Live data from Hacker News

Confirmed: Samsung is not shipping keyloggers

f-secure.com

41–50 of 84 posts

Re: Confirmed: Samsung is not shipping keyloggers

#41

This is a good reminder to always do your homework before making such a strong accusation. Samsung's reputation is probably largely undamaged, other than among people who just read the headlines on news aggregator sites. Even searching for 'Samsung Key Logger' pulls up mostly articles about the false alarm situation. Mohamed Hassan [MSIA, CISSP, CISA and graduate of the Master of Science in Information Assurance (MSI…

To be fair, Mohamed Hassan did contact Samsung support and they didn't clear up the issue. In fact, I believe they may have even confirmed that there was a key logger installed! At that point his due dilligence has been done and he has confirmation. He doesn't need to do anything further than that. Shame on Samsung support for such a pathetic showing.

[deleted]

Re: Confirmed: Samsung is not shipping keyloggers

#42
post #21
post #18

Earlier quoted context omitted.

He did not fulfill his due diligence. Not if they're going to add this to the article: "Mohamed Hassan, MSIA, CISSP, CISA is the founder of NetSec Consulting Corp, a firm that specializes in information security consulting services. He is a senior IT Security consultant and an adjunct professor of Information Systems in the School of Business at the University of Phoenix." If they're going to pass him off as an exper…

Wait, University of Phoenix? Isn't it the same university associated with scams and sham degrees, am I wrong?

Not sham degrees, exactly. They require the absolute minimum level of educational achievement necessary to edge over the fuzzy line between a diploma mill and legitimate education. Students go to UoP to get a piece of paper that helps their career and that they would generally be incapable of acquiring at a real university, while in exchange UoP is there to milk the students for every federally-guaranteed loan they can qualify for.

Re: Confirmed: Samsung is not shipping keyloggers

#43
post #22

This is a good reminder to always do your homework before making such a strong accusation. Samsung's reputation is probably largely undamaged, other than among people who just read the headlines on news aggregator sites. Even searching for 'Samsung Key Logger' pulls up mostly articles about the false alarm situation. Mohamed Hassan [MSIA, CISSP, CISA and graduate of the Master of Science in Information Assurance (MSI…

It should also be a good reminder to all of the people on HN who jumped to the conclusion that this guy was right on very sketchy evidence. This place is influential. We should do better.

I think the vast majority of top-level comments on that item considered the information dubious or were holding out for independent confirmation; I don't think HN leapt to a conclusion. My comment, one of the less obvious, was more from a good-idea perspective instead of assuming the story was true -- I had not decided yet.

Overall in that item I think HN did better than you imply, unless you mean the upvotes the item received.

Re: Confirmed: Samsung is not shipping keyloggers

#44
post #22

This is a good reminder to always do your homework before making such a strong accusation. Samsung's reputation is probably largely undamaged, other than among people who just read the headlines on news aggregator sites. Even searching for 'Samsung Key Logger' pulls up mostly articles about the false alarm situation. Mohamed Hassan [MSIA, CISSP, CISA and graduate of the Master of Science in Information Assurance (MSI…

It should also be a good reminder to all of the people on HN who jumped to the conclusion that this guy was right on very sketchy evidence. This place is influential. We should do better.

Thankfully, it looked to be very few people. His article was written--and his tests were conducted--just about as poorly as they could have been. It was a huge show, and HN caught on quickly as far as I can tell.

Re: Confirmed: Samsung is not shipping keyloggers

#45

Earlier quoted context omitted.

Not everything is useless. Code auditing is not necessarily useless; looking at the physical security of smart cards is not necessarily useless (but it looks like they could use some tougher certifications); pentesting/social engineering can have its uses. That said, "security appliances" and other magical solutions tend to be rather imperfect. tptacek (of http://insecure.org/stf/secnet_ids/secnet_ids.pdf ) may have…

Everyone I've met who's been working in the "IT Security Industry" have been exceptionally coy about what they test for and how. After a few drinks I've managed to get out that they're testing for "XSS, and SQL injection, you know things like that". It stinks of proprietary crap and I wonder what it would look like if they took a more OSS approach? When you can't even talk about XSS testing without a bit of prodding…

I've met some guys who were pretty fit in encryption topics / key management etc on whole corporations. And it actually works, so you rarely hear about that. Quite some skills are needed to master that actually.

Re: Confirmed: Samsung is not shipping keyloggers

#46
The laptop story yesterday led me to learn about CarrierIQ on my cell phone, which was equally disturbing. Maybe the laptop was a false alarm, but my Samsung cell phone did indeed have a keylogger on it. So I'm not inclined to cut them a lot of slack right now. http://forum.xda-developers.com/showpost.php?p=11763089

Re: Confirmed: Samsung is not shipping keyloggers

#48
post #22

This is a good reminder to always do your homework before making such a strong accusation. Samsung's reputation is probably largely undamaged, other than among people who just read the headlines on news aggregator sites. Even searching for 'Samsung Key Logger' pulls up mostly articles about the false alarm situation. Mohamed Hassan [MSIA, CISSP, CISA and graduate of the Master of Science in Information Assurance (MSI…

It should also be a good reminder to all of the people on HN who jumped to the conclusion that this guy was right on very sketchy evidence. This place is influential. We should do better.

HN had many skeptical comments right off the bat. I guess simply publicizing this story before its confirmed is bad, but it's also how you shine light on an issue - in this case, clearing Samsung of any wrongdoing.

Reddit fared much worse, IMO, in that people continued to upvote the wrong story after the truth was out. The correction has been posted but isn't anywhere near the front page.

Re: Confirmed: Samsung is not shipping keyloggers

#49
post #42
post #21

Earlier quoted context omitted.

Wait, University of Phoenix? Isn't it the same university associated with scams and sham degrees, am I wrong?

Not sham degrees, exactly. They require the absolute minimum level of educational achievement necessary to edge over the fuzzy line between a diploma mill and legitimate education. Students go to UoP to get a piece of paper that helps their career and that they would generally be incapable of acquiring at a real university, while in exchange UoP is there to milk the students for every federally-guaranteed loan they c…

Students go to UoP to get a piece of paper that helps their career ... while in exchange UoP is there to milk the students for every federally-guaranteed loan they can qualify for.

Wait, so just like a real university?

Re: Confirmed: Samsung is not shipping keyloggers

#50

Perhaps I read it wrong, but the article never says Samsung didn't ship a keylogger, it just indicates that the AV software can make false positives based on a folder. Can we get a link to an article that actually checks a Samsung laptop (and lists their methodology, not this "Duh, there were not any keyloggers") instead of anecdotal evidence and attacking the previous reseaerchers methods? Even if the previous guy w…

The article says two things:

1) The whole saga was caused by a bad antivirus alert. This story never even happens if not for that.

2) They checked a set of Samsung laptops and found no trace of keylogger software. See http://www.f-secure.com/weblog/archives/00002132.html

Is there more you'd like to see be done?

Post reply on HN