Live data from Hacker News

Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

washingtonpost.com

251–260 of 298 posts

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#251

Earlier quoted context omitted.

Good riddance.

What was so bad about Kaspersky that you consider it good riddance? I recall reading about legitimate good security work and breach investigations from them just a few years ago. It's not like anybody forced you to use their software.

their decor is AWFULLLLLLL!

woudl yu cae for some capirinñas

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#252
post #32

Earlier quoted context omitted.

NYT: Israeli intelligence officers informed the N.S.A. that in the course of their Kaspersky hack, they uncovered evidence that Russian government hackers were using Kaspersky’s access to aggressively scan for American government classified programs, and pulling any findings back to Russian intelligence systems. They provided their N.S.A. counterparts with solid evidence of the Kremlin campaign in the form of screens…

The thing I don't understand about allegations like this is that, if true, why in the world did the US not take up Kaspersky on its offer of complete source access? Scans are executed client side using client side heuristics. And so what is or is not sent back would be contained within the client. It could be trivially verified that the source code they proffered compiles to the product at the time. And so it would a…

You need more than the source; you need the selector/signature configuration at all times the program was running, and the total state of every update ever applied to every running instance of the software.

The US already has Kaspersky's source.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#253
post #166
post #138

This is what I read between the lines: An NSA spook was working on his home laptop and playing around with some special NSA malware. Kaspersky AV detected it - AS IT SHOULD - based on heuristic or behavior-based technology that just about every modern AV has. The data was sent back to Kaspersky servers. This is also how everyone else does it, because this is how A/V companies create signatures that are pushed out to…

Wait, does it really send (suspected) malware home, without asking the user?

Yes it's among most antivirus packages advertised features. And example from everyones favorite anti virus vendor https://home.mcafee.com/Secure/CloudAV/HowItWorks.html but they all market a similar feature.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#254
post #190
post #188

Earlier quoted context omitted.

How would switching to macOS provide any protection against an APT? Against Malware in general yeah sure but against the NSA or FSB in a targeted attack I don't see how that benefits you at all. If the NSA can put the screws on Microsoft then Apple should be no different. Apple refusing the FBI is one thing but faced with a gag order and an NSL their only recourse is to appeal to a secret court that basically always…

Everyone who think they are safe using macOS should see this presentation : https://www.youtube.com/watch?v=q7VZtCUphgg Patrick Wardle has reversed the C2 com protocol and found it had "advanced" capabilities (remote exec, key and mouse sniffing, screenshot, etc.). The malware was found on several thousands Macs too (mostly in the US).

Any suggestion a good tools (good source one) on mac that can scan and detect this kind of malware?

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#255
post #239

Earlier quoted context omitted.

I assume if you voluntarily give Kaspersky root access to your laptop, they don't care whether it's Windows, Mac, or Linux.

Does Karpersky sell that run on Macs or desktop Linux?

According to Google they have both, and based on the descriptions they probably follow the same model as the Windows one. That said, it would be kind of ironic if the original comment actually meant, "Use Mac or Linux for sensitive stuff because there's a good chance Kaspersky doesn't exist (or work very well) on them."

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#256
post #187
post #147

Earlier quoted context omitted.

Europeans had a few. There was StudiVZ in Germany and tuenti in Spain. Once Facebook arrived with localised versions on the European market it destroyed all of the clones. Talk about network effects.

But search engines and email services? Operating systems? Europe is really not on top of this game.

Indefinite Pessimism. China and to a large extent Russia are Definite Pessimists.

The US and the UK are Indefinite Optimists while many in US tech are Definite Optimists (such as Elon Musk.)

Cultural attitudes about the future of our world has a huge influence on the type and velocity of innovation.

Those are generalizations, but just compare investment philosophies of various countries. EU: with a few exceptions that prove the rule, very conservative, less likely to back 100x technology innovations, more likely to back 2x innovations that have low risk and low reward (but enough reward to make a return.)

Russia and China: more likely to invest in keep-up technology (me-too stuff) that promotes domestic stability — much more defensive investing to promote Juche ideas. North Korean “tech” is the extreme example.

US: willing to bet huge on low percentage, future changing tech (speaking of the Valley specifically,) while much of the rest of the US tends to be closer to the EU in terms of risk tolerance, with notable exceptions.

You won’t have an EU investor funding self-driving cars generally and you won’t have a Valley investor funding incremental 2x tech (generally.)

All countries have visionaries and innovators, but due to who controls the finances (and tax policy,) most of those future Elon Musk types are shot down before they even get off the runway.

Exceptions abound of course, but that’s my general take.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#257

Earlier quoted context omitted.

Way down this thread, so time to ask the question: Do American anti-virus, social media, and search companies do exactly the same, but for the US military? I've always found it suspicious that Russia and China created their own social networks, email providers, and search engines. Almost like they know the power of a capable search engine or social network for intelligence gathering purposes. Google and US anti-virus…

'I've always found it suspicious that Russia and China created their own social networks, email providers, and search engines. Almost like they know the power of a capable search engine or social network for intelligence gathering purposes.' Seems like the Europeans are the only ones stupid enough not to.

It isn't stupidity.

Europe has been destroyed in WWII only to be liberated by the USA and the USSR (China is also among the winners). The USSR collapsed and withdrew from Eastern Europe, on condition that it remains a buffer zone (think about Ukraine in this context).

The EU is therefore essentially a peace project, subject to the peace treaties ending WWII (this hasn't happened in N. Korea, think about it in this context).

Those treaties are still in force today, including the stationing of liberating forces. This pretty much sets the boundaries, including the defense (read supervision) of strategic resources, such as gas pipelines, energy grids, and yes, communication lines and information technology. Obviously, these restrictions hardly reflect current German economic strength (just like after WWI), which inevitably leads to tensions (‘The Germans Are Bad, Very Bad’, as the POTUS puts it).

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#258
post #201
post #199

Earlier quoted context omitted.

I read that in the WSJ article that first revealed the security breach. https://www.wsj.com/articles/russian-hackers-stole-nsa-data-... >The hackers appear to have targeted the contractor after identifying the files through the contractor’s use of a popular antivirus software made by Russia-based Kaspersky Lab, these people said.

It is behind a paywall but the quote you give has no sense in the context of the rest of the information I've read. That narration would be different then. Israelis hacked Kaspersky offices, discovered what the antivirus automatically transferred. It is not claimed they discovered anything else there. NSA obviously didn't know what their worker did at home, until Israelis informed them, so how do they know he was tar…

Here is sans paywall link: https://archive.is/hB3eo

No mention of FSB in that article.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#259
post #238

Earlier quoted context omitted.

Many open source projects are infiltrated. You may use Linux but if you run on x86 you are already owned.

Not via Linux, but via the IME that Intel puts on every CPU with full access to all memory and the network cards.

One source of entropy in Linux is the RDRND instruction. If you control or predict its output you can do a lot of harm.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#260

Earlier quoted context omitted.

Why would a hacker not use Mac or Linux for sensitive stuff?

Why would a NSA guy use Russian security software?

Why would a NSA guy even run any AV? Isolate and compartmentalize everything based on the task and its dependencies. You should assume everything you run could be bad or that you are already compromised.
Post reply on HN