Live data from Hacker News

Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

washingtonpost.com

51–60 of 298 posts

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#51
post #45

At this point you just assume that any sufficiently large company based in Russia with capabilities of misusing their power in a way to profit Russian state government will be coerced into doing so or go out of business at some point. Russian thugs have no issues applying pressure till the victim collapses or agrees to cooperate even against their interests. I lived in Russia for 25 years and I saw that happen many t…

Unfortunately, it does happen here as well(1,2).

1-https://theintercept.com/2017/10/10/recordings-capture-bruta... 2-https://www.theguardian.com/technology/2013/aug/08/lavabit-e... 3-https://en.m.wikipedia.org/wiki/Marvin_Heemeyer

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#52
post #4
post #2

So, if I understand this right... some NSA TAO employee was doing work on their home computer (???), where they installed Kaspersky AV (reasonable), and Kaspersky promptly identified the malware they were working on as malware and uploaded it? And then Israel hacked Kaspersky 'cause that's what they do or something, found the NSA development malware, and was like "Hey NSA, you should figure out how this got here"? Th…

Perhaps he was doing the bidding of his employers in order to test a theory that Kaspersky was an attack vector? I mean, this is exactly how you tell if your data has been breached or your source code leaked -- you put fake but unique records in your database then watch the dark webs for folks selling dumps containing those values; and plausible but bogus code containing unique constants then check competitors' binar…

Real data works too.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#54
post #46

Earlier quoted context omitted.

Tell that to McAfee

What about McAfee? He divested from the software/company shortly after it was created. He has a colorful personal life, but I doubt that has much of anything to do with the software that he hasn't been involved with for a around 2 decades. (Other than the software made him rich/a minor celebrity.)

> He has a colorful personal life

I think the gp was referring to what accusations people have made of McAfee since he sold the company.

Showtime aired up a documentary[1] about him. I think "colorful personal life" can only be interpreted as a euphemism since he was accused of murder, rape, running a local armed gang, fleeing the country from the police, etc.

I have no reason to believe Kaspersky will have similar issues as I suspect McAfee was eccentric from the start.

[1] http://www.sho.com/titles/3437264/gringo-the-dangerous-life-...

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#55
post #17

Earlier quoted context omitted.

>Kaspersky promptly identified the malware they were working on as malware and uploaded it? If the news story is to be believed, Kaspersky was scanning for classified data using US intelligence codewords as a selector. >I'm sort of surprised Kaspersky had servers vulnerable to Israel I'm not, everyone's servers are vulnerable. Intelligence agencies can buy exploits. If they want in, they get in. >but I'm really surpr…

> If the news story is to be believed, Kaspersky was scanning for classified data using US intelligence codewords as a selector. Assuming you mean the linked article, it doesn’t say that. It says that Kaspersky uses “silent signatures”, which are supposed to be indicators of malware, but could hypothetically be adapted to search for classified data instead. But it doesn’t allege Kaspersky was actually doing that. (ed…

> But this article seems to suggest that they were sending the executable in full

It doesn't necessarily need to be an executable.

Imagine this filter:

- File type: .docx

- Silent Signature: "TOP SECRET//COMINT//NOFORN"

That means all word documents with:

- the "top secret" classification

- in the "Special Intelligence(ComInt)" area

- marked as "No Foreign Nationals"

will automatically be sent back to servers for review.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#56
post #46

Earlier quoted context omitted.

What about McAfee? He divested from the software/company shortly after it was created. He has a colorful personal life, but I doubt that has much of anything to do with the software that he hasn't been involved with for a around 2 decades. (Other than the software made him rich/a minor celebrity.)

> He has a colorful personal life I think the gp was referring to what accusations people have made of McAfee since he sold the company. Showtime aired up a documentary[1] about him. I think "colorful personal life" can only be interpreted as a euphemism since he was accused of murder, rape, running a local armed gang, fleeing the country from the police, etc. I have no reason to believe Kaspersky will have similar i…

He also ran for POTUS as a Libertarian.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#57
post #31

Earlier quoted context omitted.

Do you mean the company or the man?

The company. The man will be fine.

In the case of McAfee, the man and company both have terrible reputations. And quite frankly deserve them

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#58
post #45

At this point you just assume that any sufficiently large company based in Russia with capabilities of misusing their power in a way to profit Russian state government will be coerced into doing so or go out of business at some point. Russian thugs have no issues applying pressure till the victim collapses or agrees to cooperate even against their interests. I lived in Russia for 25 years and I saw that happen many t…

Unfortunately, it does happen here as well(1,2). 1- https://theintercept.com/2017/10/10/recordings-capture-bruta... 2- https://www.theguardian.com/technology/2013/aug/08/lavabit-e... 3- https://en.m.wikipedia.org/wiki/Marvin_Heemeyer

How is the Lavabit case an instance of the government misusing its power? The government got a court order to monitor the metadata of an account of a user that they had probable cause to link to a crime. (The alleged criminal had already admitted to the crime.)

Lavabit had previously complied with search warrants to obtain data for users suspected of dealing in child pornography. https://www.docketalarm.com/cases/Maryland_District_Court/1-...

When Lavabit delayed implementing the monitoring they had agreed to, losing forever the ability to collect data generated during that time, only then did the government effectively put them out of business.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#59
Israel (Mossad?) can hack something in Russia, see tools and recognise those tools as top secret NSA gear. Do you wonder how they made that recognition? Were they shared with Israel so they knew, in which case the source could have been Israel being hacked, right? Or they knew because hacking the NSA is something multiple nation states have done. I'd be completely amazed if the NSA wasn't absolutely full of spies acting for foreign powers and organised crime.

At this point should you just fire everybody in the NSA and start again? If not, why not? I'm struggling to see genuine competence in improving the security of Americans amongst the constitutional attacks on the citizenry, attacks which most definitely have the opposite effect.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#60
post #43

Earlier quoted context omitted.

"Israeli government hackers saw something suspicious in the computers of a Moscow-based cybersecurity firm: hacking tools that could only have come from the National Security Agency". The Israelis seem to be able to poke around on other people's servers whenever they want....

I think that is the message being missed. They are poking around American servers as well. Future problem I guess.

[deleted]
Post reply on HN