CCleaner Command and Control Causes Concern
blog.talosintelligence.com
blog.talosintelligence.com
Will we end up with a setup where every system within range of a wifi chip is instantly and persistently compromised? Could we even recover from that?
*every system within range of a wifi chip and connected to a power source
It would be devastating but nothing we couldn't rebuild from.
If your recovery strategy is "drive as fast as you can to the thrift shop" then I don't know how effective "rebuilding" would be. This is fucking terrifying.
I find that more interesting than the article itself. Some unknown entity just happened to hack the command server and drop a dump of it in their lap?
Whilst companies like Microsoft can likely afford to harden their software update systems well enough to deter this, I do wonder what impact it'll have if smaller software providers/open source software providers who can't afford high-end OpSec teams start getting targeted.
Realistically a lot of software auto-updates these days so it's a nice avenue for attackers to exploit...
operating systems like windows give no indication to the ordinary user what internet connections they are making either legitimately themselves or
from software installed separately and giving users the opportunity to review and grant or deny access.
If ALL connections were transparent it would be much easier to see what was not appropriate.
Operating systems should say that a connection is being made and for what purpose and the user given the opportunity to grant or deny.
This is what i liked about Sophos' original interface sadly gone by the wayside.
Regardless the amount of components (whether it be OS, software or website elements) which attempt connecting is overwhelming for even a non-average tech savvy user.
For example install https://pi-hole.net/ and you'll no doubt realise that most of the DNS queries traversing your home network are not directly made by the end-user.
Even as a technical user, my reaction to windows privilege escalation is pretty much just to smash yes.
Like all good things, there is a balance... and there will always be people keen to be more attuned to whats happening.
I run glasswire, and regularly see legitimate traffic from odd sounding processes. A non-technical user would have zero chance of determining what was legitimate and what wasn't.
So whilst it is handy for technical users (who are willing to put in the effort to check all the various processes that make network access) it's not likely to work well for the wider user population