[HN Gopher] Malloc (YC S21) takes on mobile spyware
___________________________________________________________________
Malloc (YC S21) takes on mobile spyware
Author : Phithagoras
Score : 16 points
Date : 2021-09-28 05:12 UTC (17 hours ago)
(HTM) web link (techcrunch.com)
(TXT) w3m dump (techcrunch.com)
| amelius wrote:
| Cat and mouse in an asymmetrical playing field. The problem is
| that the bad guys can use this app to fine-tune their malware.
| asveikau wrote:
| I think this is the category of comment that I've seen downvoted
| in the past, but it needs to be said:
|
| I wouldn't name a company "malloc".
|
| The meaning is very specific, its usage well established and old,
| and it would seem to me this company has nothing to do with it
| and shouldn't claim the name.
| Zababa wrote:
| I feel the same. I don't like when companies use a word that
| already exists.
| asveikau wrote:
| I think a word that already exists is probably fine a lot of
| the time. But an _unrelated technical term_ with a 50+ year
| history...
| Zababa wrote:
| You're right, that's a better way to put it.
| md_ wrote:
| > The rising threat of spyware has prompted both Apple and Google
| to introduce indicators when a device's microphone or camera are
| used. But some of the more elusive and more capable spyware --
| the spyware typically used by governments and nation states --
| can slip past the hardened defenses built into iOS and Android.
|
| > That's where Malloc says Antistalker comes in. Malloc's co-
| founders Maria Terzi, Artemis Kontou and Liza Charalambous built
| the app around a machine learning (ML) model, which allows the
| app to detect and block device activity that could be construed
| as spyware recording or sending data.
|
| That's a bit of a non sequitur, right?
|
| If sophisticated malware is bypassing the OS-level "open mic"
| warning, that's presumably because it's bypassed the OS security
| model. As such, it should just as easily be able to avoid
| detection or simply disable any other detection mechanism, ML-
| driven or otherwise.
|
| (If the issue is sophisticated malware that does _not_ involve
| privilege escalation, e.g. by executing code inside the sandbox
| of a trusted app, I could see how an improved detection approach
| would help, but e.g. NSO and similar tend to use sandbox escapes
| + privesc, AFAIK.)
| motohagiography wrote:
| Threat model is the business model on this. Notable that the
| founders are women, and though it shouldn't be remarkable at all,
| and perhaps it's sexist to speculate they're going to leverage
| that, but it's a useful indicator because antistalker tech by/for
| women is an influencer channel for other products. They're a
| consumer app company and gender doesn't matter to the tech
| itself, except from a product perspective, it's really a
| potential advantage in this case.
|
| The generic threat model for most security tools (which, suck)
| has been the individual vs. the state or various generic
| criminals, whereas the threat actor in a mostly feminine threat
| model would be the much higher likelihood/impact scenario of
| stalkers, who are as likely to be co-workers and IT admins as
| they are classmates, neighbours, or internet followers. Few want
| to even say this out loud because just verbalizing it is off-
| brand and comes with an ick factor. Hence no good products for
| it, yet. Stalkers get away with it because acknowledging them as
| part of your story at all elevates them to the level of peer or
| factor, and so the product discussion itself is often too gross
| to want to get into.
|
| Solving for that is technically much more focused and useful from
| a secuirty perspective than say, taking on the universe of bad
| cops and spies. Plus, women are more likely to leverage recourse
| to law enforcement (instead of physically beating a stalker), and
| so security tech that has to be designed to keep out a nation
| state to get security influencer adoption isn't helping most of
| them.
|
| Nobody in the security companies I worked for wanted to talk
| about these issues seriously because of the ick factor and a
| bunch of nerdy white knights diverting all uncomfortable
| discussions to blockchains, but it's also what creates the
| opportunity. This seems like a really smart play.
| SanthoshAditya wrote:
| Hey, I am new to this site. I want to talk to you. How can I
| send you a message?
| newbamboo wrote:
| This is great but I think we're heading towards a world where we
| just have to assume our devices are compromised. Maybe I'm alone
| in that, but I feel like it's only a matter of time before we all
| get there.
| thatfunkymunki wrote:
| if your security people are not doing this already, they are
| decades behind the curve.
| btheshoe wrote:
| While this is very cool and I hope it succeeds, I find myself
| worried that Malloc's dependence on ML makes it extremely
| vulnerable to adversarial attacks.
|
| Though at the same time, it's probably much harder to change
| software behavior than it is to modify a bunch of pixels on a
| photo, so it might be hard to do adversarial attacks with
| spyware. I wonder if there's research on stuff like this.
| IgorPartola wrote:
| This reminds me so much of the Angel problem:
| https://en.m.wikipedia.org/wiki/Angel_problem
___________________________________________________________________
(page generated 2021-09-28 23:02 UTC)