Specifically:
You are whatever entity (I assume the FSB?) that can demand Kaspersky implant backdoors into its desktop antivirus software.
You decide to target that backdoor at the component of Kaspersky's software that gets, by design, unrestricted access to the plaintext of all TLS sessions on the machine, in addition to practically unrestricted access to every file on machine itself, and to the machine's memory in cpl0 and cpl3.
From that vantage point, you decide to...
... collide certificates?
Remember, your evil backdoor only impacts machines running your software already. From this thread, I'm wondering if that's maybe unclear to people.
I feel like the people claiming this is a smoking gun backdoor don't really understand what it means that Kaspersky's software is designed to proxy TLS. Yes: it is batshit that they proxy TLS. It's so batshit that this particular bug makes absolutely no sense as a backdoor. That idea is Xzibit-level crazy.
But even in the bizarro world --- which I do not concede that we live in but will briefly stipulate to --- where you would backdoor kernel AV software that looks at TLS plaintext solely to give people the ability to get access to TLS plaintext, this still doesn't make sense. They terminate TLS locally. They are the client to every TLS session originating from the machine. They don't need to create a noisy 32 bit certificate collision, so noticeable to the Internet it shows up in CT logs, to accomplish this task. They can backdoor TLS itself in a zillion plausibly deniable ways that would give network observers access to plaintext.
Which is all the more reason not to believe that it's enemy action.
So instead you consider ways to introduce vulnerabilities that leave plausible deniability.
Indeed, from that vantage point, you decide to...
... collide certificates.
Not only are there better plausibly deniable backdoors they could use from this vantage point, but there are NOBUS backdoors they could use from this vantage point. You propose an attacker so clever that they've carefully calibrated the sophistication of their backdoors, but not clever enough to know how to backdoor a TLS MITM (a TLS MITM installed by design) without leaving the absurd tracks this one does.
No. It's not a conspiracy. As usual: it's just a bug.
Sure. Kaspersky creates security software. The FSB benefits from vulnerabilities in antivirus software. Kaspersky knows this and puts company resources into particular areas. ie how to spot the next stuxnet, rather than fix bugs like this.
The FSB does not need to write the source code (for Kaspersky Anti-virus) to benefit from vulnerabilities. In fact NSA, GCHQ, and FSB all benefit from subversion of https.
I agree that cert collisions is a strange way to backdoor, but to dismiss any questions as to possible malice as "conspiracy theories" seems to ignore many recent events (such as Juniper Networks)
And this makes way more sense than that one did. Not that I'm convinced that it is one. But if it is, it's a pretty good one IMO.