Live data from Hacker News

How Antivirus Companies Handle State-Sponsored Malware

schneier.com

11–16 of 16 posts

Re: How Antivirus Companies Handle State-Sponsored Malware

#11
I enjoyed the article, but explicitly asking anti-virus companies if they have complied with such a government request seems silly.

It's like asking a politician, "Have you ever been unfaithful to your wife?"

"What's that? No? Okay, well you heard the man. Time to move on."

Re: How Antivirus Companies Handle State-Sponsored Malware

#12
post #10

There are now some companies which provide non-signature based anti-virus detection to potentially detect zero-day malware. Most of them work by spinning up a vm, run or open the file to check, and verify any changes to the system. Check out http://www.fireeye.com/ (funded by the CIA's startup incubator In-Q-Tel) http://www.fidelissecurity.com/ (from General Dynamics) and Northrop Grumman is releasing one soon too. N…

I deployed Fireeye over a year ago, and can confirm it's very good a spotting malware that most AV vendors don't. I can't, however, confirm it doesn't have back doors so that three-letter agencies can't tell it not to detect something they don't want it to.

Re: How Antivirus Companies Handle State-Sponsored Malware

#13
I doubt the NSA needs to co-opt antivirus companies, they are already worthless. Besides, Kaspersky for one is lying. His company works closely with the FSB:

We have very good relations with both the FSB cybersecurity department and the Moscow police department. They know us. They know us as people who support them when they need it.

http://www.wired.com/dangerroom/2012/07/ff_kaspersky/all/

(edit:) and the FBI:

Даже США: мы периодически консультируем ФБР.

http://www.rusrep.ru/2008/32/interview_kasperskiy

Re: How Antivirus Companies Handle State-Sponsored Malware

#14
post #4

NSA doesn't need to ask anti-virus companies to ignore certain malware, as long as Microsoft is handing them lists of fresh Windows vulnerabilities months before they even begin working on fixing them. http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t... Until that policy changes at Microsoft, at least 90 percent of the PC users will never be truly safe.

That program is MAPP (Microsoft Active Protections Program). [1] All governments (except Iran, Syria, etc.) are part of it, as well as hundreds of private companies internationally. Of course, vulnerabilities are routinely leaked. [2] Other programs include the SSI (Shared Source Initiative) [3] by which governments get access to the Windows source code, and the GSP (Government Security Program) [3] which helps governments find vulnerabilities in said source code.

Not to mention COFEE [4] -- I wonder how many antivirus detect that, especially since its source code was leaked...

[1] http://technet.microsoft.com/en-us/security/dn467918

[2] http://www.zdnet.com/blog/security/microsoft-kicks-chinese-c...

[3] https://www.microsoft.com/en-us/sharedsource/default.aspx

[4] https://wikileaks.org/wiki/Microsoft_COFEE_(Computer_Online_...

Re: How Antivirus Companies Handle State-Sponsored Malware

#15

I enjoyed the article, but explicitly asking anti-virus companies if they have complied with such a government request seems silly. It's like asking a politician, "Have you ever been unfaithful to your wife?" "What's that? No? Okay, well you heard the man. Time to move on."

Agreed. This sounds like a debate that could be settled by testing different antivirus products (and their old versions) against state-sponsored malware.

Re: How Antivirus Companies Handle State-Sponsored Malware

#16
post #15

I enjoyed the article, but explicitly asking anti-virus companies if they have complied with such a government request seems silly. It's like asking a politician, "Have you ever been unfaithful to your wife?" "What's that? No? Okay, well you heard the man. Time to move on."

Agreed. This sounds like a debate that could be settled by testing different antivirus products (and their old versions) against state-sponsored malware.

I'm not sure that's a good test; any publicly known example of state-sponsored is almost certainly in current antivirus software. Since they're publicly known, there's no advantage to continuing to be sneaky about it — it would certainly tip people off that the companies were under the thumb of a government. And testing older version probably won't help, because you can't prove that the company knew about them before the rest of us did.
Post reply on HN