https://www.tomsguide.com/us/kaspersky-hack-israel-nsa,news-...
Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached
11–20 of 298 posts
Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached
#12Kaspersky should spin this into an ad campaign on how their machine learning malware A.I uncovered secret NSA malware and uploaded the files for analysis, thus, preventing another Stuxnet/Olympic Games outbreak.
Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached
#13Earlier quoted context omitted.
They probably didn't hack anything, they just have people who receive these AV samples as malware researchers. Any intelligence agency worth their money should. And yes, this is the gist of what's behind all the Kaspersky hysteria. The NSA trying to obscure another extremely embarrassing leak. Every AV software uploads new detections for analysis. It just so happened that this fool used Kaspersky. It's abundantly cle…
Basically. I've seen what now looks like state sponsored bullshit blogs posing as tin foil hatters being posted to HN saying Kaspersky is part of the Russian intelligence apparatus, and that's why the US government pressured stores to remove Kaspersky AV from store shelves, etc etc etc. Most likely, they did their job, and they did it correctly. The NSA can't really defeat competent AV researchers who aren't even loo…
https://www.dhs.gov/news/2017/09/13/dhs-statement-issuance-b...
> The Department is concerned about the ties between certain Kaspersky officials and Russian intelligence and other government agencies, and requirements under Russian law that allow Russian intelligence agencies to request or compel assistance from Kaspersky and to intercept communications transiting Russian networks. The risk that the Russian government, whether acting on its own or in collaboration with Kaspersky, could capitalize on access provided by Kaspersky products to compromise federal information and information systems directly implicates U.S. national security.
Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached
#14So, if I understand this right... some NSA TAO employee was doing work on their home computer (???), where they installed Kaspersky AV (reasonable), and Kaspersky promptly identified the malware they were working on as malware and uploaded it? And then Israel hacked Kaspersky 'cause that's what they do or something, found the NSA development malware, and was like "Hey NSA, you should figure out how this got here"? Th…
They probably didn't hack anything, they just have people who receive these AV samples as malware researchers. Any intelligence agency worth their money should. And yes, this is the gist of what's behind all the Kaspersky hysteria. The NSA trying to obscure another extremely embarrassing leak. Every AV software uploads new detections for analysis. It just so happened that this fool used Kaspersky. It's abundantly cle…
That said, it's still extremely embarrassing. Why is someone from TAO taking this kind of work home?
0. https://www.nytimes.com/2017/10/10/technology/kaspersky-lab-...
Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached
#15So, if I understand this right... some NSA TAO employee was doing work on their home computer (???), where they installed Kaspersky AV (reasonable), and Kaspersky promptly identified the malware they were working on as malware and uploaded it? And then Israel hacked Kaspersky 'cause that's what they do or something, found the NSA development malware, and was like "Hey NSA, you should figure out how this got here"? Th…
>Kaspersky promptly identified the malware they were working on as malware and uploaded it? If the news story is to be believed, Kaspersky was scanning for classified data using US intelligence codewords as a selector. >I'm sort of surprised Kaspersky had servers vulnerable to Israel I'm not, everyone's servers are vulnerable. Intelligence agencies can buy exploits. If they want in, they get in. >but I'm really surpr…
Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached
#16Earlier quoted context omitted.
Basically. I've seen what now looks like state sponsored bullshit blogs posing as tin foil hatters being posted to HN saying Kaspersky is part of the Russian intelligence apparatus, and that's why the US government pressured stores to remove Kaspersky AV from store shelves, etc etc etc. Most likely, they did their job, and they did it correctly. The NSA can't really defeat competent AV researchers who aren't even loo…
The DHS is "tin foil hatters"? https://www.dhs.gov/news/2017/09/13/dhs-statement-issuance-b... > The Department is concerned about the ties between certain Kaspersky officials and Russian intelligence and other government agencies, and requirements under Russian law that allow Russian intelligence agencies to request or compel assistance from Kaspersky and to intercept communications transiting Russian networks. The…
Yes?
To be fair, that is kind of their job. I don't suppose their precept says that they should be paranoid and believing in conspiracy theories - in those exact words. But, that seems to be how it is manifest.
Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached
#17So, if I understand this right... some NSA TAO employee was doing work on their home computer (???), where they installed Kaspersky AV (reasonable), and Kaspersky promptly identified the malware they were working on as malware and uploaded it? And then Israel hacked Kaspersky 'cause that's what they do or something, found the NSA development malware, and was like "Hey NSA, you should figure out how this got here"? Th…
>Kaspersky promptly identified the malware they were working on as malware and uploaded it? If the news story is to be believed, Kaspersky was scanning for classified data using US intelligence codewords as a selector. >I'm sort of surprised Kaspersky had servers vulnerable to Israel I'm not, everyone's servers are vulnerable. Intelligence agencies can buy exploits. If they want in, they get in. >but I'm really surpr…
Assuming you mean the linked article, it doesn’t say that. It says that Kaspersky uses “silent signatures”, which are supposed to be indicators of malware, but could hypothetically be adapted to search for classified data instead. But it doesn’t allege Kaspersky was actually doing that.
(edit2: But the NYT report [2] does seem to allege that! This reporting is such a mess…)
Apparently, silent signatures are a technique to test new signatures where instead of blocking files with the signature, the AV reports the finding back to a server, allowing the vendor to identify false positives before fully deploying the signature. The question is what exactly Kaspersky is/was reporting to their server. I googled ‘silent signature’ and found a patent [1], issued to Kaspersky, which describes sending only hashes of the executable with the signature. But this article seems to suggest that they were sending the executable in full - at least if the leak of NSA tools occurred via that mechanism. (The article doesn’t say it did, but it sounds like a plausible route for a customer’s executable to find its way to Kaspersky’s network.) If this is the case, it sounds extremely troubling from a privacy perspective even without any intelligence services getting involved.
edit: Actually, I think the body of the patent does disclose sending the whole file to a server, which isn’t mentioned in the summary. The text is a little vague, though.
> If no threat is detected in step 720, statistics regarding the executable file and the frequency of launches of the executable file are collected in step 740. Then, in step 750, the file is downloaded and sent for a further analysis in step 760. After the analysis, either a white list or black list can be updated with a signature of this executable file.
[1] https://www.google.com/patents/US20110126286
[2] https://www.nytimes.com/2017/10/10/technology/kaspersky-lab-...
Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached
#18Earlier quoted context omitted.
>Kaspersky promptly identified the malware they were working on as malware and uploaded it? If the news story is to be believed, Kaspersky was scanning for classified data using US intelligence codewords as a selector. >I'm sort of surprised Kaspersky had servers vulnerable to Israel I'm not, everyone's servers are vulnerable. Intelligence agencies can buy exploits. If they want in, they get in. >but I'm really surpr…
> If the news story is to be believed, Kaspersky was scanning for classified data using US intelligence codewords as a selector. Assuming you mean the linked article, it doesn’t say that. It says that Kaspersky uses “silent signatures”, which are supposed to be indicators of malware, but could hypothetically be adapted to search for classified data instead. But it doesn’t allege Kaspersky was actually doing that. (ed…
It's from the original NY Times article, which is linked to from the WP article.
Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached
#19Earlier quoted context omitted.
They probably didn't hack anything, they just have people who receive these AV samples as malware researchers. Any intelligence agency worth their money should. And yes, this is the gist of what's behind all the Kaspersky hysteria. The NSA trying to obscure another extremely embarrassing leak. Every AV software uploads new detections for analysis. It just so happened that this fool used Kaspersky. It's abundantly cle…
Read the original New York Times story, it gives a lot more technical details on the hack than this one[0]. Assuming the Israeli and NYT accounts are to be believed, this was a very deliberate hack. Israel watched in real-time as Kaspersky sent out searches for NSA codename programs on all computers with Kaspersky AV installed (this was related to the whole Duqu 2.0 intrusion into Kaspersky's network that Kaspersky b…
An assumption nobody who knows anything about history will make.
Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached
#20Kaspersky should spin this into an ad campaign on how their machine learning malware A.I uncovered secret NSA malware and uploaded the files for analysis, thus, preventing another Stuxnet/Olympic Games outbreak.
There's no realistic spin for Kaspersky for anyone who wants to protect their data from the Russian government. True or not, the reputational damage is complete.
The Israelis seem to be able to poke around on other people's servers whenever they want....