13 ms·
My application ran away and called home from Redmond
- 2rsf 7y ago> Microsoft Windows 10 sends all new unique binaries for further analysis to Microsoft by default. They run the executable in an environment where network connectivity is available. how did the author reach to this conclusion ? is it documented somewhere ?
- antsar 7y agoHe includes this screenshot[0], addressing the "send" part. The "run" part seems evident from the network traffic coming from MSFT. [0] https://miro.medium.com/max/334/0*g_3L3SxR4IYoBAxD https://miro.medium.com/max/334/0*g_3L3SxR4IYoBAxD
- AlexandrB 7y agoFrom a copyright law perspective, this seems wild. Microsoft is downloading and running binaries from entities that may have never given Microsoft license to do so, including Microsoft's competitors. All based on a permission setting configured by an unrelated third party (the user).
- gnode 7y ago> never given Microsoft license to do so It's possible that they don't need it. There are fair use exemptions for reverse engineering and automated analysis. These may be the legal basis on which anti-malware research can be conducted.
- Analemma_ 7y agoIndeed, there have to be exceptions like this. Otherwise malware authors could sue AV companies for infringement, which don’t seem to fit the intention of IP law.
- zeveb 7y ago> Otherwise malware authors could sue AV companies for infringement, which don’t seem to fit the intention of IP law. 'You may sue the AV company for $1 million; users who suffered from your malware will civilly sue for $100 billion, and the government will charge you with crimes and put you away for a decade. Your move.'
- wtracy 7y agoA tangent: There's this fascinating (to me, anyway) line between "viruses" (including worms, Trojans, and similar malware) that antivirus programs will tackle, and adware/spyware that they usually don't. The difference between the two is whether it not there's a corporation publicly taking credit for the program and suing antivirus companies for defamation over calling it a "virus". Adware/spyware is limited in distribution methods and payload types by the letter of the law, but otherwise the two classes are functionally identical.
- appleflaxen 7y agobut until there is a court case with specific facts, that is very much a hope and a prayer by microsoft. it is, indeed, a risk they are taking.
- em-bee 7y agoi believe fair use only applies to software that you legally acquired. if microsoft copies an application from my computer without asking, then it did not legally acquire it. malware is a different case. malware entered my computer with the permission of the malware creator. i didn't steal it from them, but it came to me willingly. hence i am allowed to analyze it, and i am allowed to delegate that task to someone else.
- cududa 7y agoYes but who’s to say it came to your machine under such circumstances
- icebraining 7y agoMicrosoft is the one that has to prove it has a valid license, not the other way around.
- crest 7y agoLet Microsoft deal with VirtualBox license claims from Oracle.
- Someone1234 7y agoYou didn't explain what this has to do with copyright? CFAA[0] (or even [1]) seems like a better avenue to explore, but still likely a dead-end. Copyright seems like a misnomer. [0] https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act [1] https://en.wikipedia.org/wiki/Economic_Espionage_Act_of_1996 https://en.wikipedia.org/wiki/Economic_Espionage_Act_of_1996
- TeMPOraL 7y agoSoftware is covered by copyright; if I write some program and compile it, and they copy it off my machine behind my back to run somewhere, it is copyright violation, is it not?
- GhettoMaestro 7y agoPretty sure by you having this malware submission feature enabled you have given a limited license for them to execute the binary. You're barking up the wrong tree.
- 0xffff2 7y agoYou (the user) may not have the right to grant such a license.
- moomin 7y agoAssume for a second this is correct. What's to stop virus writers from embedding a ToS preventing Microsoft from running the code? I'm not saying you're wrong, I'm saying it's really hard to work out how this is meant to work.
- 0xffff2 7y agoI don't think a virus is relevant here. I'm not a lawyer, but the idea of a "terms of service" for an unwanted and maliciously installed executable seems nonsensical. Virus authors can include whatever TOS they want, but the "user" hasn't agreed to the TOS practically by definition.
