Live data from Hacker News

Kaspersky believes it found new CIA malware

therecord.media

51–60 of 314 posts

Re: Kaspersky believes it found new CIA malware

#51
post #4

Earlier quoted context omitted.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

If I had to wager I'd always bet on the CIA lying, I don't see how anyone could come to another conclusion given their history.

Intelligence is as much about focusin and finding as it is about distraction and deception.

There's absolutely no morals or ethics at the means level. That's not a judgement. The fact is, the driver is the ends. Meet the objective by (nearly) any means necessary.

The CIA, NSA, etc. will - and have - say pretty much anything. That's their job. But why people liken them to some holy higher power is beyond me. Maybe it's a result of the IC's own disinformation? Ironic but fitting.

Re: Kaspersky believes it found new CIA malware

#52
post #42

I always wonder. The CIA/NSA must essentially target the big Amazon, google and microsoft clouds to get blanket access to everything running and stored there. Seems like a no brainer from their standpoint.

I’d say the likelihood of an American Big Tech without CIA covert operatives working there is essentially zero, even if there’s no direct cooperation. It doesn’t make sense to not utilize some of your most valuable assets.

Re: Kaspersky believes it found new CIA malware

#53
post #4

Earlier quoted context omitted.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

Its probably because the US government is the single greatest force for evil in the world right now.

I think this strays from the original topic but why do you believe that? What makes you think the US is more evil then say, North Korea, China, or Russia?

Re: Kaspersky believes it found new CIA malware

#54
post #4
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

Because the entire goal is to promote skepticism about the USA while remaining as mum as possible on Russia and China. In the case of Russia, it’s not a secret that they try to disrupt and divide the states via internal conflicts so they can take over if we decline because of it. Here is just one example:

https://www.wsj.com/articles/russian-backed-facebook-account...

We also know that hundreds of thousands of foreign-sponsored accounts on Twitter, Reddit, Facebook, etc, have been banned over the years. (Please fact check by googling!)

Re: Kaspersky believes it found new CIA malware

#55

"Kaspersky believes it found new CIA malware"... being itself russian FSB malware...

Your comment makes no sense. If it were russian malware it would be outed by counterparts in a second. Still ZERO evidence, just FUD. I would also prefer to have FSB malware, just because their power is limited.

Well they have been outed as working with the FSB. You know it randomly uploads files to be analyzed and those files have been found in the poccession of the FSB right?

Re: Kaspersky believes it found new CIA malware

#56
post #4
post #2

So this was deployed in 2014 and we’re just connecting all the dots now? It really makes you wonder what’s being deployed at the moment. The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

The Broadcom link in the posted tweet records [some of?] their reasoning. Things like very North America specific strings, activity happening M-F for certain things (compilation, etc), capability (access to zero days implying deep pockets to buy said zero days), and breadth of target, etc.

That said - it ABSOLUTELY BOGGLES MY MIND that, if these are not leaked, but rather recovered from attempted attacks, how are _any_ valid timestamps and strings not randomized as part of the build process!? I'm not saying it refutes or confirms, I'm just wondering - how difficult is it to read an ELF | PE and remove / change those things, and if it's as easy as I'm thinking, why would you not do so? Or replace with preprocessor directives that you could setup to random values for production builds to use strings and timestamps that indicate some other entity? All of this seems straightforward to me, like, could do via shell scripting or python. Is there a valid reason to leave this stuff in? Are we seeing some low priority work that the TLA wants to leak to show that they're out there and capable?

Re: Kaspersky believes it found new CIA malware

#57
post #4

Earlier quoted context omitted.

I recall how when we had North Korean hacking activities and official attributions people would say, but how do we know it was them and how do we know the government isn’t making things up? But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.

Its probably because the US government is the single greatest force for evil in the world right now.

This falls under nationalistic flamebait according to HN's guidelines.

Re: Kaspersky believes it found new CIA malware

#58

I may have missed it in the article, but as a sysadmin, i’m trying to figure out what I should do. It appears the CIA has created malware. I assume, if they have exploited some hole, others will too. While I appreciate the heads up, Can anyone offer suggestions on how to mitigate this malware? What do I do? Do I have to rely on Kaspersky?

Rather than try to protect yourself from this, I personally would just live in a constant state of fear and paranoia. Maybe join a social group who can help you through it, like the Targeted Individuals club?

Re: Kaspersky believes it found new CIA malware

#59

Earlier quoted context omitted.

I'm sure the intended purpose is to vent frustrations, but maybe also to make aware those who've turned their eye from the US's terrible tyrannical and oppressive nature at home and abroad in favor of tribal political trivialities. It's not an incorrect statement either. I'd put the US up there with China, Russia, Big Tech, and the UN for forces of evil in the world right now.

What does "force of evil" mean anyway? It seems like a subjective measurement based entirely on tribalism as a foundation.

> What does "force of evil" mean anyway?

Yes, subjective. But here's my belief and how I believe it applies.

I believe evil is the abandonment of reason in any way. Instigation of force or coercion is an un-reason-able act no matter whether done by an individual or group of people.

Currently the US is engaged in numerous instigative forceful and coercive acts.

Further, much of what the US does would not be possible without people abandoning their own reasoning for the fallacy of authority. Here I do not mean appealing to authority, but instead `following orders` without consideration to one's own responsibility to also not instigate force/violence/coercion.

We could go down the path listing instigative acts of the US, but I believe most reasonable people know that the US is engaged in a number of these acts and would prefer it wasn't.

Re: Kaspersky believes it found new CIA malware

#60
post #36

Earlier quoted context omitted.

I've come to a conclusion that, from the evolutionary standpoint, lying (and stealing) is one of the most important forms of the intelligent behavior. We see it in the animal world, so this unavoidably should be seen as such in the world of humans...

Humans have the option of trying to be ethical as well and a lot of people would question if the CIA always behaves ethically.

Surely no-one believes the CIA always behaves ethically. Especially after the post-9/11 kidnap, torture and murder rampage. Perhaps you meant a lot of people question if the CIA ever behaves ethically.
Post reply on HN