Live data from Hacker News

Duqu 2.0 Hits Kaspersky Lab

securelist.com

51–60 of 60 posts

Re: Duqu 2.0 Hits Kaspersky Lab

#51
post #29

Earlier quoted context omitted.

> a Russian company started with government support From what I know this is simply not true. Got a source? But I think your overall point holds. Kaspersky's 400 million user base includes a boatload of US/Western users, including enterprise and government clients. This simply cannot NOT be of some concern to respective countries, so it's perfectly logical that they would want to keep an eye on the situation.

I thought I had a source, but when I went looking I found tons of interesting connections (eg Kaspersky having gotten started in anti-virus while he was KGB) but no actual proof of involvement. Given how Russian business works, though, it would seem likely that there is a connection. But http://www.bloomberg.com/news/articles/2015-03-19/cybersecur... is an article that gives more recent reason for why Kaspersky is a…

>tons of interesting connections

Mind sharing those?

>he was KGB.

A claim unsupported by evidence.

>Given how Russian business works

"Given how I assume Russian business works based at most on anecdotal evidence." FTFY

Anyway I wouldn't bother to reply to your post, if you hadn't had used source that is full of shit, pardon my French. You can check out Kaspersky's blog for rebuttal of this article. Now if you insist on inductive reasoning I can offer you no evidence to the contrary, of course. And no, I don't work for Russian troll agency and am not Russian in any way. I doubt they would bother with ycombinator anyway. In no way this is attack on you of course, but I find these kind of posts severely annoying because of aforementioned reasons.

Re: Duqu 2.0 Hits Kaspersky Lab

#52
post #37

Earlier quoted context omitted.

Even if it's the only one they've admitted to, I think it's readily known that Microsoft has numerous zero-days (discovered or not) in their software. Combine that with their prevalence in Enterprise businesses, they're going to be a logical starting point for any top tier blackhat org.

"I think it's readily known that Microsoft has numerous zero-days (discovered or not) in their software." This is true for every single piece of software ever written. Msft is no different in this regard.

I don't think it's fair to say "every single piece of software", as the claim that it's impossible to write secure software is just a myth. It's not very hard to write a secure "hello world".

Then there's also Coq and such.

Of course, usually the amount of vulnerabilities exponentially correlates to the size of the codebase.

Re: Duqu 2.0 Hits Kaspersky Lab

#53
post #45
post #30

It's kind of cute how the technical report[1] goes to great lengths to finger Israel, without explicitly stating it (see page 43). [1] https://securelist.com/files/2015/06/The_Mystery_of_Duqu_2_0...

Outsiders have no clue about Israel's role in the Equation Group. Or who the Equation Group actually serves, for that matter.

Equation Group was very clearly the NSA, given that actual NSA codenames appeared in the binaries.

Re: Duqu 2.0 Hits Kaspersky Lab

#54

"Despite the beefed up operational security of the malware, its unmistakable connection to the Duqu 1.0 and the times of day Duqu attackers manually entered Kaspersky's network leave little doubt in the minds of company researchers that the 2011 and 2014 attacks were carried out by the same group." Not only is this a total stretch, it's complete hearsay. The reasons for hackers to go after Kaspersky are just as numer…

Did you actually read the report? There are similarities that are way more consistent than just "looking similar". I tend to agree that attribution is usually a hard guess, but in this case, it's pretty hard to argue against them. Keep in mind that most of those similarities are totally not on the exploit parts, but on the very little quirks on how to handle the 'trivial' things that are extremely specific to your coder. (Also keep in mind that developing such a framework takes tons of time & money, we're talking about years & millions).

Re: Duqu 2.0 Hits Kaspersky Lab

#55

So, correct me if I'm wrong: A non-technical user on their network DIDN'T have EMET running? Or did they, perhaps, have an EMET bypass in their shellcode? If it's the latter, that's what I would be more interested in.

What makes you think that EMET can't be bypassed?

Re: Duqu 2.0 Hits Kaspersky Lab

#56
post #40

Earlier quoted context omitted.