- jumpingmice 7y agoIndeed the ENTIRE basis of the EULA is that the user copies the software by executing it, whereupon a copy exists both on-disk and in-memory. This is long settled jurisprudence. I’m sure that if Microsoft downloads and runs an AGPL-licensed work they expose themselves to pretty severe problems.
- moron4hire 7y agoThere is also the issue that MS would have been given the copy by someone who did not have rights to distribute it, so the infringement is with the user.
- paxys 7y ago> that may have never given Microsoft license to do so I'm willing to bet it is in the license agreement for Windows and Windows Defender, so you have likely allowed Microsoft to do this
- ZiiS 7y agoJust because I have a license to run a program does not mean I have a license to sub-license it to Microsoft.
- jhanschoo 7y agoI'm pretty sure that for most home users who are also administrators of their computers, a setting pops up asking if you consent for telemetry to be collected. I'm not sure if an appropriate warning or option is given for third-party users of a computer, or if it is required for administrators to warn third-party users as such.
- mschuster91 7y ago> They run the executable in an environment where network connectivity is available. Why does MS run unknown executables? On the other hand, should be a nice DDoS provider for blackhats...
- inanutshellus 7y agoPerhaps it's not running the EXE but instead identifying URLs in the code, cURLing them to see what it gets, and doing so to verify what they get isn't malware?
- oherrala 7y agoThe software in question (called Beacon) is designed to call home. The binary has built-in cryptographic keys and it sends traffic encrypted. The receiving end, called Home, receives these packets, decrypts it and verifies the sender and after that gives an alert. The exe must have been running to be able to generate the proper encrypted payload and send it to right place. In this case ports 20 and 1025 over TCP. Disclaimer: I am one of the people who wrote the software.
- kemonocode 7y agoString obfuscation is trivial to do so I have a feeling they're actually running the binaries in order to do anything. Just a feeling, though- I don't think the author of the post stuck around long enough to see if the remote instance behaved as it should.
- SketchySeaBeast 7y agoMaybe not DDoS - I doubt that MS allows that service to have that much throughput, but if you wanna try to get past someone's firewall rules, like the author points out - people may whitelist those particular IP's.
- LorenPechtel 7y agoI'm sure Microsoft is keeping a very close eye on what they are actually doing. Run them in a virtual environment, see what they do to the environment and what internet communications they make. When it's done destroy the environment. If it tried to do something like a DDoS it would be identified as doing so and marked as malware, end of test.
- thexa4 7y agoCool, is kind of like STUN but for networks with almost no connectivity. Create a binary that sends info when started, submit it and wait for it to send the info from Redmond to your server. Too bad there is no return channel or you could make IP over windows update.
- Uristqwerty 7y agoCan you return a bit by deciding whether the executable gets flagged as malicious in response to the network activity? Can you set up a timing difference to send more than one bit per executable?
- kemonocode 7y agoThat's frankly alarming. They should be doing nothing but static analysis on those binaries and if they must execute them, then certainly not giving them any network access. That's without even touching on any IP law concerns and how an end user can be unwillingly complicit in such things...
- dahdum 7y agoMalware will pull updates and commands from the internet, if they didn’t allow network access it would be near useless of a service. Attackers can make the binary pre-update look as innocent as they want.
- LorenPechtel 7y agoMalware often checks to see if it has internet access and doesn't activate if it doesn't--to keep it from running in a test environment.
- Bartweiss 7y agoI can understand why people are saying that network access is necessary for meaningful execution, given how much malware conditions on it. (For instance, WannaCry's kill switch.) But it's still hair-raising from a developer's standpoint since network actions you expected to control are now triggering unexpectedly. I can think of a few ways for that to get ugly. In this case Beacon was sandboxed for security observation, but a build could easily be sandboxed for network-unsafe testing instead. Perhaps it's issuing malformed or high-volume requests to test internal functionality, safe in the knowledge that it's not actually connected to anything, and so it becomes a DoS attack when it's launched in the wild. Or worse, maybe it's calling home to an endpoint that does something when it gets the call. It's not hard to imagine somebody putting together a binary with any required auth baked in on the logic "this only exists on my machine", and then suddenly getting it called from Redmond as well. Best practices ought to handle that alright, but it's still an awfully surprising thing to have happen to your test build.
