Skip to content

Comment on Handbrake malware analysis

Comments

Article talks about a fake authentication popup.

Has anyone used a platform that had an unspoofable one of these?

It's only "fake" in that the real Handbrake doesn't need to install extra codecs—it's a real authentication dialog. They are just hoping to catch the user off guard and unaware so they can install the persistent malware agent.

How would one make such a thing unspoofable, barring seperate hardware?

Could use a hardware LED to inform user key input is secure. Could also reserve part of the screen for OS messages.

This prevents hostile apps from stealing your root password, but doesn't stop them from tricking you into giving them root access (which is nearly as bad).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.