Live data from Hacker News

A New Malware Detection Tool That Can Expose Illegitimate State Surveillance

eff.org

21–30 of 56 posts

Re: A New Malware Detection Tool That Can Expose Illegitimate State Surveillance

#21
post #7

Earlier quoted context omitted.

Probably, but the suspicion is that some antivirus software "looks the other way" for some signatures. Hard to say if that it true or not.

Name one AV company that "looks the other way"?

Microsoft AV, Norton, McAfee, etc. We know this, how? Because we can look at Google's virustotal and see when a sample was first submitted and when it was "detected." With typical malware there is a fairly short window between A and B, with US G malware there is a HUGE window (months, sometimes years).

Either the US G just gets very lucky that their samples aren't ever looked at deeper or more likely they have national security agreements with most of the large US based anti-virus firms to hush hush.

Re: A New Malware Detection Tool That Can Expose Illegitimate State Surveillance

#23

Earlier quoted context omitted.

Name one AV company that "looks the other way"?

Microsoft AV, Norton, McAfee, etc. We know this, how? Because we can look at Google's virustotal and see when a sample was first submitted and when it was "detected." With typical malware there is a fairly short window between A and B, with US G malware there is a HUGE window (months, sometimes years). Either the US G just gets very lucky that their samples aren't ever looked at deeper or more likely they have nation…

"looks the other way" and poor detection are two separate things. I'm sorry but you don't know what you are talking about.

Re: A New Malware Detection Tool That Can Expose Illegitimate State Surveillance

#25

I love the EFF (and have donated money) but I am going to disagree with them on this one. As they themselves fully admit, the first thing the big g is going to do is test that their malware v2 isn't detected by this. In the same way that malware authors now check against Microsoft AV because it is the most popular. So my point is that traditional AV in this scenario is a loser and will remain a loser because it is a…

> As they themselves fully admit, the first thing the big g is going to do is test that their malware v2 isn't detected by this ... it is a race AV just cannot win.

This can be said of every security solution. The value of security is to increase the attackers' cost, which will deter attackers who don't want to pay the higher price. There is no absolute security.

Also, the prospect of updates will increase attacker costs more, as some attackers will feel the need to proactively avoid detection by future versions too.

Re: A New Malware Detection Tool That Can Expose Illegitimate State Surveillance

#27

Earlier quoted context omitted.

Name one AV company that "looks the other way"?

Microsoft AV, Norton, McAfee, etc. We know this, how? Because we can look at Google's virustotal and see when a sample was first submitted and when it was "detected." With typical malware there is a fairly short window between A and B, with US G malware there is a HUGE window (months, sometimes years). Either the US G just gets very lucky that their samples aren't ever looked at deeper or more likely they have nation…

This is a very interesting claim, and I want to check for myself. Could you give more details? Name of usg malware? How to check time of submission and detection?

Re: A New Malware Detection Tool That Can Expose Illegitimate State Surveillance

#28

I love the EFF (and have donated money) but I am going to disagree with them on this one. As they themselves fully admit, the first thing the big g is going to do is test that their malware v2 isn't detected by this. In the same way that malware authors now check against Microsoft AV because it is the most popular. So my point is that traditional AV in this scenario is a loser and will remain a loser because it is a…

Grab a live DVD, but how do you make sure that the hash used to verify the ISO is what it should be? transfer it offline? because if you are trying to avoid being spied on by the government, I don't think CAs/TLS can be used

Re: A New Malware Detection Tool That Can Expose Illegitimate State Surveillance

#29

I love the EFF (and have donated money) but I am going to disagree with them on this one. As they themselves fully admit, the first thing the big g is going to do is test that their malware v2 isn't detected by this. In the same way that malware authors now check against Microsoft AV because it is the most popular. So my point is that traditional AV in this scenario is a loser and will remain a loser because it is a…

All of these memory signature scanning tools have a limited window of opportunity before the malware adapts. The involved organizations probably determined that the value of the current set of signatures was near the end and there was value to getting some parties outside of direct collaborators using the tool during a brief window.

Re: A New Malware Detection Tool That Can Expose Illegitimate State Surveillance

#30

Earlier quoted context omitted.

Name one AV company that "looks the other way"?

Microsoft AV, Norton, McAfee, etc. We know this, how? Because we can look at Google's virustotal and see when a sample was first submitted and when it was "detected." With typical malware there is a fairly short window between A and B, with US G malware there is a HUGE window (months, sometimes years). Either the US G just gets very lucky that their samples aren't ever looked at deeper or more likely they have nation…

Don't forget Kaspersky (at least for Russian gov malware). I believe their CEO came out in favor of surveillance in a blog post for a brief period.
Post reply on HN