Kaspersky: Yes, we obtained NSA secrets. No, we didn’t help steal them
arstechnica.com
arstechnica.com
Seems like massive incompetence from this user rather than Kaspersky doing anything malicious, and those files where destined to be leaked somehow the moment they left the NSA.
I'm sure there are some employees there who may report or leak things to the Russian government, but I don't buy the narrative that Kaspersky is some evil Russian cyber hoover. Maybe I'm naive though.
"...found they contained malicious code from Equation Group..."
"Equation Group" is Kaspersky's label for a malware group believed to be NSA.
Kaspersky's software possibly then detected as malware the very confidential code the NSA contractor/employee illegally took home, ha!
Those files were destined to be leaked somehow the moment they were created.
> Seems like massive incompetence from this user
So when we delete production data, it is a process failure[Gitlab postmortem] but when employees at a three letter agency cause spillage, it is a felony? It is wrong on several counts. One: this is data that we should not be hoarding in the first place. We should be helping vendors fix their stuff so the cachet of information automatically loses its value to people who want to get it. Two: Even if we are an axis of evil and don't want to do the right thing, punishing this individual seems like the thing the higher ups at an oppressive regime would do to prevent the wrath of the dictator on themselves for failing to prevent what is really a system failure.
[Gitlab postmortem] https://about.gitlab.com/2017/02/10/postmortem-of-database-o...
Edit while I have your attention I would like your support in ending the CFAA https://cfaa.eff.org/
Are you equating an accident that resulted in deleted data with someone intentionally taking confidential materials and putting them on an insecure, personal computer?
We treat nude photos differently than photos of a dog.
We treat credit card/user information differently than app logs.
That's why we have concepts such as HIPAA and PCI.
I am very saddened by my inability to communicate this in a better way but punishing this person will not solve any problem except someone somewhere can check a box saying they did their job.
Truly shocking revelation I know.
One of the reasons I ask, is related to Telegram. I'm aware of the crypto argument. But it seems (from the outside, so could be a complete cover of course) that Pavel Durov is somewhat taking a stand against their government[1][2][3]. Is that simply because he has enough money to do so? Or is it just a show to give people the idea he's taking a stand?
[1] https://www.reuters.com/article/us-russia-telegram-security/...
[2] https://www.neowin.net/news/russian-government-fines-telegra...
[3] https://www.deepdotweb.com/2017/10/30/russian-government-fin...
FWIW this is bullshit, telegram office in St. Petersburg is literally one floor below the VK office and Durov is regularly present there.
The whole exile thing is a charade, they’ve gone as far as assaulting people to try to keep it up https://m.lenta.ru/news/2017/03/20/durov/
Or in other words, when you operate a business of considerable size you start being part of the inner circle.
No, you can't, except in some abstract sense that loses all meaning.
In the west, it's routine to find wealthy and powerful members of the establishment pursue goals and policies that are directly opposed to the government with both success and failure. And of course these governments change hands relatively commonly.
In Russia, there are no wealthy or powerful people pursuing anything but Putin's agenda. All those who tried have been removed, via various methods ranging from banal to horrifying.
Now I'm sure there are nuts on the internet who will try to claim that the political divisions of the west are "really" just a front for a kleptrocrat cabal or whatever. But in the real world we have one country arresting its enemies and a bunch that don't, and that distinction matters.
The grandparent was treating it in the sense of security analysis: requiring proof of safety before granting trust.
I know which paradigm I'd pick before installing an trusted piece of software that can literally snoop on the whole system. But, y'know, whatever. You be you.
Basically: almost the whole of the Russian economy has been subverted to serve the needs of Putin's government. What are the chances that Kaspersky alone has not? Seems low enough to maybe look elsewhere for your AV needs.
Who cares if Putin personally calls the shots to the leaders of the company? There are a thousand shades of grey, for instance: Kaspersky knowledgeably allowing backdoors about which they could later feign ignorance.
I don’t trust US, Chinese, or Russian software. Big companies with access to sensitive data invariably become targets, and are only allowed to exist peacefully with the blessing of their masters.
Does delivering Uranium to The Enemy in exchange for cash donations to a slush fund count as "garden variety corruption you find in western countries"?
Does employing El Salvadorian gangs in your nation's capital to intimidate and assassinate your political enemies count as "garden variety corruption you find in western countries"?
I have to admit, even in a subthread where I was sure we'd see conspiracy nuttery, this is not the conspiracy I would have expected. You realize this is a totally fabricated thing, right? The timing alone should tell you all you need to know about what the intent behind it was.
https://wikileaks.org/podesta-emails/emailid/225
Suggest that it's not fabricated?