- 0xcde4c3db 7y agoIf this is Microsoft's idea of performing a security function, I have to assume that submitted executables are also going into a giant database/archive that can be turned over to the three-letter agencies with a single National Security Letter, complete with any secrets embedded therein. Like Bo Burnham says, I guess I should lower my expectations a lot.
- deleted 7y ago[deleted]
- rahuldottech 7y agoHaha, it's always great to see a Bo Burnham reference in the wild. He said that about love, though. Not... Microsoft.
- mirimir 7y agoIt's already happening.[0] Marketplace Hansa was running Bitdefender, which pwned them to Europol. > Europol has been supporting the investigation of criminal marketplaces on the Dark Web for a number of years. With the help of Bitdefender, an internet security company advising Europol's European Cybercrime Centre (EC3), Europol provided Dutch authorities with an investigation lead into Hansa in 2016. Subsequent enquiries located the Hansa market infrastructure in the Netherlands, with follow-up investigations by the Dutch police leading to the arrest of its two administrators in Germany and the seizure of servers in the Netherlands, Germany and Lithuania. Europol and partner agencies in those countries supported the Dutch National Police to take over the Hansa marketplace on 20 June 2017 under Dutch judicial authorisation, facilitating the covert monitoring of criminal activities on the platform until it was shut down today, 20 July 2017. In the past few weeks, the Dutch Police collected valuable information on high value targets and delivery addresses for a large number of orders. Some 10 000 foreign addresses of Hansa market buyers were passed on to Europol. 0) https://www.europol.europa.eu/newsroom/news/massive-blow-to-criminal-dark-web-activities-after-globally-coordinated-operation https://www.europol.europa.eu/newsroom/news/massive-blow-to-...
- MzHN 7y agoI think the key quote here is "This opens interesting data leak vector for attacker and also includes some privacy concerns. It is quite common that even in isolated environments, many of the Microsoft IP address ranges are whitelisted to make sure systems will stay up to date. This enables adversary to leak data via Microsoft services which is extremely juicy covert channel." As a user, you can just disable automatic sample submission. In fact I'm pretty sure you can set it during installation, as I've never had to go through the settings to disable it, but it's still disabled on all my installations. But the question is, from an adversary perspective, does your victim have it disabled? Most likely they won't, so you can use Microsoft as a mule to exfiltrate data from otherwise firewalled victims.
- Nextgrid 7y ago> you can use Microsoft as a mule to exfiltrate data from otherwise firewalled victims This is actually a smart idea. Make your spyware collect & encrypt data into a (new and unknown) binary and execute it, relying on the fact that Microsoft will exfiltrate it for you. When that binary itself is run (within MS' premises) it will then reach out to you with its embedded data.
- zelon88 7y agoAnd it all slips through the firewalls and whitelists because it looks just like official "Microsoft Telemetry" data. Wow.
- undersuit 7y agoFree data uploads. You could make unique binaries that when run start seeding a torrent. Maybe MS will put the kibosh on you uploading Seinfeld_S1_E1_obfuscated.exe to their cloud, but... how about a worm serving up its own updates through MS IPs?
- rkagerer 7y agoYet another reason I'm reluctant to upgrade to Windows 10. Too many buttons and toggles to turn off to arrive at a PC that functions the way I expect it to, and an update mechanism that's likely turning new ones on faster than I can spot them.
- pletnes 7y agoCould you do ssh -R and get shell on the testing machine in Redmond? Could make a nice tunnel for getting US netflix.
- winkeltripel 7y agoI was thinking of doing some folding at home via this mechanism.
- hiccuphippo 7y agoYou could use it for crypto mining.
- LeoPanthera 7y agoAssuming they only run it once, in one sandbox, that would probably not be particularly profitable.
