Mac malware signed with Apple ID infects activist’s laptop
arstechnica.com
arstechnica.com
Gatekeeper is meant to prevent a wide-ranging attack. If you've got someone custom crafting an attack vector for you specifically, you've got some serious problems. I don't think Gatekeeper adds any more false security than an antivirus app would, and I don't know of any software that'd prevent an attack like this.
At best, it adds a small amount of information for authorities to try to track the attack. I doubt it'll be fruitful, but it's better than nothing.
So yeah, I guess in a certain light, a machine that can't launch apps is definitely secure.
It's true that we could do that, but their original purpose was to protect us in the first place. The same is true for code signing certificates, to a certain extent.
That sounds kind of shitty to me... Is there any simple way around that?
At any given point in time, half of America is posting some sort of critical message about the government online.
Maybe they just have a better spam filter than you
Again that's what I thought too. But it was coming from different friends. Which means all of them must have done the same thing.
I also sent the email to my friend who works at facebook for investigation in case it was some service that wasn't playing by the rules.
Edit: To be more specific, the emails use the names of my Facebook friends, but have incorrect sender addresses, indicating that they're just spoofing the name rather than hacking the email accounts of my friends. They're usually fairly short, with an obvious phishing link to a gibberish domain. They come from Facebook friends that I don't necessarily communicate with, and I've confirmed with at least two of those friends that their accounts have not been hacked.
First and foremost, it cost $100 to get the signature. It was paid somehow. Hello money trail, this is way more information on malware authors / pushers than we tend to get. If they somehow obfuscated every bit of data in that account to the point that it's worthless, then it's merely identical to it lacking a signature, no worse.
Second, it can be revoked. This severely limits the spread, reducing the total damage. Sure, the people prior to this are impacted, but they would be if it didn't have a signature, so again, no worse, no matter what.
Third, people click 'yeah, let this program do whatever the hell it wants' all the time, so the lack of a signature really doesn't prevent its spread / limit the damage. Maybe for the techy-elite, but they're less likely to get this anyway. Probably more likely to run unnoticed because it's signed, but I'd argue not by much. Slightly worse.
CVE-2013-1014 as it impacts iTunes for Mac OS X v10.6.8 or later, Windows 7, Vista, XP SP2 or later (http://support.apple.com/kb/HT5766) -
"Impact: An attacker in a privileged network position may manipulate HTTPS server certificates, leading to the disclosure of sensitive information
Description: A certificate validation issue existed in iTunes. In certain contexts, an active network attacker could present untrusted certificates to iTunes and they would be accepted without warning. This issue was resolved by improved certificate validation."
There were almost forty other CVEs for iTunes on Windows. And just a last bit - the discussion and quality of submissions here at Hacker News has taken a substantial fucking nose dive in the last year. I change my name every so often, but i can tell you that i've been here long enough to say that.
I'd be interested to know how this works? How can you just "take control" over a server/IP address like that? Is there some law that allows botnet control servers to be seized?
I imagine that if a similar thing happened to an Egyptian activist during Mubarak's time in power that it would not be such a stretch to say such a thing.
Looks like Macs market share is growing. Was this distributed in the store?
Anything distributed through the App Store is signed by Apple. Developer ID signed binaries can only be distributed outside of the store.
"Android malware attack spreads via e-mail"
http://www.usatoday.com/story/tech/2013/03/28/android-malwar...
http://securitywatch.pcmag.com/mobile-security/311417-window...
2) FTA:
>Q: What can or should individuals do?
> Stone-Gross: Do not allow installation of applications that are not distributed through the official Google Play marketplace on the device
So this malware isn't effective unless the user explicitly makes their device vulnerable, doing something normally only developers or hard core users - people who are likely to spot this attack - would do.
There's nothing anyone can do if a user installs software. UNIX design or not, if the user runs a program, it can access everything that the user can. Nothing that this malware did needed special access (e.g. root exploit).
The idea that all apps run under a single "user" and all share the permissions of that "user" is just how UNIX does it, not how things must work. I don't think we've figured out proper app sandboxing yet (Mac, iOS, and Android all have their problems with it, and differently) but it seems to be the way to go.
- a recent convert to Apple
However, this will break nearly everything – and I am rather positive that Windows offers similar security measures, if required.
Now the malware problems on both platforms rarely rely on privilege escalation. They use trojan horses instead, and wait for you to install them.