5 ms·
i always worry about tools like this, maintained by small teams, that are so universal that even if only a small fraction of installs are somehow co-opted by ma
by jmole 8mo ago
i always worry about tools like this, maintained by small teams, that are so universal that even if only a small fraction of installs are somehow co-opted by malicious actors, you have a wide open attack surface on most tech companies.
e.g. iTerm, Cyberduck, editors of all shades, various VSCode extensions, etc.
- josho 8mo agoSimilarly I worry about how these apps automatically update themselves. I know it can be done securely. I also doubt that these companies invest the engineering effort to do so.
- hsbauauvhabzb 8mo agoIf you think large companies are somehow immune to this, you’re gonna have a bad time.
- Arainach 8mo agoIt's not a matter of "immune" - larger organizations generally have more resources to allocate to things like this. That doesn't mean they get it right 100% of the time, but they are at least able to try, while small teams or volunteer projects often simply don't have the hours to spend on things like this.
- calvinmorrison 8mo agoand unlike GPL software, there is typical an army of lawyers, an expressed warranty, legal liability, etc.
- SoftTalker 8mo agoTerms of use typically disclaim all liability.
- its_ubuntu 8mo ago[flagged]
- marcosdumay 8mo agoHum... We keep pretending the Solar Winds scandal never happened?
- hsbauauvhabzb 8mo agoThat didn’t cause tangible pain for the everyday person, even if it did cause non tangible long standing damage. Every windows PC ransomwaring at the same time worldwide would cause mr robot level chaos.
- hellzbellz123 8mo agothat wasnt really microsoft massive though.
- marcosdumay 8mo agoIt didn't happen by Microsoft fault. It reached all of Microsoft... and every other company that sells software or computers to the US government.
- shaboinkin 8mo agoAnecdotally, my company has a device driver posted on Windows Update. I inherited the project and was digging through Microsoft’s hardware dashboard trying to find information on the stability of the driver. I ended up finding that our driver was crashing rather frequently. Looking closer, the name of the driver shown was curious as it contained the name of our driver as defined in the inf file, and appended at the end was “(WeTest)”. I looked through all source code looking for a reference to this string with no avail. Eventually I googled “WeTest” and find out WeTest is something owned by Tencent. I double checked all drivers that were ever posted to the server from our account and found no reference to “WeTest” in any of the driver packages uploaded. I emailed our Microsoft contact and got no answers as to where this driver came from and why it was visible from our account. After a few months, this driver finally was removed from our dashboard and our administrator for the account had to submit government documents to Microsoft to show he worked at where he said he did. I won’t give specifics on who’s or what’s, and anyone is more than welcome to dismiss what I’m saying without evidence. But your comment, “when Microsoft’s update servers get compromised..”, made me want to share this experience. Maybe it was some terrible software bug on Microsoft’s end that managed to combine information from two different entities, but we were never given an explanation as to how this happened.
- hsbauauvhabzb 8mo agolol larger organizations don’t spend money on this, they add some useless ‘secops’ tools to their CI and call it a day. They are certainly not doing things like reproducible builds, lol half of them don’t deploy signature verification.
- technion 8mo agoI've sat in some pretty large orgs and my own experience was the "resources allocated" went to the PR team. I can assure you that they would have had a more boring, corporate sounding announcement with multiple references to their legal team and the actions they would have taken, alongside some useless information about being PCI compliant or something. I'm not convinced the practical output is any better.
- guessmyname 8mo agoI don’t get it, why don’t you all—absolutely all of you reading—use Little Snitch? [1] It really doesn’t compute in my head why would any macOS user not use a network firewall like this, or similar, to block unwanted outgoing HTTP(s) requests. You can easily inspect the packet with tools like Wireshark or Burp Suite Professional (or Community) edition, or any other proxy tool, of which there are many in the macOS ecosystem. And this is not unique to macOS, this is all possible in Windows, Linux and any other OS. [1] https://www.obdev.at/products/littlesnitch/index.html https://www.obdev.at/products/littlesnitch/index.html
- jonas21 8mo agoIsn't Little Snitch exactly the sort of application they're worried about?
- 3eb7988a1663 8mo agoZing! The state of the world is such that I have started running everything inside VMs. Baseline OS install + virtual machine management and that is it. Which is still not immune, but makes me feel a lot better than core OS utilities are probably getting better vetting than nifty-utility-123 on which I depend.
- velocity3230 8mo agoQubes OS?
- 3eb7988a1663 8mo agoNo, poor man's Qubes with manually assembled VMs. I keep meaning to take the plunge, but have been too lazy to rebuild my system.
- drum55 8mo agoIt’s a false sense of security, more or less. If an application wants to talk to a C2 they don’t have to make a connection at all, just proxy a connection through something already allowed, or tunnel through DNS. Those juicy cryptocurrency keys? Pop Safari with them in the URL and they’re sent to the malicious actor instantly. If you’re owned Little Snitch does nothing at all for you except give you the impression that you’re not.