So much "just works" because no one is paying attention. Of course now that the spotlight is on the issue it's all downhill from here for anyone who doesn't [auto-]update.
So much "just works" because no one is paying attention. Of course now that the spotlight is on the issue it's all downhill from here for anyone who doesn't [auto-]update.
[1]: Because only other way to exploit it would be noticed by everyone else. Like python.org domain would need to be hijacked or something similar.
I'd still guess zero times though.
Still, I doubt anyone noticed this, and you'd also still need the victim to use qBittorrent and go through this flow that downloads python.
Zero seems pretty likely, yeah.
Still the easiest way to MitM random people is to set up your own free WiFi. I've done that in the past, and it works, but HSTS and certificate caching mean it's pretty useless.
I think there's a kind of vaccination effect - nobody is going to put much effort into MitMs because it's useless most of the time, so it isn't as critical when people don't validate certificates.
Fucking hell, how often do you use torrents in coffee shops let alone install new torrent client while you're at it?
Any public wifi network setup not by a complete idiot today has fully isolated clients.
https://news.ycombinator.com/item?id=37961166
Read this and tell me if you really think it unlikely that whoever performed the mitm there wouldn't be able to or interested enough in doing similar things to known seedbox hosts, distributors, or just whoever is distributing information they'd rather not be.
Qbittorrent is one of the most be popular choices for hosted bittorrent seeders across the world. This was trivially exploitable for anyone with access to the right network path for >10years. Sure it'd have to be targeted to qbittorrent users but I don't think much individual targeting is needed if you aim for dozens, hundreds, thousands, or just as many as you can of them.
Besides sketchy government-related entities with legal wiretapping capabilities, you also have well-funded private interest groups on the malicious side.
Generally not. Seedbox services are heavily cost-driven; running a Windows install for each client would add a lot of unnecessary hardware and licensing costs.
Second, attacker here had a valid certificate, it was only noticed when certificate expired (so 6 months after, since it was LE cert).
> Besides sketchy government-related entities with legal wiretapping capabilities, you also have well-funded private interest groups on the malicious side.
If you're targeted by goverment-related entities you probably shouldn't run windows and torrent software.
My comment was about Python.org and I think that it wouldn't be unusual for a student to start doing some work in a coffee shop and get MITMd.
However, it'd be quite easy for someone to have setup QBitTorrent to auto-start on their laptop and then to forget about it when they're doing something else at an airport, coffee shop or other place where you would expect to use someone's wifi. Note that it doesn't even have to be wifi setup by the business - it could be a bad actor setting up an access point that just looks like it belongs there.
Again, this vulnerability can't exploited unless attacker is able MitM you or python.org is hijacked.
It's very hard to exploit in real-life en-masse. Targeted attack is possible, but it requires attacker to:
1) Be able to do MitM in the first place
2) You need to use qBitTorrent
3) You need to use Windows
4) You must not have python version installed that supported by qBitTorrent
Without all 4 this can't be exploited.
IMHO close to 0 --- and for those who were affected, it would've likely been a targeted attack.
I use a web browser for web browser stuff... and I'll only open a torrent application when I want to download a manually downloaded .torrent file.
Worked well enough then we promptly forgot how to do it again when we needed it.
And DCC being Direct Cable Connection.
??
S/He did reply "I am" though.
That said, I think torrents are still a great way to share files, perhaps IPFS[2]. I use LocalSend[3], too, at times, although not for large files.
Has an optional step to password-protect the contents if you have any qualms with security-by-obscurity of using an unlisted torrent on a public tracker.