Live data from Hacker News

Russian antivirus firm faked malware to harm rivals, say ex-employees

reuters.com

71–80 of 102 posts

Re: Russian antivirus firm faked malware to harm rivals, say ex-employees

#71
post #62
post #35

Earlier quoted context omitted.

The first and foremost "target" here is not only Kaspersky (i.e. Russian tech/security industry) but Russia itself. Notice again the title ;)

so, the whole article is bunk because it is based on anonymous sources and did not get responses from all parties involved, but then because the headline has the word "Russia" in it, that's firm evidence of secret US government collusion with a major news outlet.

No, it's a bunk because it provides zero evidence but plenty of innuendos and unfounded allegations/accusations, and yes it's infinity more plausible a secret plan between the us gov and a us based media corporation than a reputable antivirus vendor like Kaspersky sabotaging its rivals.

Re: Russian antivirus firm faked malware to harm rivals, say ex-employees

#72
I believe it. We supported several shareware products during the period described in the article and most of our sharewares were at some point tagged as malware by antivirus programs - Norton Antivirus, most notably, but never by Kaspersky.

The signatures that triggered it were in 3rd party installer code that we used. If you think of it, it is a perfect attack method as by targeting shared installer many products were made false positive with little effort.

Re: Russian antivirus firm faked malware to harm rivals, say ex-employees

#74
post #67
post #43

Earlier quoted context omitted.

No, it just reports. The agencies and the governments make the agenda (unfortunately). That said, Reuters IMHO is the top reporting authority worldwide along with AP.

> The agencies and the governments make the agenda (unfortunately). Pretty hefty accusation on the integrity and journalistic ethics of the Associated Press. Do you have a reliable and credible source for this claim?

> journalistic ethics

no one takes this seriously.

Re: Russian antivirus firm faked malware to harm rivals, say ex-employees

#76
post #63

I'd find this very surprising, if true. When I worked for a company that was essentially developing malware, we were able to get ourselves whitelisted by most anti-virus software (either by going through an automated submission process, or outright bribery). The only one who wouldn't budge on principal, no matter what we offered, was Kaspersky. All the others either auto-whitelisted us when we asked or after we paid…

This is interesting, because I thought Symantec was the incorruptible AV co.

Re: Russian antivirus firm faked malware to harm rivals, say ex-employees

#77
This seems like fair game, and it benefits the consumer by keeping the anti-virus people on their toes.

Kaspersky has demonstrated a weakness: that the firms copy each other's data and blindly trust each other as well as the initial submissions. They have a submission process for infected files which can be demonstrably abused to inject false positives.

Also this:

> Then, when competitors ran this doctored file through their virus detection engines, the file would be flagged as potentially malicious. If the doctored file looked close enough to the original, Kaspersky could fool rival companies into thinking the clean file was problematic as well.

What?? Infected files are always similar to clean files. An infected MS Word 2010 still looks mostly like MS Word 2010 and is even usable as such. Knowing clean from infected is the bread and butter of anti-virus. They are supposed to take doctored files, and register them as malicious, while recognizing clean ones as clean. If similarity between dirty and clean them causes a false positive, you would think that this is a fundamental problem. It shows they are using some weak heuristics to guess that files are clean instead of, say, strong checksums. They are guessing whether that DLL belonging to MS Word 2010 is clean or not because they have no idea what clean looks like, and Kaspersky has shown that they can be induced to guess wrong.

A proper implementation would detect so much as a single bit difference between a clean file and an altered one. Rather, they must be working off the assumption that there is some minimum difference between a viable infection and the clean file. In keeping with this, there is a database of the known dirty files only, and not of the clean reference files. Anything close to the dirty example within some small "edit distance" is just a variation on dirty and is declared dirty. Anything distant is either a different, unknown form of dirty, or clean. Either way it is declared clean. If that's how things work in an AV program, it has a weakness. Competitors should be merciless in identifying and exposing that weakness, because that's good for the consumer in the end.

Re: Russian antivirus firm faked malware to harm rivals, say ex-employees

#78
post #63

I'd find this very surprising, if true. When I worked for a company that was essentially developing malware, we were able to get ourselves whitelisted by most anti-virus software (either by going through an automated submission process, or outright bribery). The only one who wouldn't budge on principal, no matter what we offered, was Kaspersky. All the others either auto-whitelisted us when we asked or after we paid…

Can you tell us a bit more? This is absolutely fascinating.

Re: Russian antivirus firm faked malware to harm rivals, say ex-employees

#79
post #76
post #63

I'd find this very surprising, if true. When I worked for a company that was essentially developing malware, we were able to get ourselves whitelisted by most anti-virus software (either by going through an automated submission process, or outright bribery). The only one who wouldn't budge on principal, no matter what we offered, was Kaspersky. All the others either auto-whitelisted us when we asked or after we paid…

This is interesting, because I thought Symantec was the incorruptible AV co.

Have you ever used their product(s)? Given the way they used to slow PCs down to a halt, I didn't/wouldn't trust them to do a halfway-decent job.

Re: Russian antivirus firm faked malware to harm rivals, say ex-employees

#80
post #51

Earlier quoted context omitted.

I agree that it smells a bit, but take a quick look at the author, Joseph Menn. He's been floating around tech reporting for a while and seems to have some netsec chops. This isn't an article coming out of the State Department or some anonymous blog; there's a name behind it of someone who'd have their reputation to lose if it turned out to be a bunch of false allegations. (Not that that's never happened before...)

It's impossible to prove that these allegations were false. So there's no reputation to lose. The only ways i can think of to prove innocence (in general) are a) an alibi b) finding who actually did it. Both of these don't work here, you can't have an alibi for the whole company for 10 years, obviously. You can't find out who did "it" because there's no concrete example. At the very best you can prove that others did…

If any if the downvoters could elaborate why I'm wrong I'd appreciate that. I really don't know.
Post reply on HN