TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

The Advanced Persistent Threat You Have: Google Chrome [pdf]

42 点作者 epsylon超过 9 年前

8 条评论

skybrian超过 9 年前
This seems like a good paper that isn't actually about something wrong with Chrome. It's about what security tools need to do to track auto-updating software.
epsylon超过 9 年前
&quot;Making of&quot; paper is here: <a href="http:&#x2F;&#x2F;www.netsq.com&#x2F;Documents&#x2F;MakingOfGoogleAPT.pdf" rel="nofollow">http:&#x2F;&#x2F;www.netsq.com&#x2F;Documents&#x2F;MakingOfGoogleAPT.pdf</a>
dkokelley超过 9 年前
I found the paper very eye-opening, but perhaps I missed the &quot;moral&quot; of the story. I understand that Google&#x27;s auto updater can behave similarly to a malicious utility by an APT, but what recourse or mitigation techniques are available? According to the paper, each step individually is indistinguishable from benign activity. Techniques for identifying the end result of the activity and flagging it as suspicious are omitted (or perhaps I missed them).
sjg007超过 9 年前
Presumably Chrome and its updater are digitally signed... not that that stops malware but at least it is another layer.
RachelF超过 9 年前
Others are dumping Chrome for similar reasons: <a href="http:&#x2F;&#x2F;www.extremetech.com&#x2F;computing&#x2F;210576-why-im-dumping-google-chrome" rel="nofollow">http:&#x2F;&#x2F;www.extremetech.com&#x2F;computing&#x2F;210576-why-im-dumping-g...</a>
irickt超过 9 年前
The paper is dated 18-Apr-2012
NickHaflinger超过 9 年前
total FUD .. nothing gets updated here unless I want it to. And why isn&#x27;t the Microsoft software updater or your AV updater considered an equal threat. Who paid for this &#x27;study&#x27;.
xpaulbettsx超过 9 年前
I can&#x27;t read through the pages and pages of grandstanding in this PDF, does this at all have some sort of escape of a security boundary, or is it just &quot;I found a weird way to hack myself&quot;?
评论 #10125161 未加载
评论 #10126170 未加载