Live data from Hacker News

Kaspersky believes it found new CIA malware

therecord.media

141–150 of 314 posts

Re: Kaspersky believes it found new CIA malware

#141
post #121
post #95

Earlier quoted context omitted.

> Let's not pretend Who is pretending? The discussion is about the CIA. When I discuss cats, there is no reason I should have to always qualify it by saying "yes, and dogs are cute, too."

Kaspersky's ties to FSB are an open secret, so it's really believing FSB vs believing CIA unless you have a way to verify them.

I think it’s much more likely for both these orgs to be telling the truth when they’re accusing their enemies of doing bad things than it is when they’re denying that they’ve done bad things themselves. It’s not a simple case of one consistently telling the truth, and the other consistently lying...

Re: Kaspersky believes it found new CIA malware

#142

Earlier quoted context omitted.

> my country has been at war my entire adult life The US has been at war for most it’s existence. Someone made a search tool to see how many years the US had been at war for, and then ran it on Wikipedia. Interestingly, France performed worse (assuming one doesn’t like war), though being involved in things like ‘The 100 years war’ skews things a little. https://freakonometrics.hypotheses.org/50473

I probably wouldn't be complaining if I was born in the 1930's, WW1 and 2 were fairly well justified. However what are the current wars even still about? WMD? No, that was a fabrication. Bin Laden? He's long dead. Oil? With fracking, the US has the largest oil reserves on the planet. ISIS? Essentially gone, not much of a threat to US citizens in any case. There was no reason for these wars, there is certainly no reas…

To be fair the fracking thing is a last 5 years thing, until about 2-3 years ago the all in cost of fracking wasn't competitive with saudi arabia/iraq.

Re: Kaspersky believes it found new CIA malware

#143

Earlier quoted context omitted.

> my country has been at war my entire adult life The US has been at war for most it’s existence. Someone made a search tool to see how many years the US had been at war for, and then ran it on Wikipedia. Interestingly, France performed worse (assuming one doesn’t like war), though being involved in things like ‘The 100 years war’ skews things a little. https://freakonometrics.hypotheses.org/50473

I probably wouldn't be complaining if I was born in the 1930's, WW1 and 2 were fairly well justified. However what are the current wars even still about? WMD? No, that was a fabrication. Bin Laden? He's long dead. Oil? With fracking, the US has the largest oil reserves on the planet. ISIS? Essentially gone, not much of a threat to US citizens in any case. There was no reason for these wars, there is certainly no reas…

It's nearly always about natural resources, just because the US has the largest oil reserves doesn't mean it's going to stop there. And the wars you mentioned are just the boots on the ground (or drones in the air) conflicts. Were still backing coups in Latin America (Honduras, Venezuela, Bolivia) so US friendly governments are put into place that will allow American companies to extract their resources.

Re: Kaspersky believes it found new CIA malware

#144
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

I’d say it’s likely they were instructed to sit on it until the time is right

Did you take occam’s razor into account? Why is this likely?

Re: Kaspersky believes it found new CIA malware

#145

Earlier quoted context omitted.

https://en.m.wikipedia.org/wiki/Niger_uranium_forgeries Folks inside the CIA knew that the yellow cake uranium was a lie and at best, did not make any of this knowledge public as the justification for war was coming together. That silence resulted in the loss of at least one hundred and fifty thousand human beings needlessly and a war that has lasted decades.

Huh, you went from > I have witnessed the CIA justify those wars to > the CIA knew that the yellow cake uranium was a lie and at best, did not make any of this knowledge public ? Isn't that a bit of a... large jump? Also, do/should intelligence agencies generally come out and make public announcements of intelligence at all? I mean, maybe you can argue they should do that (for the public good), but unless they alread…

Not defending the cia, but the yellow cake thing was not a lie of commission (arguably a lie of omission): it was very much true in the strictest senses - hussein did have yellow cake and we did not know for sure where it was and he blocked inspectors that he was supposed to let in. but utterly overblown and misrepresented: yellow cake is not that dangerous by itself, hussein had stopped trying to enrich it - and we probably knew that - and it turned out to be exactly where it was last known to be to be under the UN inspections regime.

As they say, technically correct, the best kind of correct.

Re: Kaspersky believes it found new CIA malware

#146
post #82

Earlier quoted context omitted.

The only thing you can truly do is look for anomalies in network traffic, processes, files, etc. This malware is not immune to that unless it has features specifically to hide from monitoring tools. Even then there will almost always be evidence if you log network traffic. But obviously this is very difficult.

> Even then there will almost always be evidence if you log network traffic. You'd need to know what to look for though. It was shown that the CIA can hide its communication in metadata of legitimate traffic which is then recovered at intermediate hops to the target. So, do you know precisely what an innocent DNS packet looks like to detect this anomaly?

>do you know precisely what an innocent DNS packet looks like to detect this anomaly

Wouldn't an abnormal amount of DNS data also stand out? I assume for this to work they'd still have to send a lot of data unless they're willing to wait for half an eternity.

Just curious, since I hadn't heard of this before.

Re: Kaspersky believes it found new CIA malware

#147
We're lucky that we can still catch some of them now. The current status of closed CPUs running proprietary firmware talking with closed chipsets running proprietary firmware blobs would make trivially easy to move the malware injection to the iron level for agencies funded by governments. Once they accomplish it, detecting their spyware using software, at any privilege level, will become impossible. I fear the scenario in which magic packets with a signature that turns off detection in network hardware (proprietary firmware) and interfaces (again, proprietary firmware) can directly instruct a system (proprietary firmware) unbeknownst to the user; it seems impossible today, however all it takes is having enough closed software and firmware so that a covert channel can be created from the CPU to the external world. Governments have enough funds and motivation to tell most network iron manufacturers to produce hardware according to some additional specifications.

Re: Kaspersky believes it found new CIA malware

#148

We're lucky that we can still catch some of them now. The current status of closed CPUs running proprietary firmware talking with closed chipsets running proprietary firmware blobs would make trivially easy to move the malware injection to the iron level for agencies funded by governments. Once they accomplish it, detecting their spyware using software, at any privilege level, will become impossible. I fear the scena…

not convinced. since its the CIA, I trust them they are doing it for a good cause.

Re: Kaspersky believes it found new CIA malware

#149
post #148

We're lucky that we can still catch some of them now. The current status of closed CPUs running proprietary firmware talking with closed chipsets running proprietary firmware blobs would make trivially easy to move the malware injection to the iron level for agencies funded by governments. Once they accomplish it, detecting their spyware using software, at any privilege level, will become impossible. I fear the scena…

not convinced. since its the CIA, I trust them they are doing it for a good cause.

you forgot /s
Post reply on HN