Live data from Hacker News

Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

washingtonpost.com

271–280 of 298 posts

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#271
post #84

Earlier quoted context omitted.

Yes. I find it annoying in these threads how people refuse to acknowledge that we have much stronger rule of law in the west. Even though it's flawed and abused, every rational actor prefers our system.

>I find it annoying in these threads how people refuse to acknowledge that we have much stronger rule of law in the west. No we don't. We have a stronger belief in the rule of law, but not an actual practice of rule of law. It's been getting worse and worse over the past two decades and at this point I see little difference between any particular western government and Russia's. If you haven't noticed it, you've been…

The parent comment is probably right. In Russia even election results are forged by Putin supporters.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#272
post #165
post #154

Earlier quoted context omitted.

"Everything else is speculation" ignores the well sourced "speculation" about Kaspersky's next step: letting the FSB know about this contractor so they could target and breach his machine. It's speculative in the sense that we weren't there, but the information comes from the same source as all of those facts.

There is no single source for the article. It refers to a "person familiar with the case" when they explain how an NSA guy exposed his malware to Kaspersky. It refers to different sources which discuss how any malware might have made its way from Kaspersky to the NSA -- unnamed "information security analysts" (they think the KGB hacked Kaspersky), "other experts" (they say the Russian's version of PRISM picked it up)…

It is obvious to me that Kaspersky is beholden to the Kremlin. The founders of Kaspersky are after all Russian.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#273
post #260

Earlier quoted context omitted.

Why would a NSA guy use Russian security software?

Why would a NSA guy even run any AV? Isolate and compartmentalize everything based on the task and its dependencies. You should assume everything you run could be bad or that you are already compromised.

He works for the NSA, but he was on his home computer which is unlikely to stay air-gapped unless he's content with making mspaint art and playing skifree :)

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#274
post #260

Earlier quoted context omitted.

Why would a NSA guy use Russian security software?

Why would a NSA guy even run any AV? Isolate and compartmentalize everything based on the task and its dependencies. You should assume everything you run could be bad or that you are already compromised.

Straight up. They spew forth this stupid reasoning so that the general public will become frightened. Most people don't understand what any AV does, or how it operates anyway. For them to understand compartmentalization based on dependencies is way too far out there. The US government might have granted access as well in another effort to spread fear amongst the uneducated American populus.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#275
post #260

Earlier quoted context omitted.

Why would a NSA guy even run any AV? Isolate and compartmentalize everything based on the task and its dependencies. You should assume everything you run could be bad or that you are already compromised.

Is this reasonable to do with number of softwares even average people use? There was a person on the docker team, who had dockerized every other applications like chrome, firefox, ALSA sound server, and more. But even she found it hard to sandbox everything. I'm using docker as a leading sandboxing tech. Do you mean something else when you mean sandbox?

I should warn that Docker was never planned as a security tool. If you read the documentation on Linux containers you will see that they are pretty complicated and therefore can have vulnerabilities.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#276
post #268

Earlier quoted context omitted.

Here is sans paywall link: https://archive.is/hB3eo No mention of FSB in that article.

Thanks. There is however: "Investigators did determine that, armed with the knowledge that Kaspersky’s software provided of what files were suspected on the contractor’s PC, hackers working for Russia homed in on the machine and obtained a large amount of information, said the people familiar with the matter." But that sounds very implausible, which entry would "the hackers" use? Note that nobody claims that Kaspersk…

The implications may be that the FSB provided specific signatures for them to look for, they came back when they popped up on a machine located at this contractors house, then further assessments were performed. In context that’s not far fetched at all.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#277
post #238

Earlier quoted context omitted.

Not via Linux, but via the IME that Intel puts on every CPU with full access to all memory and the network cards.

One source of entropy in Linux is the RDRND instruction. If you control or predict its output you can do a lot of harm.

It really depends on a lot of the software as well. Linux doesn't inherently trust just the CPU instructions for entropy. In fact, it recently borrowed a new feature from OpenBSD and added it called getrandom():

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/lin...

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#278
post #164

Earlier quoted context omitted.

He was born in Scotland so that was never going to work, lol

Born on an Army base to an American father. John McCain was born under similar circumstances, Ted Cruz and George Romney were both born abroad and neither was seriously considered disqualified. The only difference between McCain and McAfee afaict is both McCain's parents were US citizens at the time of his birth. That may be relevant, that part of the law can change, but simply being born oversees doesn't stop a pers…

Didn’t know that, cool!

I’m not American so not that clued up on the specifics.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#280
post #268

Earlier quoted context omitted.

Thanks. There is however: "Investigators did determine that, armed with the knowledge that Kaspersky’s software provided of what files were suspected on the contractor’s PC, hackers working for Russia homed in on the machine and obtained a large amount of information, said the people familiar with the matter." But that sounds very implausible, which entry would "the hackers" use? Note that nobody claims that Kaspersk…

The implications may be that the FSB provided specific signatures for them to look for, they came back when they popped up on a machine located at this contractors house, then further assessments were performed. In context that’s not far fetched at all.

How do you think FSB "came back" to the machine of the NSA malware developer who's in the USA? I think that's exactly what is not plausible. He surely isn't going to open a trojan named isthatyou.jpg.exe in the e-mail sent by them to him. He actually made such stuff (trojans or something) himself as he let Kaspersky's software automatically collect the sample of his "work in progress." Now the unnamed government sources "leak" this as a case of apparent "Russian hackers" whereas the only known hackers in the story are the NSA and the Israel's hackers who hacked the office computers of Kaspersky. Kaspersky's software just did what other antivirus software does too.
Post reply on HN