Live data from Hacker News

Kaspersky Lab cybersecurity firm is hacked

bbc.com

41–50 of 54 posts

Re: Kaspersky Lab cybersecurity firm is hacked

#41
post #33

Earlier quoted context omitted.

I hear a lot of people talk about security but very few people talk about threat models. We need more of this.

Are there any good introductory taxonomies or categorisations of threats and potentially appropriate responses? The obvious distinctions that spring to my (uninformed) mind are: active (mitm, injection) vs passive (snooping, traffic analysis), targeted/opportunistic (maybe insider/outsider too?), and perhaps level of available resources (on the s'kiddie - lone hacker - collective - governmental spectrum, or something…

STRIDE is the acronym used at Microsoft to categorize different threat types. STRIDE stands for:

Spoofing Spoofing is attempting to gain access to a system by using a false identity. This can be accomplished using stolen user credentials or a false IP address. After the attacker successfully gains access as a legitimate user or host, elevation of privileges or abuse using authorization can begin.

Tampering Tampering is the unauthorized modification of data, for example as it flows over a network between two computers.

Repudiation Repudiation is the ability of users (legitimate or otherwise) to deny that they performed specific actions or transactions. Without adequate auditing, repudiation attacks are difficult to prove.

Information disclosure Information disclosure is the unwanted exposure of private data. For example, a user views the contents of a table or file he or she is not authorized to open, or monitors data passed in plaintext over a network. Some examples of information disclosure vulnerabilities include the use of hidden form fields, comments embedded in Web pages that contain database connection strings and connection details, and weak exception handling that can lead to internal system level details being revealed to the client. Any of this information can be very useful to the attacker.

Denial of service Denial of service is the process of making a system or application unavailable. For example, a denial of service attack might be accomplished by bombarding a server with requests to consume all available system resources or by passing it malformed input data that can crash an application process.

Elevation of privilege Elevation of privilege occurs when a user with limited privileges assumes the identity of a privileged user to gain privileged access to an application. For example, an attacker with limited privileges might elevate his or her privilege level to compromise and take control of a highly privileged and trusted process or account.

They use the DREAD model to calculate threat impact (risk). You can get the risk rating for a given threat by asking the following questions:

Damage potential How great is the damage if the vulnerability is exploited?

Reproducibility How easy is it to reproduce the attack?

Exploitability How easy is it to launch an attack?

Affected users As a rough percentage, how many users are affected?

Discoverability How easy is it to find the vulnerability?

Therese's more detail in chapter 3 [1] (threat modelling) of the book Improving Web Application Security: Threats and Countermeasures [2] Note the book was published 12 years ago.

[1] https://msdn.microsoft.com/en-us/library/ff648644.aspx#c0361...

[2] https://msdn.microsoft.com/en-us/library/ff649874.aspx

Re: Kaspersky Lab cybersecurity firm is hacked

#42
post #15
post #13

Does anyone get the impression this was some sort of early detection mechanism, done intentionally by the hackers, to know when it has been publicly discovered? Is this stupid? Probably stupid.

I personally believe this is a honeypot or trial of sorts. The reason could've been to determine whether or not the intrusion was detected at all as a sort of validation of just how "almost invisible" the malware is, or it could've been to determine the time required to detect. Alternatively, it could be a way of getting at the company's data or even to instigate a thorough review of their platform from the client's…

The simplest, most obvious explanation is: Israeli intelligence wanted to spy on Kaspersky because they are the best at finding and analysing state sponsored malware, they were over-cocky and they eventually got caught.

Re: Kaspersky Lab cybersecurity firm is hacked

#43
post #17

Intel Security just reported that "[p]ersistent and virtually undetectable attacks by the Equation Group that reprogram hard disk drives and solid state drive firmware."[0,1] It's interesting that this threat was first reported by Kaspersky in February.[2] The firmware exploits are part of the attack system with Duqu 2.0, right? [0] http://www.mcafee.com/us/security-awareness/articles/mcafee-... [1] https://news.ycom…

Different groups in this case. According to Kapersky's report, Duqu used a zero-day to promote into kernel space, then loaded the full payload into memory. Less terrifying than the firmware revision from EG as a single attack, but Duqu was unique in that it replicated itself around in the local network, making it impossible to remove short of powering down everything.

Re: Kaspersky Lab cybersecurity firm is hacked

#44
post #29
post #24

Earlier quoted context omitted.

Who is trying to control and rein in antivirus companies?

https://www.schneier.com/blog/archives/2013/12/how_antivirus...

