Live data from Hacker News

Kaspersky: Yes, we obtained NSA secrets. No, we didn’t help steal them

arstechnica.com

41–50 of 139 posts

Re: Kaspersky: Yes, we obtained NSA secrets. No, we didn’t help steal them

#41
post #6

So an NSA contractor or employee takes confidential/highly sensitive code and documents home and leaves it on their machine. They then install a pirated version of Office, after disabling their antivirus software which is telling them it is infected with a virus and preventing the installation. Seems like massive incompetence from this user rather than Kaspersky doing anything malicious, and those files where destine…

You are being naive. You can not operate a business the size of Kaspersky in Russia without being a part of the the inner circle.

Re: Kaspersky: Yes, we obtained NSA secrets. No, we didn’t help steal them

#42

Before this article was published I don't think it was alleged that Kaspersky ever did anything. All the public knew is that allegedly Israel hacked Kaspersky and noticed the Russian government using Kaspersky's tools to try and dig out secret documents. I mean who knows, maybe the Russian government had a backdoor that they were abusing, maybe they hacked Kaspersky themselves, or maybe they were just given access. I…

"Israelis were watching in real-time as agents searched computers around the world for secret codenames"

is just a highly misleading way of saying

"Kaspersky added strings/.text/.rodata from the analysed malware sample to their virus database"

And no shit, a antivirus will then search computers "around the world" (this qualifier is here.. why?) for that data. That is why you paid for it.

The objectionable part here is "Iraelis were watching" but nobody seems all too concerned any more with economic espionage.

Re: Kaspersky: Yes, we obtained NSA secrets. No, we didn’t help steal them

#43
post #29
post #11

Earlier quoted context omitted.

> Just as is Russian “collusion” with trump. Absolutely zero evidence at all only unnamed sources and speculation. Just out of curiosity, what makes you think there is zero evidence? How would we know what evidence Mueller's team has uncovered? How do you reconcile all of the interactions between the trump campaign and the various Russian entities involved?

None of which were illegal. There has been zero evidence uncovered or produced by anyone in 10 months. This is nothing but a witch hunt to demonize some idiot the left hates. It’s transparent and disappointing. While the left gets away with Benghazi and uranium one. There is no justice only the decision of those in power.

> away with Benghazi

Wasn't Benghazi investigated to death by the right for an absurdly long time? Why do you think nothing was found?

I'm not sure if your willfully trolling or actually believe the misinformation you are spreading, and I'm not sure which is worse.

Re: Kaspersky: Yes, we obtained NSA secrets. No, we didn’t help steal them

#44
post #6

So an NSA contractor or employee takes confidential/highly sensitive code and documents home and leaves it on their machine. They then install a pirated version of Office, after disabling their antivirus software which is telling them it is infected with a virus and preventing the installation. Seems like massive incompetence from this user rather than Kaspersky doing anything malicious, and those files where destine…

Incompetence? For all we know that guy was trying to sell the data to China or Saudi Arabia. Why isn't his investigation a bigger story? I thought the NSA hated leakers?

Re: Kaspersky: Yes, we obtained NSA secrets. No, we didn’t help steal them

#45

Earlier quoted context omitted.

The best part of all of this is how there is all this media coverage on a fricking antivirus, but nobody seems all too concerned with the NSA losing more secrets. It's like incident #100, maybe Kaspersky is the KGB, good on them since they are clearly more competent than the NSA. Maybe we can poach them?

Stands to reason that the media coverage is a smoke screen to eat up attention on the issue. Easier to give people a boogeyman so they don't have as much energy to spend on noticing the really important problems. And our media outlets will happily run with anything that produces those sweet clicks.

Our media outlets will happily run anything the government tells them. Here is the line from that infamous NYT article:

"The current and former government officials who described the episode spoke about it on condition of anonymity because of classification rules."

And now you know why Snowden wouldn't touch the NYT with 10 foot pole. This isn't "current and former government officials" committing a felony and treason to leak information to the NYT, no, they are just telling that reporter the NSA press report with a hushed voice.

Re: Kaspersky: Yes, we obtained NSA secrets. No, we didn’t help steal them

#46
post #3

I have to ask: Is there any concrete evidence against Kaspersky doing anything remotely concerning since this whole charade against them started in 2015 or is it still "they're Russian, so they must be doing something bad" scenario? EDIT: Fuck if I understand why people like JohnStrange, revelation and ryanlol are downvoted in their replies to this comment. They're on topic.

