Skip to content

Comment on As Customers Seek Privacy, AeroFS Emerges With Stealthy File Sharing Softwareparent

Comments

If you store binaries on the system and the system can recognize them, it could change the served versions to insert malware.

This attack isn't purely theoretical. I believe Ian Goldberg and David Wagner's group at UC Berkeley demonstrated it in the 1990s against a LAN-based NFS server that was serving shared software to workstations. Instead of making the NFS server itself malicious, they raced against it to provide modified binaries that the workstations would then execute. However, if the NFS server had been malicious, it could have carried out the same attack, without directly leaking user data to the Internet.

I guess this is a reference to that work:

https://www.cs.berkeley.edu/~daw/papers/endpoint-security.ht...

If you could compromise workstations this way, you could then try to find another channel through which to have the workstations themselves exfiltrate data. One example might be a variant on the Telex system:

https://telex.cc/

Instead of signaling Internet routers with requests to browse censored websites, you could signal them with the content of exfiltrated files.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.