Live data from Hacker News

Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

washingtonpost.com

71–80 of 298 posts

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#71

Why would anyone unaffiliated with NSA be alarmed that its tools had been breached? What legitimacy does it have at this point? Serious question.

It's valuable information that can be used to either secure a future favor or serve as a quid pro quo for a previously extended favor.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#72
post #65

Earlier quoted context omitted.

Unfortunately, it does happen here as well(1,2). 1- https://theintercept.com/2017/10/10/recordings-capture-bruta... 2- https://www.theguardian.com/technology/2013/aug/08/lavabit-e... 3- https://en.m.wikipedia.org/wiki/Marvin_Heemeyer

If your company is in Russia, China or the US, and the government in that country has any interest in the data you collect, you will have to give it away. In Russia and China they just do it, in the US it's a matter of "National Security". I'm not sure why this would surprise anyone - maybe because most of us are on the side of the latter.

This is a gross false equivalence.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#73
post #27

It would be really surprising if Kaspersky survived this.

Yeah, and Israel too in Russia. I mean what could happen from here. Even if NSA get evidence that their networks were hacked without doubt, which is a hard thing in itself as there are thousands of vectors and even harder is to say that it had been directly done or funded by Kaspersky, they are likely not going to expose themselves in court. Israel has even bigger reason, considering Kaspersky has at least some relat…

What does that even mean? A "counter-attack to secure themselves"?

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#74
post #14

Earlier quoted context omitted.

Read the original New York Times story, it gives a lot more technical details on the hack than this one[0]. Assuming the Israeli and NYT accounts are to be believed, this was a very deliberate hack. Israel watched in real-time as Kaspersky sent out searches for NSA codename programs on all computers with Kaspersky AV installed (this was related to the whole Duqu 2.0 intrusion into Kaspersky's network that Kaspersky b…

>Assuming the Israeli and NYT accounts are to be believed, An assumption nobody who knows anything about history will make.

This shouldn't be modded down.

Security services are completely unreliable and release these things for their own benefit. The question with this is why are the Israelis pushing this now?

The NYT has a poor record on this stuff as does pretty much everyone.

WMD.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#75

Earlier quoted context omitted.

Unfortunately, it does happen here as well(1,2). 1- https://theintercept.com/2017/10/10/recordings-capture-bruta... 2- https://www.theguardian.com/technology/2013/aug/08/lavabit-e... 3- https://en.m.wikipedia.org/wiki/Marvin_Heemeyer

How is the Lavabit case an instance of the government misusing its power? The government got a court order to monitor the metadata of an account of a user that they had probable cause to link to a crime. (The alleged criminal had already admitted to the crime.) Lavabit had previously complied with search warrants to obtain data for users suspected of dealing in child pornography. https://www.docketalarm.com/cases/Mar…

Well, fair point. My bias may come from the fact that I see NSA domestic surveillance as grossly unconstitutional as well as an undemocratically implemented abuse of state power. I suppose it's useful to ask at what point can the State grant an order that is illegitimate, if this isn't one of those cases? If Putin has a court order drafted to do his dirty work does that make it any more legitimate?

Maybe Snowden broke laws, but every single person breaks some frivolous laws every year of their life that they can be prosecuted for, see The Intercept source I posted on this.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#76
post #34

Kaspersky has been known to collaborate with the Russian government and promote Russian interest. They've actively pursued state actors that are hostile to Russian interest, for example The Equation Group ( https://en.wikipedia.org/wiki/Equation_Group ), which wouldn't be an organic part of the function or activities of a normal civilian cyber-security company. Such an "innocent" company would have no reason to get i…

Way down this thread, so time to ask the question: Do American anti-virus, social media, and search companies do exactly the same, but for the US military? I've always found it suspicious that Russia and China created their own social networks, email providers, and search engines. Almost like they know the power of a capable search engine or social network for intelligence gathering purposes. Google and US anti-virus…

Well there were the Snowden revelations of the PRISM program which apparently had all the major US tech companies onboard. So it’s highly probable.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#77

Earlier quoted context omitted.

What was so bad about Kaspersky that you consider it good riddance? I recall reading about legitimate good security work and breach investigations from them just a few years ago. It's not like anybody forced you to use their software.

The fact that they collaborate with the Russian gov't secret services.

You mean you can't even stand their mere existence even without ever actually touching any of their products? Note that I'm not asking why you're not installing their antivirus, I'm asking why you don't want them to exist...

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#78
post #69
post #65

Earlier quoted context omitted.

If your company is in Russia, China or the US, and the government in that country has any interest in the data you collect, you will have to give it away. In Russia and China they just do it, in the US it's a matter of "National Security". I'm not sure why this would surprise anyone - maybe because most of us are on the side of the latter.

Russian and China coercion are on a completely different scale, and we all know it. Especially after the Snowden backlash. Imagine any major Chinese IT company pushing back against government requests like Dreamhost did. Even the biggest ones can't/won't. It helps that the government is a huge investor in most of them, of course. "Chinese IT company rebuffs government demand for user information on its website". This…

A lot of that is because Russia and China don't feel very secure compared to the US for various historical/geopolitical reasons. The US govt is known to act ruthlessly when it feels there's an existential threat.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#79
post #59

Israel (Mossad?) can hack something in Russia, see tools and recognise those tools as top secret NSA gear. Do you wonder how they made that recognition? Were they shared with Israel so they knew, in which case the source could have been Israel being hacked, right? Or they knew because hacking the NSA is something multiple nation states have done. I'd be completely amazed if the NSA wasn't absolutely full of spies act…

Governments never fire spies. They move them to reserve and pay them good pensions.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#80
post #34

Kaspersky has been known to collaborate with the Russian government and promote Russian interest. They've actively pursued state actors that are hostile to Russian interest, for example The Equation Group ( https://en.wikipedia.org/wiki/Equation_Group ), which wouldn't be an organic part of the function or activities of a normal civilian cyber-security company. Such an "innocent" company would have no reason to get i…

> Kaspersky has [...] actively pursued state actors that are hostile to Russian interest, for example The Equation Group (https://en.wikipedia.org/wiki/Equation_Group), which wouldn't be an organic part of the function or activities of a normal civilian cyber-security company.

According to that Wikipedia page, The Equation Group refers to "a collection of tools used for hacking". Targeting hacking tools seems to me exactly what a security software company should be doing.

>Such an "innocent" company would have no reason to get involved in cyberwarfare between state-actors, while Kaspersky is heavily involved in such activities and pouring considerable resources into them.

Even if we assume these tools can only target governments and not businesses or individuals, perhaps Kaspersky wishes to obtain contracts with the governments targeted. I don't see how this is particularly sinister or illegitimate.

> This is especially damning since they are clearly targeting state-actors that are antagonistic to Russian interest, such as the US (Equation Group) and its allies (Israel)

Your Wikipedia link states: "The Shadow Brokers announced that it had stolen malware code from the Equation Group [...] Exploits against Cisco Adaptive Security Appliances and Fortinet's firewalls were featured in some malware samples released by The Shadow Brokers [...] Juniper also confirmed that its NetScreen firewalls were affected. The EternalBlue exploit was used to conduct the damaging worldwide WannaCry ransomware attack."

Three American companies and vast numbers of individual users and civil government institutions around the world (including the UK Health Service). Are they all Russian interests?

Post reply on HN