Live data from Hacker News

Kaspersky Lab cybersecurity firm is hacked

bbc.com

11–20 of 54 posts

Re: Kaspersky Lab cybersecurity firm is hacked

#11
post #7

Earlier quoted context omitted.

Depends on your threat model. I'm more worried about something nasty in one of the many pieces of random software I download from the internet than my AV being compromised.

Unfortunately our standard web browsers are insecure because of the way Javascripts work.

In practice, JavaScript on the Web doesn't seem to be very high on the list of malware vectors.

Re: Kaspersky Lab cybersecurity firm is hacked

#14
post #5

Here's one of the reason not to install antivirus software: if a malicious adversary finds a vuln in the AV or hacks C&C servers, you have a nice backdoor you installed to "protect" yourself.

Yes, but it's a bit paranoid. Windows and Office are likely going to give you more entry points than the net gain you get from having antivirus/malware protection.

Re: Kaspersky Lab cybersecurity firm is hacked

#15
post #13

Does anyone get the impression this was some sort of early detection mechanism, done intentionally by the hackers, to know when it has been publicly discovered? Is this stupid? Probably stupid.

I personally believe this is a honeypot or trial of sorts. The reason could've been to determine whether or not the intrusion was detected at all as a sort of validation of just how "almost invisible" the malware is, or it could've been to determine the time required to detect.

Alternatively, it could be a way of getting at the company's data or even to instigate a thorough review of their platform from the client's perspective. There's a lot of subtle information in the Kaspersky report that might be interesting to intelligence services: - Simultaneous Duqu & Equation Group infection of one victim - Feature coverage (and those omitted, like other payloads) - Red herrings detected/ignored; strings, faked compile timestamps - Noticed misspelling of "Excceeded" & lack of other linguistic errors

Kaspersky mulled this issue:

"So the targeting of security companies indicates that either they are very confident they won't get caught, or perhaps they don't care much if they are discovered and exposed. By targeting Kaspersky Lab, the Duqu attackers have probably taken a huge bet hoping they’d remain undiscovered; and lost."

However they also conceded that they aren't sure:

"The exact reason why Kaspersky Lab was targeted is still not clear – although the attackers did seem to focus on obtaining information about Kaspersky's future technologies, Secure OS, anti-APT solutions, KSN and APT research."

https://securelist.com/files/2015/06/The_Mystery_of_Duqu_2_0...

Re: Kaspersky Lab cybersecurity firm is hacked

#16
post #5

Here's one of the reason not to install antivirus software: if a malicious adversary finds a vuln in the AV or hacks C&C servers, you have a nice backdoor you installed to "protect" yourself.

That's bordering on complete paranoia. You can make this argument for any software you install with auto-update capabilities... which is likely significantly more than half the software the average person has.

Your AV company's infrastructure is probably a lot more secure than the infrastructure of browser plugins you use and games you play.

Re: Kaspersky Lab cybersecurity firm is hacked

#17
Intel Security just reported that "[p]ersistent and virtually undetectable attacks by the Equation Group that reprogram hard disk drives and solid state drive firmware."[0,1] It's interesting that this threat was first reported by Kaspersky in February.[2]

The firmware exploits are part of the attack system with Duqu 2.0, right?

[0] http://www.mcafee.com/us/security-awareness/articles/mcafee-...

[1] https://news.ycombinator.com/item?id=9685829

[2] http://www.kaspersky.com/about/news/virus/2015/equation-grou...

Re: Kaspersky Lab cybersecurity firm is hacked

#18
post #5

Here's one of the reason not to install antivirus software: if a malicious adversary finds a vuln in the AV or hacks C&C servers, you have a nice backdoor you installed to "protect" yourself.

I also knew a guy who wore a seat belt and it broke his neck when he crashed his car into a tree. I still wear a seat belt.

Re: Kaspersky Lab cybersecurity firm is hacked

#19
post #5

Here's one of the reason not to install antivirus software: if a malicious adversary finds a vuln in the AV or hacks C&C servers, you have a nice backdoor you installed to "protect" yourself.

That's bordering on complete paranoia. You can make this argument for any software you install with auto-update capabilities... which is likely significantly more than half the software the average person has. Your AV company's infrastructure is probably a lot more secure than the infrastructure of browser plugins you use and games you play.

If, like our phones, workstation software actually had to request specific access at install or use, then it would be much more dangerous if software that needed quite extensive access was exploited like this.

But we don't. Our workstations are actually fairly dumb in this regard. Why is that?

Note: Newer Windows an Mac systems might have this with their stores, I don't know. But a store isn't a requirement for this, so why have we had to wait so long?

Re: Kaspersky Lab cybersecurity firm is hacked

#20
A lot of beating around the bush; just say the US and/or Isreal did it.

We already know Duqu was made by the same people who made Stuxnet. We already know Stuxnet was made by the US and/or Isreal to hurt the Iranian nuclear program. So if they have strong evidence it was the same people... we know who those people are and we should just say their names.

Post reply on HN