Live data from Hacker News

Kaspersky believes it found new CIA malware

therecord.media

181–190 of 314 posts

Re: Kaspersky believes it found new CIA malware

#181
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

Using inductive reasoning, they're probably still deploying first-stage malware en mass that activates under certain network conditions. Truly scary stuff.

Re: Kaspersky believes it found new CIA malware

#182

Earlier quoted context omitted.

The tit-for-tat goes the other way: 1. expose malware the CIA doesn't want exposed 2. get accused by the CIA of being in bed with the Russians "working for the Russians" is the go to baseless political smear these days

I would like to point out that a russian security company almost certainly has ties with the russian government. Particularly a very large, well respected one. It would be like accusing oracle or amazon of having ties with the US government.

Kaspersky himself is a 1987 KGB school alumni. The naïveté of Westerners is sometimes astonishing.

Re: Kaspersky believes it found new CIA malware

#183

Earlier quoted context omitted.

The tit-for-tat goes the other way: 1. expose malware the CIA doesn't want exposed 2. get accused by the CIA of being in bed with the Russians "working for the Russians" is the go to baseless political smear these days

I would like to point out that a russian security company almost certainly has ties with the russian government. Particularly a very large, well respected one. It would be like accusing oracle or amazon of having ties with the US government.

The "well respected" part of that has partly to do with no evidence of them being partial.

If they were known as a kremlin puppet, they wouldn't be respected.

Re: Kaspersky believes it found new CIA malware

#184
post #4

Earlier quoted context omitted.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

Because the entire goal is to promote skepticism about the USA while remaining as mum as possible on Russia and China. In the case of Russia, it’s not a secret that they try to disrupt and divide the states via internal conflicts so they can take over if we decline because of it. Here is just one example: https://www.wsj.com/articles/russian-backed-facebook-account... We also know that hundreds of thousands of foreig…

Meanwhile all you people stoking nationalist fervor keep the global population of generally-well-meaning humans divided and hating each other instead of uniting into a whole that demands a better life for everyone. Please stop.

Re: Kaspersky believes it found new CIA malware

#185
post #42

I always wonder. The CIA/NSA must essentially target the big Amazon, google and microsoft clouds to get blanket access to everything running and stored there. Seems like a no brainer from their standpoint.

It should noted that they can also assign agents to work at these firms or recruit existing employees, so they have a broad pallet to deal with. And a given person working for the secret agencies might not have to do more than turn a blind eye to something once in a while.

However, these large firms have enterprise-wide security and too many people would notice the vacuuming of data for this to be done by single agents. So that would require secret court order and secret laws, as we know existed a few years ago.

So no doubt you have some level of secret agency access but exactly how much is difficult to say. Remember these are companies operating globally and it's in their interests to not be seen as mere extension of US intelligence and foreign policy but at the same time these agencies can very persuasive, etc. etc.

Re: Kaspersky believes it found new CIA malware

#186
post #3

Aside: Kaspersky is a Russian company.

Not sure it's really meaningful to simply say they're a "Russian company". More specifically, they're a company that has been accused of cooperating with the FSB in attacks against the US government. https://en.wikipedia.org/wiki/Kaspersky_bans_and_allegations... Whatever the case, it's probably wise to take their statements with some skepticism of bias in this regard.

Role reversal: If a US antivirus company's heuristic and file analysis uploaded a trove of russian zero-day exploits they are using against their adversaries, you better damn well believe they're going to hand that over to the CIA/NSA and the CIA/NSA may weaponize them against our adversaries.

When it comes to US crafted malware, I trust the Russians in detecting it and telling the world more than I would any US-based company.

Re: Kaspersky believes it found new CIA malware

#188

Earlier quoted context omitted.

> Let's not pretend the FSB and MSS don't also lie constantly How do you go from reading "the CIA is lying" to "the FSB is telling the truth"? Do you understand the difference between those statements? Reminds me of a stand up bit, "are you a Jew or an antisemite?"

>How do you go from reading "the CIA is lying" to "the FSB is telling the truth"? The link is a Kaspersky press release, so there’s potential for an FSB connection: https://www.bloomberg.com/news/articles/2017-07-11/kaspersky...

Using that same logic most statements out of the US corporate InfoSec establishment should be similarly scrutinized.

A whole lot of these outfits are started by former NSA employees, and they love having people that previously worked in US national security on their rooster for the marketing value.

Yet whenever one of these outfits accuses China/Russia/Iran of being responsible for the latest "cyber incident"/"misinformation campaign" these accusations are widely regurgitated without any doubt like some kind of definitive factual truth.

Re: Kaspersky believes it found new CIA malware

#189
post #156
post #154

Two weeks ago, the NSA accused the Russian SVR (intelligence agency) of exploiting vulnerabilities in US networks and suggesting that they were behind the SolarWinds compromise[1]. Now, Kaspersky (which is suspected to be affiliated with Russian intelligence - possibly unwillingly) claims to have found CIA malware (effectively "burning" it, if it's real). The timing does not seem to be a coincidence. Tit-for-tat? [1]…

But CIA developing malware isn't news to anyone. How is this a tit-for-tat then?

Well, at least for once the general public wins. Let's hope they fight more this exact way, and less on every other way.

Re: Kaspersky believes it found new CIA malware

#190

Earlier quoted context omitted.

I'm actually curious precisely what CIA justification you're referring to. What I'm aware of are [1] and [2]. [1] https://www.washingtonpost.com/politics/2019/03/22/iraq-war-... [2] https://www.washingtonpost.com/archive/opinions/2003/11/28/m...

The NIE that the CIA wrote up was declassified. It makes it very clear that they believe with "high confidence" (a very specific term in intelligence which means "we're pretty damn sure, normally enough to start a war over") that Iraq was continuing to make active progress on their nuclear weapons program and delivery systems in contrast to their UN sanctions. There's been a bunch of opinions since then that they wer…

Ah! It took me a while to get what's going on (I didn't know what INR was!), but I think I finally see what you're saying. I assume you're talking about page 9 [1]. For anyone else interested, here are the relevant quotes I can find:

> Iraq is continuing. and in some areas expanding, its chemical, biological, nuclear and missile programs contrary to UN resolutions.

> If left unchecked, [Iraq] probably will have a nuclear weapon during this decade. (See INR alternative view at the end of these Key Judgments.)

> [State/INR Alternative View] The activities we have detected do not, however, add up to a compelling case that Iraq is currently pursuing what INR would consider to be an integrated and comprehensive approach to acquire nuclear weapons. Iraq may be doing so, but INR considers the available evidence inadequate to support such a judgment.

So basically the CIA is saying:

- The INR (separate agency) doesn't believe this is enough to start a war over.

- The other agencies (presumably including CIA) do.

However, their justifications in the bullet points seem to rely on a fair bit of speculation about motivations behind things, not as much actual concrete evidence as you'd hope. Whereas the INR evaluated the same evidence and said they aren't confident enough in this yet.

OK, so I'm with you here so far. Now the question to me is: did the CIA really lie here, or did they (and other agencies) really fail at their job? If it was a lie, are we using that to mean a falsehood, or does it refer to omission of critical information that they were reasonably confident about? On the face of it, it looks like they really just failed spectacularly, not that there was malice per se, but I don't have more details. (Though I guess that means we should listen more to the INR in the future?)

[1] https://nsarchive2.gwu.edu/NSAEBB/NSAEBB129/nie.pdf#page=13

Post reply on HN