This is a good reminder to always do your homework before making such a strong accusation. Samsung's reputation is probably largely undamaged, other than among people who just read the headlines on news aggregator sites. Even searching for 'Samsung Key Logger' pulls up mostly articles about the false alarm situation. Mohamed Hassan [MSIA, CISSP, CISA and graduate of the Master of Science in Information Assurance (MSI…
To be fair, Mohamed Hassan did contact Samsung support and they didn't clear up the issue. In fact, I believe they may have even confirmed that there was a key logger installed! At that point his due dilligence has been done and he has confirmation. He doesn't need to do anything further than that. Shame on Samsung support for such a pathetic showing.
Confirmed: Samsung is not shipping keyloggers
41–50 of 84 posts
Re: Confirmed: Samsung is not shipping keyloggers
#42Earlier quoted context omitted.
He did not fulfill his due diligence. Not if they're going to add this to the article: "Mohamed Hassan, MSIA, CISSP, CISA is the founder of NetSec Consulting Corp, a firm that specializes in information security consulting services. He is a senior IT Security consultant and an adjunct professor of Information Systems in the School of Business at the University of Phoenix." If they're going to pass him off as an exper…
Wait, University of Phoenix? Isn't it the same university associated with scams and sham degrees, am I wrong?
Re: Confirmed: Samsung is not shipping keyloggers
#43This is a good reminder to always do your homework before making such a strong accusation. Samsung's reputation is probably largely undamaged, other than among people who just read the headlines on news aggregator sites. Even searching for 'Samsung Key Logger' pulls up mostly articles about the false alarm situation. Mohamed Hassan [MSIA, CISSP, CISA and graduate of the Master of Science in Information Assurance (MSI…
It should also be a good reminder to all of the people on HN who jumped to the conclusion that this guy was right on very sketchy evidence. This place is influential. We should do better.
Overall in that item I think HN did better than you imply, unless you mean the upvotes the item received.
Re: Confirmed: Samsung is not shipping keyloggers
#44This is a good reminder to always do your homework before making such a strong accusation. Samsung's reputation is probably largely undamaged, other than among people who just read the headlines on news aggregator sites. Even searching for 'Samsung Key Logger' pulls up mostly articles about the false alarm situation. Mohamed Hassan [MSIA, CISSP, CISA and graduate of the Master of Science in Information Assurance (MSI…
It should also be a good reminder to all of the people on HN who jumped to the conclusion that this guy was right on very sketchy evidence. This place is influential. We should do better.
Re: Confirmed: Samsung is not shipping keyloggers
#45Earlier quoted context omitted.
Not everything is useless. Code auditing is not necessarily useless; looking at the physical security of smart cards is not necessarily useless (but it looks like they could use some tougher certifications); pentesting/social engineering can have its uses. That said, "security appliances" and other magical solutions tend to be rather imperfect. tptacek (of http://insecure.org/stf/secnet_ids/secnet_ids.pdf ) may have…
Everyone I've met who's been working in the "IT Security Industry" have been exceptionally coy about what they test for and how. After a few drinks I've managed to get out that they're testing for "XSS, and SQL injection, you know things like that". It stinks of proprietary crap and I wonder what it would look like if they took a more OSS approach? When you can't even talk about XSS testing without a bit of prodding…
Re: Confirmed: Samsung is not shipping keyloggers
#46Re: Confirmed: Samsung is not shipping keyloggers
#47Re: Confirmed: Samsung is not shipping keyloggers
#48This is a good reminder to always do your homework before making such a strong accusation. Samsung's reputation is probably largely undamaged, other than among people who just read the headlines on news aggregator sites. Even searching for 'Samsung Key Logger' pulls up mostly articles about the false alarm situation. Mohamed Hassan [MSIA, CISSP, CISA and graduate of the Master of Science in Information Assurance (MSI…
It should also be a good reminder to all of the people on HN who jumped to the conclusion that this guy was right on very sketchy evidence. This place is influential. We should do better.
Reddit fared much worse, IMO, in that people continued to upvote the wrong story after the truth was out. The correction has been posted but isn't anywhere near the front page.
Re: Confirmed: Samsung is not shipping keyloggers
#49Earlier quoted context omitted.
Wait, University of Phoenix? Isn't it the same university associated with scams and sham degrees, am I wrong?
Not sham degrees, exactly. They require the absolute minimum level of educational achievement necessary to edge over the fuzzy line between a diploma mill and legitimate education. Students go to UoP to get a piece of paper that helps their career and that they would generally be incapable of acquiring at a real university, while in exchange UoP is there to milk the students for every federally-guaranteed loan they c…
Wait, so just like a real university?
Re: Confirmed: Samsung is not shipping keyloggers
#50Perhaps I read it wrong, but the article never says Samsung didn't ship a keylogger, it just indicates that the AV software can make false positives based on a folder. Can we get a link to an article that actually checks a Samsung laptop (and lists their methodology, not this "Duh, there were not any keyloggers") instead of anecdotal evidence and attacking the previous reseaerchers methods? Even if the previous guy w…
1) The whole saga was caused by a bad antivirus alert. This story never even happens if not for that.
2) They checked a set of Samsung laptops and found no trace of keylogger software. See http://www.f-secure.com/weblog/archives/00002132.html
Is there more you'd like to see be done?