And so it does. I stand corrected. The USSR was indeed called the lesser Satan 35 years ago. However the link that I provided to http://en.wikipedia.org/wiki/Iran%E2%80%93Russia_relations says that Iran and the USSR had poor relations (due to the whole atheism thing), but Iran and Russia have had good relations since the USSR fell. Do you have a reference to Iran calling Russia any version of Satan in, say, the last…

Lets better return to the subject. I agree with your overall conclusion that it's possible the attack was carried out by some special agencies, and that it might be reasonable from their standpoint. But the chain of causality you draw looks to me as an arbitrary fantasy; or to say better, only one of many possible explanations. It puts together several unverified assumptions - statements which are not 100% true, but…

You are missing the fact that there are other logical routes to the scenario, and some of those assumptions are correlated.

For example instead of Russia wanting to provide cyber security, Russia saw the opportunity to embarrass the US and score brownie points with Iran.

Instead of Kaspersky detected because of intelligence order, Kaspersky detected because they happened to be the ones in a position to do so.

And if Russia wanted to provide cyber security for Iran, then the odds are high that Kaspersky would be a component of that. Not because Russia has no other options, but because it is an obvious component that can be made available.

Re: Duqu 2.0 Hits Kaspersky Lab

#57
post #45

Earlier quoted context omitted.

Outsiders have no clue about Israel's role in the Equation Group. Or who the Equation Group actually serves, for that matter.

Equation Group was very clearly the NSA, given that actual NSA codenames appeared in the binaries.

Equation Group very clearly includes the NSA. But how do we really know what the NSA is? Given the maze of secrecy, does anyone at the NSA even know what the NSA is, in any comprehensive sense? Or who it serves?

Re: Duqu 2.0 Hits Kaspersky Lab

#58
post #57

Earlier quoted context omitted.

Equation Group was very clearly the NSA, given that actual NSA codenames appeared in the binaries.

Equation Group very clearly includes the NSA. But how do we really know what the NSA is? Given the maze of secrecy, does anyone at the NSA even know what the NSA is, in any comprehensive sense? Or who it serves?

A fair point. One of the most surprising revelations from Snowden is that NSA and GCHQ apparently have conjoined intranets.

Re: Duqu 2.0 Hits Kaspersky Lab

#59
post #57

Earlier quoted context omitted.

Equation Group very clearly includes the NSA. But how do we really know what the NSA is? Given the maze of secrecy, does anyone at the NSA even know what the NSA is, in any comprehensive sense? Or who it serves?

A fair point. One of the most surprising revelations from Snowden is that NSA and GCHQ apparently have conjoined intranets.

Yes, blood brothers ;)

Another surprising revelation was that need-to-know structure isn't necessarily congruent with management structure or chain of command. That is, one can report to someone who isn't authorized to know what one is doing. As I recall, the focus was on financial accountability, duplication of effort, empire building, etc. But there are deeper concerns about accountability.

Re: Duqu 2.0 Hits Kaspersky Lab

#60
post #56

Earlier quoted context omitted.

Lets better return to the subject. I agree with your overall conclusion that it's possible the attack was carried out by some special agencies, and that it might be reasonable from their standpoint. But the chain of causality you draw looks to me as an arbitrary fantasy; or to say better, only one of many possible explanations. It puts together several unverified assumptions - statements which are not 100% true, but…

You are missing the fact that there are other logical routes to the scenario, and some of those assumptions are correlated. For example instead of Russia wanting to provide cyber security, Russia saw the opportunity to embarrass the US and score brownie points with Iran. Instead of Kaspersky detected because of intelligence order, Kaspersky detected because they happened to be the ones in a position to do so. And if…

> You are missing the fact that there are other logical routes to the scenario.

No, you are missing the fact that there are lot of possible explanations outside of the scenario.

Even if the current attack was by US and/or Israel intelligence, penetrating Kaspersky may be useful for them just as it is, to keep eye on Kaspersky anti-virus technologies and find a way to to avoid them. Without any "revenge" for Iran.

Moreover, I've just checked https://en.wikipedia.org/wiki/Stuxnet#History , stuxnet wasn't detected by Kaspersky, it was another company. Also, "The reason for the discovery at this time is attributed to the virus accidentally spreading beyond its intended target (the Natanz plant) due to a programming error introduced in an update". So this whole episode doesn't present Kaspersky as an active enemy of US intelligence.

I doubt very very much Russia wants to help Iran to get nuclear weapons - no country will help another country to get nuclear weapons, even if they can win "brownie points".

Post reply on HN