Live data from Hacker News

Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

washingtonpost.com

171–180 of 298 posts

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#171
post #155

Earlier quoted context omitted.

I can look at a Git commit and tell you exactly which of my coworkers wrote it without looking at %cn. Code has style, like spoken language has accents. One could argue that e.g. German spy tools copy the American style so that those decompiling it will think it is American. I argue that is a lot harder that it sounds. Code style is much deeper than whether or not to use braces around lone if clauses. The whole way o…

You might find De-anonymizing Programmers via Code Stylometry ( http://www.princeton.edu/~aylinc/papers/caliskan-islam_deano... ) an interesting read. I suspect that coding style guides are detectable in compiled output too. As an aside, a bit that caught my eye here: > This material is based on work supported by the ARO (U.S. Army Research Office) Grant W911NF-14-1- 0444, the DFG (German Research Foundation) under t…

>I suspect that coding style guides are detectable in compiled output too.

I strongly doubt that (while I concur that source coding style is often recognizable).

More or less a decompiler (when it works properly) attempts to interpret the machine code and translate it into the source. In order to do so, it must have some "templates" corresponding to regognizable "patterns" in the code, so the source derived from the decompilation will reflect these templates and not the "original".

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#172

Our company uses the enterprise version of Kaspersky. But if we drop this over surveillance issues then it would be a pretty hypocritical to switch to AV software from the USA. Since they are proven to do the exact thing that Kaspersky is now suspected / blamed of doing. So, fellow Europeans, what now? Avast? Any other options? EDIT: Ok so I found a pretty useful Wiki list[1] with European made AV products. I haven't…

> Iceland: FRISK (F-PROT)

FRISK was bought by Israeli company Commtouch several years ago. They wound down operations in Iceland to the point that I doubt any real technical work goes on there.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#173

I guess Kaspersky is rumoured to be to the Russian government what Apple / Google / Microsoft / Facebook are proven to be to the US government. Secret FISA courts rule away all of your basic privacy rights? Fear not. Russia is the enemy.

Correct. Russia IS the enemy. Secret warrants by a secret court is also the enemy. One is just more important and dangerous than the other (look out of the window). Perfect example of whataboutism BTW.

>One is just more important and dangerous than the other

Not if you're not American. The American government has shown it doesn't care at all or stop at anything to promote its self interest through American made software outside the US.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#174

I guess Kaspersky is rumoured to be to the Russian government what Apple / Google / Microsoft / Facebook are proven to be to the US government. Secret FISA courts rule away all of your basic privacy rights? Fear not. Russia is the enemy.

Correct. Russia IS the enemy. Secret warrants by a secret court is also the enemy. One is just more important and dangerous than the other (look out of the window). Perfect example of whataboutism BTW.

> Russia IS the enemy

In what sense?

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#175
post #165
post #154

Earlier quoted context omitted.

"Everything else is speculation" ignores the well sourced "speculation" about Kaspersky's next step: letting the FSB know about this contractor so they could target and breach his machine. It's speculative in the sense that we weren't there, but the information comes from the same source as all of those facts.

There is no single source for the article. It refers to a "person familiar with the case" when they explain how an NSA guy exposed his malware to Kaspersky. It refers to different sources which discuss how any malware might have made its way from Kaspersky to the NSA -- unnamed "information security analysts" (they think the KGB hacked Kaspersky), "other experts" (they say the Russian's version of PRISM picked it up)…

Why would a hacker not use Mac or Linux for sensitive stuff?

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#176

Our company uses the enterprise version of Kaspersky. But if we drop this over surveillance issues then it would be a pretty hypocritical to switch to AV software from the USA. Since they are proven to do the exact thing that Kaspersky is now suspected / blamed of doing. So, fellow Europeans, what now? Avast? Any other options? EDIT: Ok so I found a pretty useful Wiki list[1] with European made AV products. I haven't…

Use Linux :) there is no other option

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#177

Earlier quoted context omitted.

Correct. Russia IS the enemy. Secret warrants by a secret court is also the enemy. One is just more important and dangerous than the other (look out of the window). Perfect example of whataboutism BTW.

> Russia IS the enemy In what sense?

In a very direct sense.

It's a de facto totalitarian dictatorship. Its proliferation harms human rights, poses real danger to Ukraine, claims lives. ( https://en.wikipedia.org/wiki/Casualties_of_the_Ukrainian_cr... , corruption also claims lives https://www.youtube.com/watch?v=3eO8ZHfV4fk )

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#178
post #138

This is what I read between the lines: An NSA spook was working on his home laptop and playing around with some special NSA malware. Kaspersky AV detected it - AS IT SHOULD - based on heuristic or behavior-based technology that just about every modern AV has. The data was sent back to Kaspersky servers. This is also how everyone else does it, because this is how A/V companies create signatures that are pushed out to…

I'm not a malware developer but you can tell an AntiVirus not to scan a specific directory so that could of been completely avoided. You can also tell an antivirus what not to send over to the AV developers / company as far as I remember. I stopped using antiviruses years back, but I remember this from when I would download cheating tools I would define a folder for those tools, some of which I had the source code to but they were all flagged as potential malware.

I always setup my AV software to ask me before it does any thing whatsoever. I don't trust most software, I'm not about to start trusting my AV not to randomly send proprietary software over to their homebase.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#179

Why would anyone unaffiliated with NSA be alarmed that its tools had been breached? What legitimacy does it have at this point? Serious question.

The NSA is angry that their toys were lost because of their incompetence of using a tool that was just doing its job (to find malware) on a system that also hosted their secret toys. They're even more angry that they didn't notice themselves so their buddies from Israel had to tell them. _That_ must have burned.

Since the cover-up among relevant folks failed, and since Russia is slowly elevated to "not really friendly" status again by the US gov't, there's a great opportunity by the US deep state to send a big f*ck you to Kaspersky for their impertinence of doing their job.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#180
post #165

Earlier quoted context omitted.

There is no single source for the article. It refers to a "person familiar with the case" when they explain how an NSA guy exposed his malware to Kaspersky. It refers to different sources which discuss how any malware might have made its way from Kaspersky to the NSA -- unnamed "information security analysts" (they think the KGB hacked Kaspersky), "other experts" (they say the Russian's version of PRISM picked it up)…

Why would a hacker not use Mac or Linux for sensitive stuff?

Why would a NSA guy use Russian security software?
Post reply on HN