Zacinlo adware affecting Windows 10 Users
bleepingcomputer.com
bleepingcomputer.com
Err. Can we blame Windows if a user installs software?!
At the moment, unless you’re a celebrity or other high-profile individual, there isn’t really anything that can happen - the main financial risk - credit card fraud - will be refunded by the bank.
Should banks stop taking liability for idiot’s stupidity, all it would take is a few published cases of people getting their life savings emptied because of malware and idiots will wisen up or refrain from using the internet (which is fine too).
But yeah, let's put that on idiot grandmas.
There's always sob stories* about how little old granny lost her savings because of some scam website
Yet people still fall for them, especially the ones that promise to get rich quick. From Nigerian princes to bitcoing investing
This one has been advertised with fake newspaper reports about how it was on "Dragons Den" (I believe it's Shark Tank in the U.S.): https://bitcoin-trader.biz/
When people fall for What kind of results can I expect? Bitcoin Trader members typically profit a minimum of $13,000 daily.
there's simply no helping them
* (Usually from the kids/grandkids who wanted the money instead)
I also don't think people losing their life savings will change anything. Ponzi schemes are still a big thing, MLM is still a big thing, Nigerian princes are still a big thing, and people lose it all through those scams constantly. The state of bank security is so bad that every time I write a check, I'm giving the recipient my bank's name, my account number, my home address, and my signature. That's a lot of sensitive information that a phisher could do some real damage with.
Ultimately, if a fraudulent transaction clears the bank, it is the bank's fault. It's their job to verify transactions and verify identity before clearing the transaction. In a perfect world, financial malware would cease to exist because bank security was locked down so tight that fraudulent transactions would never clear.
Seems insane that my credit card number is displayed in plain text to anyone I deal with in the physical world and is enough for anyone else on the planet to charge my account.
Most users can be safely assumed to operate on the same intelligence level as a chipmunk the moment they are handed a keyboard. I've met people who had difficulty handling the instruction "open excel" because excel wasn't in the familiar spot on the desktop and confused "save and exit word" with "hold power button for 5 seconds" without a malicious thought.
People still install sketchy Apps and "Make your computer clean", they respond to emails from the nigerian prince about his money and pills to make body parts larger and they will continue to remain ignorant of the dangers lurking in the internet.
Instead of educating them we should protect them. Users will do dumb things and we need to make sure that when a user wants to do a dumb thing they know it's a dumb thing. Sysadmins may install a rootkit on purpose or may install a self-signed driver.
The average user should under no circumstance be given the power to install a self-signed anything.
Give the sysadmins power and prevent the user from abusing it.
Yes, but don't treat me as a idiot, when I am admin. And windows does that increasingly to a point where I simply hate it. (even though I only use Windows if I have to)
The user has to have some level of technical knowledge and personal responsibility in keeping their machines clean. Downloading random VPN software that is free seems like such a dangerous thing to do. If the user doesn't understand this, they haven't really learnt how to computer properly.
Meanwhile Mac will go so far as to completely deny you the right to run code it can't identify the developer of, until you go into the settings and temporarily grant yourself the permission to do so.
It is fundamentally impossible to prevent a user from doing bad things to their systems unless you are willing to 100% prevent the running of code that you can't identify with 100% certainty.
The problem with the desktop security model is the controls are ridiculously course-grained.
it'd be really nice if it was more efficient to run an OS like https://www.qubes-os.org/. I think only true security model that works is the sandbox isolation model of virtual machines.
It will also warn you that you are installing unsigned software in scary language.
OSes should be redesigned to make it nearly impossible to install a rootkit. Sure there will be bugs in the OS but those bugs will be fixed but the goal should be that apps can't own your entire computer anytime you install one and asking for admin should have big giant warnings and be shunned and shamed from any software that asks for it.
Linux, for example, does it out of the box. Most Linux systems don't give you root access, and some even disable logins to the root account altogether. You have to specifically escalate your privileges. If the user account isn't in the sudoers group, tough luck.
