Live data from Hacker News

Kaspersky believes it found new CIA malware

therecord.media

261–270 of 314 posts

Re: Kaspersky believes it found new CIA malware

#261
post #154

Two weeks ago, the NSA accused the Russian SVR (intelligence agency) of exploiting vulnerabilities in US networks and suggesting that they were behind the SolarWinds compromise[1]. Now, Kaspersky (which is suspected to be affiliated with Russian intelligence - possibly unwillingly) claims to have found CIA malware (effectively "burning" it, if it's real). The timing does not seem to be a coincidence. Tit-for-tat? [1]…

> which is suspected to be affiliated with Russian intelligence - possibly unwillingly I have yet to see actually compelling evidence that this is the case.

There are several examples. This is one: https://www.theguardian.com/technology/2017/oct/26/kaspersky...

Re: Kaspersky believes it found new CIA malware

#262

Earlier quoted context omitted.

Maybe it's less suspicious to have benign metadata than no metadata.

Yeah, which is why I suggest faking metadata than simply stripping it. There are anti-forensic tools for doing that.

Honest question, how do we know that this wasn't faked? What makes the 2014 date more problematic, and what would it be faked to be?

Re: Kaspersky believes it found new CIA malware

#263

Earlier quoted context omitted.

you can use military spending as a proxy.

I don't think you can, I expect different countries to have a wide variety of intelligence budgets as a percentage of military. But, if you did this anyway for the US and China, you would get 3.1x, closer to 2x than 10x.

Also difficult to know if the CIA gets as much spying done per dollar spent.

Re: Kaspersky believes it found new CIA malware

#264
post #225

Earlier quoted context omitted.

The timing is very sus given recent and ongoing spy mania in eastern europe (if you’ve been following)

The thing in EastEurope is not intelligence-based, its' political.

There’s a difference?

Re: Kaspersky believes it found new CIA malware

#265

We're lucky that we can still catch some of them now. The current status of closed CPUs running proprietary firmware talking with closed chipsets running proprietary firmware blobs would make trivially easy to move the malware injection to the iron level for agencies funded by governments. Once they accomplish it, detecting their spyware using software, at any privilege level, will become impossible. I fear the scena…

Why is this impossible today? Isn't this exactly what Intel's "Management Engine" and AMD's "Platform Security" is? Bonus question, does apples new MX chips have an equivalent backdoor?

https://www.quora.com/Does-Apples-processor-or-any-other-har...

Re: Kaspersky believes it found new CIA malware

#266
post #121

Earlier quoted context omitted.

Kaspersky's ties to FSB are an open secret, so it's really believing FSB vs believing CIA unless you have a way to verify them.

I mean would Kaspersky even have a choice not to work with FSB? I mean it is a Russian company , I doubt if anyone other than Putin can naysay FSB dictates.

With Eugene Kaspersky being a graduate of both KGB special school and higher school and later an intelligence officer [1] - no, I doubt that he had a choice or even ever had that question in mind.

1. https://en.wikipedia.org/wiki/Eugene_Kaspersky#Early_life

Re: Kaspersky believes it found new CIA malware

#267

Earlier quoted context omitted.

>How do you go from reading "the CIA is lying" to "the FSB is telling the truth"? The link is a Kaspersky press release, so there’s potential for an FSB connection: https://www.bloomberg.com/news/articles/2017-07-11/kaspersky...

Using that same logic most statements out of the US corporate InfoSec establishment should be similarly scrutinized. A whole lot of these outfits are started by former NSA employees, and they love having people that previously worked in US national security on their rooster for the marketing value. Yet whenever one of these outfits accuses China/Russia/Iran of being responsible for the latest "cyber incident"/"misinf…

If the leader of the infosec company is ex-CIA... that doesn't seem unreasonable.

Re: Kaspersky believes it found new CIA malware

#268

Earlier quoted context omitted.

Don't look too closely at how we got into World Wars 1 and 2, if you want to maintain that opinion.

Roosevelt won in 1940 in large part because he was running against an interventionist that wanted to join the war alongside the allies, but the US population was either largely against any intervention, or was outwardly pro-Nazi[0]. If it wasn't for Japan forcing our hand, the US would have been perfectly happy profiting from supplying other countries' war efforts, and building up their military while the rest of the…

During early WWII, prior to Pearl Harbour, the US used to place supplies on the US side of the Canadian/US border.

We'd then "steal" those supplies, thus allowing the US to avoid breaking non-aggression treaties, and (as you mentioned) the ire of some of its citizenry.

Not much profit in theft.

Re: Kaspersky believes it found new CIA malware

#269

Earlier quoted context omitted.

Because the entire goal is to promote skepticism about the USA while remaining as mum as possible on Russia and China. In the case of Russia, it’s not a secret that they try to disrupt and divide the states via internal conflicts so they can take over if we decline because of it. Here is just one example: https://www.wsj.com/articles/russian-backed-facebook-account... We also know that hundreds of thousands of foreig…

It's pretty easy to spot Russian/Chinese trolls on facebook. I've seen tons of it on conservative news feeds. Just find a ridiculous statement and trace back to the source. Usually they have public facing feeds to maximize propaganda and it's so blatantly obvious it usually makes me giggle.

They are just as blatant on liberal news feeds but don’t seem blatant to liberals just like the blatant ones on conservative feeds don’t seem blatant to conservatives.

Re: Kaspersky believes it found new CIA malware

#270

Earlier quoted context omitted.

It's nearly always about natural resources, just because the US has the largest oil reserves doesn't mean it's going to stop there. And the wars you mentioned are just the boots on the ground (or drones in the air) conflicts. Were still backing coups in Latin America (Honduras, Venezuela, Bolivia) so US friendly governments are put into place that will allow American companies to extract their resources.

which natural resources were we getting out of afghanistan

Afghanistan sits on top of trillions of dollars of mineral resources, including large reserves of copper, lithium, cobalt, and rare earth metals.
Post reply on HN