Firefox contains spyware (probably)

User avatar
Mysturji
Clint Eastwood
Posts: 5005
Joined: Thu Feb 26, 2009 4:08 pm
About me: Downloading an app to my necktop
Location: http://tinyurl.com/c9o35ny
Contact:

Firefox contains spyware (probably)

Post by Mysturji » Thu May 02, 2013 11:54 am

Sir Figg Newton wrote:If I have seen further than others, it is only because I am surrounded by midgets.
Cormac wrote:Doom predictors have been with humans right through our history. They are like the proverbial stopped clock - right twice a day, but not due to the efficacy of their prescience.
IDMD2
I am a twit.

User avatar
klr
(%gibber(who=klr, what=Leprageek);)
Posts: 32964
Joined: Wed Mar 04, 2009 1:25 pm
About me: The money was just resting in my account.
Location: Airstrip Two
Contact:

Re: Firefox contains spyware (probably)

Post by klr » Thu May 02, 2013 11:56 am

Finfisher is a legitimate surveillance software thought to be used by governments to covertly obtain data.

It is installed unknowingly by its target computer user, often by disguising itself as an update to a well known programme such as Firefox.
So how would one actually fall for this in practice? :?
God has no place within these walls, just like facts have no place within organized religion. - Superintendent Chalmers

It's not up to us to choose which laws we want to obey. If it were, I'd kill everyone who looked at me cock-eyed! - Rex Banner

The Bluebird of Happiness long absent from his life, Ned is visited by the Chicken of Depression. - Gary Larson

:mob: :comp: :mob:

User avatar
Mysturji
Clint Eastwood
Posts: 5005
Joined: Thu Feb 26, 2009 4:08 pm
About me: Downloading an app to my necktop
Location: http://tinyurl.com/c9o35ny
Contact:

Re: Firefox contains spyware (probably)

Post by Mysturji » Thu May 02, 2013 12:02 pm

klr wrote:
Finfisher is a legitimate surveillance software thought to be used by governments to covertly obtain data.

It is installed unknowingly by its target computer user, often by disguising itself as an update to a well known programme such as Firefox.
So how would one actually fall for this in practice? :?
:think: It's right there in the bit you quoted.
Never mind WTF is "legitimate surveillance software". All you need to do is click "yes" when Firefox says it wants to install an update. I mean, who wouldn't? Everyone trusts trusted firefox, didn't they?
Sir Figg Newton wrote:If I have seen further than others, it is only because I am surrounded by midgets.
Cormac wrote:Doom predictors have been with humans right through our history. They are like the proverbial stopped clock - right twice a day, but not due to the efficacy of their prescience.
IDMD2
I am a twit.

User avatar
klr
(%gibber(who=klr, what=Leprageek);)
Posts: 32964
Joined: Wed Mar 04, 2009 1:25 pm
About me: The money was just resting in my account.
Location: Airstrip Two
Contact:

Re: Firefox contains spyware (probably)

Post by klr » Thu May 02, 2013 12:04 pm

Mysturji wrote:
klr wrote:
Finfisher is a legitimate surveillance software thought to be used by governments to covertly obtain data.

It is installed unknowingly by its target computer user, often by disguising itself as an update to a well known programme such as Firefox.
So how would one actually fall for this in practice? :?
:think: It's right there in the bit you quoted.
Never mind WTF is "legitimate surveillance software". All you need to do is click "yes" when Firefox says it wants to install an update. I mean, who wouldn't? Everyone trusts trusted firefox, didn't they?
Yes, but how is Firefox being tricked into presenting you with this false update in the first place?

Anyway, time to (maybe) change all of my passwords ... or to check first if my AV programs have let this blighter through.
God has no place within these walls, just like facts have no place within organized religion. - Superintendent Chalmers

It's not up to us to choose which laws we want to obey. If it were, I'd kill everyone who looked at me cock-eyed! - Rex Banner

The Bluebird of Happiness long absent from his life, Ned is visited by the Chicken of Depression. - Gary Larson

:mob: :comp: :mob:

User avatar
Gawdzilla Sama
Stabsobermaschinist
Posts: 151265
Joined: Thu Feb 26, 2009 12:24 am
About me: My posts are related to the thread in the same way Gliese 651b is related to your mother's underwear drawer.
Location: Sitting next to Ayaan in Domus Draconis, and communicating via PMs.
Contact:

Re: Firefox contains spyware (probably)

Post by Gawdzilla Sama » Thu May 02, 2013 12:06 pm

Image
Ein Ubootsoldat wrote:“Ich melde mich ab. Grüssen Sie bitte meine Kameraden.”

