Live data from Hacker News

Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

washingtonpost.com

121–130 of 298 posts

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#121
post #34

Kaspersky has been known to collaborate with the Russian government and promote Russian interest. They've actively pursued state actors that are hostile to Russian interest, for example The Equation Group ( https://en.wikipedia.org/wiki/Equation_Group ), which wouldn't be an organic part of the function or activities of a normal civilian cyber-security company. Such an "innocent" company would have no reason to get i…

> Kaspersky has been known to collaborate with the Russian government and promote Russian interest I would like to see some actual evidence of this, instead of just allegations.

How else can you explain their obsessive occupation with The Equation Group, which they themselves claim to be a (US) state actor, targeting other (US-unfriendly) state actors?

https://en.wikipedia.org/wiki/Equation_Group

An ordinary anti-virus company would never get involved in state-vs-state cyber warfare, let alone pour tons of money into researching it. How does that support their business model?

Do you think it's normal for a commercial company to spend so much time, money, and effort researching areas that have nothing to do with their core business, and will likely get them in trouble with their customers and antagonistic governments?

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#122
post #34

Kaspersky has been known to collaborate with the Russian government and promote Russian interest. They've actively pursued state actors that are hostile to Russian interest, for example The Equation Group ( https://en.wikipedia.org/wiki/Equation_Group ), which wouldn't be an organic part of the function or activities of a normal civilian cyber-security company. Such an "innocent" company would have no reason to get i…

Way down this thread, so time to ask the question: Do American anti-virus, social media, and search companies do exactly the same, but for the US military? I've always found it suspicious that Russia and China created their own social networks, email providers, and search engines. Almost like they know the power of a capable search engine or social network for intelligence gathering purposes. Google and US anti-virus…

'I've always found it suspicious that Russia and China created their own social networks, email providers, and search engines. Almost like they know the power of a capable search engine or social network for intelligence gathering purposes.'

Seems like the Europeans are the only ones stupid enough not to.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#123
post #34

Kaspersky has been known to collaborate with the Russian government and promote Russian interest. They've actively pursued state actors that are hostile to Russian interest, for example The Equation Group ( https://en.wikipedia.org/wiki/Equation_Group ), which wouldn't be an organic part of the function or activities of a normal civilian cyber-security company. Such an "innocent" company would have no reason to get i…

This is a lot of BS. Kaspersky have also documented Russian government malware, so that is one nail in a very weak argument.

Having a lot of experience in this space, no loyalties to Russia, and all loyalties to the US, if anywhere, I strongly disagree that there has ever been any meaningful current or historical link between Kaspersky and the Russian government.

Posts like this do not seem to be informed by actual industry experience and those speculations are not even agreeable to those who are suspicious of Kaspersky. You're sharing a lot of FUD.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#124
post #34

Kaspersky has been known to collaborate with the Russian government and promote Russian interest. They've actively pursued state actors that are hostile to Russian interest, for example The Equation Group ( https://en.wikipedia.org/wiki/Equation_Group ), which wouldn't be an organic part of the function or activities of a normal civilian cyber-security company. Such an "innocent" company would have no reason to get i…

> Kaspersky has [...] actively pursued state actors that are hostile to Russian interest, for example The Equation Group ( https://en.wikipedia.org/wiki/Equation_Group ), which wouldn't be an organic part of the function or activities of a normal civilian cyber-security company. According to that Wikipedia page, The Equation Group refers to "a collection of tools used for hacking". Targeting hacking tools seems to me…

> According to that Wikipedia page, The Equation Group refers to "a collection of tools used for hacking"

Are we reading the same Wikipedia page? Here's what mine says:

> The Equation Group, classified as an advanced persistent threat, is a highly sophisticated threat actor suspected of being tied to the United States National Security Agency (NSA). Kaspersky Labs describes them as one of the most sophisticated cyber attack groups in the world and "the most advanced ... we have seen", operating alongside but always from a position of superiority with the creators of Stuxnet and Flame. Most of their targets have been in Iran, Russia, Pakistan, Afghanistan, India, Syria, and Mali.

