Live data from Hacker News

Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

washingtonpost.com

81–90 of 298 posts

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#81
post #2

So, if I understand this right... some NSA TAO employee was doing work on their home computer (???), where they installed Kaspersky AV (reasonable), and Kaspersky promptly identified the malware they were working on as malware and uploaded it? And then Israel hacked Kaspersky 'cause that's what they do or something, found the NSA development malware, and was like "Hey NSA, you should figure out how this got here"? Th…

I can think of at least 1 reason why Israel would hack Kaspersky... https://en.wikipedia.org/wiki/Stuxnet#Discovery

>>I can think of at least 1 reason why Israel would hack Kaspersky...

Reason 4512F : Hamas leader uses Kasperky

and so on and on. AVs are in tens of millions of computers and have "license" to go looking for files, to take files out of the computer (talk back to the server) and firewalls let them through because you installed it. What more can you want?

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#82
post #37
post #2

So, if I understand this right... some NSA TAO employee was doing work on their home computer (???), where they installed Kaspersky AV (reasonable), and Kaspersky promptly identified the malware they were working on as malware and uploaded it? And then Israel hacked Kaspersky 'cause that's what they do or something, found the NSA development malware, and was like "Hey NSA, you should figure out how this got here"? Th…

some NSA TAO employee was doing work on their home computer Given that they haven't been charged, it's pretty likely there's more to this story. Two possibilities: It wasn't actually their home computer, but it was a non-classified system where code was being move for non-attributable active deployment. The code was developed or acquired in a non-classified space first. There are probably more possibilities too. Ther…

Given that they haven't been charged, it's pretty likely there's more to this story.

Probably their best employee, his mom died...it was a mistake, a bad one but a mistake. Prosecutorial discretion.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#83
post #78
post #69

Earlier quoted context omitted.

Russian and China coercion are on a completely different scale, and we all know it. Especially after the Snowden backlash. Imagine any major Chinese IT company pushing back against government requests like Dreamhost did. Even the biggest ones can't/won't. It helps that the government is a huge investor in most of them, of course. "Chinese IT company rebuffs government demand for user information on its website". This…

A lot of that is because Russia and China don't feel very secure compared to the US for various historical/geopolitical reasons. The US govt is known to act ruthlessly when it feels there's an existential threat.

Arrant nonsense

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#84
post #65

Earlier quoted context omitted.

If your company is in Russia, China or the US, and the government in that country has any interest in the data you collect, you will have to give it away. In Russia and China they just do it, in the US it's a matter of "National Security". I'm not sure why this would surprise anyone - maybe because most of us are on the side of the latter.

This is a gross false equivalence.

Yes. I find it annoying in these threads how people refuse to acknowledge that we have much stronger rule of law in the west. Even though it's flawed and abused, every rational actor prefers our system.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#85
post #31

Earlier quoted context omitted.

Do you mean the company or the man?

The company. The man will be fine.

Why would they be done for? If they are basically funded by the FSB then they can't really die, no? Or is it more that it's over to them wrt running in the USA in general

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#86
post #78
post #69

Earlier quoted context omitted.

Russian and China coercion are on a completely different scale, and we all know it. Especially after the Snowden backlash. Imagine any major Chinese IT company pushing back against government requests like Dreamhost did. Even the biggest ones can't/won't. It helps that the government is a huge investor in most of them, of course. "Chinese IT company rebuffs government demand for user information on its website". This…

A lot of that is because Russia and China don't feel very secure compared to the US for various historical/geopolitical reasons. The US govt is known to act ruthlessly when it feels there's an existential threat.

Feel like this is moving goalposts, especially given the context of this discussion (IT corps protecting their users from the government).

Think about the fact that the FBI had to actually get a warrant to even begin talking to Lavabit. They had to actually go through bureaucracy. It was not instantly handed over to them on request.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#87
post #84

Earlier quoted context omitted.

This is a gross false equivalence.

Yes. I find it annoying in these threads how people refuse to acknowledge that we have much stronger rule of law in the west. Even though it's flawed and abused, every rational actor prefers our system.

> we have much stronger rule of law in the west

Domestically perhaps, but not when it comes to international law (eg. sanctioning torture, extrajudicial killings, drone strikes, illegal invasion etc.)

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#88
post #78
post #69

Earlier quoted context omitted.

Russian and China coercion are on a completely different scale, and we all know it. Especially after the Snowden backlash. Imagine any major Chinese IT company pushing back against government requests like Dreamhost did. Even the biggest ones can't/won't. It helps that the government is a huge investor in most of them, of course. "Chinese IT company rebuffs government demand for user information on its website". This…

A lot of that is because Russia and China don't feel very secure compared to the US for various historical/geopolitical reasons. The US govt is known to act ruthlessly when it feels there's an existential threat.

As a Ukrainian Jew, the idea that Russia doesn't act as, if not more, ruthlessly than the U.S. is pretty laughable.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#89
post #37

Earlier quoted context omitted.

some NSA TAO employee was doing work on their home computer Given that they haven't been charged, it's pretty likely there's more to this story. Two possibilities: It wasn't actually their home computer, but it was a non-classified system where code was being move for non-attributable active deployment. The code was developed or acquired in a non-classified space first. There are probably more possibilities too. Ther…

Given that they haven't been charged, it's pretty likely there's more to this story. Probably their best employee, his mom died...it was a mistake, a bad one but a mistake. Prosecutorial discretion.

Maybe.

I've been in SCIFs. It would take a lot of effort to make a mistake like that.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#90
post #34

Kaspersky has been known to collaborate with the Russian government and promote Russian interest. They've actively pursued state actors that are hostile to Russian interest, for example The Equation Group ( https://en.wikipedia.org/wiki/Equation_Group ), which wouldn't be an organic part of the function or activities of a normal civilian cyber-security company. Such an "innocent" company would have no reason to get i…

> Kaspersky has been known to collaborate with the Russian government and promote Russian interest

I would like to see some actual evidence of this, instead of just allegations.

Post reply on HN