Live data from Hacker News

Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

washingtonpost.com

161–170 of 298 posts

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#161

Earlier quoted context omitted.

You mean you can't even stand their mere existence even without ever actually touching any of their products? Note that I'm not asking why you're not installing their antivirus, I'm asking why you don't want them to exist ...

I don’t because they are collaborating with a fundamentally dictatorial gov’t.

If you want a slightly more nuanced understanding of Russia, I found this quite good as a crash course to why Russians like Putin:

http://www.bbc.co.uk/iplayer/episode/b097l4s7/russia-with-si...

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#162

Earlier quoted context omitted.

> Kaspersky has [...] actively pursued state actors that are hostile to Russian interest, for example The Equation Group ( https://en.wikipedia.org/wiki/Equation_Group ), which wouldn't be an organic part of the function or activities of a normal civilian cyber-security company. According to that Wikipedia page, The Equation Group refers to "a collection of tools used for hacking". Targeting hacking tools seems to me…

> According to that Wikipedia page, The Equation Group refers to "a collection of tools used for hacking" Are we reading the same Wikipedia page? Here's what mine says: > The Equation Group, classified as an advanced persistent threat, is a highly sophisticated threat actor suspected of being tied to the United States National Security Agency (NSA). Kaspersky Labs describes them as one of the most sophisticated cyber…

Kaspersky is preoccupied with this group, that by their own description, targets state actors that are hostile to the US. They've obsessively documented 500 of their alleged attacks worldwide, which would be negligible blip on the radar for any normal, purely commercial cyber-security company.

You keep saying this, and it is completely wrong which detracts from your point (which is right!).

All commercial cyber-security companies collect and report on hacking groups.

Here's the Mandiant/FireEye report on APT-1: https://www.fireeye.com/content/dam/fireeye-www/services/pdf... and here is the APT_28 one: https://www2.fireeye.com/apt28.html

Here's the report by a group of companies on the Chinese Axiom group: http://www.novetta.com/wp-content/uploads/2014/11/Executive_...

And finally, here's the FireEye one I linked to previously talking about the Equation Group: https://www.fireeye.com/content/dam/fireeye-www/company/even...

The only government that may and probably does employ Kaspersky is the Russian one.

That's not true either as a quick Google shows, eg: https://www.crn.com.au/news/kaspersky-to-protect-prime-minis...

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#163
post #154
post #138

This is what I read between the lines: An NSA spook was working on his home laptop and playing around with some special NSA malware. Kaspersky AV detected it - AS IT SHOULD - based on heuristic or behavior-based technology that just about every modern AV has. The data was sent back to Kaspersky servers. This is also how everyone else does it, because this is how A/V companies create signatures that are pushed out to…

"Everything else is speculation" ignores the well sourced "speculation" about Kaspersky's next step: letting the FSB know about this contractor so they could target and breach his machine. It's speculative in the sense that we weren't there, but the information comes from the same source as all of those facts.

Where did you read "letting the FSB know about this contractor so they could target and breach his machine."

I somehow missed to see that anybody but you claims that, so please give some link. I also, like the parent poster, only read that the antvirus program, as it should, collected the virus to the company servers.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#164
post #56

Earlier quoted context omitted.

> He has a colorful personal life I think the gp was referring to what accusations people have made of McAfee since he sold the company. Showtime aired up a documentary[1] about him. I think "colorful personal life" can only be interpreted as a euphemism since he was accused of murder, rape, running a local armed gang, fleeing the country from the police, etc. I have no reason to believe Kaspersky will have similar i…

He also ran for POTUS as a Libertarian.

He was born in Scotland so that was never going to work, lol

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#165
post #154
post #138

This is what I read between the lines: An NSA spook was working on his home laptop and playing around with some special NSA malware. Kaspersky AV detected it - AS IT SHOULD - based on heuristic or behavior-based technology that just about every modern AV has. The data was sent back to Kaspersky servers. This is also how everyone else does it, because this is how A/V companies create signatures that are pushed out to…

"Everything else is speculation" ignores the well sourced "speculation" about Kaspersky's next step: letting the FSB know about this contractor so they could target and breach his machine. It's speculative in the sense that we weren't there, but the information comes from the same source as all of those facts.

There is no single source for the article.

It refers to a "person familiar with the case" when they explain how an NSA guy exposed his malware to Kaspersky.

It refers to different sources which discuss how any malware might have made its way from Kaspersky to the NSA -- unnamed "information security analysts" (they think the KGB hacked Kaspersky), "other experts" (they say the Russian's version of PRISM picked it up) and Steven Hall, a former spook with no disclosed ties to the case (he says Kaspersky is "likely to be beholden to the Kremlin").

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#166
post #138

This is what I read between the lines: An NSA spook was working on his home laptop and playing around with some special NSA malware. Kaspersky AV detected it - AS IT SHOULD - based on heuristic or behavior-based technology that just about every modern AV has. The data was sent back to Kaspersky servers. This is also how everyone else does it, because this is how A/V companies create signatures that are pushed out to…

Wait, does it really send (suspected) malware home, without asking the user?

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#167
post #141

Our company uses the enterprise version of Kaspersky. But if we drop this over surveillance issues then it would be a pretty hypocritical to switch to AV software from the USA. Since they are proven to do the exact thing that Kaspersky is now suspected / blamed of doing. So, fellow Europeans, what now? Avast? Any other options? EDIT: Ok so I found a pretty useful Wiki list[1] with European made AV products. I haven't…

Hire a team from your native country to manually inspect each packet before it is passed on to the client machines. This kind of Biological neural network isn't always the fastest approach but you can be sure it isn't forwarding all your traffic to the government.

Your ridicule is misplaced. We truly cannot trust the computers we use, from the silicon up.

To call that paranoia isn't naivity anymore, it's foolhardiness.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#168
post #153
post #148

Earlier quoted context omitted.

Of those, all but Finland are NATO members.

NATO is a military alliance, not a intelligence sharing agreement. We know that five-eyes intel doesn't go to NATO, and it is pretty doubtful that eg Turkey and Germany share their intel.

Five Eyes > NATO > non-NATO

We actually have no insight into military secret services' infoflow.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#169

I guess Kaspersky is rumoured to be to the Russian government what Apple / Google / Microsoft / Facebook are proven to be to the US government. Secret FISA courts rule away all of your basic privacy rights? Fear not. Russia is the enemy.

Correct. Russia IS the enemy.

Secret warrants by a secret court is also the enemy.

One is just more important and dangerous than the other (look out of the window).

Perfect example of whataboutism BTW.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#170
post #166
post #138

This is what I read between the lines: An NSA spook was working on his home laptop and playing around with some special NSA malware. Kaspersky AV detected it - AS IT SHOULD - based on heuristic or behavior-based technology that just about every modern AV has. The data was sent back to Kaspersky servers. This is also how everyone else does it, because this is how A/V companies create signatures that are pushed out to…

Wait, does it really send (suspected) malware home, without asking the user?

As far as I know most antivirus companies have such defaults which the users can somehow turn off. That means they consider that the user is informed and has agreed by using the product with such a setting unchanged.

I think Microsoft for their threat detection software does the same.

So I guess all the antivirus companies from time to time have such "lucky finds" like these that were obviously automatically collected by Kaspersky. Even the "secret" viruses will eventually be detected in the broader areas from time to time.

Post reply on HN