Live data from Hacker News

Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

washingtonpost.com

291–298 of 298 posts

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#291

Earlier quoted context omitted.

I'll cut you some slack because you stated you're not a malware developer. But even if you're a normal developer, you should know that telling software to do something does not mean that the software will do that something. When the software in question is subject to being controlled by adversaries, all guarantees go out of the window.

Yeah. I facepalmed at that assumption as well. It's as naive as a parent telling an 18 year old not to have friends over while they go on vacation for 2 weeks and thinking its all good from there.

You're saying nobody would be able to test if, when and what an Antivirus program is sending over the internet? If it all of a sudden is uploading enough data over to some server vs downloading (for updates) it's kind of a tall tale sign that it's phoning home with files. I don't use AV software anymore since I'm mostly on Linux, if I'm on Windows it's dedicated to Windows based programming, all my browsing is isolated usually.

You can go as far as finding the amount of data software is sending over the wire through the Task Manager -> Performance -> Resource Monitor. And to say an AntiVirus can hide this would mean it shouldn't be trusted whatsoever if it behaves like malware. The type of reputation any sane A/V company does not want to fall under.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#292

Earlier quoted context omitted.

That paragraph reeks of either journalistic license or a journalist who doesn't seem to understand what antivirus does. Every antivirus program aggressively scans for malicious programs and sends them back to the security firm for inspection and creation of fingerprints. If the collection wasn't incidental, what mechanism could the FSB exploit to non-naively identify tools that it didn't already have, and flag them f…

Your comment doesn't really say anything. Obviously, most AV software relays files back to the AV vendor's servers. But that's not what this graf implies. The graf suggests that Russian hackers are sending selectors down to the installed base of AV software to retrieve specific files, and that, once they obtained files that way, they passed the files on to Russian intelligence.

You seem to miss the part where I say

>If the collection wasn't incidental, what mechanism could the FSB exploit to non-naively identify tools that it didn't already have, and flag them for retrieval?

Emphasis on "non-naively." Antivirus seems like a highly ineffective tool for espionage of the sort being claimed in the article. You either have to blindly fish for something or already have a fingerprint of what you're looking for.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#293
post #137

Earlier quoted context omitted.

How else can you explain their obsessive occupation with The Equation Group, which they themselves claim to be a (US) state actor, targeting other (US-unfriendly) state actors? https://en.wikipedia.org/wiki/Equation_Group An ordinary anti-virus company would never get involved in state-vs-state cyber warfare, let alone pour tons of money into researching it. How does that support their business model? Do you think it…

Are you saying state sponsored malware should not be looked into? It seems like American companies tend to find Russian state-sponsored malware and Russian ones keep finding US/US allies-sponsored malware.

And in addition Israeli hackers keep on finding malware in locations they've hacked into..... hmmmmm

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#294

Our company uses the enterprise version of Kaspersky. But if we drop this over surveillance issues then it would be a pretty hypocritical to switch to AV software from the USA. Since they are proven to do the exact thing that Kaspersky is now suspected / blamed of doing. So, fellow Europeans, what now? Avast? Any other options? EDIT: Ok so I found a pretty useful Wiki list[1] with European made AV products. I haven't…

eset

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#295

Earlier quoted context omitted.

Your comment doesn't really say anything. Obviously, most AV software relays files back to the AV vendor's servers. But that's not what this graf implies. The graf suggests that Russian hackers are sending selectors down to the installed base of AV software to retrieve specific files, and that, once they obtained files that way, they passed the files on to Russian intelligence.

You seem to miss the part where I say >If the collection wasn't incidental, what mechanism could the FSB exploit to non-naively identify tools that it didn't already have, and flag them for retrieval? Emphasis on "non-naively." Antivirus seems like a highly ineffective tool for espionage of the sort being claimed in the article. You either have to blindly fish for something or already have a fingerprint of what you'r…

Obviously, they have fingerprints of what they're looking for.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#296

Earlier quoted context omitted.

You seem to miss the part where I say >If the collection wasn't incidental, what mechanism could the FSB exploit to non-naively identify tools that it didn't already have, and flag them for retrieval? Emphasis on "non-naively." Antivirus seems like a highly ineffective tool for espionage of the sort being claimed in the article. You either have to blindly fish for something or already have a fingerprint of what you'r…

Obviously, they have fingerprints of what they're looking for.

To have a hash of a file, you need the file (or a large portion of the file), especially in the context of antivirus, which searches for very specific files and needs to have a very low false positive and false negative rate. Consequently, they would already have to have the tool (or a large portion of the tool) to find it and retrieve it. A little non-productive, don't you think?

Saying that they "obviously have fingerprints of what they're looking for" is an active attempt to make the events fit a narrative.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#297
post #52
post #4

Earlier quoted context omitted.

Perhaps he was doing the bidding of his employers in order to test a theory that Kaspersky was an attack vector? I mean, this is exactly how you tell if your data has been breached or your source code leaked -- you put fake but unique records in your database then watch the dark webs for folks selling dumps containing those values; and plausible but bogus code containing unique constants then check competitors' binar…

Real data works too.

Not if your competitors have the same data in their DB.

Re: Israel Hacked Kaspersky, Then Tipped NSA Its Tools Had Been Breached

#298
post #225
post #187

Earlier quoted context omitted.

But search engines and email services? Operating systems? Europe is really not on top of this game.

Operating systems seems like a weird one to throw in there. For a start I'm pretty sure some Finnish guy wrote and maintains one of the better-known operating system kernels, which happens to be used in certain popular operating systems as Ubuntu (UK) and SuSE (Germany). Or perhaps you meant mobile operating systems, in which case I would note that the most promising and well-known mobile OS after Android, iOS, and W…

I was thinking more alongside of mobile systems, true, but I never heard of SailfishOS. I think it's pretty irrelevant in the market right now.

Also FOSS software can't solely be attributed to the one guy who started it. I would say the Linux Kernel is global and it took a lot from Unix.

Post reply on HN