"The N.S.A. bans its analysts from using Kaspersky antivirus at the agency, in large part because the agency has exploited antivirus software for its own foreign hacking operations and knows the same technique is used by its adversaries."
"The N.S.A. bans its analysts from using Kaspersky antivirus at the agency, in large part because the agency has exploited antivirus software for its own foreign hacking operations and knows the same technique is used by its adversaries."
1. Is hacking into a foreign AV company by a state an OK thing to do?
2. How do we know the anonymous source is being truthful?
3. If yes to the first two, are we certain that it wasn't exploited but was coerced?
4. If all of these things are true and they were coerced, what is the practical difference for the party being monitored?
In China it is not even theoretically possible because the gov't mandates backdoors and can easily shut down your company if you don't comply. You have way less recourse on rule of law.