Kaspersky is preoccupied with this group, that by their own description, targets state actors that are hostile to the US. They've obsessively documented 500 of their alleged attacks worldwide, which would be negligible blip on the radar for any normal, purely commercial cyber-security company.

Doesn't it strike you as odd?

> Even if we assume these tools can only target governments and not businesses or individuals, perhaps Kaspersky wishes to obtain contracts with the governments targeted.

I'm going to take a wild guess that none of the targets of the Equation Group like Afghanistan or Syria will trust Kaspersky enough to hire them for a sensitive project. These countries are very busy with ground wars and have no attention or money to spend on cyber security.

The only government that may and probably does employ Kaspersky is the Russian one. Which of itself hints at heavy collusion between these two.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#125
post #34

Kaspersky has been known to collaborate with the Russian government and promote Russian interest. They've actively pursued state actors that are hostile to Russian interest, for example The Equation Group ( https://en.wikipedia.org/wiki/Equation_Group ), which wouldn't be an organic part of the function or activities of a normal civilian cyber-security company. Such an "innocent" company would have no reason to get i…

Way down this thread, so time to ask the question: Do American anti-virus, social media, and search companies do exactly the same, but for the US military? I've always found it suspicious that Russia and China created their own social networks, email providers, and search engines. Almost like they know the power of a capable search engine or social network for intelligence gathering purposes. Google and US anti-virus…

Facebook has CIA related people on its board.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#126
post #85
post #31

Earlier quoted context omitted.

The company. The man will be fine.

Why would they be done for? If they are basically funded by the FSB then they can't really die, no? Or is it more that it's over to them wrt running in the USA in general

They are not funded by the FSB. Not even Washington thinks that. They're a very successful multinational antivirus company, and they make one of the least bad products in that space.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#127
post #116
post #106

Earlier quoted context omitted.

In this article and the nyt one they are actually saying US is doing it and it's not even a secret. Here is a quote: "The N.S.A. bans its analysts from using Kaspersky antivirus at the agency, in large part because the agency has exploited antivirus software for its own foreign hacking operations and knows the same technique is used by its adversaries."

That is not the same thing. The fact that they've exploited AV does not mean that they coerced an AV company into installing 0day for them. Those are very very different things.

Ok, four questions:

1. Is hacking into a foreign AV company by a state an OK thing to do?

2. How do we know the anonymous source is being truthful?

3. If yes to the first two, are we certain that it wasn't exploited but was coerced?

4. If all of these things are true and they were coerced, what is the practical difference for the party being monitored?

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#129
post #17

Earlier quoted context omitted.

>Kaspersky promptly identified the malware they were working on as malware and uploaded it? If the news story is to be believed, Kaspersky was scanning for classified data using US intelligence codewords as a selector. >I'm sort of surprised Kaspersky had servers vulnerable to Israel I'm not, everyone's servers are vulnerable. Intelligence agencies can buy exploits. If they want in, they get in. >but I'm really surpr…

> If the news story is to be believed, Kaspersky was scanning for classified data using US intelligence codewords as a selector. Assuming you mean the linked article, it doesn’t say that. It says that Kaspersky uses “silent signatures”, which are supposed to be indicators of malware, but could hypothetically be adapted to search for classified data instead. But it doesn’t allege Kaspersky was actually doing that. (ed…

Pretty much all AV products do this, for "suspicious" files too. Doesn't even need a signature to get collected. This includes non-executables such as docs or pdfs, since those are common 0day vectors.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#130
post #125

Earlier quoted context omitted.

Way down this thread, so time to ask the question: Do American anti-virus, social media, and search companies do exactly the same, but for the US military? I've always found it suspicious that Russia and China created their own social networks, email providers, and search engines. Almost like they know the power of a capable search engine or social network for intelligence gathering purposes. Google and US anti-virus…

Facebook has CIA related people on its board.

Source?
Post reply on HN