You're of course referring to that exploratory deal involving no delivery of Uranium anywhere.
Where the hell do people come up with this? It's not only untrue, it's not even feasible.
And all these positions are staffed with individuals who have intimate contact to Putin himself. Ranging from the husband of his daughter (Kirill Shamalov) who within months after the marriage took over Sibur, one of the largest petro businesses in the country, to old KGB aides of Putin who are now in charge of say, Rostec (Sergey Viktorovich Chemezov ) Russia's largest tech company. He too met Putin during his KGB time in East Germany. The list is too long for one post.
This is called an oligarchy and it's a fairly common historical arrangement. Nothing special about it and can be found in stratified countries where economic and political power is concentrated in the hand of a few families.
What about the minor detail that the oligarchs existed not only before Putin, but before Yeltsin, his predecessor, as well (not that they didn't grow under Yeltsin, but still)?
Most documentation that even passes a smell test of being reasonably plausible also suggests that the relationship was inverted - the oligarchs had more influence over Yeltsin than he did over them. When Putin took power, he was known for getting rid of many of them. The interesting thing about that, is that can be interpreted charitably or uncharitably - reducing the level of corruption and oligarch abuse of the government would be a positive thing, but banishing those who don't get in line (where we are assuming "getting in line" means they are being asked to do bad things, not follow laws) seems to be the default assumption in Russia's case. As far as I've seen, there's really never been anything to substantiate the uncharitable narrative, but so many people who have never been to Russia or spoken to a Russian person have themselves thoroughly convinced that they understand these secret "arrangements".
The whole idea that he could be a mafia boss and the CEO of literally everything is just crazy thinking, yet many of us westerners seem to just eat it up, and anything shady that happens even close to the government is always personally attributed to Putin's orders. It'd be like calling Trump a mafia boss because some random cop took a bribe in some city in the mid west. The idea is laughable, and the fact that we got here warrants a little bit of self-reflection on our part.
Nobody is doubting that. The country wasn't liberal or less oligarchic under Yeltsin, it was just as oligarchic under Soviet rule. Russia never meaningfully deviated from this course.
And this doesn't just come from a 'westerner far removed from Russia'. I have family in the country and lived there and I have experienced the degree of corruption not just under Putin but his predecessors personally.
Also, why do you believe that the corruption you experienced was because of the leader, rather than despite the leader's efforts?
I do not think anyone would even try to claim that Russia does not have a corruption problem. Putin himself has discussed it at length, particularly expressing frustration over how it cripples the economy, which is probably his biggest obsession.
Furthermore, and I am assuming here, but unless you're from an extremely important family, it seems unlikely that the flavor of corruption you would experience is even in the same universe as what the oligarchs and president are dealing with. This goes back to the idea of him being the mafia boss CEO of literally everything.
because of the programs he has put in place. Role of state owned entreprises has nearly doubled up to 70% of the economy, he has consciously put these close friends in place, he has cut down on any form of opposition and dissent within the country. It is the official course of his politics. The Russian government is not even hiding this, which makes the constant apologia from people not even affected by it seem only more baffling.
Russia had a few of those in the mid 90's. They're all jailed or exiled, or in more than a few cases murdered. Who are Putin's powerful domestic opponents whose existence you think is unfeasible to deny?
And even if there are those who oppose, there are also those who do not - and the do nots often get favors, inside info, etc. The opposers aren't really a concern.
It doesn't get more macro than what happened to Khodorkovsky, who got his company (Russia's biggest at the time) stolen from him once Putin started consolidating his power (in the early 2000s). That's like the Democrats confiscating the Koch brothers' conglomerate business and putting them in prison, or like the Republicans doing the same thing to some big Hollywood media mogul. It's not going to happen.
I'm sorry but Kaspersky gets NSA files and deletes them, instead of handing them to FSB? Nope, I don't believe it. You can get away with xx murders in exchange for that
And that's the most generous assumption--that Kaspersky wasn't looking for them
Why not both?
I don't know about this particular story, but Kaspersky is certainly has strong ties with FSB, FSO and other official structures. I don't mean that it's their main business model — developing anti-virus software pays well enough not to be some cover story — but they're definitely _friendly_ on a deep personal level. Kaspersky himself was educated in KGB school, worked in government structures and has a lot of connections (which he used, for example, with that shady story when his son was kidnapped).