That is, nobody: they claim they have never received a request to not detect malware.

Re: Kaspersky Lab cybersecurity firm is hacked

#45
post #7

Earlier quoted context omitted.

Depends on your threat model. I'm more worried about something nasty in one of the many pieces of random software I download from the internet than my AV being compromised.

Unfortunately our standard web browsers are insecure because of the way Javascripts work.

Any scripting language can be properly sandboxed, JavaScript being no exception.

Re: Kaspersky Lab cybersecurity firm is hacked

#46
post #15

Earlier quoted context omitted.

I personally believe this is a honeypot or trial of sorts. The reason could've been to determine whether or not the intrusion was detected at all as a sort of validation of just how "almost invisible" the malware is, or it could've been to determine the time required to detect. Alternatively, it could be a way of getting at the company's data or even to instigate a thorough review of their platform from the client's…

The simplest, most obvious explanation is: Israeli intelligence wanted to spy on Kaspersky because they are the best at finding and analysing state sponsored malware, they were over-cocky and they eventually got caught.

Or investigation of the relationship between Kaspersky and Russian intelligence, which according to 6 Kaspersky employees, is too close for my comfort: http://www.bloomberg.com/news/articles/2015-03-19/cybersecur...

It sucks that it's so hard to trust anybody's software (or hardware) today.

Re: Kaspersky Lab cybersecurity firm is hacked

#47
post #22

A lot of beating around the bush; just say the US and/or Isreal did it. We already know Duqu was made by the same people who made Stuxnet. We already know Stuxnet was made by the US and/or Isreal to hurt the Iranian nuclear program. So if they have strong evidence it was the same people... we know who those people are and we should just say their names.

Kaspersky has been a pain in the ass of the status quo because they are Russian and so it's difficult to control them and rein them in. Lots of exploits depends on the cooperation and complacency of security companies that are in the pocket of the various governments. Kaspersky wasn't one of these, or at least in the pockets of Russia, and so had to be compromised to try to control their oversight on security and to…

That kind of conspiracy is just too fragile to be believable. While the opsec of such coersion operation with a company full of unpatriotic foreigners sounds like an absolute nightmare, it's also much much safer and much easier to build your APT attack vector not be caught by your targets' AV solution.

Kaspersky is also much easier to control than most AV vendors, Eugene has often been quite positive about Russia spying on its citizens more aggressively than the US does, and he has deep connections with other powerful people of Russia.

Re: Kaspersky Lab cybersecurity firm is hacked

#49
post #26
post #22

Earlier quoted context omitted.

Kaspersky has been a pain in the ass of the status quo because they are Russian and so it's difficult to control them and rein them in. Lots of exploits depends on the cooperation and complacency of security companies that are in the pocket of the various governments. Kaspersky wasn't one of these, or at least in the pockets of Russia, and so had to be compromised to try to control their oversight on security and to…

I'm sure it knew it was a target for this kind of thing since they did exhibit bias. That is to say they showed greater interest in exposing western gov't hacking capabilities and activities than they did in exposing Russian and Chinese govt actors in the same arena. I'm sure this is no surprise to them.

> That is to say they showed greater interest in exposing western gov't hacking capabilities and activities than they did in exposing Russian and Chinese govt actors in the same arena.

Kaspersky early detected, nailed, and exposed an advanced nation-state attack on its network.

BBC spin - "Kaspersky Lab cybersecurity firm is hacked"

Re: Kaspersky Lab cybersecurity firm is hacked

#50
post #44
post #29

Earlier quoted context omitted.

https://www.schneier.com/blog/archives/2013/12/how_antivirus...

That is, nobody: they claim they have never received a request to not detect malware.

I think you need to look more closely at the list of companies and their locations in the second paragraph, and the list of companies that actually replied to the letter.

But we don't actually have to speculate about what the silence of the american companies means: they are quite open about their policies: http://slashdot.org/story/01/11/28/173201/symantec-will-not-...

>Symantec chief researcher Eric Chien stated that provided a hypothetical keystroke logging tool was used only by the FBI, Symantec would avoid updating its antivirus tools to detect such a Trojan, echoing a similar stance Network Associates allegedly took with its McAfee anti-virus software earlier this week. 'If it was under the control of the FBI, with appropriate technical safeguards in place to prevent possible misuse, and nobody else used it -- we wouldn't detect it,' said Chien. 'However we would detect modified versions that might be used by hackers.

Post reply on HN