5 ms·
The Bvp47 - a Top-tier Backdoor [sic] of US NSA Equation Group
- oDot 3y agoAren't the popular Linux distros, with default configuration, much less secure than the other OS like macOS, Windows and surely Android and iOS? I thought this was the working assumption.
- jraph 3y agoI would be interested in knowing which threat model we'd be considering to draw this conclusion.
- bediger4000 3y agoInteresting. I believe the opposite, especially with respect to Windows.
- ageofwant 3y agoNo, popular Linux distros, with default configuration, is considerably more secure than Windows, and probably more secure than MacOS. This is universally accepted and basic infosec ken. You thought very wrong, fix your ken.
- oDot 3y agoDon't the others OS have varying levels of app sandboxing while Linux has basically none?
- ageofwant 3y ago'app sandboxing' is one part, of a small part, of a subsection of a general thread model, why would you pick that when you talk about 'secure'? And LOL no, Linux has SELinux, apparmor, firejail, flatpak, snap, docker, lxc, and various hypervisors for 'app sandboxing', Linux does not have 'basically none', it has arguably to many.
- oDot 3y agoStill talking about default config here
- jraph 3y agoAFAIK the default config on Windows to install a program is still downloading an executable installer on Windows. On Linux, the default config is you install most programs from the "trusted" distribution's repositories. Flatpaks and Snaps are increasingly used for apps that are not in the repository. They are not perfect, but they are improving. I don't know how it works for macOS. You'd download a program image but I don't know what the program can do and if there's a sandbox.
- 0daystock 3y agoNo, I don't think anything is safe from a determined adversary with near-infinite resources, especially if they are specifically targeting you. This is a basic tenet of infosec.
- GartzenDeHaes 3y agoFor self proclaimed "security researchers", this article is lacking in specifics. For example, what are the CVE's for this backdoor, installation method, processes affected, anything at all?
- l0new0lf-G 3y agoThere is a link to a PDF with technical details right in the beginning.
- GartzenDeHaes 3y agoSo there is. I guess the backdoor is distributed through malicious PDF's.
- deleted 3y ago[deleted]
- Dylan16807 3y agoI read it and didn't see answers to any of that. Nor did I see any description of a backdoor in Linux, just a backdoor that runs on Linux.
- mr_mitm 3y agoIn western infosec circles, the term C2 framework (command and control) would have been more appropriate.
- l0new0lf-G 3y agoIt is striking that such a backdoor in seemingly safe OSs like Linux and FreeBSD, is nearly completely unknown one year after the revelation. No social media outcries, no mention on the TV, no debates, no comments from people like Torvalds and Stallman (though I by no means imply they were direcly involved). The reason why is remains a "secret" is that the whole matter is deeply, deeply political. We are amidst a new Cold War -this time between the US and China. The sole purpose of this backdoor could be exactly to spy on the Chinese government or corporations. Yet we all know that the NSA would not limit the use of the backdoor to that.
- 0daystock 3y agoLinux is not a "safe" operating system by any stretch of imagination. The only saving grace is the fact Linux users are not profitable to malware authors due to very low market share. Still, I think it's naive to view it as a secure operating system/kernel because it is not designed nor built for that goal explicitly. OpenBSD on the other hand is a worthy contender against a determined adversary and is developed by skilled and highly paranoid people.
- LinuxBender 3y agoHaving managed just about every OS I have learned to see it a little differently. Rather just about every OS can be hardened to the point of being secure but each OS and each iteration of said OS will have different default kernel compile options, admin configurable settings, kernel tuned settings that vary the amount of "friction" the end user is meant to experience. Even Windows NT had more security controls than Linux and BSD combined mostly pilfered from VMS but the defaults were opened up to minimize friction for businesses. Windows XP, Linux, MacOS reduced friction even further to improve adoption by developers and end users alike, to a fault. Not just security but also memory management behavior. Windows Linux and Mac allow over-committing memory by default to improve adoption by people early in their development career. So I guess what I am trying to say is that people have decided they will trade in friction for usability and thus has resulted in a myriad of gaping holes by design. Each OS have tools to harden them as far as one wishes to go. The BSD community have accepted that they will endure a little more friction by default and I can respect that.
- deleted 3y ago[deleted]
- upofadown 3y agoThe term "backdoor" in the title is misleading. What is described in the article are a series of what most here would describe as "rootkits". There is no evidence provided of any malicious modification of the Linux kernel or distributions before the user receives them. I don't think that anyone would think that Linux (or any other OS) would be safe after an attacker had obtained complete control of the system.
- l0new0lf-G 3y agoIt doesn't matter what fancy word we are using -what matters is that our systems are compromised by an agency that can just steal our data without us even knowing. Why should we even care about the academic definition of a backdoor? Is it less of a privacy problem if it is a "malware"?
- tmpX7dMeXU 3y agoWords mean things. The term backdoor has specific connotations and GP is right to call the title out as misleading. Your reaction, to immediately accuse them of being a lawyer for the NSA, is absurd, entirely emotionally driven, and makes me question what you think a lawyer working at the NSA would actually do.
- mrob 3y agoIt's far less of a problem if it's malware, because malware has to be installed. If it's a real backdoor it's already present on every Linux machine.
- Dylan16807 3y agoBecause anyone that downloads Linux is fine. Someone has to take your computer and install this software into it before you become vulnerable. 99.999% of our systems are not compromised. So yes they do cyber attacks but the scope and method is so very different between those two categories.
- olddustytrail 3y agoWe care for the same reason we care about someone calling their monitor "the CPU". If you don't know basic terminology you're probably clueless.
- dariosalvi78 3y agothere are some discussions online: https://www.reddit.com/r/linux/comments/umk24z/linux_backdoor/ https://www.reddit.com/r/linux/comments/umk24z/linux_backdoo...
- yellow_lead 3y agoDon't editorialize titles. Original: The Bvp47 - a Top-tier Backdoor of US NSA Equation Group Also, (2022)
- l0new0lf-G 3y agoIs this the reason why it got flagged?
- Dylan16807 3y agoSo for the record the current title is: So you think Linux is safe from the NSA? You couldn't be more wrong Personally, I flagged it because that's very misleading and it's not a backdoor. If anything, the original title should have been edited in the opposite direction, to not use the word "backdoor". Or to add [sic]. But "a backdoor" without "in Linux" is not super egregious.
- l0new0lf-G 3y agoI changed it to the original title of the post. Is it ok? If not I am adding [sic] as you suggest -but I've never seen it in other posts here
- Dylan16807 3y agoI'm not really sure what's optimal but I removed my flag.
- l0new0lf-G 3y agoIt is still flagged
- ageofwant 3y agoI flagged it because your silly clickbait title is a misinterpretation of both the contents of the article and narrates a enormous jump to a ridiculous conclusion. Its fake tiktok gosh-wow horseshit and does not belong on hacker news.
- scrumlord 3y ago[dead]