- lvs 7y agoOr launch ddos on a third party with a series of unique executables.
- TeMPOraL 7y agoOk, so if I compile an executable that pops up a screen with a picture I drew + lots of personal and medical information about me, and phones me whenever it's executed, and then just leave it on my machine only for it to phone home from Redmond, can I sue them for copyright, GDPR, HIPAA violations and whatnot? How good is their "new unique binaries" detection? Could I do the same with just a bunch of files wrapped in a good ol' self-extracting archive? Seriously, what in hell? Like always, blatant violations of users in the name of "security".
- delfinom 7y ago1. You can turn it off and on fresh install it even asks you for permission to upload unknown executables 2. In business/corporate environments especially, there are many options that should be group policied by a proper functioning IT team as one of their many tasks.
- NewsAware 7y agoToo much FUD in this thread. Thanks for something level-headed.
- lazyasciiart 7y agoI'm not sure how you would invoke HIPAA with no medical professionals involved. It doesn't just magically apply because you wrote down your own medical information.
- Bartweiss 7y agoThere seems to be a widespread misconception that any information covered by HIPAA is always covered, when the reality is that it's only protected health information by covered entities. There also seems to be a lot of confusion about what's a violation: as far as I know only covered entities can be liable, not people they wrongly pass information on to. Now, if a covered medical software company accidentally let a build with accessible PHI go to Microsoft, I guess it's possible they could be HIPAA liable. But that's a pretty narrow case, and not one that's a threat to Microsoft.
- pnako 7y ago>Microsoft Windows 10 sends all new unique binaries for further analysis to Microsoft by default. Wait, what? Let's say you write code that you compile using MSVC or MinGW or whatever to an .exe file. Surely there is no way this gets automatically sent to MS?
- unionpivo 7y agoThat is exactly what happens. And it happens with any new executable. I noticed it when i was trying out how well rust works on windows.
- fortran77 7y agoI couldn't even get Rust to install on Windows!
- steveklabnik 7y agoWhat did you run into? Did you file a bug? That’d be helpful! I use Rust on Windows every day, though that means I’m not often re-installing it...
- unionpivo 7y agorustup is your friend. install that, and then rust with rustup. Edit: forgot link: https://rustup.rs/ https://rustup.rs/
- ufmace 7y agoSeems bizarre. If I build 30 .NET binaries a day while building and testing a new feature, I guess all 30 get uploaded to MS and tested. And the same for all of the other developers doing the same sort of thing around the world. I wonder how often their test cluster goes down in flames while some C++ developer somewhere is trying to fix a memory access bug.
- vortico 7y agoYes, you can test this yourself. Compile a 50MB binary and watch your bandwidth for a bit after attempting to run it. I believe MacOS 10.15 also does this because there's a massive delay the first time I run a binary compiled with clang.
- maltalex 7y agoThis shouldn't be hard to test. Just create a native executable in your language of choice that connects to a hardcoded address of a server you have access to and try executing it on a windows machine with sample submission enabled.
- Havoc 7y agoAlso seems like a viable vector to DOS something - if Microsoft runs this on some sort of cloud infra with a fat pipe
- Bartweiss 7y agoMy first thought was this leading to DoS, even accidental ones. If you're testing that your binary builds requests properly, maybe you've got it making them as fast as possible and you're running it without network permissions. Fine, until it suddenly runs with full network access and hammers whatever service you're pointing at.
- Terr_ 7y agoI think that's less likely, if MS gets a thousand identical copies of a binary, they probably aren't going to bother test-analyzing more than one. There also might be some rate-limiting on what they'll do from a particular machine. So your attack might require first controlling a swam of Windows 10 machines, in which case you might as well do it directly :P
- dTal 7y agoWho said anything about identical binaries? It's trivial to make two completely differently obfuscated binaries that do the same thing. If it were possible to determine behavior by static analysis, they wouldn't need to run it...
