Live data from Hacker News

Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

washingtonpost.com

241–250 of 298 posts

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#241
post #177

Earlier quoted context omitted.

In a very direct sense. It's a de facto totalitarian dictatorship. Its proliferation harms human rights, poses real danger to Ukraine, claims lives. ( https://en.wikipedia.org/wiki/Casualties_of_the_Ukrainian_cr... , corruption also claims lives https://www.youtube.com/watch?v=3eO8ZHfV4fk )

But you could say much of the same about the US.

Much of the same?

Do you refer to military intervention in Iraq, Afghanistan, Yemen, Syria, ...?

Do you dispute that these countries/areas are/were different from Ukraine?

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#242
post #239

Earlier quoted context omitted.

Why would a hacker not use Mac or Linux for sensitive stuff?

I assume if you voluntarily give Kaspersky root access to your laptop, they don't care whether it's Windows, Mac, or Linux.

Does Karpersky sell that run on Macs or desktop Linux?

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#243
post #55
post #17

Earlier quoted context omitted.

> If the news story is to be believed, Kaspersky was scanning for classified data using US intelligence codewords as a selector. Assuming you mean the linked article, it doesn’t say that. It says that Kaspersky uses “silent signatures”, which are supposed to be indicators of malware, but could hypothetically be adapted to search for classified data instead. But it doesn’t allege Kaspersky was actually doing that. (ed…

> But this article seems to suggest that they were sending the executable in full It doesn't necessarily need to be an executable. Imagine this filter: - File type: .docx - Silent Signature: "TOP SECRET//COMINT//NOFORN" That means all word documents with: - the " top secret " classification - in the " Special Intelligence(ComInt) " area - marked as " No Foreign Nationals " will automatically be sent back to servers f…

Why the heck is a file that says "TOP SECRET//COMINT//NOFORN" on anyone's personal laptop? Isn't that, like, not just a firing offense but also a criminal offense?

Again, in my industry I'm not allowed to take code home with me; I have to remote into work and edit it on my work desktop. And the worst-case scenario of code leaking is basically that a competitor makes money that we would otherwise have made. Can't people who literally have (in their belief, at least) the fate of the free world in their hands be at least this careful?

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#244

Earlier quoted context omitted.

Why would a NSA guy use Russian security software?

Why would an NSA guy put secret government tools on his personal laptop?

Too restrictive corporate policies?

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#245
post #127
post #116

Earlier quoted context omitted.

That is not the same thing. The fact that they've exploited AV does not mean that they coerced an AV company into installing 0day for them. Those are very very different things.

Ok, four questions: 1. Is hacking into a foreign AV company by a state an OK thing to do? 2. How do we know the anonymous source is being truthful? 3. If yes to the first two, are we certain that it wasn't exploited but was coerced? 4. If all of these things are true and they were coerced, what is the practical difference for the party being monitored?

You are absolutely right that we don't know any of these things for sure. My point is not that we know them for sure. Simply that, as written, the article does not claim the US to have done something morally equivalent to Russia. And to my knowledge, there is no evidence that the US has done something like that, either.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#246
post #182

Earlier quoted context omitted.

Your ridicule is misplaced. We truly cannot trust the computers we use, from the silicon up. To call that paranoia isn't naivity anymore, it's foolhardiness.

Standard intelligence practice is to assume that your information is already compromised. All it takes is a mole, or a disgruntled employee and all the cybersecurity in the world is naught. You'd be foolish to think anything else.

Standard Practice is to have honeypots, and watch carefully who puts his paws where..

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#247
post #166
post #138

This is what I read between the lines: An NSA spook was working on his home laptop and playing around with some special NSA malware. Kaspersky AV detected it - AS IT SHOULD - based on heuristic or behavior-based technology that just about every modern AV has. The data was sent back to Kaspersky servers. This is also how everyone else does it, because this is how A/V companies create signatures that are pushed out to…

Wait, does it really send (suspected) malware home, without asking the user?

you can turn off and it's on the agreements/license bla bla nobody reads.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#248
post #44

Earlier quoted context omitted.

> Do American anti-virus, social media, and search companies do exactly the same, but for the US military? Doubtful. Keep in mind that in Russia / China the state has a lot more leverage against commercial companies. It's very easy for the state to effectively shut any non-complying company, not to mention far worse (Russia and China have thrown businessowners into jail for no reason before). > Almost like they know…

> Doubtful. Keep in mind that in Russia / China the state has a lot more leverage against commercial companies. It's very easy for the state to effectively shut any non-complying company, not to mention far worse (Russia and China have thrown businessowners into jail for no reason before). That is pretty disingenuous. Noncompliance with an NSL is a quick route to contempt charges. On top of that, the gag order preven…

NSL is a statutory authority document issued directly by the executive without judicial involvement. It is not a legal proceeding nor a warrant, nor is it even on court letterhead. There are no statutory penalties for noncompliance set out in the law defining NSLs, but it has provisions to request a court order to enforce if the recipient does not comply. That requires filing a federal case, bringing the intelligence operation to the attention of the judiciary, and probable argument with an opportunity for the target to argue. This is where you hear about folks like EFF defending an NSL, since replying to an NSL usually does nothing.

After a court issues an order, contempt of court is a possibility. Just clarifying that the route to contempt is not quick. It’s also largely untested. Writing an NSL is two pages in a Microsoft Word template, while arguing a federal case to get your way is a much bigger prospect; if the investigation is small enough, or they’re not totally legal in how they got intelligence, etc., etc., they might not wish to argue and calling the bluff might be smart.

The gagging facility of NSLs actually has a non-coercive purpose: as designed, an NSL basically invites an unknown third party into a sensitive intelligence or counterintelligence operation. Tipping off the target or anyone else could lead to a collapse of the investigation, burning other sources that were used before you got your NSL, diplomatic repercussions, and so on. That’s the thinking that went into it, and it’s actually understandable. Two problems are that (a) the gag is indefinite, with no circling back once the operation concludes and (b) NSL is horrifically abused for stuff it shouldn’t be, since FBI realized the gagging lets them mostly get away with it.

Source: Have held more than one and read the citations.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#249
post #32

Earlier quoted context omitted.

NYT: Israeli intelligence officers informed the N.S.A. that in the course of their Kaspersky hack, they uncovered evidence that Russian government hackers were using Kaspersky’s access to aggressively scan for American government classified programs, and pulling any findings back to Russian intelligence systems. They provided their N.S.A. counterparts with solid evidence of the Kremlin campaign in the form of screens…

That paragraph reeks of either journalistic license or a journalist who doesn't seem to understand what antivirus does. Every antivirus program aggressively scans for malicious programs and sends them back to the security firm for inspection and creation of fingerprints. If the collection wasn't incidental, what mechanism could the FSB exploit to non-naively identify tools that it didn't already have, and flag them f…

Your comment doesn't really say anything. Obviously, most AV software relays files back to the AV vendor's servers. But that's not what this graf implies. The graf suggests that Russian hackers are sending selectors down to the installed base of AV software to retrieve specific files, and that, once they obtained files that way, they passed the files on to Russian intelligence.
Post reply on HN