8 ms·
New details on commercial spyware vendor Variston
- itake 4y agoMy friend works there! This is the most I have heard about his work since he was so secretive.
- kingforaday 4y agoAt Variston IT or Google/TAG? :)
- itake 4y agoVariston IT
- LinkLink 4y agoDisclosing this was a terrible idea, especially since your profile doxxes you, deleting your account immediately is probably advisable.
- pprotas 4y agoWhat a way to overreact
- itake 4y agoI don’t work in this industry and I never plan to. I haven’t done anything illegal and AFAIK, their work is in a legal grey area as well. I’m not seeing the issue.
- LinkLink 4y agoThese companies make a lot of enemies, you're likely on a list at this point just in case those enemies should ever need some temporary leverage. If your friend has integrity to his company and self you will likely not survive such an encounter. Good luck.
- shkkmo 4y ago> TAG became aware of the Heliconia framework when Google received an anonymous submission to the Chrome bug reporting program. The submitter filed three bugs, each with instructions and an archive that contained source code. They used unique names in the bug reports including, “Heliconia Noise,” “Heliconia Soft” and “Files.” TAG analyzed the submissions and found they contained frameworks for deploying exploits in the wild and a script in the source code included clues pointing to the possible developer of the exploitation frameworks, Variston IT. Does that mean that this was likely an internal whistleblower at Variston since the bug reports had internal build tools?
- willcipriano 4y agoConsidering it's a malware vendor, I'd put my money on they ship it with the internal build tools by accident, mistakes like that are pretty typical in that space.
- shkkmo 4y agoCould be, but the three separate reports/leaks make that seem unlikely to me. It could also the a hacker that compromised the company to obtain the tools.
- soci 4y ago"Variston IT" EBITDA was between 6M to 15M € in 2021 [1][2]. Interesting numbers from a completely unknown tech company in Barcelona whatsoever. [1] https://www.iberinform.es/empresa/8097556/variston-information-technology https://www.iberinform.es/empresa/8097556/variston-informati.... [2] P&L and Balances are public data in Spain, but usually behind paywalls. Sometimes the financial data without the paywall just shows the order of magnitude, like in this specific case.
- zelon88 4y ago> As is currently normal for internally found Chrome bugs, no CVE was assigned. Why I don't care about or trust anything from Google TAG, PZ, or any other "security blog" that Google publishes. They have no problems copping CVEs on competitors like Mozilla, Microsoft, or Apple.... but squirrel away zero days on their own products for the better part of a year or more and then quietly publish blog posts without actually filing for a CVE.
- jnwatson 4y agoNearly every bug is a security bug. If Google made a CVE for every bug, we’d have millions of CVEs to wade through. Linux works the same way.
- fomine3 4y agoRelated wrote by gregkh https://github.com/gregkh/presentation-cve-is-dead https://github.com/gregkh/presentation-cve-is-dead https://lwn.net/Articles/801157/ https://lwn.net/Articles/801157/
- joshuamorton 4y ago[I work at Google, but not on anything related to TAG or P0] I feel like you're misreading the timeline here. The Chrome vuln you mention was found in June 2021 and fixed in August 2021, not 2022. From the bug, it was found and fixed due to automated regression testing done by the chrome team. This is the equivalent of asking every buffer overflow in Chrome to be assigned a CVE, which is odd. Further, it's exactly the same behavior as Mozilla follows, as demonstrated by the line > The sandbox escape is specific to the Windows version of Firefox and was fixed without a CVE in September 2019. in the blog post. Neither vendor is acting badly by not filing a CVE for vulnerabilities they found and fixed internally. CVEs are usually for communication across organizations, which isn't needed if everything is handled within the chrome or mozilla bug trackers.
- kbenson 4y ago> They have no problems copping CVEs on competitors like Mozilla, Microsoft, or Apple.... but squirrel away zero days on their own products for the better part of a year or more and then quietly publish blog posts without actually filing for a CVE. This comes up from time to time, but I'm not sure it's actually supported by the evidence, and maybe it's just random anecdotes from people that are consumed and then become opinion. Project Zero reports on Google vulnerabilities often, and in fact just made a post critical of Android's security practices.[1] I remember reading years back metrics on who they publish bugs about, and on looking, I see they published something earlier this year about the prior year in review[2] with data. It's really not hard to look some of this stuff up to see whether your feelings are supported by the data. Maybe this changes your opinion, maybe it doesn't, but at least you have some data to look at now. 1: https://arstechnica.com/gadgets/2022/11/google-says-google-should-do-a-better-job-of-patching-android-phones/ https://arstechnica.com/gadgets/2022/11/google-says-google-s... 2: https://googleprojectzero.blogspot.com/2022/02/a-walk-through-project-zero-metrics.html https://googleprojectzero.blogspot.com/2022/02/a-walk-throug...
- avsteele 4y agoWhy do companies like Google and Microsoft not get more aggressive with these semi-criminal-orgs? Couldn't they massively raise the cost of being in this business by by making an example of a few? Brainstorming: - Sue them, aggressively. - Looks for exploits in their own systems and publish their code, making it worthless. - Publish lists of their owners and employees and/or ban them from Google/Microsoft services. I'm sure folks here could think of more/better ideas.
