The Internationalization of Malware
Ant brings us a write-up from a former malware analyst about the difficulties in fighting malware as it expands beyond English-language targets and into societies with different standards for privacy and security. Quoting:
"One of the most fascinating facets of the increasing internationalization of malware is the cultural assumptions around such software. What is considered malware in the US may be commonly accepted in China or Japan, and this is largely due to the society that it exists in. Anti-cheating rootkits are very common in games released in these countries. What is considered to be invasive in the North American or European world is acceptable there. These anti-cheating rootkits would hook into the kernel space in a very invasive way, and have the behavioral characteristics of malware such as hooking into the keyboard driver. This made it very difficult from a purely technical standpoint to distinguish them."
Oh lord, what's next, people being executed for blogging?
The country lives and dies on activeX. Trying to do anything other than read basic text on most korean websites requires the installation of several activeX controls, which means IE only for a lot of sites. And if you want to create an account on one as a foreigner and don't have your foreign registration with immigration you can just give them copies of your passport..
Malware is supposed to do Bad Things to your computer/information. If it's hooking into the kernel, it may not necessarily be malware, per se. It may just be doing business in the entirely wrong place.
Or is it lack of awareness. Add south Korea to that list because is currently seems acceptable to have about 10 useless browser bars attempting to take over and uninstall the competitors bar in internet explorer.
Awareness didn't come overnight in North American or European either.
If a piece of software makes it clear, before you purchase it, that it will install monitoring software on your machine and/or it would phone home then that's one thing. You have the option of not buying it.
If this situation only becomes apparent after the package has been installed, then (IMHO) that's not an acceptance practice.
politicians are like babies' nappies: they should both be changed regularly and for the same reasons
While most people probably don't consider them malware, a lot of people find internet ads intrusive and obnoxious and we install popup blockers to get away from some of them. But the advertisers wouldn't pay for them if someone wasn't reading them and clicking on them.
More to the point, there is a huge difference in what people care about regarding their computers. Many of my friends think I "put up" with a lot because I use Linux and install things relatively methodically, always keeping control of my system. I think they "put up" with a lot, because they have no idea what is running on their computers and what the machines might be doing with their information.
It concerns me that the anti-privacy people have time on their side, because after a few more years, they will just point out how so many people haven't been enjoying much privacy anyway, so what's the big deal?
I was extremely pissed off with the whole sony rootkit debacle, which was covert. I was even more pissed off when they bought one of my favourite music production programs Acid Pro and I checked it for the tell-tale signs of the rootkit (the processes that are started with $SYS$ are hidden from the process list) and found it present in that too. If anyone uses this product then the last rootkit free version is Acid Pro 4. Just a heads up.
I just finished installing the QQ 2008 Beta version, and kept having to make exceptions for about half of the .exes. Avast! aborted the download twice. My anti-virus software also seems hellbent on gutting PPStream and PPlive. True, the update files do behave exactly like Trojans- but they are good Trojans!
I like TFA suggestions for teaching security software to recognize the difference between legit software and trojans, but asking malware analysts to become fluent in non-Roman languages that don't have mathematics as their base might be a tall order. Math inclined folks don't always have time to learn Chinese/Japanese/Korean. Having studied Chinese for almost two years (living in the environment for about 8 months), I can read newspapers, but technical documentation would be a whole different issue.
What is considered malware in the US may be commonly accepted in China or Japan [...] These anti-cheating rootkits would hook into the kernel space in a very invasive way, and have the behavioral characteristics of malware such as hooking into the keyboard driver
Indeed. And if you look back in history, you will find documented examples in medieval Japan of samurais making alliances with kernel-space rootkit developers to repel Mongol invasions. But it actually goes back to the roots of Zen Buddhism which de-emphasized the attachment to privacy and instead favoured experimental realisation, including with various sorts of early meditation-space thought-loggers.
You just got troll'd!
Many people I know don't care for their computer's privacy because they say they don't have any important information in them. But then I ask them if the same applies for their homes and private properties and whether they would let the police or anybody in without a warrant... of course they say no.
I think is up to us to make this kind of people realize that computer privacy is something that really matters and prevent this kind of stuff from happening.
I'm currently living and Japan and would like to note that for all of the notoriously computer-ignorant people in America, Japan's computer ignorancy problem is ten-fold. Computers simply aren't used as a part of every day life in Japan as they are in America, and there aren't even basic use classes is most schools through college. IE6 is still the big web browser, and the most important factor in buying a computer (which is terribly overpriced because of Japan's tendency to use only Japan-made products for everything) is how cute it is.
The best response in this aspect seems to be a little of what is so irritating in windows, the barrage of popups. This is probably one of the most sensible bitter pills in windows. OK if the software manufacturers are going to be completely retarded or write malware, we are going to harass the user continually as long as the software is running. Since we cannot make them change, and only the consumer's dollar is going to help.