Usually, in Moscow, there is a strong correlation between being a highly educated, well-paid IT professional and having a negative opinion about current Russian regime; but judging from my second-hand stories from friends and colleagues, guys at Kaspersky tend to be very patriotic and pro-government. So, while I don't think that Kaspersky lab was founded deliberately like some sort of cover. But they're the kind of people who would definitely help FSB with whatever they ask — not because of some secret court order, but happily, thinking that they are serving their country and doing a good thing.
Do you have sources for this? Well-paid professional might not care about politics at all or might be OK with current regime because it doesn't interfere with their life. Furthermore, some of them might be even proud for occupying Crimea.
But I can agree that there is relatively high percent of anti-Putin people in Moscow.
Read the first-person account by Igor Ashmanov who witnessed the whole incident. [1] Kaspersky's son was found not by FSB, he was found by the unit of Moscow police that was specifically created to deal with kidnappings, with cases like that one. If the story with the kidnapping proves anything, it proves the opposite, that he actually had NO any serious FSB connection.
[1] https://roem.ru/18-10-2017/261503/kaspersky-poprosil-dokazat... and following comments
Yeah, a really good and unbiased source you got there.
I don't think it even needs a narrative about Kaspersky. You could expect that they're infiltrated in some way (worker, infrastructure, hosting, ...) and leak information to FSB. I'm exactly the same way Symantec could leak information to NSA. Without the evil qualifier and narrative for the reasons, both are likely to happen to some extent.
In this case, _if_ you buy into the arc of the story then I would say it was it was likely another family member who tried to do the pirated software. But that would be a massive faux pas. So there's likely other nips and tucks, etc.
All the public knew is that allegedly Israel hacked Kaspersky and noticed the Russian government using Kaspersky's tools to try and dig out secret documents.
I mean who knows, maybe the Russian government had a backdoor that they were abusing, maybe they hacked Kaspersky themselves, or maybe they were just given access.
I would have given Kaspersky plausible deniability before this article.. now I just don't believe them.
At face value their explanation sounds reasonable.
However, the original claim is that the Israelis were watching in real-time as agents searched computers around the world for secret codenames [0]... which is a world away from the explanation given in the submitted article.
[0] https://www.nytimes.com/2017/10/10/technology/kaspersky-lab-...
"For many months, U.S. intelligence agencies studied the software and even set up controlled experiments to see if they could trigger Kaspersky’s software into believing it had found classified materials on a computer being monitored by U.S. spies, these people said. Those experiments persuaded officials that Kaspersky was being used to detect classified information."
https://www.wsj.com/articles/russian-hackers-scanned-network...
It's basically saying 'ha ha, we caught you, and now the whole world can look at what you were up to'.
Presumably, the NSA will have automated monitoring tools scanning every bit of AV software and AV databases looking for any of their own tools there, so they know right away when someone has publically outed them.
I wouldn't be surprised if these weren't even hooked up to automated self-removal logic so that NSA malware could remove itself in seconds worldwide if an AV database were updated to detect it.
is just a highly misleading way of saying
"Kaspersky added strings/.text/.rodata from the analysed malware sample to their virus database"
And no shit, a antivirus will then search computers "around the world" (this qualifier is here.. why?) for that data. That is why you paid for it.
The objectionable part here is "Iraelis were watching" but nobody seems all too concerned any more with economic espionage.
Either way the flavor of the comments on this thread are really, really unusual for Hacker News and YCombinator in general.
Is there any concrete evidence against Kaspersky doing anything remotely concerning since this whole charade against them started in 2015 or is it still "they're Russian, so they must be doing something bad" scenario?
EDIT: Fuck if I understand why people like JohnStrange, revelation and ryanlol are downvoted in their replies to this comment. They're on topic.
So yes, it is possible, maybe even likely, that Kasperky is doing nothing shady and has only the best intentions. It's also somewhat irresponsible to entrust them with any data of value. Those two things are not mutually exclusive.
[0] https://en.wikipedia.org/wiki/Note_(typography) Like so.
Litvienko (Polonium)
Politovskaya (Journalist)
Nemtsov (Politician)
And no, you do not need to leave a note (IMHO) since the fact that Russian government murders its critics is common knowledge.
It's like incident #100, maybe Kaspersky is the KGB, good on them since they are clearly more competent than the NSA. Maybe we can poach them?
And our media outlets will happily run with anything that produces those sweet clicks.
"The current and former government officials who described the episode spoke about it on condition of anonymity because of classification rules."
