Live data from Hacker News

A New Malware Detection Tool That Can Expose Illegitimate State Surveillance

eff.org

31–40 of 56 posts

Re: A New Malware Detection Tool That Can Expose Illegitimate State Surveillance

#32

Earlier quoted context omitted.

Microsoft AV, Norton, McAfee, etc. We know this, how? Because we can look at Google's virustotal and see when a sample was first submitted and when it was "detected." With typical malware there is a fairly short window between A and B, with US G malware there is a HUGE window (months, sometimes years). Either the US G just gets very lucky that their samples aren't ever looked at deeper or more likely they have nation…

Don't forget Kaspersky (at least for Russian gov malware). I believe their CEO came out in favor of surveillance in a blog post for a brief period.

If Microsoft AV looks the other way for one set and Kaspersky looks the other way for another set, is it possible that there is a value of using a union of the two?

I assume Microsoft AV isn't going to look the other way for Russian exploits, unless the US is also using them, and vice versa.

Re: A New Malware Detection Tool That Can Expose Illegitimate State Surveillance

#33
post #19

Isn't clamAV[1] very good at this already and free of charge AND not keen to close an eye on specific signatures . [1] http://www.clamav.net/doc/install.html [2] http://www.clamxav.com for OSX

I believe Cisco now owns clamAV.

Re: A New Malware Detection Tool That Can Expose Illegitimate State Surveillance

#35

I love the EFF (and have donated money) but I am going to disagree with them on this one. As they themselves fully admit, the first thing the big g is going to do is test that their malware v2 isn't detected by this. In the same way that malware authors now check against Microsoft AV because it is the most popular. So my point is that traditional AV in this scenario is a loser and will remain a loser because it is a…

> As they themselves fully admit, the first thing the big g is going to do is test that their malware v2 isn't detected by this ... it is a race AV just cannot win. This can be said of every security solution. The value of security is to increase the attackers' cost, which will deter attackers who don't want to pay the higher price. There is no absolute security. Also, the prospect of updates will increase attacker c…

or, gosh, incorporate a security system that doesn't rely on obscurity of defenses or ignorance on the part of your attacker..?

Re: A New Malware Detection Tool That Can Expose Illegitimate State Surveillance

#36

I love the EFF (and have donated money) but I am going to disagree with them on this one. As they themselves fully admit, the first thing the big g is going to do is test that their malware v2 isn't detected by this. In the same way that malware authors now check against Microsoft AV because it is the most popular. So my point is that traditional AV in this scenario is a loser and will remain a loser because it is a…

Hey, Danny O'Brien from EFF here. You're absolutely right: the best defense against malware attacks of any kind is to increase the level of protection that systems have, whether that's read-only distributions, compartmentalization approaches like Qubes" rel="nofollow">https://qubes-os.org/">Qubes, or just generally fixing the vulnerabilities that malware must exploit to take control.

Detekt is mostly about a different and earlier part of the problem: allowing groups that may be currently targets of illegitimate state surveillance to confirm that they have been infected by specific tools that we know to be used by state attackers, and therefore confirm that they are indeed under this specific sort of surveillance.

Up until now getting to the point of confirming that fact, has mostly relied on manual examination by experts. If an activist or journalist suspects they may be under surveillance or infected with malware, they need to navigate the usual challenges to fixing a malware infection, plus they need to eliminate the (often far more probable) case that they are infected with the usual petty criminal spyware.

This is about being able to positively identify a relatively small number of cases of targeted illegitimate surveillance, out of a ecosystem of hundreds of thousands of potential targets, and a huge array of potential exploiters of vulnerabilities. Right now all the organizations supporting Detekt (EFF, Amnesty International, Privacy International and Digitale Gesellschaft) receive queries about potential infection cases from all around the world: now we can scale up a little the first step of that triage we conduct. The positive identifications that come out of Detekt we can take further, and base, for instance, the court" rel="nofollow">http://www.washingtonpost.com/business/technology/us-citizen... cases against the Ethiopian government in the UK and US that PI and EFF are conducting.

Re: A New Malware Detection Tool That Can Expose Illegitimate State Surveillance

#37

I love the EFF (and have donated money) but I am going to disagree with them on this one. As they themselves fully admit, the first thing the big g is going to do is test that their malware v2 isn't detected by this. In the same way that malware authors now check against Microsoft AV because it is the most popular. So my point is that traditional AV in this scenario is a loser and will remain a loser because it is a…

> A far better EFF suggestion to "at risk" individuals (e.g. journalists, activists, etc) is read only systems. For example grab a Live DVD of a Linux distribution, boot it, use it, and then as soon as you turn it off everything is reset to 0.

It's called TAILS. It also triggers scrutiny by "the big g".

http://www.theregister.co.uk/2014/07/03/nsa_xkeyscore_stasi_...

Re: A New Malware Detection Tool That Can Expose Illegitimate State Surveillance

#38
post #35

Earlier quoted context omitted.

> As they themselves fully admit, the first thing the big g is going to do is test that their malware v2 isn't detected by this ... it is a race AV just cannot win. This can be said of every security solution. The value of security is to increase the attackers' cost, which will deter attackers who don't want to pay the higher price. There is no absolute security. Also, the prospect of updates will increase attacker c…

or, gosh, incorporate a security system that doesn't rely on obscurity of defenses or ignorance on the part of your attacker..?

Got a link to this consumer OS whose implementation is mathematically proven secure?

Re: A New Malware Detection Tool That Can Expose Illegitimate State Surveillance

#39

I love the EFF (and have donated money) but I am going to disagree with them on this one. As they themselves fully admit, the first thing the big g is going to do is test that their malware v2 isn't detected by this. In the same way that malware authors now check against Microsoft AV because it is the most popular. So my point is that traditional AV in this scenario is a loser and will remain a loser because it is a…

Hey, Danny O'Brien from EFF here. You're absolutely right: the best defense against malware attacks of any kind is to increase the level of protection that systems have, whether that's read-only distributions, compartmentalization approaches like Qubes " rel="nofollow">https://qubes-os.org/">Qubes , or just generally fixing the vulnerabilities that malware must exploit to take control. Detekt is mostly about a differ…

Just to back up what Danny is saying here.

As part of a number of groups that do digital and physical security training for journalists and human rights defenders, most of us have/do recommend the use of live CDs like TAILS etc. Unfortunately my experience has shown that it is very very difficult to get anything other than a small percentage of journalists or HRDs using them for any period of time - especially in countries where IT literacy levels are low. Linux (and also PGP) is just too much of a cultural shift for most people. I mean even a security conscious guy like Glen Greenwald didn't even bother to learn PGP or Live CD usage in the first few months of Snowden reaching out to him.

It is a gap in capability that many of us (including Danny at EFF) are working on day and night to try and bridge though!

Post reply on HN