The simplest argument to make is that, regardless of whether the top people at Kaspersky are gleefully collaborating with the Russian government, they probably are required to give the Russian security service a backdoor to their networks as a condition of existing.

Given what we know about the feds installing black boxes in ISPs' networks here in the US- a country nominally committed to the rule of law- it seems somewhat naive to think that the Russian government doesn't have access to Kaspersky servers.

Does that make Kaspersky uniquely evil? Probably not. Do the feds have an agreement with Microsoft to take a peek at anything they turn up from a foreign intelligence service? I don't know. It wouldn't be too surprising.

Re: Kaspersky: Yes, we obtained NSA secrets. No, we didn’t help steal them

#47

The article contains a useful recap of the evidence so far regarding this particular Kapersky issue, but the news is Kerpersky's denial. I don't take the latter to mean too much either way; when you get into the world of intelligence, plausible denials are the norm, and corporations practice it pretty commonly too. Of course the U.S. government had to remove Kapersky from its computers. Russian intelligence has been…

What I find hilarious about this whole story is that the US government allowed highly intrusive software from a non-allied country on government machines in the first place. It seems fairly reasonable to restrict software on machines that potentially hold confidential information (incl. e.g. patient data, payrolls) to software that is produced in the same country or by companies of close allies, or at least by compan…

I don't know what the particular condition with Kaspersky and the US government was, but I work for a non-US based software company that has multiple special contracts with the US Federal Government; we have a special build of the software which was remade piece by piece on US soil, meets some Federal encryption guidelines, and our support is very strict on who can do what with any Federal Government account.

I'm not sure if this is common place or not, but I was under the impression that if you were from outside the US and wanted to land Federal contracts, you had to be ready to bend over a bit for the US Federal Government. No other government gets the same treatment currently.

Re: Kaspersky: Yes, we obtained NSA secrets. No, we didn’t help steal them

#48

The article contains a useful recap of the evidence so far regarding this particular Kapersky issue, but the news is Kerpersky's denial. I don't take the latter to mean too much either way; when you get into the world of intelligence, plausible denials are the norm, and corporations practice it pretty commonly too. Of course the U.S. government had to remove Kapersky from its computers. Russian intelligence has been…

What I find hilarious about this whole story is that the US government allowed highly intrusive software from a non-allied country on government machines in the first place. It seems fairly reasonable to restrict software on machines that potentially hold confidential information (incl. e.g. patient data, payrolls) to software that is produced in the same country or by companies of close allies, or at least by compan…

> the US government allowed highly intrusive software from a non-allied country on government machines in the first place.

This is the key point. Also, the US Government was recently found to have fake Kaspersky SSL certs.

Re: Kaspersky: Yes, we obtained NSA secrets. No, we didn’t help steal them

#49
post #5

Kasperky's story here seems completely believable. Yet the US government's warnings also seem reasonable even given just the facts everyone agrees on. I guess the larger lesson may be how Russia's failure to establish rule of law makes it impossible to run a business that depends on trust. The US should take note: if they succeed in breaking Apple et al's attempts to protect their users, pretty soon the only countrie…

> Yet the US government's warnings also seem reasonable even given just the facts everyone agrees on.

But somehow these warnings only became necessary in the past year or so, when the US has had ongoing conflict with Russia over the past 20 years?

Re: Kaspersky: Yes, we obtained NSA secrets. No, we didn’t help steal them

#50
post #31
post #6

So an NSA contractor or employee takes confidential/highly sensitive code and documents home and leaves it on their machine. They then install a pirated version of Office, after disabling their antivirus software which is telling them it is infected with a virus and preventing the installation. Seems like massive incompetence from this user rather than Kaspersky doing anything malicious, and those files where destine…

> those files where destined to be leaked somehow the moment they left the NSA Those files were destined to be leaked somehow the moment they were created. > Seems like massive incompetence from this user So when we delete production data, it is a process failure[Gitlab postmortem] but when employees at a three letter agency cause spillage, it is a felony? It is wrong on several counts. One: this is data that we shou…

> So when we delete production data, it is a process failure[Gitlab postmortem] but when employees at a three letter agency cause spillage, it is a felony?

Are you equating an accident that resulted in deleted data with someone intentionally taking confidential materials and putting them on an insecure, personal computer?

Post reply on HN