Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Jeff – Jev-compatible 0.8B decision models, trained at home, ~30 ms (github.com/firelex)
    131comments
  2. Pirating the Pirates (mubi.com)
    234comments
  3. 12,000-year-old Göbeklitepe burials explain scattered bones (archaeologymag.com)
    22comments
  4. 1996 chat room simulator connected to Win95 and System 7 web desktops (lolchat.rip)
    21comments
  5. MicroLLM Lab – Try 7 tiny LLM's in the browser (stateofutopia.com)
    66comments
  6. U.S. Strategic Petroleum Reserve Falls to Lowest Level Since 1982 (oilprice.com)
    1comments
  7. California farmers are struggling to sell grapes as demand for wine drops (kqed.org)
    204comments
  8. Scientists solve 1840s space weather mystery (arstechnica.com)
    38comments
  9. Sonnet 5.5 (anthropic.com)
    423comments
  10. Tank Body Problem (jimsitu.com)
    7comments
  11. ESP32S3 cluster running 1.58-bit (BitNet) Language model (github.com/low-zi-hong)
    5comments
  12. World Labs Is Joining AMD (worldlabs.ai)
    78comments
  13. Hijacking the PS5's RTMP stream (yashgarg.dev)
    67comments
  14. How to win a beer with high-dimensional statistics (jamiesimon.io)
    2comments
  15. Kids turned low-traffic NPR Spotify comments into a secret group chat (thisamericanlife.org)
    187comments
  16. Bluegraph – Explore NOAA buoy data, rebuilt in 3D from measured spectra (bluegraph.io)
    2comments
  17. What is the best shape of a city? Modelling effect of urban form on distance (sagepub.com)
    10comments
  18. Does Reddit have an astroturfing problem? What the data suggests (petervijeh.com)
    159comments
  19. It's Time to Investigate the AI Labs (calnewport.com)
    130comments
  20. Updated Google Maps shows destruction of the city of Rafah (twitter.com/aliabunimah)
    147comments
  21. Show HN: HN.watch – Videos of all Hacker News posts (hn.watch)
    82comments
  22. Nvidia wants to put a watchdog chip next to every AI agent (cnbc.com)
    153comments
  23. What reversing, modernising old games tells us about the economic impact of AI (isfine.org)
    29comments
  24. Cf: The Agentic CLI for the Cloudflare API (cloudflare.com)
    56comments
  25. The Art Forger Who Became a National Hero (priceonomics.com)
    1comments
  26. Blend and Haul: Fertilizer Blending Simulator (wedgworth.com)
    1comments
  27. Behold the pawpaw (cbc.ca)
    19comments
  28. Show HN: Destroy Any Website with Stickman (spritefusion.com)
    28comments
  29. First Steps of the PLC Organization – Independent Public Ledger of Credentials (plcred.org)
    19comments
  30. Coding is not solved (alexewerlof.com)
    444comments

FireEye confirms APT41 hacked TeamViewer, may have accessed billions of devices

306 pointsby 7y agotwitter.com
70 comments
7y agoHN ↗

Website lists October 14th, 2019 as the article date and quotes a tweet from four days earlier. So I'd assume it's new.

7y agoHN ↗

Unfortunately, this is not the first time TeamViewer is the victim of threat actors. About four years ago...

Sounds like a new one.

7y agoHN ↗

Has anyone noticed that archive.is has pretty apalling dns-based tracking?

7y agoHN ↗

They still refuse to serve users with Cloudflare DNS.

7y agoHN ↗

Fascinating, they embed a tracking pixel of: http://onion.[SOME_NUMERIC_ID].pixel.archive.today/pixel.gif for Tor endpoint (archivecaslytosk.onion) connections but https:// [YOUR_IP].[COUNTRY_CODE].[SHORT_ALPHANUMERIC_ID].[SOME_NUMERIC_ID].pixel.archive.is/pixel.gif for regular (archive.is/archive.fo/archive.today/etc) connections.

