7 ms·
Symantec found evidence of Longhorn against 40 targets spread in 16 countries
- janwillemb 9y ago> [Longhorn] has used a range of back door Trojans in addition to zero-day vulnerabilities to compromise its targets. I genuinely don't see the added value of antivirus corporations in this or anywhere else. Better tactics are: - patch - educate wife and children
- andrewguenther 9y agoWhile I think that consumer antivirus is pretty terrible, I think it is hard to say that antivirus companies don't add any value. I'd highly recommend reading up on Stuxnet and the work done by security firms (many of whom would qualify as antivirus corporations) to identify the source, spread, impact, and intent behind one of the most advanced technical attacks ever identified. Fun Wired article on the topic: https://www.wired.com/2011/07/how-digital-detectives-deciphered-stuxnet/ https://www.wired.com/2011/07/how-digital-detectives-deciphe... Also a book: http://a.co/0WGJm1H http://a.co/0WGJm1H
- janwillemb 9y agoThank you, that was a nice read.
- kjs3 9y ago- Don't run day to day with local admin
- chrisper 9y agoMany people say that the first thing they do is disable UAC. One person even told me that people who know what they are doing disable UAC. Not sure what to think of these people
- kefka 9y agoWell, I think this picture sums up a lot of thoughts on this subject: https://xkcd.com/1200/ https://xkcd.com/1200/ In a nutshell, your user account has all your data, all your session cookies, all your logins and passwords, all your documents.... Everything. And what can root/Administrator do? That's right, play with device drivers and systems stuffs. Once you have the primary user's account, unless it's a multiuser system, it's game over. Just with user creds, I can start encrypting files to #evil_private_key , emailing browser data, keylogging, screencapping, data injection, and being a general nuisance. The only good defense I've seen to this is what Qubes incorporates: Zones. It's virtual machines, with unique unspoofable borders, that you can configure to only allow the minimum amount of permission the container needs. Bank Zone only needs to talk to bank and financial websites. It doesn't need sound, or direct graphics access. Tor Zone allows talking through TCP on specified ports to and from, to allow Tor across system. In that case, yes a specific system could be compromised, but using containers like that keeps damage limited.
- problems 9y agoYes, exactly, I also have sudo no password on my linux boxes. If you're on my account you can keylog me or dump my keepass DB from memory. You may as well go ahead and have root too. UAC is particularly bad in that it also produces problems with older applications and causes other applications to pop up UAC dialogs frequently. It's a huge annoyance with little security impact. At worst it may make malware harder to remove if I do get infected - but in my experience, 99% of the malware you find kicking around on the internet isn't rootkit loaded 0 days - it's script kiddies crapping out iStealer to dump browser passwords or darkcomet to run DDoS botnets.
- Godel_unicode 9y agoLack of root makes being stealthy and covering tracks more difficult. Log clearing almost always requires elevation. If getting owned is a given (and it is) then the most important thing is detection after the fact.
- jsmthrowaway 9y ago
- sp332 9y agoMost attacks do not involve 0-days. Being protected against many known kinds of attacks is valuable.
- DougN7 9y ago> educate wife and children I'm guessing you don't have teens who have to have the latest mod for every game they play. Giving up a very real download for the slight chance of a virus is a risk they are very willing to make.
- M_Grey 9y agoSeriously, it's not just teens either, it's many college students too. In general, anyone who didn't have to buy their own stuff has a bit less respect for it, and while that doesn't describe all teens or college students, it describes a huge number of them; a rich target pool. I remember in the early days of exploitative XDCC botting, practically all of the most exploited ip ranges were scholastic; new devices each semester, often given to teens as a present.
- ryanmarsh 9y agoThis is why abstinence education results in teen pregnancies. Teenagers require birth control and supervision.
- munin 9y agoMy wife has a PhD and ran up to date Firefox with noscript, Flash disabled, and ad-blockers, uses webmail, and doesn't install software or download executables in general. She still got hacked, due to a bug in Firefox that was exploited despite having noscript and Flash disabled. How, exactly, would you have educated her?
