Earlier quoted context omitted.
Depends on your threat model. I'm more worried about something nasty in one of the many pieces of random software I download from the internet than my AV being compromised.
Unfortunately our standard web browsers are insecure because of the way Javascripts work.
Kaspersky Lab cybersecurity firm is hacked
11–20 of 54 posts
Re: Kaspersky Lab cybersecurity firm is hacked
#12Re: Kaspersky Lab cybersecurity firm is hacked
#13Re: Kaspersky Lab cybersecurity firm is hacked
#14Here's one of the reason not to install antivirus software: if a malicious adversary finds a vuln in the AV or hacks C&C servers, you have a nice backdoor you installed to "protect" yourself.
Re: Kaspersky Lab cybersecurity firm is hacked
#15Does anyone get the impression this was some sort of early detection mechanism, done intentionally by the hackers, to know when it has been publicly discovered? Is this stupid? Probably stupid.
Alternatively, it could be a way of getting at the company's data or even to instigate a thorough review of their platform from the client's perspective. There's a lot of subtle information in the Kaspersky report that might be interesting to intelligence services: - Simultaneous Duqu & Equation Group infection of one victim - Feature coverage (and those omitted, like other payloads) - Red herrings detected/ignored; strings, faked compile timestamps - Noticed misspelling of "Excceeded" & lack of other linguistic errors
Kaspersky mulled this issue:
"So the targeting of security companies indicates that either they are very confident they won't get caught, or perhaps they don't care much if they are discovered and exposed. By targeting Kaspersky Lab, the Duqu attackers have probably taken a huge bet hoping they’d remain undiscovered; and lost."
However they also conceded that they aren't sure:
"The exact reason why Kaspersky Lab was targeted is still not clear – although the attackers did seem to focus on obtaining information about Kaspersky's future technologies, Secure OS, anti-APT solutions, KSN and APT research."
https://securelist.com/files/2015/06/The_Mystery_of_Duqu_2_0...
Re: Kaspersky Lab cybersecurity firm is hacked
#16Here's one of the reason not to install antivirus software: if a malicious adversary finds a vuln in the AV or hacks C&C servers, you have a nice backdoor you installed to "protect" yourself.
Your AV company's infrastructure is probably a lot more secure than the infrastructure of browser plugins you use and games you play.
Re: Kaspersky Lab cybersecurity firm is hacked
#17The firmware exploits are part of the attack system with Duqu 2.0, right?
[0] http://www.mcafee.com/us/security-awareness/articles/mcafee-...
[1] https://news.ycombinator.com/item?id=9685829
[2] http://www.kaspersky.com/about/news/virus/2015/equation-grou...
Re: Kaspersky Lab cybersecurity firm is hacked
#18Here's one of the reason not to install antivirus software: if a malicious adversary finds a vuln in the AV or hacks C&C servers, you have a nice backdoor you installed to "protect" yourself.
Re: Kaspersky Lab cybersecurity firm is hacked
#19Here's one of the reason not to install antivirus software: if a malicious adversary finds a vuln in the AV or hacks C&C servers, you have a nice backdoor you installed to "protect" yourself.
That's bordering on complete paranoia. You can make this argument for any software you install with auto-update capabilities... which is likely significantly more than half the software the average person has. Your AV company's infrastructure is probably a lot more secure than the infrastructure of browser plugins you use and games you play.
But we don't. Our workstations are actually fairly dumb in this regard. Why is that?
Note: Newer Windows an Mac systems might have this with their stores, I don't know. But a store isn't a requirement for this, so why have we had to wait so long?
Re: Kaspersky Lab cybersecurity firm is hacked
#20We already know Duqu was made by the same people who made Stuxnet. We already know Stuxnet was made by the US and/or Isreal to hurt the Iranian nuclear program. So if they have strong evidence it was the same people... we know who those people are and we should just say their names.