So at least this lets archive.is correlate your IP with your DNS server (which must pass EDNS Client Subnet to get any meaningful response, this is the reason why Cloudflare DNS is not that great for accessing archive.is; more: https://news.ycombinator.com/item?id=19828317).

7y agoHN ↗

There is something weird going on - both demanding the EDNS detail and then the extra tracking. I'm happy to avoid them using cloudflare's privacy stuff.

7y agoHN ↗

The article doesn’t give me any confidence in their reporting and is a site I’ve not heard of, so I’m feeling it’s a bit suspect. Anyone have a better source?

7y agoHN ↗

The title could still be a bit better, the story is about the ability to access billions of devices. There is zero indication that billions of devices were actually accessed.

7y agoHN ↗

Sorry for the belated reply; I just saw this. I suppose "may have accessed" was intended to communicate that in the title?

7y agoHN ↗

I'm sure it was, I'm just not so sure that it does a very good job at that.

I feel like the most obvious interpretation of this is "APT41 possibly accessed billions of devices" which is incorrect, they had the ability but it is known that they only accessed a rather limited set of devices.

I'm not sure what would've been a better title though, especially given the length restrictions" ¯\_(ツ)_/¯

7y agoHN ↗

There is an ongoing trend the last several weeks of highly sensationalized cybersecurity incidents being mis-reported and ending up being nothing.

Not sure if it’s just a cluster of fuckups or if something is contributing to the uptick in false reports. But add this one to the list.

7y agoHN ↗

How do we tell if we are affected? Also, how could it do anything if TV isn't open?

7y agoHN ↗

This is from 2016. It's hard to say how you can tell without knowing what techniques were used against you specifically,if you have FireEye's network or endpoint products (or any other major vendor) they would provide coverage for any remnants of compromise by that threat actor.

7y agoHN ↗

TeamViewer is safe to use

How often has that been true? TV has been hacked more than once AFAIK.

7y agoHN ↗

TV gives full access to computers through passwords and it seems it's not brute-force resistant. Think about how long an SSH server with password enabled and no autoban would last in the open...

Edit: nevermind, the attack is apparently through some malware.

7y agoHN ↗

Think about how long an SSH server with password enabled and no autoban would last in the open

quite long? unless you're using a bad password I don't really see any risk other than filling logs from password attempts.

7y agoHN ↗

Most useless statement in the history of mankind.

7y agoHN ↗

Speaking of TeamViewer, do you know a good open source alternative that I can self host (I mean self host the relay server for NAT traversal). That is as easy to use? Works on windows, mac and linux? It should also be installable in a few slick with no network configuration required.

7y agoHN ↗

I haven't tried this, but I imagine a situation where computer A uses SSH to connect to VPS B and computer C connect to VPS B using SSH. If both SSH connections port-forward a VNC port, you can use VNC.

7y agoHN ↗

This is what I use. In Unix it just works (TM). If you have an ssh client in windows, it also works with Remote Desktop via ssh port forwarding. In lieu of a (configured) ssh client on Windows, you can send the other person a self-contained Go program to do the job.

7y agoHN ↗

Yes technically it could work, but I cannot ask the users to use SSH and configure VNC. The force of team viewer is that you download it, open it, and give number over the phone and it works.

7y agoHN ↗

Chrome remote desktop works pretty well

7y agoHN ↗

But for remote control, it stops after every few minutes, asking the "controlled" user to click on a button to continue. Not so practical in a few situations.

7y agoHN ↗

What do you mean? I've never had it do that.

7y agoHN ↗

It always happens for me when accessing a Linux machine remotely. I can't find a screenshot now, so the next time I do it, I'll take one. It seems to be a security measure, to prevent someone from sharing remote access and then forgetting about it afterwards, but it makes for terrible usability.

7y agoHN ↗

you can also port forward from/to unix sockets

7y agoHN ↗

I've been looking at a combination of SoftEther (for dynamic IPs) and Guacamole to replace TeamViewer, ConnectWise, etc.

