Live data from Hacker News

Confirmed: Samsung is not shipping keyloggers

f-secure.com

21–30 of 84 posts

Re: Confirmed: Samsung is not shipping keyloggers

#21
post #18

Earlier quoted context omitted.

To be fair, Mohamed Hassan did contact Samsung support and they didn't clear up the issue. In fact, I believe they may have even confirmed that there was a key logger installed! At that point his due dilligence has been done and he has confirmation. He doesn't need to do anything further than that. Shame on Samsung support for such a pathetic showing.

He did not fulfill his due diligence. Not if they're going to add this to the article: "Mohamed Hassan, MSIA, CISSP, CISA is the founder of NetSec Consulting Corp, a firm that specializes in information security consulting services. He is a senior IT Security consultant and an adjunct professor of Information Systems in the School of Business at the University of Phoenix." If they're going to pass him off as an exper…

Wait, University of Phoenix? Isn't it the same university associated with scams and sham degrees, am I wrong?

Re: Confirmed: Samsung is not shipping keyloggers

#22

This is a good reminder to always do your homework before making such a strong accusation. Samsung's reputation is probably largely undamaged, other than among people who just read the headlines on news aggregator sites. Even searching for 'Samsung Key Logger' pulls up mostly articles about the false alarm situation. Mohamed Hassan [MSIA, CISSP, CISA and graduate of the Master of Science in Information Assurance (MSI…

It should also be a good reminder to all of the people on HN who jumped to the conclusion that this guy was right on very sketchy evidence. This place is influential. We should do better.

Re: Confirmed: Samsung is not shipping keyloggers

#24
post #21
post #18

Earlier quoted context omitted.

He did not fulfill his due diligence. Not if they're going to add this to the article: "Mohamed Hassan, MSIA, CISSP, CISA is the founder of NetSec Consulting Corp, a firm that specializes in information security consulting services. He is a senior IT Security consultant and an adjunct professor of Information Systems in the School of Business at the University of Phoenix." If they're going to pass him off as an exper…

Wait, University of Phoenix? Isn't it the same university associated with scams and sham degrees, am I wrong?

[deleted]

Re: Confirmed: Samsung is not shipping keyloggers

#25

This is a good reminder to always do your homework before making such a strong accusation. Samsung's reputation is probably largely undamaged, other than among people who just read the headlines on news aggregator sites. Even searching for 'Samsung Key Logger' pulls up mostly articles about the false alarm situation. Mohamed Hassan [MSIA, CISSP, CISA and graduate of the Master of Science in Information Assurance (MSI…

> Any Google search on his name from now on will probably reveal this whole debacle. Actually, he has a sufficiently common name that those results will be relegated to the 2nd or 3rd page of search results within a few weeks: http://www.google.com/search?q=Mohamed+Hassan

Probably not if you throw in a few relevant keywords like 'security'.

Re: Confirmed: Samsung is not shipping keyloggers

#26
post #21
post #18

Earlier quoted context omitted.

He did not fulfill his due diligence. Not if they're going to add this to the article: "Mohamed Hassan, MSIA, CISSP, CISA is the founder of NetSec Consulting Corp, a firm that specializes in information security consulting services. He is a senior IT Security consultant and an adjunct professor of Information Systems in the School of Business at the University of Phoenix." If they're going to pass him off as an exper…

Wait, University of Phoenix? Isn't it the same university associated with scams and sham degrees, am I wrong?

UoP is accredited by the same board which accredits University of Michigan. [http://www.phoenix.edu/about_us/accreditation.html] For whatever that is worth.

They have experienced difficulty regarding the rates at which students receiving Federal Financial Aid graduate - i.e. their issues are based on low graduation rates and not based on being a diploma mill.

Disclosure: my spouse teaches for UoP part time.

Re: Confirmed: Samsung is not shipping keyloggers

#27
post #21
post #18

Earlier quoted context omitted.

He did not fulfill his due diligence. Not if they're going to add this to the article: "Mohamed Hassan, MSIA, CISSP, CISA is the founder of NetSec Consulting Corp, a firm that specializes in information security consulting services. He is a senior IT Security consultant and an adjunct professor of Information Systems in the School of Business at the University of Phoenix." If they're going to pass him off as an exper…

Wait, University of Phoenix? Isn't it the same university associated with scams and sham degrees, am I wrong?

[deleted]

Re: Confirmed: Samsung is not shipping keyloggers

#28
If you Google http://www.google.com/search?q=samsung+keylogger+monitor+the...

You'll have thousands of quotes from a so-called "Samsung supervisor" who "said it's used to "monitor the performance of the machine and to find out how it is being used."

What is this bullshit ? From where did the quote come from ?

Amazing how most are just copy-paste. It just prove that very few online news websites verify their source if the keylogger claim is false.

Re: Confirmed: Samsung is not shipping keyloggers

#29
post #2

I'm no expert of Antivirus software, but figuring whether something is a threat by its _folder name_ ??? With all the money going into the industry? That has to be some sort of april fool's prank gone really bad.

AV software is written to pass the tests of AV software reviewers. This is subtly but importantly different from "written to accurately detect and block malware"; in particular, it's extremely difficult for a reviewer to test an AV's ability to block completely novel malware (unless they're a malware author themselves or connected with someone who is). So, people tend to set the AV software to scanning a folder full of known samples and judging the software on how many it detected (this is a nice, easy metric: you can make bar graphs out of it!) - in this situation, if chucking in a signature for C:\windows\SL gives you an easy extra malware detection at the cost of a false positive (that no reviewer's going to spot anyway), it's a no brainer.
Post reply on HN