And now you know why Snowden wouldn't touch the NYT with 10 foot pole. This isn't "current and former government officials" committing a felony and treason to leak information to the NYT, no, they are just telling that reporter the NSA press report with a hushed voice.
I'm merely speculating, of course. Personally, I never take ordinary public announcements or claims from intelligence agencies at face value, since they have plenty of reasons to lie and disinform. That doesn't entail that their secret reports are bogus, of course, and senate hearings are also reliable. I've followed the senate hearings close enough to be reasonably certain that the US intelligence community is right about the accusations concerning Russian meddling in politics in the US and the EU. But that's a different case, people were testifying under oath in front of senate committees and senators from both parties who went to meetings behind closed doors were also convinced of the (classified) evidence.
As for Kaspersky, the information is unreliable and my personal guess is that whatever happened wasn't their fault. If someone has malware on his machine, it's the job of the antivirus software to detect and analyze it. If at all, the story has increased my overall trust in the technical quality of Kaspersky software.
Another speculation that I find overall credible is that since Snowden's revelations there is some concerted effort to further discredit the NSA in order to weaken their ability to operate. If that's so, then this campaign seems to be quite successful.
Kaspersky is just easy target and apparently three-letter-agencies have means to steer the media to pursue this direction.
[1] https://www.computerworld.com/article/3141470/security/kaspe...
[2] https://www.theverge.com/2017/6/20/15836208/microsoft-kasper...
Kaspersky was probably using some private API they shouldn't have been using, and when Microsoft changed the API or changed the way it worked, they had to disable Kaspersky or computers would no longer boot up.
When companies do that, they nearly always reach out to the affected vendors with advance warning so the vendor can do a rushed fix, but repeat offenders, or issues detected very late in the game before release can end up with no notice.
How else would you justify all that Defense budget spending?
Given what we know about the feds installing black boxes in ISPs' networks here in the US- a country nominally committed to the rule of law- it seems somewhat naive to think that the Russian government doesn't have access to Kaspersky servers.
Does that make Kaspersky uniquely evil? Probably not. Do the feds have an agreement with Microsoft to take a peek at anything they turn up from a foreign intelligence service? I don't know. It wouldn't be too surprising.
The Hacker News community largely gets its non-hacker news from CNN, the NYT, HuffPo, etc. As mainstream US media parrots whatever the FVEY IC tells them to, it's not surprising that most HN voters end up uncritically believing the Russia-Is-Evil narrative from the same IC that conducted MKULTRA and sold us a war predicated on the lie that Saddam was loaded up with WMDs.
Downvoting any and all dissent from CIA psyops is the natural consequence of this. Because, patriotism, or something.
I guess on the bright side at least the anti-virus market has a variety of firms based in many different countries, so you can choose your poison based on how trustworthy you find the respective governments. Doesn't help you when they themselves get hacked though.
As for the story itself, I kinda dislike the reliance on access journalism and "unnamed" sources in many of the reports. Yes, there surely are many legitimate reasons why sources have to remain anonymous, no doubt about that. But in a case that's so highly political it kinda leaves a bad taste if the story is so dependent on unnamed government sources.
no offense, it is just very entertaining(and educational) to observe how people from one culture try to apply their mental frameworks to completely different mentality. There is no "whether", "or not", "gag order" (in the sense as if explicit one was necessary) in the Russian reality in the context of private company cooperating with FSB. Hell, there is no even much of "cooperating". An FSB guy just says what he wants to get, and he gets it pronto. And in cases like Kaspersky it is even more straightforward as Kaspersky and the others there are FSB guys.
I mean it is like a joke among Russians here:
"Did you hear? The NSA thinks about stopping to use Kaspersky on their computers!"
"Wow! How did they discovered (the ploy)? Was it the parachute?"
(the parachute is a reference to a very well known joke about a USSR spy in Nazi Germany from very popular TV movie - the spy was so good and invincible that only the deployed parachute he was dragging behind him in the open daylight on the streets of Berlin was the only possible clue for the Nazis)
Again, it is different reality. In US law protects from and punishes for illegal cooperation, whereis in Russia the system protects for cooperation and punishes for refusal to do so.
Then they can insist on legal cooperation. I remember how Pavel Durov (founder of Telegram) wrote that US secret service agents were stalking him in US and tried to bribe one of his developers.
If you believe this I have an AT&T switch closet to show you.
I guess the larger lesson may be how Russia's failure to establish rule of law makes it impossible to run a business that depends on trust. The US should take note: if they succeed in breaking Apple et al's attempts to protect their users, pretty soon the only countries you'll want to buy software from are Norway and Canada.