- Cyberdog 4y ago> - Sue them, aggressively. On what grounds? > - Looks for exploits in their own systems and publish their code, making it worthless. Are you saying Google should publish exploits of Variston's systems? There's kind of a "two wrongs" problem there; such information would likely require illegal hacking ("accessing a computer system without permission") to discover. > - Publish lists of their owners and employees I'm sure they do as much as they can in that regard, but I'm sure such companies do much to hide their ownership and employees, and at any rate it could be seen as encouraging illegal harassment of said employees. > ban them from Google/Microsoft services. To the extent possible I'm sure they do this, but Google can't really stop someone from using Chrome, or always reliably detect when someone representing a malicious company is using their services.
- deleted 4y ago[deleted]
- kbenson 4y ago>> - Sue them, aggressively. > On what grounds? Love it or (more likely) hate it, the DMCA has anti-circumvention provisions in it, and breaking out of a sandbox sounds like it matches that. > Are you saying Google should publish exploits of Variston's systems? There's kind of a "two wrongs" problem there; such information would likely require illegal hacking ("accessing a computer system without permission") to discover. I don't think there's actually any problems here, as long as the "publish" portion is adhered to. Making sure they don't break the law in finding those exploits would be the hard part though, as you note.
- deleted 4y ago[deleted]
- LinkLink 4y agoIt's hilarious how nobody is pointing out the extreme irony of microsoft and google calling anyone elses software spyware. I'd rather have my bank password leaked by some brazillian than my web browser, purchase, location, social connections, interests, and work activities leaked by big tech and stored in perpetuity.
- Closi 4y agoIf you were a journalist or activist operating in Rwanda you might have a slightly different view. These are tools that target individuals, and if you are being targeted by a nation state (some of which don’t have the best human rights record) that’s going to be worse than Microsoft’s storing everything you listed.
- Applethief 4y agoI love how the devs are all named after Dragon Ball Z villains.
- bvhvhfcgxfdf 4y agoIt's funny that a spyware company calling other companies products spyware.
- motohagiography 4y agoWhat's interesting to me about this is that someone would pay for a scheme that required spear phishing (malicious pdf or other file), whereas other known players in this space base their offerings on zero-click RCEs.
- aew4ytasghe5 4y agoBecause zero-click attacks is approaching impossible.
- 752963e64 4y ago
- iJohnDoe 4y agoI know it’s not a fair parallelism, but I can’t help to think how laughable it is when Google calls out anyone for spyware, privacy violations, zero days, CVEs, etc. Google doesn’t even manage their own App Store for spyware. They don’t play fair on disclosures. They violate public trust all the time with tracking users when they say they don’t. They shutdown GCP accounts with zero chance of support. Google really just needs to stay quiet and work on improving their search results. I think they would find it surprising that the less they say and do would actually improve their public support. The Google engineers can keep getting paid to do nothing and the public support and trust would go up.
- adg001 4y agoIndeed it sounds hypocritical to state "Google and TAG will continue to take action against, and publish research about, the commercial spyware industry.", while not including Google itself in the said industry.
- TeMPOraL 4y agoIt does smell like an attempt to redefine "spyware" to mean a subset of "cyber crime", instead of its original meaning, which now covers most of "legitimate" adtech and software telemetry.
- aew4ytasghe5 4y agoIt sounds to me like you insist that "spyware" has a different meaning than the majority in this thread. From https://en.wikipedia.org/wiki/Spyware#History https://en.wikipedia.org/wiki/Spyware#History: > The first recorded use of the term spyware occurred on October 16, 1995 in a Usenet post that poked fun at Microsoft's business model. Spyware at first denoted software meant for espionage purposes.
- TeMPOraL 4y agoI'm insisting it has the meaning that... the entire Wikipedia article you linked uses. You quoted the beginning of the first paragraph of the History section, but the full paragraph reads: > The first recorded use of the term spyware occurred on October 16, 1995 in a Usenet post that poked fun at Microsoft's business model. Spyware at first denoted software meant for espionage purposes. However, in early 2000 the founder of Zone Labs, Gregor Freund, used the term in a press release for the ZoneAlarm Personal Firewall. Later in 2000, a parent using ZoneAlarm was alerted to the fact that Reader Rabbit, educational software marketed to children by the Mattel toy company, was surreptitiously sending data back to Mattel. Since then, "spyware" has taken on its present sense. I wasn't aware of the earlier, truly original meaning - actual espionage. That doesn't change the fact that for the past 20+ years, the common meaning - dare I say, original mainstream one - encompassed every kind of hidden tracking, data collection and exfiltration, almost none of it being part of actual espionage, but rather most of it being in service of targeting ads.
- nosmokewhereiam 4y agoAnyone remember Cyber Privateering being brought up on another forum, someone trying to call it the Morgan Doctrine? Found it: https://www.themorgandoctrine.com/?m=1 https://www.themorgandoctrine.com/?m=1 I'm not pushing this, just thought it was interesting when I read about it in ~2009, and here we are 2022, and no magic beans have appeared... I'd also like to add that during the Obama presidency, a law was written and passed to the effect of authorizing kinetic effects in response to cyber attacks. Bombs for bits basically.
- throwaway23597 4y agoSo the way this was discovered was through an anonymous tip. How often is this the means of discovery for malware / 0-days / etc? Would Google have found this if it wasn't for the tip?