FBI pushes private sector to cut ties with Kaspersky
cyberscoop.com
cyberscoop.com
If this was a problem for the country, wouldn't it be DHS's job? And if there was an issue to be looked in to, it's FBI's job. And if there is something about spying to figure out if someone is doing something, there is the CIA and the NSA depending on where they need to look?
On top of that: wouldn't this be something that should simply be looked at internally at agencies and if there is an actual problem, resolve it for the country by issuing a law or directive or bill or whatever name they put to rules the US-based companies have to follow?
They do have somewhat orthogonal missions (HUMINT vs SIGINT) as others have commented, but never underestimate each piece of the government wanting their own agents.
Basically: US law enforcement is telling US companies that Kaspersky products are likely compromised by Russian intelligence. Surely foreign law enforcement is issuing similar warnings about Symantec and McAfee products being compromised by the NSA.
------------------------------------
[1]https://en.wikipedia.org/wiki/United_States_Intelligence_Com...
> In view of the fact that significant cyber incidents will often involve at least the possibility of a nation-state actor or have some other national security nexus, the Department of Justice, acting through the Federal Bureau of Investigation and the National Cyber Investigative Joint Task Force, shall be the Federal lead agency for threat response activities.
https://obamawhitehouse.archives.gov/the-press-office/2016/0...
https://www.fbi.gov/news/stories/new-us-cyber-security-polic...
Much of the US critical infrastructure is owned and operated by private industry. For that reason, a collaboration between the FBI and private industry was formed in 1996, called Infragard [0]. Today, there are chapters in each of various regions of the US, each with an FBI coordinator who facilitates the communication between feds and local industry.
[0] http://www.infragardmembers.org/critical-infrastructures.htm...
Whether the federal government should be lobbying against a private companies’ products is a more complicated issue. I think, if it could be demonstrated that there is sufficient evidence to link them to unethical behavior, it might be appropriate.
Pretty much anyone with money in Russia crosses the Putin government at their own peril. There are numerous cases of Russian billionaires in opposition to Putin losing their companies to supposedly trumped-up charges of tax evasion and subsequently dying in jail under suspicious circumstances.
Having money is not a prerequisite, and in some cases even being in Russia is not a prerequisite.
As depressing as it sounds, assuming any government is keeping their nose out of their tech companies is honestly pretty naive.
No actual technical mechanism has come out suggesting how Kaspersky is spying, only that it could. We've seen technical mechanisms which impact US firm's hardware such as Cisco and how they're embedding that malware into specific target's endpoints (postal intercepts). We've also seen firmware updates go out to US company's industrial hardware which MIGHT have needed the companies help to produce.
I'm yet to see anyone publish an article talking in technical terms about what Kaspersky is meant to be doing. All people keep repeating is that one of the top executives has Russian military experience. But technical facts are more key here than anecdotes or fear mongering. I'd stop using them tomorrow if someone can show me why, but even the FBI/DHS/NSA hasn't produced a paper on it or done a presentation at Blackhat.
Let's talk actual facts here. Software or even hardware isn't magic, if you can show that Kaspersky is evil show it already.
Edit: Not dismissing the Russian scenario, but this is McCarthyism 2.0 as far as I'm concerned.
A recent rebuttal by himself: https://eugene.kaspersky.com/2015/03/20/a-practical-guide-to...
Edit: and a more recent one: https://eugene.kaspersky.com/2017/05/12/they-asked-me-everyt...
Edit 2: "FBI officials point to multiple specific accusations of wrongdoing by Kaspersky, such as a well-known instance of allegedly faking malware."
Ok, if they are bringing that incident up, this really does mean they have nothing and are grasping at straws. This is referring to a time when Kaspersky trolled competitors who were stealing their signatures, and they made some fake detections. It's the antivirus equivalent of "Trap Streets" used by mapmakers. It doesn't create any kind of back door or weakness.
1. Russia’s Top Cyber Sleuth Foils US Spies, Helps Kremlin Pals
2. What Wired Is Not Telling You – a Response to Noah Shachtman’s Article in Wired Magazine
3. HN Discussion on 2
_____________________________
[1]: http://www.wired.com/dangerroom/2012/07/ff_kaspersky/all/
[2]: https://eugene.kaspersky.com/2012/07/25/what-wired-is-not-te...
NOW I know win7 also phone backs home T_T
http://www.lansingstatejournal.com/story/news/local/watchdog...
"Microsoft Wins Appeal on Overseas Data Searches" https://www.nytimes.com/2016/07/15/technology/microsoft-wins...
[edit]https://www.mcafee.com/us/resources/solution-briefs/sb-quart...
Except when it's not.
If anything, it seems like the Russian intelligence agencies are more capable that the US ones right now ...
It is actually quite difficult to intentionally ignore nation state malware from certain regions, because attributing the origin is not something a private entity can accurately do with confidence.
http://www.reuters.com/article/us-kaspersky-rivals-idUSKCN0Q...
"Microsoft's antimalware research director, Dennis Batchelder, told Reuters in April that he recalled a time in March 2013 when many customers called to complain that a printer code had been deemed dangerous by its antivirus program and placed in "quarantine."
"Over the next few months, Batchelder's team found hundreds, and eventually thousands, of good files that had been altered to look bad."
"Batchelder told his staff not to try to identify the culprit"
This last part seems incredibly suspicious.. perhaps it was Microsoft trying to discredit Kaspersky
Would this catch everything?
Disclosure: I am Russian-American, but always voted against Putin. Not that it mattered, of course.
What if they build something bad into the Kotlin language?