TeamViewer users are being hacked in bulk, and we still don’t know how
arstechnica.co.uk
arstechnica.co.uk
I ran teamviewer on 2 computers.
The teamviewer windows appear.
On neither instance do I log into my teamviewer account, so I don't enter my account password and therefore I don't enter a 2FA code from my phone.
However I can still open a session from one computer to the other using either the random password or the stored computer-specific password.
So how exactly does 2FA increase my protection from the alleged scam?
My guess is that the hackers have found a way to acquire these random passwords, or are simply brute forcing them on a massive scale and we're seeing reports of the minority of successes.
However I am so paranoid at the moment that I have decided to exit teamviewer completely between uses until this all blows over.
EDIT: In the comments below the linked article is the best explanation yet in my opinion:
>They sign into the website/client with the compromised credentials, and get a list of what computers are online and waiting for connections from that account.
http://arstechnica.com/security/2016/06/teamviewer-users-are...
The fact that all of these questions are up in the air means that I really have no choice but to quit using the product. I don't do a lot of remote support with other people but do need to access different computers of my own (that are in different locations) at certain times. Before TeamViewer I would use Hamachi + VNC which worked fine with the exception that Hamachi always goes into "relay mode" when I am not on a very good connection, which was always a joy to find out when I was on vacation and was unable to access anything because all of the nodes were connected in "relay mode".
Someone else here mentioned ZeroTier as an hamachi alternative, so I think I will give that a try. A longer term goal is to link the machines together using OpenVPN, which I am not currently an expert in.
I am not an expert. The top comment helped me assess the risk.
This is also why I'm glad I've never used the accounts for TV and have always resorted to the number generating system (if of course the breach is related directly to the accounts)
[1] https://www.teamviewer.com/en/help/410-what-is-a-teamviewer-...
This breach could also be data leaked from TeamViewer but as of right now there has been no official word as far as I can see. Considering users like to use the same username and password a bot could easily run through a leaked list and report any successful logins back to an attacker (an older exploit).
As far as I can tell the random numbers being generated are not affected but users who have actual accounts are being affected. There has been no official word but the number generating system being exploited over the accounts being exploited seems far less likely. Only time will tell thought so hopefully we will get an official word soon!
edit Seeing a lot of different theories in the comments and honestly I'm not sure which one makes the best sense. I really do hope TV makes a comment soon about how it's happening but we probably won't see that announcement until they release the fixes which are supposedly later this year.
Especially considering such hijack would've in all likelihood been logged.
search "Do you have a TV Account" I have yet to find an answer from someone that said No (meaning they use the numbering system- only yes, used to and "free" which still is a login). A lot of answers to include that they use the same password for the same email for various accounts. A few that don't but those numbers are very small and more than likely that user was compromised another way.
edit Of course this is speculation and as mentioned in the original post of this article we should assume this was TV being hacked versus just a simple re-used password
Reading the source code we cannot be sure that some vulnerable software was not updated quickly enough on some production system of theirs, or say anything about DNS poising etc.
Or a piece of malware that checks if teamviewer is running (or maybe even opens it), reads the id and password from the window and sends those home
Nothing else I know of is free.
I use Back to my Mac from work all the time and I have no problem accessing my iMac at home from my MacBook Pro at work.
My home setup still doesn't work with Back to My Mac (and hasn't for years).
No need to take blame - I gather that TV is not exactly a transparent organization, and perhaps their customers are less amenable to security update or outage post-mortems than most HN readers, but they ought not stick their heads in the sand.
As a paying customer, I should not have to find this out through Reddit and HN.
In the end when I was asked to install teamviewer (I use Linux BTW) I could see all thr process even after I turned it off. i would find myself killing off the 3 or so process that maintained a connection to a server. Heck i get alot of I am silly and its secure. Now I have not had anything happen to me and yet to see anyone beyond stories online. Do not take my word for it run a debugger or trace it wireshark do what you will you will get a suprise. sorta like when I ran skype in linux and traced what it accessed (scary stuff)