User avatar
klr
(%gibber(who=klr, what=Leprageek);)
Posts: 32964
Joined: Wed Mar 04, 2009 1:25 pm
About me: The money was just resting in my account.
Location: Airstrip Two
Contact:

Re: Firefox contains spyware (probably)

Post by klr » Thu May 02, 2013 12:06 pm

God has no place within these walls, just like facts have no place within organized religion. - Superintendent Chalmers

It's not up to us to choose which laws we want to obey. If it were, I'd kill everyone who looked at me cock-eyed! - Rex Banner

The Bluebird of Happiness long absent from his life, Ned is visited by the Chicken of Depression. - Gary Larson

:mob: :comp: :mob:

User avatar
Mysturji
Clint Eastwood
Posts: 5005
Joined: Thu Feb 26, 2009 4:08 pm
About me: Downloading an app to my necktop
Location: http://tinyurl.com/c9o35ny
Contact:

Re: Firefox contains spyware (probably)

Post by Mysturji » Thu May 02, 2013 12:07 pm

klr wrote:
Mysturji wrote:
klr wrote:
Finfisher is a legitimate surveillance software thought to be used by governments to covertly obtain data.

It is installed unknowingly by its target computer user, often by disguising itself as an update to a well known programme such as Firefox.
So how would one actually fall for this in practice? :?
:think: It's right there in the bit you quoted.
Never mind WTF is "legitimate surveillance software". All you need to do is click "yes" when Firefox says it wants to install an update. I mean, who wouldn't? Everyone trusts trusted firefox, didn't they?
Yes, but how is Firefox being tricked into presenting you with this false update in the first place?

Anyway, time to (maybe) change all of my passwords ... or to check first if my AV programs have let this blighter through.
If I understand correctly, they didn't trick Firefox, they're tricking Firefox users by pretending to be a Firefox update.
Sir Figg Newton wrote:If I have seen further than others, it is only because I am surrounded by midgets.
Cormac wrote:Doom predictors have been with humans right through our history. They are like the proverbial stopped clock - right twice a day, but not due to the efficacy of their prescience.
IDMD2
I am a twit.

User avatar
klr
(%gibber(who=klr, what=Leprageek);)
Posts: 32964
Joined: Wed Mar 04, 2009 1:25 pm
About me: The money was just resting in my account.
Location: Airstrip Two
Contact:

Re: Firefox contains spyware (probably)

Post by klr » Thu May 02, 2013 12:10 pm

Mysturji wrote:If I understand correctly, they didn't trick Firefox, they're tricking Firefox users by pretending to be a Firefox update.
Yup, that's it.

From 'Zilla's wiki link:
Bill Marczak said of FinSpy mobile "As we saw with respect to the desktop version of Finfisher, antivirus alone isn't enough, as it bypassed antivirus scans."[20] Sara Yin predicts that antivirus vendors are likely to have updated their signatures to detect FinSpy mobile.[20] ESET have announced detection of the desktop FinFisher as Win32/Belesak.D Trojan,[21][22] and antivirus vendors have claimed they detect malware they know about regardless of origin or purpose.
That's not exactly clear as to whether AV programs are blocking it or not. :what:
God has no place within these walls, just like facts have no place within organized religion. - Superintendent Chalmers

It's not up to us to choose which laws we want to obey. If it were, I'd kill everyone who looked at me cock-eyed! - Rex Banner

The Bluebird of Happiness long absent from his life, Ned is visited by the Chicken of Depression. - Gary Larson

:mob: :comp: :mob:

User avatar
Gawdzilla Sama
Stabsobermaschinist
Posts: 151265
Joined: Thu Feb 26, 2009 12:24 am
About me: My posts are related to the thread in the same way Gliese 651b is related to your mother's underwear drawer.
Location: Sitting next to Ayaan in Domus Draconis, and communicating via PMs.
Contact:

Re: Firefox contains spyware (probably)

Post by Gawdzilla Sama » Thu May 02, 2013 12:11 pm

Mysturji wrote:If I understand correctly, they didn't trick Firefox, they're tricking Firefox users by pretending to be a Firefox update.
Yeah, the "okay-click" people.
Image
Ein Ubootsoldat wrote:“Ich melde mich ab. Grüssen Sie bitte meine Kameraden.”

User avatar
pErvinalia
On the good stuff
Posts: 60798
Joined: Tue Feb 23, 2010 11:08 pm
About me: Spelling 'were' 'where'
Location: dystopia
Contact:

Re: Firefox contains spyware (probably)

Post by pErvinalia » Thu May 02, 2013 12:13 pm

But how is it presenting itself? What is causing it to create a popup to get you to install it? You'd have to click on something malicious first, wouldn't you?
Sent from my penis using wankertalk.
"The Western world is fucking awesome because of mostly white men" - DaveDodo007.
"Socialized medicine is just exactly as morally defensible as gassing and cooking Jews" - Seth. Yes, he really did say that..
"Seth you are a boon to this community" - Cunt.
"I am seriously thinking of going on a spree killing" - Svartalf.