- throwaheyy 7y agoReminds me of the story about the NSA contractor who had pirated Office on their laptop, and when Kaspersky AV predictably collected a sample of the virus-infected keygen to its servers, the US tried to spin it as "Russian data exfiltration".
- BlueTemplar 7y agoOh, yeah, I remember that one !
- dralley 7y agoMy recollection was that he had samples of NSA malware on his computer, that Kaspersky detected this, and that shortly afterwards he was directly targeted by Russian state hackers. It was not so much that Kaspersky was acting as malware, but that they were sending tips to the FSB.
- Silhouette 7y agoOne of the main reasons we don't want anything to do with most recent Microsoft software at my office is concern that unspecified data we're working with -- which might include information obtained under NDAs, clients' trade secrets, sometimes personal data, etc. -- might get sent up to the mothership when one of the telemetry systems phones home. People look at me as if we're crazy for worrying about this possibility, even though Microsoft of 2019 is notoriously vague about how any of this works and we could be flagrantly violating multiple laws and contractual obligations if it happened.
- philpem 7y agoThis. If they were at least up-front and said what it collects, how, when, and how to turn it off (or better yet, followed privacy best practice and turned it into informed opt-in), I'd be more eager to upgrade. With that said -- there's still room for due diligence. I've built systems which handle personal data, and we pretty much started with Debian minimal and worked from there. To make damn sure, we stuck them behind a whitelisted firewall. They had access only to things we allowed them to see, and only in the direction we allowed.
- BlueTemplar 7y agoIf it was just Microsoft... it also goes for Intel and Ryzen era AMD processors. Maybe IBM's new PowerPCs are safe ?
- jimnotgym 7y agoI was interested in this Beacon software, but then I found you had to contact them for pricing and I gave up on the idea. Lesson: clear pricing keeps people like me in the game
- arcboii92 7y agoI'm the same! I like to plan things, so if something doesn't allow me to fit it into my plan easily I will discard it as not an option. Unknown costs, talking to other people, negotiating; these things produce trace amounts of anxiety. Anxiety I'd rather not deal with. A simple Pricing page solves this. I'd rather spend an hour googling your competitors than contact someone for a quote.
- SteveNuts 7y agoI've found a lot more software startups and SaaS companies using this method lately. When I actually am interested enough to talk to their salespeople (and they're straightforward enough with me) they've told me it helps them target whales more easily. They can charge a lot more to a huge Enterprise and adjust lower for SMBs.
- philpem 7y agoOf course the fun part of that is when the sales staff mistake a minnow for a whale. Case in point, a large FTSE, NYSE, NASDAQ listed company with largely siloed internal departments, all with their own budgets. Your yearly budget might be $20,000 -- but they see the Inc. or Plc. with a turnover in the hundreds of millions and quote accordingly... That situation makes for some fun sales calls.
- PeterStuer 7y agoIf the price is not on the website, it is either: (1) 'Enterprise' oriented software, in which case it is too expensive for you anyway (those long and personal sales trajectories, negotiations and commissions have to be recouped somehow) (2) Not actually a product, but a Trojan horse to sell you lots of consulting and bespoke development services.
- kazinator 7y ago> Microsoft Windows 10 sends all new unique binaries for further analysis to Microsoft by default. That's not only a privacy concern; it's blatant copyright infringement.
- deleted 7y ago[deleted]
- Animats 7y ago"Microsoft Windows 10 sends all new unique binaries for further analysis to Microsoft by default." Even if you're developing? Even if you're developing proprietary applications not for public use? All your code are belong to us.
- zamadatix 7y agoI mean it's either send all or send none, there is not really an inbetween way to do this method.
- anonymousisme 7y agoIt would be a fun experiment to create a network probe executable that exfiltrates results back to you, and then push it to Microsoft in this way. I wonder how secure their test environment could be if it has Internet access...
- zamadatix 7y agoI'd imagine the app is run in a DMZ and the internet FW blocks typical malware behavior once detected. After all the whole point of running it is to find if the executable is going to do these types of things so they'd be prepared.
