Live data from Hacker News

Kaspersky believes it found new CIA malware

therecord.media

271–280 of 314 posts

Re: Kaspersky believes it found new CIA malware

#271

We're lucky that we can still catch some of them now. The current status of closed CPUs running proprietary firmware talking with closed chipsets running proprietary firmware blobs would make trivially easy to move the malware injection to the iron level for agencies funded by governments. Once they accomplish it, detecting their spyware using software, at any privilege level, will become impossible. I fear the scena…

If this is the case, then you only need to set a packet monitor between the computer and the ISP router to observe such magic packet.

Or will you claim that all machines that are capable of such tasks are already compromised?

Re: Kaspersky believes it found new CIA malware

#272

We're lucky that we can still catch some of them now. The current status of closed CPUs running proprietary firmware talking with closed chipsets running proprietary firmware blobs would make trivially easy to move the malware injection to the iron level for agencies funded by governments. Once they accomplish it, detecting their spyware using software, at any privilege level, will become impossible. I fear the scena…

Why is this impossible today? Isn't this exactly what Intel's "Management Engine" and AMD's "Platform Security" is? Bonus question, does apples new MX chips have an equivalent backdoor?

The equivalent of ME and PS in Apple’s ARM processors is the “Secure Enclave Processor”.

https://www.theiphonewiki.com/wiki/Secure_Enclave_Processor

Re: Kaspersky believes it found new CIA malware

#273
post #268

Earlier quoted context omitted.

Roosevelt won in 1940 in large part because he was running against an interventionist that wanted to join the war alongside the allies, but the US population was either largely against any intervention, or was outwardly pro-Nazi[0]. If it wasn't for Japan forcing our hand, the US would have been perfectly happy profiting from supplying other countries' war efforts, and building up their military while the rest of the…

During early WWII, prior to Pearl Harbour, the US used to place supplies on the US side of the Canadian/US border. We'd then "steal" those supplies, thus allowing the US to avoid breaking non-aggression treaties, and (as you mentioned) the ire of some of its citizenry. Not much profit in theft.

Everyone except the final payer (the government, indirectly the people) made profits. Same happens if the supplies and munitions were used instead of stolen. Many people profit along the way, and it is the same today.

Re: Kaspersky believes it found new CIA malware

#274
I always wonder where EU fits into the malware scene. We already know which countries have these kind of espionage tools: US, Russia, China, North Korea, Israel.

So is EU really that ethical to not engage in these kinds of moves? Or they are smart enough not to get discovered? Or somebody here will point out that I'm just not up to date?

Re: Kaspersky believes it found new CIA malware

#275

I always wonder where EU fits into the malware scene. We already know which countries have these kind of espionage tools: US, Russia, China, North Korea, Israel. So is EU really that ethical to not engage in these kinds of moves? Or they are smart enough not to get discovered? Or somebody here will point out that I'm just not up to date?

There was malware from EU, i know that France developed some of them[1].

-- [1] https://apt.thaicert.or.th/cgi-bin/showcard.cgi?g=Snowglobe%...

Re: Kaspersky believes it found new CIA malware

#276

I always wonder where EU fits into the malware scene. We already know which countries have these kind of espionage tools: US, Russia, China, North Korea, Israel. So is EU really that ethical to not engage in these kinds of moves? Or they are smart enough not to get discovered? Or somebody here will point out that I'm just not up to date?

In Germany there was the Staatstrojaner (Federal Trojan horse) case uncovered by the Chaos Computer Club: https://en.wikipedia.org/wiki/Chaos_Computer_Club#Staatstroj...

Re: Kaspersky believes it found new CIA malware

#277
post #231

Earlier quoted context omitted.

which natural resources were we getting out of afghanistan

Afghanistan is strategically located at a major crossroads between Central and East Asia. This is useful for trade and military operations. See also: https://en.wikipedia.org/wiki/Afghanistan_Oil_Pipeline

> This is useful for trade and military operations.

This has been an unfortunate truth for the US and USSR before it (and other empires before that). For a depressing insight into how little we have learned, Boys in Zinc by Svetlana Alexievich is a good read.

Re: Kaspersky believes it found new CIA malware

#278

I always wonder where EU fits into the malware scene. We already know which countries have these kind of espionage tools: US, Russia, China, North Korea, Israel. So is EU really that ethical to not engage in these kinds of moves? Or they are smart enough not to get discovered? Or somebody here will point out that I'm just not up to date?

Europe's malware industry has mostly been legalised in the name of fighting (narco)terrorists and pedos:

E.g. on this "legalized" end of the spectrum Netherlands, Italy, UK, Germany, Switzerland, France, all have _very_ active companies and strong talent pool for offsec skills and what is "legal malware" (Bundestrojaner varieties like Mini/Mega-Panzer, etc).

ETSI in France works hard so that the term "malware" doesn't even enter language (instead it's middleboxes like eTLS or standards covering the framework of Lawful Interception). The countries listed have strong relation between offsec vendors and consultants and the IC. E.g. Kudelski Security in Geneve prides itself on breaking phones, supplying tooling and a lab to Europol. HackingTeam, Gamma International, EncroChat, Sky ECC, Vupen, ... = all European.

The EU countries which have (some) talent but lack the jobs are often "painted as corrupt" backwaters where "everyone is a criminal[1]", usually cover the rest.

[1] e.g. see this PR/FUD video produced by the ghouls at Norton pretending to be journalists: https://www.youtube.com/watch?v=un_XI4MM6QI

Re: Kaspersky believes it found new CIA malware

#280
post #121

Earlier quoted context omitted.

Kaspersky's ties to FSB are an open secret, so it's really believing FSB vs believing CIA unless you have a way to verify them.

I think it’s much more likely for both these orgs to be telling the truth when they’re accusing their enemies of doing bad things than it is when they’re denying that they’ve done bad things themselves. It’s not a simple case of one consistently telling the truth, and the other consistently lying...

> think it’s much more likely for both these orgs to be telling the truth when they’re accusing their enemies of doing bad things

That’s... not how that works at all. Disinformation campaigns very frequently include publicly signaling you’ve come to a different conclusion than the real one you’ve come to.

Post reply on HN