Earlier quoted context omitted.
I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.
If I had to wager I'd always bet on the CIA lying, I don't see how anyone could come to another conclusion given their history.
Kaspersky believes it found new CIA malware
241–250 of 314 posts
Re: Kaspersky believes it found new CIA malware
#242Two weeks ago, the NSA accused the Russian SVR (intelligence agency) of exploiting vulnerabilities in US networks and suggesting that they were behind the SolarWinds compromise[1]. Now, Kaspersky (which is suspected to be affiliated with Russian intelligence - possibly unwillingly) claims to have found CIA malware (effectively "burning" it, if it's real). The timing does not seem to be a coincidence. Tit-for-tat? [1]…
> which is suspected to be affiliated with Russian intelligence - possibly unwillingly I have yet to see actually compelling evidence that this is the case.
Re: Kaspersky believes it found new CIA malware
#243Earlier quoted context omitted.
> which is suspected to be affiliated with Russian intelligence - possibly unwillingly I have yet to see actually compelling evidence that this is the case.
Lol, after your CIA comment I thought you would try to hide your Russki loyalty. You go all in.
Re: Kaspersky believes it found new CIA malware
#244Earlier quoted context omitted.
I’d say it’s likely they were instructed to sit on it until the time is right
What's more likely: * CIA malware is discovered by a (Russian) Security company and they release a report about it. * CIA malware discovered a year or more ago by a (Russian) security company and they tell the CIA about it and the CIA asks them to wait 1y+ to release the report, and they obliged.
Re: Kaspersky believes it found new CIA malware
#245Earlier quoted context omitted.
Did you take occam’s razor into account? Why is this likely?
Occam's razor hardly ever applies to stuff like this (news in the intelligence space) because deception is the whole game. A tendency to believe simpler explanations is something they exploit. I think Occam's razor is often misapplied in this way. It's for explaining natural phenomena, not for surmising the intent of an intelligent entity with an incentive to deceive.
Re: Kaspersky believes it found new CIA malware
#246Earlier quoted context omitted.
Dude, it is well known that US is the single most powerful cyber warfare practitioner. They even had a few very successful operations in Iran and may be in China and Russia (you can guarantee that those countries won't disclose the incidents). TBH, one should be happy that US possess such power. US might be biased, but the country is at least rational.
> Dude, it is well known that US is the single most powerful cyber warfare practitioner. They even had a few very successful operations in Iran and may be in China and Russia (you can guarantee that those countries won't disclose the incidents). I don't follow that logic: > >1: The US is the single most powerful cyber warfare practitioner > >2: Successful operations in Iran, China and Russia > >3: But those countries…
Re: Kaspersky believes it found new CIA malware
#247Earlier quoted context omitted.
I think it’s much more likely for both these orgs to be telling the truth when they’re accusing their enemies of doing bad things than it is when they’re denying that they’ve done bad things themselves. It’s not a simple case of one consistently telling the truth, and the other consistently lying...
So when the CIA tells me some foreign government is doing something bad, I should believe them? Then when the CIA denies they lied about the foreign government was doing something bad, I should ignore them? This advice makes no sense to me.
Anyway, the point is that I don’t think you have to dig very deep these days to find plenty of instances of geopolitical power X doing bad things, so I’m not sure why the CIA would bother lying to stir up shit against them when they could tell the truth just as easily, with the same result. This assumes their purpose in releasing any information at all is to influence public opinion, not increase transparency, as the latter would probably mean divulging uncomfortable truths. The former does not—they can release exactly what they want, and no more.
On the other hand, flatly denying you’ve done a bad thing is a form response for governments and corporations (and politicians) at this point, even when it’s risible on its face. If you’re the guy responsible for putting those comms together and you admit wrongdoing, you’re never working in this town again. Simple as that. Deny, deny, deny. Deny everything. (Isn’t that a one-off X-Files title card?)
Has the CIA lied? Absolutely, though I’d guess far more often (orders of magnitude?) by omission than by outright explicit falsehood. The latter goes against the same ass-covering impulse that drives the bullshit denials. My brief comment above is meant to be a general observation on the sorts of public communication games the CIA and similar organizations tend to play, not an absolute truth or bible for living your life.
Re: Kaspersky believes it found new CIA malware
#248We're lucky that we can still catch some of them now. The current status of closed CPUs running proprietary firmware talking with closed chipsets running proprietary firmware blobs would make trivially easy to move the malware injection to the iron level for agencies funded by governments. Once they accomplish it, detecting their spyware using software, at any privilege level, will become impossible. I fear the scena…
Why is this impossible today? Isn't this exactly what Intel's "Management Engine" and AMD's "Platform Security" is? Bonus question, does apples new MX chips have an equivalent backdoor?
Re: Kaspersky believes it found new CIA malware
#249Earlier quoted context omitted.
I’d say the likelihood of an American Big Tech without CIA covert operatives working there is essentially zero, even if there’s no direct cooperation. It doesn’t make sense to not utilize some of your most valuable assets.
Back in the 70s to 90s the CIA had presidents of Mexico as operatives (see LITEMPO). So, I wouldn't be surprised that nowadays some high level people at Google, Microsoft, etc are CIA assets.
Re: Kaspersky believes it found new CIA malware
#250Earlier quoted context omitted.
> Let's not pretend Who is pretending? The discussion is about the CIA. When I discuss cats, there is no reason I should have to always qualify it by saying "yes, and dogs are cute, too."
Kaspersky's ties to FSB are an open secret, so it's really believing FSB vs believing CIA unless you have a way to verify them.
That was news to me, so I went looking for some context.
https://en.wikipedia.org/wiki/Kaspersky_bans_and_allegations...