- zamadatix 7y agoI'm surprised the number of people on HN that assume Microsoft's security group involved in actively trying to find malware by running unknown programs has absolutely 0 precautions that one of the programs they run would be malicious.
- opencl 7y agoMicrosoft does not exactly have the best track record with this. https://bugs.chromium.org/p/project-zero/issues/detail?id=1252&desc=5 https://bugs.chromium.org/p/project-zero/issues/detail?id=12...
- zamadatix 7y agoIn what way is "had a RCE CVE" a track record that "Microsoft's security group involved in actively trying to find malware by running unknown programs has absolutely 0 precautions that one of the programs they run would be malicious." I'm not talking about invulnerable software I'm talking about the comments assuming Microsoft doesn't expect __malware testing servers__ to run scanning or DDOS malware.
- samus 7y agoDepends on the definition of "malicious". Breaking hard drives and other hardware like in the good ol' days, or attacking other Microsoft servers? I agree, totally their problem. This is a proof of concept of phoning home though, possibly to exfiltrate data, via Microsoft servers and IP ranges!
- TYPE_FASTER 7y agoIt looks like you can manually upload submissions here: https://www.microsoft.com/en-us/wdsi/filesubmission https://www.microsoft.com/en-us/wdsi/filesubmission This may be outdated, but you can also configure Defender to always prompt before sending: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-antivirus/windows-defender-antivirus-on-windows-server-2016 https://docs.microsoft.com/en-us/windows/security/threat-pro... It would be interesting to set it to always prompt and see what triggers it. There must be some level of fingerprinting done on the client (hash of the binary? network activity, etc.) that can be used to compare against known threats.
- csande17 7y ago> Microsoft Windows 10 sends all new unique binaries for further analysis to Microsoft by default. Interestingly, Apple's now doing sort of the opposite of this. Instead of having the end-user's computer upload all executables to Apple for analysis, Apple requires the developer send them over and have them "notarized" before they run.
- foota 7y agoI'm amazed they run these with internet access. I understand though that without it a malicious program may not run the same. It probably also allows them to do some spying on networks used by malware.
- thomasdereyck 7y agoAdvanced Threat Protection in Office 365 does this as well. It's a security feature that scans all linked files and attachments sent through Outlook. A while back in my company we were deploying a client management tool (think TeamViewer but with more background management and software deployment capabilities). It needed to be very easy to install, so we just had a link to an EXE file that needed to be opened by our on-site IT departments. No extra steps were required. Imagine our surprise when we suddenly saw machines popping up that were totally unfamiliar. These were machines connecting from a Microsoft IP, and all had random (but similarly formatted) usernames. They also provided random mouse inputs. We could even take control of these machines (!) but apparently they were short lived VMs that only existed for a few minutes before being recycled. I contacted Microsoft support because at first we thought this may be a manual process (because of the mouse inputs and the user names), and we didn't want Microsoft employees seeing user data. Afterwards I also commented to the support person that someone may use these temporary machines as an attack vector (to use as an anonymous source, or in a DDoS attack), but the ticket was closed and if I recall correctly this was deemed "working as designed".
- saiya-jin 7y agoAnytime somebody here would like to claim that 'new' Microsoft is so much better and moral than 'old' one, I want to punch them in the face and start rant about Windows 10. Never met a single person, IT or not, who would not complain about it after moving from Windows 7. Now I don't have to, I can just point to this thread and this comment. This is pure arrogance - they know they have whole corporate world stuck with Office, even immediate move to Open source would take 20 years due to mostly Excel tight integration/expertise. We would all benefit from a good competition in this area...
- PeterStuer 7y agoThey probably limit the execution resources available or you would have yourself a free albeit unpredictable cloud execution platform for all your memory/CPU intensive processes.
- alyandon 7y agoIt's not just executables. I once caught Microsoft Defender sending copies of sensitives files like places.sqlite out of my Firefox profile directory to Redmond. Needless to say, I disabled that feature permanently via local policy.