Schneier is basically blogspam. Quotes entirely from another article, follows up with "I don't know what this means???" Why do people keep reading him?
Yet Another Government-Sponsored Malware
11–20 of 24 posts
Re: Yet Another Government-Sponsored Malware
#12Do any consumer AV suites actually try identifying and removing or quarantining state-actor-level malware?
Anti-Virus only finds the very most common virus' and malware. I think only 30% of malware is detected~ I remember reading about that a while back and this was after advanced heuristic methods had been around for a while.
https://www.symantec.com/security_response/writeup.jsp?docid...
https://www.microsoft.com/security/portal/threat/encyclopedi...
Re: Yet Another Government-Sponsored Malware
#13Earlier quoted context omitted.
Or what? I'm not following, but I think its clear that state malware disclosure is political. If Kaspersky finds a Russian FSB trojan, they won't go to the press. They'll call their pals at the FSB and ask what to do. In an authoritarian state, revealing such a thing could be life threatening. In other words, Kaspersky isn't going to report on Russian state malware, which we certainly know exists considering the docu…
How is that relevant to my question? Also, in US you are free to talk about anything unless you are under GAG order. https://en.wikipedia.org/wiki/Gag_order
This seems like the most relevant part -- it's not that Kaspersky is THAT much better, but that they have a lot of help from the state, which has way more resources than an anti-virus company. How much of that is true, I have no idea.
Also, "free" in the way you use it is a pretty shaky concept: In theory, you're "free" to record police officers acting in the course of their duty, but that doesn't mean the authorities won't ruin your life because of it. (To say nothing of how eerily easy it is for the government to issue gag orders.)
Re: Yet Another Government-Sponsored Malware
#14Stoxnet was discovered by Belorussian anti-virus company, Duqu & Project Sauron were discovered by Kaspersky Lab. Are US-based anti-virus companies that bad or ...?
Or what? I'm not following, but I think its clear that state malware disclosure is political. If Kaspersky finds a Russian FSB trojan, they won't go to the press. They'll call their pals at the FSB and ask what to do. In an authoritarian state, revealing such a thing could be life threatening. In other words, Kaspersky isn't going to report on Russian state malware, which we certainly know exists considering the docu…
It's not that clear cut. The UK routinely serves 'D' notices and the press defer (leading to much abuse) - here's a nice primer https://www.theguardian.com/media/2015/jul/31/d-notice-syste...
Anyone stumbling across their own state's payload and attempting to publish details is likely to rapidly receive a visit and be put in the picture that they've to drop it.
The UK even uses the Wassenaar arrangement to stifle general discussion of virus and threats : http://www.theregister.co.uk/2015/07/03/northumbria_universi...
Admittedly there's no actual murders or suspected ones (that I've ever heard of) but the polonium tea example was not about computer virus revelations either.
Re: Yet Another Government-Sponsored Malware
#15Schneier is basically blogspam. Quotes entirely from another article, follows up with "I don't know what this means???" Why do people keep reading him?
Re: Yet Another Government-Sponsored Malware
#16Schneier is basically blogspam. Quotes entirely from another article, follows up with "I don't know what this means???" Why do people keep reading him?
He's a content curator for a particular category of content. Would you prefer to follow all of the relevant sources and sift through the cruft yourself?
Re: Yet Another Government-Sponsored Malware
#17Earlier quoted context omitted.
Anti-Virus only finds the very most common virus' and malware. I think only 30% of malware is detected~ I remember reading about that a while back and this was after advanced heuristic methods had been around for a while.
That's not really what I meant. I mean in the cases where such 'super-malware' has been clearly identified and plucked apart by security researchers, could your average commercial AV kill it? I did some googling and found out for myself that apparently, they do: https://www.symantec.com/security_response/writeup.jsp?docid... https://www.microsoft.com/security/portal/threat/encyclopedi...
And in any event, when we find out about nefarious state-sponsored software it's almost always super old.
Re: Yet Another Government-Sponsored Malware
#18Stoxnet was discovered by Belorussian anti-virus company, Duqu & Project Sauron were discovered by Kaspersky Lab. Are US-based anti-virus companies that bad or ...?
Re: Yet Another Government-Sponsored Malware
#19Or... maybe I am naive. I just tend to look at this stuff with how can we get this done the easiest way??? Human emotions are much easier to target than silicon.