5 ms·
From the article: "A spokesman for the company confirmed that it scans messages to filter out spam and phishing websites. This explanation does not appear to f
by recoiledsnake 13y ago
From the article:
"A spokesman for the company confirmed that it scans messages to filter out spam and phishing websites. This explanation does not appear to fit the facts, however. Spam and phishing sites are not usually found on HTTPS pages"
From the very next story down from the same publication:
http://www.h-online.com/security/news/item/Trojans-conceal-themselves-using-instant-messaging-protocols-1789045.html http://www.h-online.com/security/news/item/Trojans-conceal-t...
"The company has reported that, since 2009, some malware has been concealing its data traffic by mimicking known instant messaging protocols or, to avoid detection, trying to camouflage its data traffic as HTTP or HTTPS. To achieve this, these trojans copy at least the header of the instant messaging protocol, leaving the remainder of the packets to carry the trojan's encrypted communications."
Looks like they're contradicting themselves here to score some click-bait headlines.
- Dylan16807 13y agoWhat is the contradiction? A program might be able to 'camouflage' its data as HTTPS to a casual observer but that has nothing to do with HTTPS urls. An HTTPS url won't work unless it's real. Therefore such a thing provides zero justification towards checking HTTPS urls.
- vidarh 13y agoThe only thing that is required to make a https url "real" is that it is hosted on a server that serves up a certificate that is valid for that domain. It's trivial enough to obtain a valid cert anonymously (shell company with bearer shares somewhere suitable) or find places to upload the malware that makes it available on https urls.
- Dylan16807 13y agoIt requires actually implementing SSL, which is a lot more work than using port 443 and faking a couple headers. Am I misreading the word 'camouflage'? I read it as 'pretends to be' not 'actually uses'. Even if the trojan is using HTTPS, that is still not a reason to scan HTTPS URLs. The command and control network is completely orthogonal to the links given to users to try to infect them.
- vidarh 13y agoThe main reason to scan urls at all would be to identify potential malware to be able to prevent users from visiting them.