April 7, 2015 By Shane Schick 2 min read

BitTorrent has rarely been considered the gold standard in protecting corporate data, but a recently discovered BitTorrent vulnerability may raise fresh concerns about the overall security of peer-to-peer sharing services.

First disclosed via an advisory from HP’s Zero-Day Initiative, the BitTorrent vulnerability involves a problem in Sync, which is a way of connecting smartphones and tablets used by workers in the field with PCs or workstations back at an office, for example. A researcher discovered that a cybercriminal could theoretically pose as a legitimate user of executive code if the legitimate user were to click on a link labeled with the bitsync: protocol after visiting a malware-laden Web page. Given the volume of phishing schemes that seem to happen every day, this presumably wouldn’t be difficult to do.

As a story on SecurityWeek noted, the potential danger was originally found late last year, and BitTorrent has reportedly already fixed it. However, the company may still need to clarify which kind of upgrades — if any — current Sync owners need to make.

It is worth pointing out that Sync only recently came out of beta. In its coverage last month, TechCrunch noted that the stakes are high to compete with similar file-sharing services such as Microsoft OneDrive, Google Drive and Dropbox. That means any BitTorrent vulnerability needs to be dealt with as quickly and as publicly as possible to reassure nervous CSOs that their organizations can experiment with new, emerging services such as Sync without putting their sensitive data at risk.

Unfortunately, in this case, BitTorrent might have a lot of persuading to do. Back in November, a group called Hackito Ergo Sum posted a detailed analysis of Sync’s potential security issues. According to Network World at the time, the findings suggested BitTorrent Sync’s “built for trust” motto should not be believed by businesses.

Plus, a piece on the The Next Web said the whole premise of Sync is that it offers a more reassuring system for file management than putting them in the cloud, an approach that has become controversial after hacking incidents involving Apple’s iCloud and other services.

On the other hand, BitTorrent has posted on its own blog that it has had Sync reviewed by third parties such as iSEC Partners, which showed the service was safe from a variety of possible cybercriminal threats. That kind of validation could come particularly in handy now that it is trying to offer a paid version of its service — at least as long as another BitTorrent vulnerability doesn’t rear its head in the near future.

More from

Unpacking the NIST cybersecurity framework 2.0

4 min read - The NIST cybersecurity framework (CSF) helps organizations improve risk management using common language that focuses on business drivers to enhance cybersecurity.NIST CSF 1.0 was released in February 2014, and version 1.1 in April 2018. In February 2024, NIST released its newest CSF iteration: 2.0. The journey to CSF 2.0 began with a request for information (RFI) in February 2022. Over the next two years, NIST engaged the cybersecurity community through analysis, workshops, comments and draft revision to refine existing standards…

What should Security Operations teams take away from the IBM X-Force 2024 Threat Intelligence Index?

3 min read - The IBM X-Force 2024 Threat Intelligence Index has been released. The headlines are in and among them are the fact that a global identity crisis is emerging. X-Force noted a 71% increase year-to-year in attacks using valid credentials.In this blog post, I’ll explore three cybersecurity recommendations from the Threat Intelligence Index, and define a checklist your Security Operations Center (SOC) should consider as you help your organization manage identity risk.The report identified six action items:Remove identity silosReduce the risk of…

Obtaining security clearance: Hurdles and requirements

3 min read - As security moves closer to the top of the operational priority list for private and public organizations, needing to obtain a security clearance for jobs is more commonplace. Security clearance is a prerequisite for a wide range of roles, especially those related to national security and defense.Obtaining that clearance, however, is far from simple. The process often involves scrutinizing one’s background, financial history and even personal character. Let’s briefly explore some of the hurdles, expectations and requirements of obtaining a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today