logoalt Hacker News

daemonhuntertoday at 3:00 AM3 repliesview on HN

So what mitigations should the end user be doing? How do we know if anything compromised?


Replies

avereveardtoday at 3:11 AM

Right the writeup doesn't mention when it started and what versions are affected

show 2 replies
kijintoday at 3:22 AM

Download the latest version and install that, instead of using the auto update feature of an old version that might not properly check signatures.

As for whether anything else has been compromised, it depends on whether you were targeted. And the payload might have been tailored to each target, so there's no way to know unless you have access to the exact binary. Unfortunately, binaries downloaded through the auto update feature tend not to linger in your Downloads folder.

username223today at 4:12 AM

Disable auto-updates, just like you should with every piece of software on your machine. This was the result of letting other people silently replace your programs. Don't allow that.

show 1 reply