Live data from Hacker News

How Antivirus Companies Handle State-Sponsored Malware

schneier.com

1–10 of 16 posts

Re: How Antivirus Companies Handle State-Sponsored Malware

#2
>>ESET, F-Secure, Norman Shark, Kaspersky, Panda and Trend Micro confirmed the detection of state sponsored malware, e.g. R2D2 and FinFisher; they have never received a request to not detect malware. And if they were asked by any government to do so in the future, they said they would not comply.

Glad to here we're safe.

Re: How Antivirus Companies Handle State-Sponsored Malware

#3
I remember the BMG Sony rootkit scandal vividly (http://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootki...)

Most of all I remember that the only company not willing to sit tight was FSecure. They contacted BMG Sony and where about to go public, when Mark Russinovich publicized this atrocity. At least that's how I recall it.

It's since then that I have zero faith in security software vendors.

Re: How Antivirus Companies Handle State-Sponsored Malware

#4
NSA doesn't need to ask anti-virus companies to ignore certain malware, as long as Microsoft is handing them lists of fresh Windows vulnerabilities months before they even begin working on fixing them.

http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t...

Until that policy changes at Microsoft, at least 90 percent of the PC users will never be truly safe.

Re: How Antivirus Companies Handle State-Sponsored Malware

#6
>> My reasoning is that antivirus is a very international industry, and while a government might get its own companies to play along, it would not be able to influence international companies.

this sounds more like an assumption than reasoning. given all we know to date about the operations of the NSA and the CIA (they collaborate closely at times), we should not be so hasty in dismissing such an important topic.

>> Understanding that the companies could certainly lie, this is the response so far: no one has admitted to doing so.

well.. they wouldn't, would they.

Re: How Antivirus Companies Handle State-Sponsored Malware

#8
post #4

NSA doesn't need to ask anti-virus companies to ignore certain malware, as long as Microsoft is handing them lists of fresh Windows vulnerabilities months before they even begin working on fixing them. http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t... Until that policy changes at Microsoft, at least 90 percent of the PC users will never be truly safe.

Microsoft does that publicly all the time. I work for a large enterprise organization, and we get notifications from Microsoft of vulnerabilities that have not been patched yet. The point is that we can mitigate the risk while waiting for the patch.

We're not running out to exploit the vulnerability in our competitor's system. The NSA or other malicious actors may be, sure, but I have doubts that this is what Microsoft wants to have happen. The goal is to mitigate the risk while a patch is being made. Microsoft doesn't want their software to be exploited, period.

Re: How Antivirus Companies Handle State-Sponsored Malware

#10
There are now some companies which provide non-signature based anti-virus detection to potentially detect zero-day malware. Most of them work by spinning up a vm, run or open the file to check, and verify any changes to the system. Check out http://www.fireeye.com/ (funded by the CIA's startup incubator In-Q-Tel) http://www.fidelissecurity.com/ (from General Dynamics) and Northrop Grumman is releasing one soon too.

Not sure if I'd trust these companies more or less than the signature based companies.

Post reply on HN