New FinFisher surveillance campaigns: Are internet providers involved?

Discussion in 'other security issues & news' started by Minimalist, Sep 21, 2017.

  1. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    https://www.welivesecurity.com/2017/09/21/new-finfisher-surveillance-campaigns/
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    This is quite scary stuff and a bit shocking. That's why I will always stick with my "trust no app" motto. Even trusted software shouldn't be fully trusted. :thumb:
     
  3. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    FinFisher also exposes the need for two-factor authorization in app software downloading. This can be done manually by comparing the hash of the download file to the hash of the download present on the legit vendors web site.

    There is also the question of whether the bogus downloads were validity signed which was not addressed in the Eset article. I assume they weren't and is also a manual validation everyone should perform prior to installing any app software from a vendor known to sign their software.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.