was distribution bad packages itself due to a hack, I'm not following how homebrew providing a checksum means that it can't re-distribute bad packages from upstream. It does mean that homebrew itself is harder to hack than transmission, but doesn't necessarily help when transmission is hacked.
- okket 10y agoYou were only at risk when downloaded fresh copies from the website. Updates were checked by the already installed Transmission.
- madeofpalk 10y agoExcept that time where the auto update mechanism was actually distributing a hacked version http://www.macrumors.com/2016/03/07/transmission-malware-downloaded-6500-times/ http://www.macrumors.com/2016/03/07/transmission-malware-dow...
- galad87 10y agoNo it did not. They distributed a new version via the build-in updater to try to remove the malware from the copies downloaded from the website. Sparkle use a digital signature and the malware author did not have the private key to create a valid signature for the update. So even if a malware was downloaded, Transmission would report a "invalid archive downloaded" error.
- rvanmil 10y agoIt was the .dmg file hosted on their own server, so any version could be compromised. I guess the safest route to take is to build the app from source.
- javitury 10y agoI thought it was a dejavu for a moment
- amykhar 10y agoConspiracy theorist in me wonders if this isn't an attack by somebody hired by an anti-piracy group.
- aj_n 10y agoI feel stupid knowing that I actually considered this when installing on the 28th, but thought that they wouldn't allow a repeat of KeRanger. Looks like I'll be building all my software from source now (and switching to Aria2).