Yet Another Government-Sponsored Malware
schneier.com
Yet Another Government-Sponsored Malware
1–10 of 24 posts
Re: Yet Another Government-Sponsored Malware
#2Re: Yet Another Government-Sponsored Malware
#3Re: Yet Another Government-Sponsored Malware
#4Re: Yet Another Government-Sponsored Malware
#5Schneier is basically blogspam. Quotes entirely from another article, follows up with "I don't know what this means???" Why do people keep reading him?
Re: Yet Another Government-Sponsored Malware
#6Stoxnet was discovered by Belorussian anti-virus company, Duqu & Project Sauron were discovered by Kaspersky Lab. Are US-based anti-virus companies that bad or ...?
If Kaspersky finds a Russian FSB trojan, they won't go to the press. They'll call their pals at the FSB and ask what to do. In an authoritarian state, revealing such a thing could be life threatening. In other words, Kaspersky isn't going to report on Russian state malware, which we certainly know exists considering the documented attacks on Ukraine, Baltics, Georgia, etc.
The US/EU has a stronger freedom of the press tradition and doesn't often follow autocratic staples like murdering inconvenient journalists and serving them polonium tea, but obviously jail-time can be in the cards if laws were violated. I imagine its just safer to report on Western state sigint compared to autocratic/authoritarian state sigint, thus we hear about Western sigint efforts a lot more, especially in the Western press. One of the downsides of having an open society is that you see the warts and all, but a more closed autocratic one has better infomation and propaganda control, so the perception of "those things don't happen here" is easy to sell to low-information constituents, and special efforts are made to keep them low-information.
Also, I think its clear Russia uses Kaspersky to make western intelligence look bad. Its more demoralizing to have a AV vendor point this stuff out than one's own security apparatus and its a good cover for the FSB's own hacking. Wired has written about the FSB/Kaspersky connection before. Note its almost always Kaspersky finding Western state malware, not the dozens of other competent AV firms and thousands of top tier researchers. Funny how that works.
Re: Yet Another Government-Sponsored Malware
#7Stoxnet was discovered by Belorussian anti-virus company, Duqu & Project Sauron were discovered by Kaspersky Lab. Are US-based anti-virus companies that bad or ...?
Or what? I'm not following, but I think its clear that state malware disclosure is political. If Kaspersky finds a Russian FSB trojan, they won't go to the press. They'll call their pals at the FSB and ask what to do. In an authoritarian state, revealing such a thing could be life threatening. In other words, Kaspersky isn't going to report on Russian state malware, which we certainly know exists considering the docu…
Also, in US you are free to talk about anything unless you are under GAG order.
Re: Yet Another Government-Sponsored Malware
#8Re: Yet Another Government-Sponsored Malware
#9Do any consumer AV suites actually try identifying and removing or quarantining state-actor-level malware?
I think only 30% of malware is detected~ I remember reading about that a while back and this was after advanced heuristic methods had been around for a while.
Re: Yet Another Government-Sponsored Malware
#10Schneier is basically blogspam. Quotes entirely from another article, follows up with "I don't know what this means???" Why do people keep reading him?