7y agoHN ↗

I also use Guacamole for remote employee/vendor access (with public IPs hidden behind a proxy like an F5 or at least SSL+HTTP Simple Auth), but I haven't ever tried to configure it for remote support session sharing type stuff. Is that how you're using it? If so, how is it set up?

7y agoHN ↗

Anybody know of a UDP-based alternative? VNC is TCP.

7y agoHN ↗

Is there a reason why you need UDP specifically?

7y agoHN ↗

What protocol do you notice this with? In my experience, Microsoft RDP (the only protocol I know with configurable udp and tcp) with and without udp is imperceptible during typical use (eg. server administration).

7y agoHN ↗

With RDP. It's not imperceptible for me. I don't just use RDP for server administration.

7y agoHN ↗

Not OSS but remotedesktop.google.com works well.

7y agoHN ↗

It sucks for multi monitor setups though, keyboard events, defocuses for no reason, unlocks the computer you rdp into, doesn't support scaling monitors.

7y agoHN ↗

I don't know how smooth it is, since I haven't tried it myself yet, but apparently Nextcloud talk can do it. I think it needs a browser extension but that might not be nearly as much of an imposition as vnc + ssh. It's also pretty easy to self host on a vps or other server of your own.

7y agoHN ↗

zerotier.com is exactly this. I am still amazed how easy this is. (Big fanboy)

7y agoHN ↗

In case when remote control capabilities are not required, one could use jitsi (https://jitsi.org) video conferencing service which provides screen sharing capabilities (implementation depends on the web browser).

The main advantage is that there is no need to install any software neither on the remote machine nor on the local one.

There is a cloud hosted free version https://meet.jit.si which does not even require registration.

7y agoHN ↗

I use nomachine behind vpn and it works much smoother than teamviewer. It's multiplatform and free for personal use.

7y agoHN ↗

So I use TV for occasional family support.

Were machines vulnerable with only Teamviewer:

1. Installed but not being used? 2. Only when being used (i.e. ask family member to fire it up and give the connection info)

7y agoHN ↗

If the software is not running when closed (system process) then it should mostly be fine.

7y agoHN ↗

Yeah, you never obviously know these days if there are background services running.

7y agoHN ↗

This group of hackers uses highly sophisticated malware variants, primarily developed for espionage, so we consider it unlikely that any State is sponsoring its operations,” Glyer says.

The web application security expert adds that, based on detected activities and attack methods, in addition to the unusual interest that APT41 has shown in attacking the video game industry, its attacks could not be politically motivated; instead, they’re focused on economic gains.

I’d like to know how can one simply assume this given a potential payoff of billions of devices...

7y agoHN ↗

Especially given that the "Video Game Industry" probably represents a pretty large group of heterogenous, idiosyncratic chat protocols, which I certainly would be interested in if I were the Chinese Govt.

7y agoHN ↗

TeamViewer devs are especially to blame for this. You can’t install it without admin permissions even if you just want to control another desktop. Unless you manually extract the .app from the .pkg, in which case it works fine.

Anyways, this isn’t the first time TeamViewer has been hacked. Wonder what their beef is against E2EE between connected computers.

7y agoHN ↗

On Windows it can be used by a standard user without being installed. It's much more difficult to do this on macos. Even on Windows there are dark patterns that make this difficult, but it can be done.

7y agoHN ↗

MeshCentral is open source, runs on Linux and works with Windows, Mac and Linux clients for one-off support and unattended remote control...

7y agoHN ↗

Thank you for the hint, I used AnyDesk (think it was built by people who worked at TV) but I'd enjoy an open source solution even more if it does what it should.

7y agoHN ↗

I've been using MeshCommander/MeshCentral (and their older tools like Open MDTK) since the first public versions, both for vPro/AMT related management tasks, and remote control. I'm very happy with them but I certainly won't rely on the assumption that they can't be hacked. With enough "motivation" an attacker has plenty of targets on the logistics chain where a vulnerability can be introduced (in the code, in the installer, etc.).

7y agoHN ↗

For a less sophisticated option for home users there's also DWService that is open source.