this post was submitted on 08 Nov 2023
102 points (86.4% liked)

Technology

58303 readers
12 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

Hackers have reportedly found a way to use the Google Calendar as command & control (C2) infrastructure which could create quite a few headaches in the cybersecurity community.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] -1 points 1 year ago (2 children)

When was anything made by Google safe?

[–] [email protected] 7 points 1 year ago (1 children)

They are encoding commands in calendar events there is not a vulnerability in Google calendar. After your device is compromised its commanded to subscribe to a calendar. Those events have commands. Since checking your calendar is a normal event unlike connecting to a nefarious server it becomes more difficult to discover.

[–] [email protected] 1 points 1 year ago

Is it? Everything is in their cloud. You’d think since they have all the data they might check it for malicious activity. I guess that’s not much of a priority for them because it’s hard to tell what’s malicious and what’s “Google”

[–] [email protected] 1 points 1 year ago (1 children)

I've always thought Chromebooks are pretty secure

[–] [email protected] 0 points 1 year ago (2 children)
[–] [email protected] 3 points 1 year ago

Can’t run viruses if you can’t run anything /s

[–] [email protected] 1 points 1 year ago (1 children)

I mean security through obscurity is a real thing. It's not real security, but the risk of attack is still lower than it would be otherwise. It's the primary reason Macs had so little malware at the time and Apple's marketing leveraged that for billions in advertising. Generally malware creators target the maximum number of devices, and MacOS and ChromeOS are small pickles compared to Windows. Even now, you're looking at Windows being about 70% of the market, OSX being around 20% and Chrome OS sitting at a whopping 4%. Most malware is based around striking as many victims as possible quickly before it is discovered and the exploits patched. doesn't matter.

[–] [email protected] 0 points 1 year ago

Well, a significant portion of windows users aren’t running the latest version. Heck, you can hardly get people to install a security update on windows.

ChromeOS doesn’t really need a virus anyway because the whole OS is leaking your info back to Google anyhow.