Windows has UAC for this, too. I find it very lacking, but it's better than nothing. macOS has a similar permissions system.
Application whitelisting is another great option. Let users install trusted and signed programs, while admins have the ability to install anything they want.
And also look for iOS versus Android. Almost no one using iOS is able to install random applications from the Internet, and it still has huge marketshare because most people don't care. Android is an option for those who do care.
It's not either/or. Options exist for both use cases. What responsible tech people need to do is use the option they're most comfortable with, while steering normal end users towards the safest option possible. It's even as simple as installing Windows, giving the user a normal (unprivileged) account, and just not giving them the admin password.
The dancing pig problem has been solved.
That leaves us with private machines: should the user have the admin access, if it is his private machine? He is the owner after all. If "not yet", who and when will grant it, when the need arises/the user educates himself/etc? Also, how will the user, who is willing to educate himself able to do, when he is not allowed to try and fail?
iOS turned this into a big brother scenario: there is someone else, who has to approve any program that you can run on the device. However, Apple might have objectives and responsibilities that may be different than yours, and they may deny you running an app, that is otherwise perfectly fine (and not just for technical reasons: imagine living in Crimea today, for example). Even on Android, there are things that you may legitimately want to do, but out of the box the system won't let you - you may either need the same signing key that the platform is signed with, or full blown root (backing up the device, for example). Both of these platforms take away possibilities in the name of what the mainstream user supposedly wants, and nobody is going to ask you, whether you are competent to use these features or not. Once you lose these possibilities, they are not going back.
But you can still have proper security features without centralization. Android's permission system, or even some form of isolated per-process virtualization/sandboxing can go a long way. If properly architectured, it can be possible to prevent a good bunch of malware.
Even for myself, I may want that for some of my actual computers. For phones and TVs and such, I'd rather it be 100% reliable and idiot proof than be able to install custom OSes or whatever.
Certainly better than the "this free fart sound app requires access to your camera, microphone, gps location, background running, contact list, ability to send sms, etc" popups that people like my mother-in-law will just press "Yes" on.
Prevents malicious apps like this from really mining their way into your devices but allows power users to have real control still.
Isn't an OS problem, and requires no redesign (well no idea about Windows), it's just a choice of how to run their machine.
Perhaps if OP believes that all apps should be containerised, but this doesn't need an OS to be redesigned, it just means a new skin. I could easily see a "Dockbuntu" which, instead of distributing programs like Firefox and spotify, distribute links to docker containers running those programs, where the user can choose which directories to mount into the application's container (and whether they should be readonly, readwrite, etc)
The problem is that most people seem to not like the limitations. Although you can now install iTunes from the Windows store, there is still no Chrome which most users really want.
This is the solution, but it has a rather important second part. It requires granular privileges, and must make it easy for developers to not need the more severe privileges. Without this, developers will continue to request full admin privileges, and users will be trained to accept giving them.
The funny thing is that win10 already treats the user as an idiot. Much to public dismay, but apparently people ARE idiots.
Since Windows 8 I have always enabled safeboot in the UEFI settings before installing the OS. Machines with pre-installled Windows usually come with this setting enabled by default. I would expect this type of malware would not run on machines with safeboot, or cause a BSOD on the next startup.
The article doesn't say anything about this, does it require an unlocked bootloader, does it silently fallback when it detects safeboot, or does it have a by-pass?
Does it simply hijack windows's restore functionality? Or does it write itself to firmware to essentially become baked into the hardware.
For example, in the past I've seen a board where the combination of booting from NVMe drive, setting up Intel RAID on SATA HDDs and Secure Boot simply didn't work together. You had to give up one of these to continue.
EDIT: They did - never mind the above, I totally missed it I need to upgrade my glasses - thanks for pointing it out!
>"The adware components are silently installed by a downloader that is presented as a free and anonymous VPN service (s5Mark)," Bitdefender experts wrote in a 104-page report detailing Zacinlo's modus operandi and all of its modules released today.