But somehow these warnings only became necessary in the past year or so, when the US has had ongoing conflict with Russia over the past 20 years?
Essentially, that the government is publicly running a campaign to openly access user data does not in any way change the fact that they already have covert access to that data in private. Why are they doing this? One can only speculate, but I'd imagine one reason is that unlawfully obtained information and evidence is not admissible in court leading to all sorts of fun things like parallel construction. [2]
[1] - https://www.theguardian.com/world/2013/jun/06/us-tech-giants...
In Apple's case, this would be any iCloud data which they can access and is not encrypted (such as contacts or calendar entries). However, the OP was referring to something completely different: Government attempts to force Apple to weaken data-at-rest encryption on everyone's devices.
It is fine if you believe that sealed/secret warrants are problematic, but it seems strange to equate that with the weakening of security for all.
Another surveillance program, that you seem to be conflating with PRISM, is MUSCULAR. That program is not as well known as PRISM. And it does what you're suggesting in directly tapping communication lines grabbing data from everywhere and archiving everything. Naturally anything that was sent on those lines unencrypted (or is otherwise able to be exploited) is then openly available. One significant difference from PRISM is that this is done without even a rubber stamping of warrants. Your post seemed to be describing the less 'cooperative' capacities of MUSCULAR with the token oversight of PRISM.
The problem that I see here is that most people are incredibly poorly informed on our surveillance programs, which include extensive domestic surveillance. And that is a shame, because in order for there to be progressive change people need to understand the current state of the situation. It's like discussing a budget when you think you have a billion dollars in the bank, but in reality you're already in the red - the sense of urgency, which should be there, has been artificially removed.
1. If Israelis were "burrowed deep" in Kaspersky's network, sure, Russian hackers may have been, too - but so could have anyone else. Also the Israelis are not exactly fans of the Russians, and are our primary (sole?) Middle East ally, so there is bias and uncertainty there.
2. From the article:
"The allegations, all attributed to unnamed officials with no supporting documentation, helped explain why the US Department of Homeland Security in September took the unprecedented step of directing all US agencies to stop using Kaspersky products and services"
So we're not even mentioning how in May the Senate was already taking Kaspersky to task, and there were rumors of them getting the boot even in 2016? The allegations don't explain shit, they are just another facet of a year long political battle between the American legislative branch and intelligence services against Kaspersky.
It is plausible that the U.S. government made these files go through Kaspersky just so they could have leverage over them for a deal they wanted (like spying on their own country), or that a stupid contractor put them on their laptop along with Kaspersky AV, and the NSA got caught with it's pants down, they're using the Israelis to try to cover the embarrassment. This is not out of the ordinary behavior for an intelligence service.
Look at it this way: flip the roles. Would Russia try a play on their contracts with a U.S. company to further their goals?
Of course the U.S. government had to remove Kapersky from its computers. Russian intelligence has been very aggressive; the U.S. can't assume they'd pass on the opportunity to utilize an opportunity this good: Antivirus is widespread and highly invasive - a confidentiality (and even integrity) violation utility, with access to all data and code on the system, that the user helpfully installs for you, and it comes with built-in remote updates and communication that the user fully approves of.
Yet allowing anything seems fairly common practice, even more so outside the US. I wonder how many government employees of countries other than the US have Gmail accounts and put all their documents on Google docs, etc. Not to mention online backups which tend to be more expensive for servers located outside the US...
I'm not sure if this is common place or not, but I was under the impression that if you were from outside the US and wanted to land Federal contracts, you had to be ready to bend over a bit for the US Federal Government. No other government gets the same treatment currently.
This is the key point. Also, the US Government was recently found to have fake Kaspersky SSL certs.
This is not true. An old commit for a leaked implant included example client certificates, which were invalid and self-signed, used to disguise C2 communications as anti-virus updates to avoid scrutiny. Part of the system involved copying fields from valid certificates into self-signed (invalid ones) so the traffic would not look suspicious.
If they actually had fake/spoofed SSL certificates valid for Kaspersky’s domain, that would be entirely different.
That sounds "fake" to me.
Receiving the goods in this case is just as much an ofence as stealing.
I am also inclined to believe Kaspersky is in the wrong here, especially given the publicizing of personal data from a customer's computer for PR purposes, but I am having trouble understanding how the Espionage Act applies?
https://www.rcfp.org/browse-media-law-resources/news-media-l...
Is there any good reason for us gov to mistrust this company or will they need to leak secrets to us before that will happen?