Live data from Hacker News

Confirmed: Samsung is not shipping keyloggers

f-secure.com

1–10 of 84 posts

Re: Confirmed: Samsung is not shipping keyloggers

#3
post #2

I'm no expert of Antivirus software, but figuring whether something is a threat by its _folder name_ ??? With all the money going into the industry? That has to be some sort of april fool's prank gone really bad.

Anti-virus software is essentially useless against attackers writing their own code anyway (evading a few signatures is not that hard).

Of course, these guys are not even trying.

Re: Confirmed: Samsung is not shipping keyloggers

#4
post #2

I'm no expert of Antivirus software, but figuring whether something is a threat by its _folder name_ ??? With all the money going into the industry? That has to be some sort of april fool's prank gone really bad.

Isn't the whole "security industry" a prank gone bad?

Re: Confirmed: Samsung is not shipping keyloggers

#6
post #4
post #2

I'm no expert of Antivirus software, but figuring whether something is a threat by its _folder name_ ??? With all the money going into the industry? That has to be some sort of april fool's prank gone really bad.

Isn't the whole "security industry" a prank gone bad?

Not everything is useless. Code auditing is not necessarily useless; looking at the physical security of smart cards is not necessarily useless (but it looks like they could use some tougher certifications); pentesting/social engineering can have its uses.

That said, "security appliances" and other magical solutions tend to be rather imperfect. tptacek (of http://insecure.org/stf/secnet_ids/secnet_ids.pdf) may have something to say about that, too.

Re: Confirmed: Samsung is not shipping keyloggers

#7
False positives are the bane of IT security products in general. I would say that 90% of issues reported are FPs and the end user is expected to figure that out, confirm then double confirm before reporting it as a potential issue.

Re: Confirmed: Samsung is not shipping keyloggers

#9
This is a good reminder to always do your homework before making such a strong accusation. Samsung's reputation is probably largely undamaged, other than among people who just read the headlines on news aggregator sites. Even searching for 'Samsung Key Logger' pulls up mostly articles about the false alarm situation.

Mohamed Hassan [MSIA, CISSP, CISA and graduate of the Master of Science in Information Assurance (MSIA) program from Norwich University in 2009 as the original article prominently states], on the other hand, is probably not so lucky. Any Google search on his name from now on will probably reveal this whole debacle. Furthermore, I wouldn't be surprised if he just opened himself up to legal action by Samsung.

Re: Confirmed: Samsung is not shipping keyloggers

#10
post #4

Earlier quoted context omitted.

Isn't the whole "security industry" a prank gone bad?

Not everything is useless. Code auditing is not necessarily useless; looking at the physical security of smart cards is not necessarily useless (but it looks like they could use some tougher certifications); pentesting/social engineering can have its uses. That said, "security appliances" and other magical solutions tend to be rather imperfect. tptacek (of http://insecure.org/stf/secnet_ids/secnet_ids.pdf ) may have…

Everyone I've met who's been working in the "IT Security Industry" have been exceptionally coy about what they test for and how. After a few drinks I've managed to get out that they're testing for "XSS, and SQL injection, you know things like that".

It stinks of proprietary crap and I wonder what it would look like if they took a more OSS approach? When you can't even talk about XSS testing without a bit of prodding as if it's something exceptional it really makes me wonder what on earth these guys are selling.

Post reply on HN