Live data from Hacker News

Confirmed: Samsung is not shipping keyloggers

f-secure.com

31–40 of 84 posts

Re: Confirmed: Samsung is not shipping keyloggers

#31

This is a good reminder to always do your homework before making such a strong accusation. Samsung's reputation is probably largely undamaged, other than among people who just read the headlines on news aggregator sites. Even searching for 'Samsung Key Logger' pulls up mostly articles about the false alarm situation. Mohamed Hassan [MSIA, CISSP, CISA and graduate of the Master of Science in Information Assurance (MSI…

To be fair, Mohamed Hassan did contact Samsung support and they didn't clear up the issue. In fact, I believe they may have even confirmed that there was a key logger installed! At that point his due dilligence has been done and he has confirmation. He doesn't need to do anything further than that. Shame on Samsung support for such a pathetic showing.

I don't expect customer support to know what a keylogger is, much less know if their own systems have them installed.

Re: Confirmed: Samsung is not shipping keyloggers

#32
post #18

Earlier quoted context omitted.

To be fair, Mohamed Hassan did contact Samsung support and they didn't clear up the issue. In fact, I believe they may have even confirmed that there was a key logger installed! At that point his due dilligence has been done and he has confirmation. He doesn't need to do anything further than that. Shame on Samsung support for such a pathetic showing.

He did not fulfill his due diligence. Not if they're going to add this to the article: "Mohamed Hassan, MSIA, CISSP, CISA is the founder of NetSec Consulting Corp, a firm that specializes in information security consulting services. He is a senior IT Security consultant and an adjunct professor of Information Systems in the School of Business at the University of Phoenix." If they're going to pass him off as an exper…

It's worse than that. The whole article was a fluff piece rambling about his awesome credentials and comparing the discovery to the discovery of Sony's rootkit and was written to create hype rather than show concrete evidence. And why needlessly break the article into two parts except to garner page hits?

The money quote:

>The findings are false-positive proof since I have used the tool that discovered it for six years now and I am yet to see it misidentify an item throughout the years.

It boggles the mind how a founder of security consulting company can be so clueless. But most of HN and the tech news site like Slashdot fell for this with completely knee-jerk reactions, so I guess I am not surprised and the people behind his fiasco got the publicity they wanted. And remember HB Gary?

I am sure this hoopla would've cost Samsung some real damage in sales and they might be considering legal action. As Churchill said:

"A lie gets halfway around the world before the truth has a chance to get its pants on."

Well, atleast I can say I called it, even after the so called Samsung confirmation. http://news.ycombinator.com/item?id=2389141

Re: Confirmed: Samsung is not shipping keyloggers

#33
Perhaps I read it wrong, but the article never says Samsung didn't ship a keylogger, it just indicates that the AV software can make false positives based on a folder.

Can we get a link to an article that actually checks a Samsung laptop (and lists their methodology, not this "Duh, there were not any keyloggers") instead of anecdotal evidence and attacking the previous reseaerchers methods?

Even if the previous guy was wrong, at least he listed all his methods for review.

Re: Confirmed: Samsung is not shipping keyloggers

#34
post #15

This is a good reminder to always do your homework before making such a strong accusation. Samsung's reputation is probably largely undamaged, other than among people who just read the headlines on news aggregator sites. Even searching for 'Samsung Key Logger' pulls up mostly articles about the false alarm situation. Mohamed Hassan [MSIA, CISSP, CISA and graduate of the Master of Science in Information Assurance (MSI…

Everything that he did was just shameful. Suggesting class-action, writing two articles essentially saying the same thing (in a "2-part series"), shoving our faces with his credentials (that obviously didn't do much for him), claiming that his anti-virus program never had false positives, drawing comparisons to the Sony rootkit debacle, etc. I hope this guy has it coming to him. If he's going to put his creds up like…

He's founder of NetSec Consulting Corp. I am sure this is great advertisement for it. Or maybe it was orchestrated to generate publicity.

Re: Confirmed: Samsung is not shipping keyloggers

#36

This is a good reminder to always do your homework before making such a strong accusation. Samsung's reputation is probably largely undamaged, other than among people who just read the headlines on news aggregator sites. Even searching for 'Samsung Key Logger' pulls up mostly articles about the false alarm situation. Mohamed Hassan [MSIA, CISSP, CISA and graduate of the Master of Science in Information Assurance (MSI…

To be fair, Mohamed Hassan did contact Samsung support and they didn't clear up the issue. In fact, I believe they may have even confirmed that there was a key logger installed! At that point his due dilligence has been done and he has confirmation. He doesn't need to do anything further than that. Shame on Samsung support for such a pathetic showing.

>To be fair, Mohamed Hassan did contact Samsung support and they didn't clear up the issue. In fact, I believe they may have even confirmed that there was a key logger installed! At that point his due dilligence has been done and he has confirmation. He doesn't need to do anything further than that. Shame on Samsung support for such a pathetic showing.

Extraordinary claims require extraordinary evidence. Especially when the person making claims is the founder of a security company. His due diligence consisted of things like "The software I used is false-positive proof since I am using it from 6 years". "I have done this on two different laptops with same results, so it must be Samsung's fault". Huh?

Re: Confirmed: Samsung is not shipping keyloggers

#37
post #22

This is a good reminder to always do your homework before making such a strong accusation. Samsung's reputation is probably largely undamaged, other than among people who just read the headlines on news aggregator sites. Even searching for 'Samsung Key Logger' pulls up mostly articles about the false alarm situation. Mohamed Hassan [MSIA, CISSP, CISA and graduate of the Master of Science in Information Assurance (MSI…

It should also be a good reminder to all of the people on HN who jumped to the conclusion that this guy was right on very sketchy evidence. This place is influential. We should do better.

I agree completely with this sentiment. It's important to remember that the vast majority of "journalism" on the web isn't conducted very professionally.

Re: Confirmed: Samsung is not shipping keyloggers

#38
post #21

Earlier quoted context omitted.

Wait, University of Phoenix? Isn't it the same university associated with scams and sham degrees, am I wrong?

UoP is accredited by the same board which accredits University of Michigan. [ http://www.phoenix.edu/about_us/accreditation.html ] For whatever that is worth. They have experienced difficulty regarding the rates at which students receiving Federal Financial Aid graduate - i.e. their issues are based on low graduation rates and not based on being a diploma mill. Disclosure: my spouse teaches for UoP part time.

They have also received criticism for the large number of loan defaults, and lobbying to change how the loan default statistics are calculated to make their numbers look better (at least according to Frontline). Same program also mentioned private for-profit schools account for a quarter of all student aid in the country, a disproportionally high number since they are not a quarter of our schools.

Re: Confirmed: Samsung is not shipping keyloggers

#39
post #4
post #2

I'm no expert of Antivirus software, but figuring whether something is a threat by its _folder name_ ??? With all the money going into the industry? That has to be some sort of april fool's prank gone really bad.

Isn't the whole "security industry" a prank gone bad?

There are a whole lot of charlatans in the field. Certifications and credentials are often a good tip-off.

Re: Confirmed: Samsung is not shipping keyloggers

#40

This is a good reminder to always do your homework before making such a strong accusation. Samsung's reputation is probably largely undamaged, other than among people who just read the headlines on news aggregator sites. Even searching for 'Samsung Key Logger' pulls up mostly articles about the false alarm situation. Mohamed Hassan [MSIA, CISSP, CISA and graduate of the Master of Science in Information Assurance (MSI…

certificate fail!
Post reply on HN