- haddr 9y agoIt's hard to be "invulnerable" these days. I guess you could avoid the majority of infections by using some "weird" software configuration: such as linux with some nightly built of chromium. I heard that Macs are also quite resistant (still). But these things are very dynamic and change fast. What was good yesterday ("educate" users), may not be relevant any more today.
- xorblurb 9y agoReal question: what kind of website she visited to get such infection? It's quite uncommon (even though theoretically an existing risk pretty much everywhere, and probably even not that hard to do if you control a website)
- munin 9y agoreddit, imgur, news sites. It was via an ad delivered over an ad network, so who knows really.
- williamscales 9y agoSounds like the kind of thing that could get anybody, even a reasonably paranoid person.
- janwillemb 9y agoHow come the adblocker didn't block the ad network?
- munin 9y ago
- happycube 9y agoToo bad it's not like Microsoft's Longhorn - then it would have been delivered years late as a shadow of it's promised self (Vista) ;)
- simlevesque 9y agoAnd it would be deprecated tomorrow [1] [1] https://support.microsoft.com/en-ca/help/22882 https://support.microsoft.com/en-ca/help/22882
- insulanian 9y agoNice catch :)
- toyg 9y agoYeah, when I read the headline I was puzzled. "What has a canned MS project got to do with Symantec?" God I'm so old.
- eganist 9y agoMan, I miss those days too. Some of the most creative UX experiments came out of the Windows team back then. Too bad they couldn't get any of it to build worth a damn.
- azinman2 9y agoI wonder if qihoo 360 or other Chinese security companies would post such blog entries on Chinese intelligence malware and operations in a similar vain. Same for Russia.
- linkregister 9y agoKaspersky just announced a comprehensive report on the Moonlight Maze Russian government campaign against U.S. military networks in the 1990s. Kaspersky has also published at least two recent (last 10 years) campaigns attributed to the Russian government or state-aligned actors.
- curiousgal 9y ago>On one occasion a computer in the United States was compromised but, following infection, an uninstaller was launched within hours, which may indicate this victim was infected unintentionally. How do they know that?
- ttctciyf 9y agoThey're being polite to the CIA whose charter forbids domestic ops (or at least severely constrains them.)
- crazyhatfish 9y agoIts Symantec, they run AV on thousands of computers across the globe. All the events generated from these computers get sent to them. Removal/cleaning procedures would be one of those events, probably for this very reason (i.e creator gets sloppy, installs and then uninstalls on their own machine).
- gwu78 9y agoOT. Symantec: Why require Javascript? Why not make it optional? For users who do not use Javascript to read news: https://www.symantec.com/connect/tr/blogs/longhorn-tools-used-cyberespionage-group-linked-vault-7 https://www.symantec.com/connect/tr/blogs/longhorn-tools-use...
- driverdan 9y agoIt's nice that Symantec has shared this info but their attempt at neutrality is frustrating. Based on their data they could easily state that Longhorn is a CIA group. They also didn't provide any links to WikiLeaks for people to learn more about what Vault 7 is.
- xorblurb 9y agoHow is this even neutrality at this point? And what is there even to attempt? It is ridiculous and serves no purpose that they do not write "CIA" once.
- jfoster 9y agoWould they want to know for absolute certain the source of it, or if they did know, would they want to acknowledge that? Suppose it is from the CIA, they acknowledge it, and then add removal of it to their tools. They (NASDAQ-listed public company) would have then just knowingly acknowledged interfering with the activities of the intelligence agency in the country in which they operate. I think it's smart for Symantec to remain completely neutral and unassuming.
- hl5 9y agoSymantec's board should be hung for treason for developing and distributing weapons that eliminate American warfare capabilities.
- sctb 9y agoLet's please not go there, here. https://news.ycombinator.com/newswelcome.html https://news.ycombinator.com/newswelcome.html https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html