5 ms·
company that violated a tons of people’s privacy with spyware had expectations of privacy
by hatenberg 4y ago
company that violated a tons of people’s privacy with spyware had expectations of privacy
- charcircuit 4y agoWhat spyware did Trustcor make?
- hamburglar 4y agoLooks to me like Trustcor’s subsidiary company MsgSafe made an app containing spyware. In addition, that spyware funneled data to a hardcoded url on a MsgSafe server which the Trustcor rep openly admits was only protected by a self-signed cert of unknown origin and was forwarded to unknown destinations as raw tcp packets. There is a lot of doubletalk in the thread that is supposed to somehow lead us to believe that TrustCor CA and MsgSafe are totally separate companies, despite lots of circumstantial evidence that they aren’t. It also happens to appear that MsgSafe and the company that actually created the malware (Measurement Systems) might be closely related and/or the same, owing to a lot of the same names on corporate documents (many of which names are shared with Trustcor and/or Trustcor CA), plus the extremely suspicious fact that the malware in question was only ever distributed elsewhere in obfuscated form, yet somehow MsgSafe seems to have an unobfuscated copy built into their app. It’s also extremely odd that despite all the protestations about Trustcor CA and MsgSafe being completely unrelated, the Trustcor CA director of business operations has intimate knowledge of the source control, server configurations, and VM snapshots of the server that the traffic was being proxied through at MagSafe.
- csande17 4y ago> There is a lot of doubletalk in the thread that is supposed to somehow lead us to believe that TrustCor CA and MsgSafe are totally separate companies, despite lots of circumstantial evidence that they aren’t. TrustCor doesn't actually dispute that MsgSafe is the same company as them. For example, here is a press release where they proudly announce they own MsgSafe: https://www.prnewswire.com/news-releases/trustcor-evolves-email-identity-protection-and-security-launches-msgsafeio-564970821.html https://www.prnewswire.com/news-releases/trustcor-evolves-em... Instead, what they claim is that these two parts of the business are operated separately. As in, MsgSafe doesn't run on the same servers as the CA. So if a "rogue contractor" adds malware to MsgSafe and it goes undetected for several years, that shouldn't reflect badly on the CA side of the business at all. (TrustCor was so evasive about this that they seem to have misled most of the people in this thread, though.)
- hamburglar 4y ago> what they claim is that these two business are operated separately except that the person doing all this claiming happens to be director of operations for both. I concede that it isn’t impossible that they have a strong firewall between these two companies. But all the obfuscation, defensiveness, and easily refuted claims don’t really make anyone willing to swallow that story.
- csande17 4y agoGiven that, according to TrustCor's own statements, MsgSafe relies heavily on certificates issued by TrustCor, I don't think there's all that much separation. (There might be, like, a network firewall in between the two server fleets, but even that is doubtful.)
- hamburglar 4y agoYeah, reading through this whole saga, one of the things I wondered was whether MsgSafe might actually have the ability to get any certificate it wants from Trustcor CA through this special relationship. If it’s got that kind of permission, all the corporate governance separation in the world isn’t going to matter.
- shkkmo 4y agoI think the concern is less about MsgSafe getting any certs it wants and more about how shoddy development practices (letting the third party malware SDK be incuded) and business ethics (false E2EE advertising and typo squatting) at MsgSafe reflect on TrustCor's ability to operate a CA given the shared management. The other large concern is the large number of links between TrustCor and Packet Forensics, Measurement Systems and Volstrom Holdings. Specifically the history of shared ownership, corporate officers, and the inclusion of a the only known non-obfuscated copy of a Measurement Systems malware SDK by a "rogue contractor" for TrustCor. As an aside, I though it was interesting that Rachel made a point of placing the blame on a contractor and then later admitted that they pay all their "employees" via 1099s.