Sucks to be us, but that's what it takes to make developers clean up their act. Give them the choice to do it right or turn their software into something totally obnoxious.
Lets say windows had a way to detect the root kit. Code it in. Make a popup come up every 5 minutes that the rootkit was detected. Cannot be disabled. (period) First thing the developers would do is mod it to hide better. A small war starts. Microsoft being the OS author, WILL win that war eventually. And the enraged customers will force them to remove the rootkit. (all the while the devs are blaming MS of course) Such is life. I wish they'd do that. It'd be messy, but effective.
There are other fun responses to someone rootkitting your os. Make intelligent, targeted updates, that do something like wreck the registration scheme of the rootkitter. Do something that forces the customer to call the vendor for help. Make it such a sever PITA to the developer that they stop doing it.
Or simply target the error message. Imagine this popup once an hour: "Windows has detected the installation of ROOTKIT_SUPERSHOOTER3v4. This software has damaged your Windows installation and compromised the security of your computer and your personal information. Please contact the software vendor SuperCoders (link/phone number) for assistance in repairing your Windows installation, or perform an erase and install to repair the damage." That would rock.
I work for the Department of Redundancy Department.
In the 70s and 80s it was common for games to bypass the operating system and talk directly to the hardware, for copy protection, to prevent cheating, for performance, for all kinds of reasons. Many of them booted directly and completely ignored the OS. Over the years these games were the first to break when new software and hardware came out, and badly behaved games got a bad reputation. Other countries haven't been through the experience of having badly behaved software rot because it couldn't be updated for new systems... yet.
It's a learning experience. They will learn.
...a computer in Japan is just another appliance.
They buy it as they would buy a second TV set for the kitchen, or a vacuum cleaner or table-top cooling fan, etc.
Nobody in his/her right mind care of the stats of a vacuum cleaner, except complete nerds.
Computers are slowly drifting toward that situation.
GSM phone have already reached that point almost worldwide - the only thing most people care is if there's "Apple iPhone" written on it. /. about remote cellphone's mic tapping, remote GPS polling, etc... to show that there slightly more than "what's written on the case" about a phone.
And there are often enough articles on
"Sufficiently advanced satire is indistinguishable from reality." - [Tips: 1DrYakQDKCQ6y52z6QbnkxHXAocMZJE61o ]
It does what I want: No malware. It does not: Malware.
Simple as that. It doesn't depend on technology. A plain vanilla keylogging trojan that phones home is, technically, in no way different than any other web application. Aside of doing what I don't want to happen.
The only essential difference between benign programs and malware is that malware exhibits a behaviour that I, as the owner of the machine and the one who should be calling the shots, do not want to happen.
So a "cheating rootkit" isn't a trojan. It does what the user wants it to do, it disguises from anti-cheat programs, and to do that it has to do the same trojans do to hide from anti-virus programs. Basically, any sensible AV tool is a trojan by that definition. It has to do the same to avoid being kicked offline by a trojan that gets past its initial scan. A lot of today's (real) malware actually does that. They search for AV processes and try to stop them, they try to keep the AV update routine from connecting to the internet and so on. An AV tool that doesn't dig itself into the system won't be able to defeat more creative malware.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
There was an interview/article not too long ago in which Microsoft basically said that UAC was intended to do just that - be really annoying and cause users to bother vendors to code better software. The big flaw in that plan is that most users are A) Don't care (or know) nearly enough to act on that, even if they understood what it was, and B) Microsoft didn't make it expressly clear that that's what it was for (probably to avoid angering third-party vendors) so that the minority of users who do know and care enough can act on it.
Result: it blows up in Microsoft's face and everyone blames them for UAC being an annoying piece of crap which does little nothing to improve security. The fact that it was *supposed* to be an annoying piece of crap that didn't really help with security only makes it worse.
They are a bunch of militaristic and racist bigots.
Right, unlike everyone else.
We Americans are far better than those chinks, we should'v f**k'n killed 'em all the last time we were there!
</sarc>
Botting programs aren't all it is intended to stop. As a matter of fact, botting is not preventable, it can only be limited in power. You could always hook up a device that would give keyboard input, and pass the video through it. What they do a fairly good job of stopping (making very difficult at least) is getting read/write access to the memory, forcing bots to rely on interpreting pixel data, which is rather unreliable, and preventing many hacks that result from those games having bad client/server separation of trust.
For example, the Korean game MapleStory relies on the client to handle lots of the monster positioning: in a given map, every client is responsible for an equal share of monster positions. This means that when you are alone, you could cause your client to lie, and warp all the monster to one spot. It would cost huge amounts to upgrade their infrastructure to handle all that positioning on the server, so they do their best to make the client trusted.
Nowadays, people use CPU virtualization to circumvent such rootkits.