Live data from Hacker News

Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

washingtonpost.com

151–160 of 298 posts

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#151
post #125

Earlier quoted context omitted.

Way down this thread, so time to ask the question: Do American anti-virus, social media, and search companies do exactly the same, but for the US military? I've always found it suspicious that Russia and China created their own social networks, email providers, and search engines. Almost like they know the power of a capable search engine or social network for intelligence gathering purposes. Google and US anti-virus…

Facebook has CIA related people on its board.

That's true. At least in the beginning, there were some people near the CIA on the board and some of the early investment funding came from entities close to the CIA.

However, that's a very old story, I doubt that there is much of a connection now.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#152

Our company uses the enterprise version of Kaspersky. But if we drop this over surveillance issues then it would be a pretty hypocritical to switch to AV software from the USA. Since they are proven to do the exact thing that Kaspersky is now suspected / blamed of doing. So, fellow Europeans, what now? Avast? Any other options? EDIT: Ok so I found a pretty useful Wiki list[1] with European made AV products. I haven't…

If you must use AV, better look for AV solutions with clear written policies on the information they collect https://www.f-secure.com/en/web/legal/privacy/security-cloud

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#153
post #148

Our company uses the enterprise version of Kaspersky. But if we drop this over surveillance issues then it would be a pretty hypocritical to switch to AV software from the USA. Since they are proven to do the exact thing that Kaspersky is now suspected / blamed of doing. So, fellow Europeans, what now? Avast? Any other options? EDIT: Ok so I found a pretty useful Wiki list[1] with European made AV products. I haven't…

Of those, all but Finland are NATO members.

NATO is a military alliance, not a intelligence sharing agreement. We know that five-eyes intel doesn't go to NATO, and it is pretty doubtful that eg Turkey and Germany share their intel.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#154
post #138

This is what I read between the lines: An NSA spook was working on his home laptop and playing around with some special NSA malware. Kaspersky AV detected it - AS IT SHOULD - based on heuristic or behavior-based technology that just about every modern AV has. The data was sent back to Kaspersky servers. This is also how everyone else does it, because this is how A/V companies create signatures that are pushed out to…

"Everything else is speculation" ignores the well sourced "speculation" about Kaspersky's next step: letting the FSB know about this contractor so they could target and breach his machine.

It's speculative in the sense that we weren't there, but the information comes from the same source as all of those facts.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#155
post #59

Israel (Mossad?) can hack something in Russia, see tools and recognise those tools as top secret NSA gear. Do you wonder how they made that recognition? Were they shared with Israel so they knew, in which case the source could have been Israel being hacked, right? Or they knew because hacking the NSA is something multiple nation states have done. I'd be completely amazed if the NSA wasn't absolutely full of spies act…

I can look at a Git commit and tell you exactly which of my coworkers wrote it without looking at %cn. Code has style, like spoken language has accents. One could argue that e.g. German spy tools copy the American style so that those decompiling it will think it is American. I argue that is a lot harder that it sounds. Code style is much deeper than whether or not to use braces around lone if clauses. The whole way o…

You might find De-anonymizing Programmers via Code Stylometry ( http://www.princeton.edu/~aylinc/papers/caliskan-islam_deano... ) an interesting read.

I suspect that coding style guides are detectable in compiled output too.

As an aside, a bit that caught my eye here:

> This material is based on work supported by the ARO (U.S. Army Research Office) Grant W911NF-14-1- 0444, the DFG (German Research Foundation) under the project DEVIL (RI 2469/1-1), and AWS in Education Research Grant award.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#156

Our company uses the enterprise version of Kaspersky. But if we drop this over surveillance issues then it would be a pretty hypocritical to switch to AV software from the USA. Since they are proven to do the exact thing that Kaspersky is now suspected / blamed of doing. So, fellow Europeans, what now? Avast? Any other options? EDIT: Ok so I found a pretty useful Wiki list[1] with European made AV products. I haven't…

What’s wrong with Windows Defender?

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#157
post #32
post #24

Earlier quoted context omitted.

One other possibility is that Kaspersky stole nothing, that it found the malware on computers it was tasked with protecting. And one should wonder did they add signatures to their A/V product to find and protect against this malware or not?

NYT: Israeli intelligence officers informed the N.S.A. that in the course of their Kaspersky hack, they uncovered evidence that Russian government hackers were using Kaspersky’s access to aggressively scan for American government classified programs, and pulling any findings back to Russian intelligence systems. They provided their N.S.A. counterparts with solid evidence of the Kremlin campaign in the form of screens…

The thing I don't understand about allegations like this is that, if true, why in the world did the US not take up Kaspersky on its offer of complete source access?

Scans are executed client side using client side heuristics. And so what is or is not sent back would be contained within the client. It could be trivially verified that the source code they proffered compiles to the product at the time. And so it would also contain clear evidence whether or not the company's product was collecting and reporting data on software/documents/etc outside the nominal domain of its purpose.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#158

Earlier quoted context omitted.

Way down this thread, so time to ask the question: Do American anti-virus, social media, and search companies do exactly the same, but for the US military? I've always found it suspicious that Russia and China created their own social networks, email providers, and search engines. Almost like they know the power of a capable search engine or social network for intelligence gathering purposes. Google and US anti-virus…

'I've always found it suspicious that Russia and China created their own social networks, email providers, and search engines. Almost like they know the power of a capable search engine or social network for intelligence gathering purposes.' Seems like the Europeans are the only ones stupid enough not to.

Poland has several, but none can match the juggernauts

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#159
post #138

This is what I read between the lines: An NSA spook was working on his home laptop and playing around with some special NSA malware. Kaspersky AV detected it - AS IT SHOULD - based on heuristic or behavior-based technology that just about every modern AV has. The data was sent back to Kaspersky servers. This is also how everyone else does it, because this is how A/V companies create signatures that are pushed out to…

[deleted]

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#160
post #14

Earlier quoted context omitted.

They probably didn't hack anything, they just have people who receive these AV samples as malware researchers. Any intelligence agency worth their money should. And yes, this is the gist of what's behind all the Kaspersky hysteria. The NSA trying to obscure another extremely embarrassing leak. Every AV software uploads new detections for analysis. It just so happened that this fool used Kaspersky. It's abundantly cle…

Read the original New York Times story, it gives a lot more technical details on the hack than this one[0]. Assuming the Israeli and NYT accounts are to be believed, this was a very deliberate hack. Israel watched in real-time as Kaspersky sent out searches for NSA codename programs on all computers with Kaspersky AV installed (this was related to the whole Duqu 2.0 intrusion into Kaspersky's network that Kaspersky b…

It's the NYT for crying out sake! Unless you believe they have the knowledge on staff to do any sort of original reporting on this, this story is exactly what a "government official speaking on the condition of anonymity" has whispered to them. It's the fricking party line.

It's right there in the article:

    The current and former government officials who described the episode spoke about it on condition of anonymity because of classification rules.
There are two options here, obviously. Someone revealed actual classified information, in which case apparently multiple government workers committed a felony to tell the NYT about a story that is entirely flattering for the employer they just betrayed. Or, and given the incidence of "government officials .. spoke on the condition of anonymity" in NYT stories the far more likely option, the press office of the NSA called the NYT, whispered some dangerous words about "off the record" and then delivered the official press release that for some reason they just didn't get to put on NSA website just yet.

This is the NYT writing a government press release into a bad thriller guided not by independently verified facts (how could you) but sheer ideology to fill in the gaps.

Post reply on HN