6 ms·
UTorrent.com compromised, malware added to installer
- ploxination 15y agonubz
- morsch 15y agoAs far as I remember, uTorrent has an internal auto-update functionality that interrogates the server for a new version. I wonder how well that is secured and if owning utorrent.com is enough to distribute a malicious update to all users unfortunate enough to start the application while owned. I'm very wary about auto-updates that pull executables (as opposed to merely data) in this way. It's one thing for Chrome to do it, I assume Google does it in a way that's safe. But freeware/shareware projects? Not so much. Hell, who's to say the authors don't lose interest in two years and let the domain expire. I had one freeware or open-source app that didn't even have the courtesy of asking, it just pulled fresh binaries and restarted -- ouch. (At least you could disable this feature in the preference.)
- pdaddyo 15y agoJust since you mentioned Chrome's updating mechanism, it is a fascinating approach that they took: http://www.chromium.org/developers/design-documents/software-updates-courgette http://www.chromium.org/developers/design-documents/software...
- wslh 15y agoYes, but it's very difficult to setup outside Google.
- vogonj 15y agocourgette is just a binary diff algorithm -- there's nothing fancy to it (they use some really neat tricks, though), and apparently (I haven't verified) the source is in the chromium tree. validating your updates via asymmetric crypto can be mildly expensive (http://www.verisign.com/code-signing/content-signing-certificates/winqual-developers/index.html http://www.verisign.com/code-signing/content-signing-certifi... lists Windows Authenticode certificates at $400/yr) but is within the realm of a small company. setting up a Google-scale CDN and writing a reliable push update framework? that's the hard part.
- wladimir 15y agoTo validate updates using asymmetric crypto you don't need to buy a special key at all. You can generate the keypair yourself... The only thing you need is some crypto lib to check a RSA or DSA signature on the downloaded data using a public key embedded in the software.
- RexRollman 15y agoIf I recall correctly, Google is facing a patent lawsuit over the Courgette technology. I don't remember if the complainant was a patent troll or not.
- itsnotvalid 15y agoWhatever the outcome would be, that is enough to stop people from using this piece of open source software to provide safer updates.
- morsch 15y agoAs stated above, courgette doesn't provide safer updates, just smaller ones. It's just a really smart executable binary diff. Signing the update is an orthogonal issue.
- deleted 15y ago[deleted]
- eps 15y ago> $400/yr That's VeriSign for you. Thawed sells the very same certificates for $200, and Comodo runs a coupon deal for Tucows members that gets you the cert for $99 (though the actual process is a bit too contrived compared to Thawte's).
- pagekalisedown 15y agostartssl.com has code signing certificates for 60$, valid for 2 years.
- jbk 15y agoFor example, VLC (and, IIRC, Firefox) uses asymetric crypto to sign the update messages and the binaries. And the private keys are in none of the VideoLAN servers, but in other secret locations. So, if the server is hacked, or a DNS is spoofed, you cannot make auto-update pull broken/malware binaries. The problem is that, if your update process is buggy in some release, you loose those users forever...
- vogonj 15y agofrom what I've gleaned from being a uTorrent user, it interrogates the server for a .torrent file and then downloads that torrent from a tracker they run. presumably, anyone who owns the host of the .torrent, or anyone who owns the tracker, could own the update download -- though I'm not sure whether they use technologies like code signing at all to verify that the bits are their own.
- eyko 15y agoI stopped using it since it wasn't open source. Worse when it became infested with "optional" ~~adware~~ search bar.
- DrJ 15y agostill using the last-open source version with the auto-updater disabled!
- kenny_r 15y agoMay I suggest Deluge (http://deluge-torrent.org/ http://deluge-torrent.org/)? It's open-source, cross-platform and very similar to µTorrent in both functionality and looks.
- skeptical 15y agoInteresting, I've been using deluge for many years, had no idea they had a build that runs on windows. Deluge has all the features I want on a torrent client, I will replace my uTorrent installations on windows by deluge.
- linker3000 15y agoJust watch out for the latest (1.3.3) Windows release - it (or one of the bundled dependencies) seems very broken and I had to revert to the previous version to make things work again.
- aptwebapps 15y agoCan I choose which files to download before it puts empties on the file system?
- djeikyb 15y agoYes. It might create some folder structure, but if you choose at the time of adding the torrent to not download particular files, it won't create files. Tested just now on 1.3.1/Linux. I haven't tested recently, but I know I've gone in after adding the torrent, told it not to download some files, deleted what it had on the fs, and it did not regenerate them.
- streptomycin 15y agoAnd this is one of many reasons I love that almost all my software is installed through a secure package manager.
- agravier 15y agopacman cough cough sorry I just lost it for a second...
- agravier 15y agoSome explanation to counter those terrible downvotes: Pacman, the package manager of Archlinux, is not implementing the verification of package signatures. It's a recurrent issue in the Arch community.
- ga2arch 15y agoIt seems things are changing http://allanmcrae.com/2011/08/pacman-package-signing-3-pacman/ http://allanmcrae.com/2011/08/pacman-package-signing-3-pacma...
- latitude 15y agoFor those on Windows, here is a bit of code that can be used to validate Authenticode signature of the update package. https://github.com/apankrat/assorted/blob/master/validate_package.cpp https://github.com/apankrat/assorted/blob/master/validate_pa... Basically the idea is to get an Authenticode certificate and sign the update .exe with it. Then, when a program checks for an update and pulls it down, it would validate the package signature and will not proceed if the details - the application and the certificate subject names - are wrong. It is as simple as it gets.