A lot of beating around the bush; just say the US and/or Isreal did it. We already know Duqu was made by the same people who made Stuxnet. We already know Stuxnet was made by the US and/or Isreal to hurt the Iranian nuclear program. So if they have strong evidence it was the same people... we know who those people are and we should just say their names.
Kaspersky Lab cybersecurity firm is hacked
31–40 of 54 posts
Re: Kaspersky Lab cybersecurity firm is hacked
#32Here's one of the reason not to install antivirus software: if a malicious adversary finds a vuln in the AV or hacks C&C servers, you have a nice backdoor you installed to "protect" yourself.
Depends on your threat model. I'm more worried about something nasty in one of the many pieces of random software I download from the internet than my AV being compromised.
Re: Kaspersky Lab cybersecurity firm is hacked
#33Earlier quoted context omitted.
Depends on your threat model. I'm more worried about something nasty in one of the many pieces of random software I download from the internet than my AV being compromised.
I hear a lot of people talk about security but very few people talk about threat models. We need more of this.
The obvious distinctions that spring to my (uninformed) mind are: active (mitm, injection) vs passive (snooping, traffic analysis), targeted/opportunistic (maybe insider/outsider too?), and perhaps level of available resources (on the s'kiddie - lone hacker - collective - governmental spectrum, or something)
I guess the biggest problem with not having a coherent threat model is that you can end up putting too much effort into the wrong things and have a false confidence in your security. Weakest links, and all that.
Re: Kaspersky Lab cybersecurity firm is hacked
#34Earlier quoted context omitted.
> than they did in exposing Russian and Chinese govt actors in the same arena. That's the job of Western companies. Keeps everyone honest. Western companies have as much bias as anyone, they are just good at covering it up with rhetoric... and Americans are good at deluding themselves about their own bias and Nationalism which is no different from anyone else's. > On balance, with the current regimes in those countri…
On balance, with the current regimes in those countries, I prefer the western alternative to these regimes. It's not as if they are equivalent just with a different opinion. I truly prefer my western govt's over Russia and China's, no doubts.
what a world we got ourselves into! :)
Re: Kaspersky Lab cybersecurity firm is hacked
#35Earlier quoted context omitted.
I'm sure it knew it was a target for this kind of thing since they did exhibit bias. That is to say they showed greater interest in exposing western gov't hacking capabilities and activities than they did in exposing Russian and Chinese govt actors in the same arena. I'm sure this is no surprise to them.
> than they did in exposing Russian and Chinese govt actors in the same arena. That's the job of Western companies. Keeps everyone honest. Western companies have as much bias as anyone, they are just good at covering it up with rhetoric... and Americans are good at deluding themselves about their own bias and Nationalism which is no different from anyone else's. > On balance, with the current regimes in those countri…
In all honesty, I still think that western security companies have less bias than those working in less free societies.
Re: Kaspersky Lab cybersecurity firm is hacked
#36Re: Kaspersky Lab cybersecurity firm is hacked
#37Here's one of the reason not to install antivirus software: if a malicious adversary finds a vuln in the AV or hacks C&C servers, you have a nice backdoor you installed to "protect" yourself.
That's bordering on complete paranoia. You can make this argument for any software you install with auto-update capabilities... which is likely significantly more than half the software the average person has. Your AV company's infrastructure is probably a lot more secure than the infrastructure of browser plugins you use and games you play.
Well I'm not a security expert and I'm using Linux, so I don't use a Windows antivirus obviously. A quick test trying to download free or trial Windows antivirus software (I'm not willing to pay for this simple experiment):
Kaspersky:
- google Kaspersky
- google result leads to http site, all the way to the download of the trial version it's http (I'm sure at least 80% of users don't notice this)
- try to type in manually https://www.kaspersky.com
- it redirects to http://www.kaspersky.com !!!!
Ok let's try Avast, it's popular, isn't it? - ok it's all https, http redirects to https, it could even have HSTS, didn't check.
- download links to http CNET site ...
- I have to allow half the World's third party js to get to the download.
- It's of course http,
- Manually rewrite it to https (not straightforward, it's behind a redirection), invalid certificate (issued to a248.e.akamai.net instead of software-files-a.cnet.com
- Its installer is probably loaded with CNET crapware anyway
Downloading Avira worked fine though, I only tried these three. These companies are supposed to be security vendors, this is freaking ridiculous.Re: Kaspersky Lab cybersecurity firm is hacked
#38Earlier quoted context omitted.
On balance, with the current regimes in those countries, I prefer the western alternative to these regimes. It's not as if they are equivalent just with a different opinion. I truly prefer my western govt's over Russia and China's, no doubts.
sounds like picking-of-lesser-evil discussion to me, which is still a bit sad considering topic... what a world we got ourselves into! :)
Re: Kaspersky Lab cybersecurity firm is hacked
#39Re: Kaspersky Lab cybersecurity firm is hacked
#40Here's one of the reason not to install antivirus software: if a malicious adversary finds a vuln in the AV or hacks C&C servers, you have a nice backdoor you installed to "protect" yourself.
That's bordering on complete paranoia. You can make this argument for any software you install with auto-update capabilities... which is likely significantly more than half the software the average person has. Your AV company's infrastructure is probably a lot more secure than the infrastructure of browser plugins you use and games you play.
Certainly not everyone will do this. Although it is probably no longer considered part of the maniac fringe, I don't think it's going to be mainstream any time soon. However, the benefits are not imaginary.