Live data from Hacker News

Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

washingtonpost.com

201–210 of 298 posts

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#201
post #199
post #163

Earlier quoted context omitted.

Where did you read "letting the FSB know about this contractor so they could target and breach his machine." I somehow missed to see that anybody but you claims that, so please give some link. I also, like the parent poster, only read that the antvirus program, as it should, collected the virus to the company servers.

I read that in the WSJ article that first revealed the security breach. https://www.wsj.com/articles/russian-hackers-stole-nsa-data-... >The hackers appear to have targeted the contractor after identifying the files through the contractor’s use of a popular antivirus software made by Russia-based Kaspersky Lab, these people said.

It is behind a paywall but the quote you give has no sense in the context of the rest of the information I've read. That narration would be different then. Israelis hacked Kaspersky offices, discovered what the antivirus automatically transferred. It is not claimed they discovered anything else there. NSA obviously didn't know what their worker did at home, until Israelis informed them, so how do they know he was targeted afterwards and that Kaspersky was directly involved? Something is still missing.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#202

Earlier quoted context omitted.

> Kaspersky has [...] actively pursued state actors that are hostile to Russian interest, for example The Equation Group ( https://en.wikipedia.org/wiki/Equation_Group ), which wouldn't be an organic part of the function or activities of a normal civilian cyber-security company. According to that Wikipedia page, The Equation Group refers to "a collection of tools used for hacking". Targeting hacking tools seems to me…

> According to that Wikipedia page, The Equation Group refers to "a collection of tools used for hacking" Are we reading the same Wikipedia page? Here's what mine says: > The Equation Group, classified as an advanced persistent threat, is a highly sophisticated threat actor suspected of being tied to the United States National Security Agency (NSA). Kaspersky Labs describes them as one of the most sophisticated cyber…

>Doesn't it strike you as odd?

No, not in the slightest. Of course a security company tracks security threats, especially when those security threats utilize multiple zero day vulnerabilities that could end up in the wild after they are finished with them. Use your head, man. I get it, "better dead than Red" and all, but let's not lose our shit purely because of the speculation of an "anonymous source close to the case."

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#204
post #187
post #147

Earlier quoted context omitted.

Europeans had a few. There was StudiVZ in Germany and tuenti in Spain. Once Facebook arrived with localised versions on the European market it destroyed all of the clones. Talk about network effects.

But search engines and email services? Operating systems? Europe is really not on top of this game.

Most of the countries had a local one.

Being local ones, they didn't have the same network effects like the US ones. Some of them still live, though.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#205
post #138

This is what I read between the lines: An NSA spook was working on his home laptop and playing around with some special NSA malware. Kaspersky AV detected it - AS IT SHOULD - based on heuristic or behavior-based technology that just about every modern AV has. The data was sent back to Kaspersky servers. This is also how everyone else does it, because this is how A/V companies create signatures that are pushed out to…

I'm not a malware developer but you can tell an AntiVirus not to scan a specific directory so that could of been completely avoided. You can also tell an antivirus what not to send over to the AV developers / company as far as I remember. I stopped using antiviruses years back, but I remember this from when I would download cheating tools I would define a folder for those tools, some of which I had the source code to…

I'll cut you some slack because you stated you're not a malware developer. But even if you're a normal developer, you should know that telling software to do something does not mean that the software will do that something. When the software in question is subject to being controlled by adversaries, all guarantees go out of the window.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#206
post #32
post #24

Earlier quoted context omitted.

One other possibility is that Kaspersky stole nothing, that it found the malware on computers it was tasked with protecting. And one should wonder did they add signatures to their A/V product to find and protect against this malware or not?

NYT: Israeli intelligence officers informed the N.S.A. that in the course of their Kaspersky hack, they uncovered evidence that Russian government hackers were using Kaspersky’s access to aggressively scan for American government classified programs, and pulling any findings back to Russian intelligence systems. They provided their N.S.A. counterparts with solid evidence of the Kremlin campaign in the form of screens…

That paragraph reeks of either journalistic license or a journalist who doesn't seem to understand what antivirus does.

Every antivirus program aggressively scans for malicious programs and sends them back to the security firm for inspection and creation of fingerprints. If the collection wasn't incidental, what mechanism could the FSB exploit to non-naively identify tools that it didn't already have, and flag them for retrieval?

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#207

Earlier quoted context omitted.

Correct. Russia IS the enemy. Secret warrants by a secret court is also the enemy. One is just more important and dangerous than the other (look out of the window). Perfect example of whataboutism BTW.

> Russia IS the enemy In what sense?

You are right. It's not so black and white.

One fact you can't argue with is Russian government is telling their people US is the enemy.

Follow @JuliaDavisNews . She posts gists of Russian state-controlled TV.

If it's not US, it's EU/NATO/gays/"democracy" (I'm not kidding you about democracy)

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#208

Earlier quoted context omitted.

Correct. Russia IS the enemy. Secret warrants by a secret court is also the enemy. One is just more important and dangerous than the other (look out of the window). Perfect example of whataboutism BTW.

>One is just more important and dangerous than the other Not if you're not American. The American government has shown it doesn't care at all or stop at anything to promote its self interest through American made software outside the US.

I wrote on this before.

Somebody is going to be on top.

Would you rather have US, Russia or China be the superpower?

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#209
post #34

Kaspersky has been known to collaborate with the Russian government and promote Russian interest. They've actively pursued state actors that are hostile to Russian interest, for example The Equation Group ( https://en.wikipedia.org/wiki/Equation_Group ), which wouldn't be an organic part of the function or activities of a normal civilian cyber-security company. Such an "innocent" company would have no reason to get i…

Well, it makes perfect sense to use Kaspersky then, if you're worried about the NSA. If you're more worried about Russian industrial espionage, on the other hand, e.g. as a US company with trade-secrets, you should probably better go with a US product. For most private citizens that aren't of particular interest to the Russian government (e.g. aren't politicians, activists, dissidents), Kaspersky seems like an excell…

Even if Kaspersky still fits your threat model (and it might), this revelation is still an existential threat, and if you use Kaspersky for an institution it's probably a good time to explore alternatives and have a plan for what to use if Kaspersky goes under.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#210
post #190
post #188

Earlier quoted context omitted.

How would switching to macOS provide any protection against an APT? Against Malware in general yeah sure but against the NSA or FSB in a targeted attack I don't see how that benefits you at all. If the NSA can put the screws on Microsoft then Apple should be no different. Apple refusing the FBI is one thing but faced with a gag order and an NSL their only recourse is to appeal to a secret court that basically always…

Everyone who think they are safe using macOS should see this presentation : https://www.youtube.com/watch?v=q7VZtCUphgg Patrick Wardle has reversed the C2 com protocol and found it had "advanced" capabilities (remote exec, key and mouse sniffing, screenshot, etc.). The malware was found on several thousands Macs too (mostly in the US).

Apple pays people to "astroturf" that they're immune from Viruses and backdoors. IMHO, that makes them much worse than Microsoft.
Post reply on HN