User avatar
Gawdzilla Sama
Stabsobermaschinist
Posts: 151265
Joined: Thu Feb 26, 2009 12:24 am
About me: My posts are related to the thread in the same way Gliese 651b is related to your mother's underwear drawer.
Location: Sitting next to Ayaan in Domus Draconis, and communicating via PMs.
Contact:

Re: Firefox contains spyware (probably)

Post by Gawdzilla Sama » Thu May 02, 2013 12:15 pm

rEvolutionist wrote:But how is it presenting itself? What is causing it to create a popup to get you to install it? You'd have to click on something malicious first, wouldn't you?
Yeah, but if it was convincing most people would just click ok and go on.
Image
Ein Ubootsoldat wrote:“Ich melde mich ab. Grüssen Sie bitte meine Kameraden.”

User avatar
pErvinalia
On the good stuff
Posts: 60798
Joined: Tue Feb 23, 2010 11:08 pm
About me: Spelling 'were' 'where'
Location: dystopia
Contact:

Re: Firefox contains spyware (probably)

Post by pErvinalia » Thu May 02, 2013 12:24 pm

But where is the pop up coming from? It can't come out of nowhere. You'd have to visit a certain website or click on some other element first to get the popup to even occur.
Sent from my penis using wankertalk.
"The Western world is fucking awesome because of mostly white men" - DaveDodo007.
"Socialized medicine is just exactly as morally defensible as gassing and cooking Jews" - Seth. Yes, he really did say that..
"Seth you are a boon to this community" - Cunt.
"I am seriously thinking of going on a spree killing" - Svartalf.

User avatar
Gawdzilla Sama
Stabsobermaschinist
Posts: 151265
Joined: Thu Feb 26, 2009 12:24 am
About me: My posts are related to the thread in the same way Gliese 651b is related to your mother's underwear drawer.
Location: Sitting next to Ayaan in Domus Draconis, and communicating via PMs.
Contact:

Re: Firefox contains spyware (probably)

Post by Gawdzilla Sama » Thu May 02, 2013 12:28 pm

rEvolutionist wrote:But where is the pop up coming from? It can't come out of nowhere. You'd have to visit a certain website or click on some other element first to get the popup to even occur.
It doesn't have to be a shady website. Someone could spoof Google and get a free ride into almost anyone's computer.
Image
Ein Ubootsoldat wrote:“Ich melde mich ab. Grüssen Sie bitte meine Kameraden.”

User avatar
Mysturji
Clint Eastwood
Posts: 5005
Joined: Thu Feb 26, 2009 4:08 pm
About me: Downloading an app to my necktop
Location: http://tinyurl.com/c9o35ny
Contact:

Re: Firefox contains spyware (probably)

Post by Mysturji » Thu May 02, 2013 1:44 pm

Gawdzilla Sama wrote:
Mysturji wrote:If I understand correctly, they didn't trick Firefox, they're tricking Firefox users by pretending to be a Firefox update.
Yeah, the "okay-click" people.
... and people who look and see it's an update for Firefox or iTunes before clicking.
Wikipedia wrote:...it could be covertly installed on suspects' computers through exploiting security lapses in the update procedures of non-suspect software...

A security flaw in Apple's iTunes allowed unauthorized third parties to use iTunes online update procedures to install unauthorized programs.[6][7] Gamma International offered presentations to government security officials at security software trade shows where they described to security officials how to covertly install the FinFisher spy software on suspect's computers using iTunes' update procedures.
The security flaw in iTunes that FinFisher is reported to have exploited was first described in 2008 by security software commentator Brian Krebs.[6][7][14] Apple did not patch the security flaw for more than three years, until November 2011. Apple officials have not offered an explanation as to why the flaw took so long to patch.
Sir Figg Newton wrote:If I have seen further than others, it is only because I am surrounded by midgets.
Cormac wrote:Doom predictors have been with humans right through our history. They are like the proverbial stopped clock - right twice a day, but not due to the efficacy of their prescience.
IDMD2
I am a twit.

User avatar
Mysturji
Clint Eastwood
Posts: 5005
Joined: Thu Feb 26, 2009 4:08 pm
About me: Downloading an app to my necktop
Location: http://tinyurl.com/c9o35ny
Contact:

Re: Firefox contains spyware (probably)

Post by Mysturji » Thu May 02, 2013 1:48 pm

rEvolutionist wrote:But where is the pop up coming from? It can't come out of nowhere. You'd have to visit a certain website or click on some other element first to get the popup to even occur.
How does Mozilla know you have Firefox installed, and that it's due for an update?
How does Apple know that you have iTunes installed, and it's due for an update?
These things are do-able, it you have the will and the technical expertise. Of course, an Apple or Mozilla insider in you pocket helps, too.
Sir Figg Newton wrote:If I have seen further than others, it is only because I am surrounded by midgets.
Cormac wrote:Doom predictors have been with humans right through our history. They are like the proverbial stopped clock - right twice a day, but not due to the efficacy of their prescience.
IDMD2
I am a twit.

Post Reply

Who is online

Users browsing this forum: No registered users and 9 guests