The Register Home Page

back to article VirusTotal: We're sorry someone fat-fingered and exposed 5,600 users

VirusTotal today issued a mea culpa, saying a blunder earlier this week by one of its staff exposed information belonging to 5,600 customers, including the email addresses of US Cyber Command, FBI, and NSA employees. The unintentional leak was due to the layer-eight problem; human error. On June 29, an employee accidentally …

  1. Anonymous Coward
    Anonymous Coward

    False sense of security

    VirusTotal may have some use cases. But from my experience for phishing and scam sites the detection rate is near zero. Not sure about malware.

    1. sitta_europea

      Re: False sense of security

      "VirusTotal may have some use cases. But from my experience for phishing and scam sites the detection rate is near zero. Not sure about malware."

      I hear what you're saying about the false sense of security which could perhaps represent a danger. I'm sure I've seen evidence for it but it would only be anecdotal so I'll say no more about that.

      The threat profile from emails arriving here might not be typical, but I can share some of my experience, which is long and well documented.

      I'm unable to comment on VirusTotal's (email) phishing and scam site detection performance because I haven't measured it, but I'd say it's pretty good for malware.

      My milters, using a few simple Yara rules, routinely catch malware in email which multiple commercial and free virus scanners fail to identify. I have records for the last four hundred or so samples and about fifteen scanners courtesy of Jotti's Virus Scan. When I submit samples using our homebrew API to Jotti, very few threats are missed by all the scanners but the norm is for most of them to miss most threats. If I submit the threats (manually) to VirusTotal, the percentage of threats missed by all of the more than seventy scanners that they use is negligible, but again many of them seem to miss most threats.

      You simply cannot rely on scanners alone. If you do, you are going to be compromised.

      HTH

    2. NoneSuch Silver badge
      Boffin

      Re: False sense of security

      "VirusTotal may have some use cases. But from my experience for phishing and scam sites the detection rate is near zero. Not sure about malware."

      No one should rely on a single source for protection. VirusTotal (and any other service you care to name) is no where near to being perfect. The best solution is to use a multi-layer protection system of multiple software scanners with firewalls, internal threat scanners and employing people who know how to intelligently interpret the results.

    3. Kurgan Silver badge

      Re: False sense of security

      Virustotal is a system made of imperfect tools. Every antivirus program is an imperfect tool. The sum is a somehow less imperfect tool.

      I use it a lot, and if the results show that it's malware, then usually it actually is malware. If the result comes out clean, then it's definitely NOT CLEAN. It usually means that no antivirus software gets that pattern right.

      Still it's a useful check. Just don't trust it blindly if the result is "clean".

      1. Anonymous Coward
        Anonymous Coward

        Re: False sense of security

        Anti virus engines have 2 modes of operation traditionally.

        Signature matches

        Heuristics

        The latter can generate false positives.

        I’ve had malware infested files given the clean bill of health by virustotal only to scan that same binary 10 years later and it has a trojan, an actual signature match so not a false positive.

        The reality is, ask yourself this, what exactly IS malware

        Clue, it’s malicious software

        So basically all modern software is malware because it rarely acts in the end users interest.

        Windows 10 is malware

        Windows defender is great at finding keygens, but not so good at detecting actual malware

  2. Anonymous Coward
    Anonymous Coward

    Surprise, surprise, surprise........

    (1) Google................what a surprise!!!

    (2) Then there's this from last year......amazing!! Link: https://isc.sans.edu/diary/Credentials+Leaks+on+VirusTotal/28426

  3. Terry 6 Silver badge

    "not the result of a security breach or vulnerability"

    Err, so a staff member being able to make a file of data available isn't just that?

    It doesn't have to be an outside baddie to make it a security breach.

  4. John Brown (no body) Silver badge

    Compensation for the victims?

    I'm all those spooks will be happy with a complimentary one year subscription to some random "identity protection" service :-)

  5. Ian Johnston Silver badge

    Why does this matter, exactly?

    1. Roland6 Silver badge

      A reminder that even bright people can do daft things.

      Given what we know, would not be surprised if the person at the centre of this simply “went on autopilot” and checked the file (as per good practise) before forwarding it to someone else.

      Would not be surprised, if as a result of this, Virustotal sees an increase in the number of users “inspecting” files others have uploaded.

  6. Anonymous Coward
    Anonymous Coward

    You check some

    You lose some…

  7. Anonymous Coward
    Anonymous Coward

    CSV files are plaintext

    I fail to understand these cretins, or how their smoothbrains work.

    Anybody up to the challenge of explaining them?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like