April 7, 2015 By Shane Schick 2 min read

BitTorrent has rarely been considered the gold standard in protecting corporate data, but a recently discovered BitTorrent vulnerability may raise fresh concerns about the overall security of peer-to-peer sharing services.

First disclosed via an advisory from HP’s Zero-Day Initiative, the BitTorrent vulnerability involves a problem in Sync, which is a way of connecting smartphones and tablets used by workers in the field with PCs or workstations back at an office, for example. A researcher discovered that a cybercriminal could theoretically pose as a legitimate user of executive code if the legitimate user were to click on a link labeled with the bitsync: protocol after visiting a malware-laden Web page. Given the volume of phishing schemes that seem to happen every day, this presumably wouldn’t be difficult to do.

As a story on SecurityWeek noted, the potential danger was originally found late last year, and BitTorrent has reportedly already fixed it. However, the company may still need to clarify which kind of upgrades — if any — current Sync owners need to make.

It is worth pointing out that Sync only recently came out of beta. In its coverage last month, TechCrunch noted that the stakes are high to compete with similar file-sharing services such as Microsoft OneDrive, Google Drive and Dropbox. That means any BitTorrent vulnerability needs to be dealt with as quickly and as publicly as possible to reassure nervous CSOs that their organizations can experiment with new, emerging services such as Sync without putting their sensitive data at risk.

Unfortunately, in this case, BitTorrent might have a lot of persuading to do. Back in November, a group called Hackito Ergo Sum posted a detailed analysis of Sync’s potential security issues. According to Network World at the time, the findings suggested BitTorrent Sync’s “built for trust” motto should not be believed by businesses.

Plus, a piece on the The Next Web said the whole premise of Sync is that it offers a more reassuring system for file management than putting them in the cloud, an approach that has become controversial after hacking incidents involving Apple’s iCloud and other services.

On the other hand, BitTorrent has posted on its own blog that it has had Sync reviewed by third parties such as iSEC Partners, which showed the service was safe from a variety of possible cybercriminal threats. That kind of validation could come particularly in handy now that it is trying to offer a paid version of its service — at least as long as another BitTorrent vulnerability doesn’t rear its head in the near future.

More from

CISA adds Microsoft SharePoint vulnerability to the KEV Catalog

3 min read - In late October, the United States Cybersecurity & Infrastructure Security Agency (CISA) added a new threat to its Known Exploited Vulnerability (KEV) Catalog. Cyber criminals used remote code execution vulnerability in Microsoft SharePoint to gain access to organizations’ networks. The CISA press release states that “these types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.” However, Microsoft identified and released a patch for this vulnerability in July 2024. Cybersecurity experts…

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today