Live data from Hacker News

Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

washingtonpost.com

261–270 of 298 posts

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#261

What is the timeline on this? If Israel knew this in 2015, why is Kaspersky tools just being banned in the US now? Was this only shared recently?

> If Israel knew this in 2015, why is Kaspersky tools just being banned in the US now?

Now that is an excellent question. Why didn't the Obama administration do more to protect U.S. government computer systems from this threat?

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#262
post #188

Earlier quoted context omitted.

I think a Mac would work too, but that relies on trusting individuals.

How would switching to macOS provide any protection against an APT? Against Malware in general yeah sure but against the NSA or FSB in a targeted attack I don't see how that benefits you at all. If the NSA can put the screws on Microsoft then Apple should be no different. Apple refusing the FBI is one thing but faced with a gag order and an NSL their only recourse is to appeal to a secret court that basically always…

Well, nothing's totally secure. You can but reduce the odds of having problems and Macs seem to be hit less. For example in the N Korea hack on Sony the Macs survived https://9to5mac.com/2014/12/18/sony-hack/

>“Some people had to send faxes. They were dragging old printers out of storage to cut checks,” she said. “It was crazy.” ... "People using Macs were fine,” she said. She said most work is done on iPads and iPhones.

Perfect is the enemy of good and all that.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#263
post #254
post #190

Earlier quoted context omitted.

Everyone who think they are safe using macOS should see this presentation : https://www.youtube.com/watch?v=q7VZtCUphgg Patrick Wardle has reversed the C2 com protocol and found it had "advanced" capabilities (remote exec, key and mouse sniffing, screenshot, etc.). The malware was found on several thousands Macs too (mostly in the US).

Any suggestion a good tools (good source one) on mac that can scan and detect this kind of malware?

the guy in the video has created a bunch of "osx sysinternals" tools for this exact purpose : https://objective-see.com/products.html.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#264
post #34

Kaspersky has been known to collaborate with the Russian government and promote Russian interest. They've actively pursued state actors that are hostile to Russian interest, for example The Equation Group ( https://en.wikipedia.org/wiki/Equation_Group ), which wouldn't be an organic part of the function or activities of a normal civilian cyber-security company. Such an "innocent" company would have no reason to get i…

Equation Group were making hacking tools so opposing them is what any decent AV company should do. Doing so they protect all their users around the world.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#265
post #187
post #147

Earlier quoted context omitted.

Europeans had a few. There was StudiVZ in Germany and tuenti in Spain. Once Facebook arrived with localised versions on the European market it destroyed all of the clones. Talk about network effects.

But search engines and email services? Operating systems? Europe is really not on top of this game.

also: Czech Republic has seznam.cz , which makes a big difference in their market

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#266
post #260

Earlier quoted context omitted.

Why would a NSA guy use Russian security software?

Why would a NSA guy even run any AV? Isolate and compartmentalize everything based on the task and its dependencies. You should assume everything you run could be bad or that you are already compromised.

Is this reasonable to do with number of softwares even average people use?

There was a person on the docker team, who had dockerized every other applications like chrome, firefox, ALSA sound server, and more. But even she found it hard to sandbox everything.

I'm using docker as a leading sandboxing tech. Do you mean something else when you mean sandbox?

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#267
post #24
post #5

Perhaps he/she had the data on a SAN while performing development from a more “secure” computer and one of his personal computers with AV installed was connected to the same SAN. A likely scenario as far as scenarios go.

One other possibility is that Kaspersky stole nothing, that it found the malware on computers it was tasked with protecting. And one should wonder did they add signatures to their A/V product to find and protect against this malware or not?

AV use other methods, except for signatures, for example running code in the sandbox or heuristics. If the malware was not obfuscated then it could be detected even without signatures.

But of course if I were installing an AV product I wouldn't like it to send my files anywhere.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#268
post #201

Earlier quoted context omitted.

It is behind a paywall but the quote you give has no sense in the context of the rest of the information I've read. That narration would be different then. Israelis hacked Kaspersky offices, discovered what the antivirus automatically transferred. It is not claimed they discovered anything else there. NSA obviously didn't know what their worker did at home, until Israelis informed them, so how do they know he was tar…

Here is sans paywall link: https://archive.is/hB3eo No mention of FSB in that article.

Thanks. There is however:

"Investigators did determine that, armed with the knowledge that Kaspersky’s software provided of what files were suspected on the contractor’s PC, hackers working for Russia homed in on the machine and obtained a large amount of information, said the people familiar with the matter."

But that sounds very implausible, which entry would "the hackers" use? Note that nobody claims that Kaspersky did that "obtaining" that way (by hacking). But it appears to me that Kaspersky software simply first detected suspicious files and then also send them to the servers, which is what the software of most antivirus vendors does. And then the "hackers" story was invented to make it more dramatic. That better fits with the story of the NSA trojan files found on Kaspersky servers by the Israeli, as they hacked Kaspersky.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#269
post #69
post #65

Earlier quoted context omitted.

If your company is in Russia, China or the US, and the government in that country has any interest in the data you collect, you will have to give it away. In Russia and China they just do it, in the US it's a matter of "National Security". I'm not sure why this would surprise anyone - maybe because most of us are on the side of the latter.

Russian and China coercion are on a completely different scale, and we all know it. Especially after the Snowden backlash. Imagine any major Chinese IT company pushing back against government requests like Dreamhost did. Even the biggest ones can't/won't. It helps that the government is a huge investor in most of them, of course. "Chinese IT company rebuffs government demand for user information on its website". This…

Even if US government doesn't have such power as chinese (though I doubt they don't have) there still can be a motivation for US companies to cooperate because it can be mutually beneficial (for example, a company in exchange can get some contracts or some changes in legislation).

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#270
post #86
post #78

Earlier quoted context omitted.

A lot of that is because Russia and China don't feel very secure compared to the US for various historical/geopolitical reasons. The US govt is known to act ruthlessly when it feels there's an existential threat.

Feel like this is moving goalposts, especially given the context of this discussion (IT corps protecting their users from the government). Think about the fact that the FBI had to actually get a warrant to even begin talking to Lavabit. They had to actually go through bureaucracy. It was not instantly handed over to them on request.

But they have successfully shut down the Lavabit as a result.
Post reply on HN