Inevitable, because the sheer popularity of peer-to-peer file sharing means that the potential return for any company successfully commercialising a popular P2P client is enormous.
Implausible, because the indelible association between P2P and piracy means that potential risk of burning out in lawsuits from copyright holders is vast.
The company is also the custodian of two popular Torrent clients: the so-called Mainline version, and its extremely popular compact cousin, uTorrent.
(The character u is commonly, if confusingly, used in Latin alphabets to represent the Greek letter μ. Short for micro, it's pronounced in English as mew, as in cat. So much for internationalisation.)
In its ten-year history, BitTorrent - the protocol, not the company - has become well known for facilitating the unregulated sharing of arbitrary material. Indeed, it's become quite the way to find all the ripped-off software, films, TV shows and porn you might need. Unsuprisingly, the cybercrooks love that sort of neo-anarchic mix, because it makes it easy for them to expose you to your fair share of malware.
Unfortunately, however, even if you are one of the several many entirely law-abiding users of BitTorrent, the folks at BitTorrent, Inc. may recently have put you in harm's way.
According to a really-ought-to-be-more-visible warning on the download pages of www.bittorrent.com and www.utorrent.com, a breach of the two servers resulted in a two-hour window in which downloading BitTorrent's software would have given you a fake anti-virus program instead.
This morning [13 Sep 2011 on the US West Coast] at approximately 4:20 a.m. PT, the uTorrent.com and BitTorrent.com Web servers were compromised. Our standard software download was replaced with a type of fake antivirus "scareware" program.
Just after 6:00 a.m. PT, we took the affected servers offline to neutralize the threat. Our servers are now back online and functioning normally
BitTorrent, Inc. identifies the malware as belonging to the Security Shieldscareware family. Program files under this "brand" of fake anti-virus should be mopped up by Sophos Anti-Virus as CXmal/FakeAV-A.
Confusingly, the BitTorrent blog has recently been updated to claim that the software available from the www.bittorrent.com URI was not affected, implying that only those who downloaded utorrent during the infection window would be at risk.
Since the two sites share the same network infrastructure - both resolve to the same IP number in Limelight Networks' cloud - you might want to ignore that blog update and assume that any recent downloads from Bittorrent, Inc. were dodgy and give yourself a thorough anti-malware checkover.
I'd also ignore the time window, since BitTorrent used the annoyingly ambiguous abbreviation "PT" to denote the timezone. I'm guessing they meant to say UTC-7, but they didn't.
Update. Allison at BitTorrent got in touch to say she's updated the official report to make it clear: Pacific Daylight Time, UTC-7. Thanks for listening, Allison!
No comments:
Post a Comment