US officials: Kaspersky “Slingshot” report burned anti-terror operation
arstechnica.com
arstechnica.com
Not really, it could be a fact based on knowledge. Although I’d agree it would be disingenuous to say it was intentional.
Is there any action that Kaspersky or the general public should take to mitigate this risk? Is the suggestion that we shouldn’t work to eliminate malware in case it serves some higher purpose.
Will there be a new US law requiring checking with a secret government agency before publishing and patching exploits? Will it matter to non-US firms?
Maybe this secretly currently happens. No way to confirm, currently, and not productive to speculate.
What does "put lives in danger" really mean? It seems to be a deliberate blurring of the lines of culpability.
Most things "put lives in danger," in some sense (a just war, the invention of the automobile, rock climbing). Obviously the benchmark for what is acceptable must be much stricter than "put lives in danger," particularly when it's the lives militants.
As Slingshot is a US-originated APT deployed against ISIS in Syria and Iraq, and the US is in conflict with the Russian state in Syria, it's a newsworthy question as to what aspect of Kaspersky's job is most relevant here.
We are not talking about some recombinant script kiddie malware: Slingshot is attributable, Stuxnet was attributable, the DNC penetration was attributable.
Nation-states with mature cyberwarfare capabilities, and their appendages such as Kaspersky, are routinely capable of identifying the authors of novel malware.
Indeed. Often a primary goal of operations such as that is to conceal and make attribution as difficult as possible.
"Kaspersky's exposure of the program will likely not win the company any points in its battle to get off a US federal government blacklist."
Is that just rhetorical flourish? Or is Kaspersky actually going to be penalized for doing their jobs? Is there an implication that other security companies have been "recruited" by the government to turn a blind eye towards government-sponsored malware?
This could've happened by accident, but the way they were treated over several years by the intelligence services, military and Congress to me says Government knew this would eventually happen and tried (and failed) to get them to not flag this kind of malware. It's possible that by not agreeing to curtail research of certain malware, they were punished by having their contracts taken away.
To guard against that you could theoretically scan using a wide range of international antivirus companies. But the problem with that is that the militaries are using the antivirus software themselves as an attack vector. Kaspersky was recently caught stealing American government secrets via its software. It's impossible to know who to trust.
Malware programs patching the same parts of the OS are likely to trip over each other.
Such a combination would be highly unstable, not to speak of incredible slow.
- WSJ: Russian Hackers Stole NSA Data on U.S. Cyber Defense: https://www.wsj.com/articles/russian-hackers-stole-nsa-data-...
- NYT: Israelis hacked into Kapersky and caught them using their software as "a sort of Google search for sensitive information" https://www.nytimes.com/2017/10/10/technology/kaspersky-lab-...
Source?
Cold War 2.0 rages on.
And indeed, if kaspersky could find something than various sophisticated adversaries certainly could too. So why bother to court that one private company?
Because they've seemingly been the leading antivirus company for years? In terms of vulnerabilities found, at least.
[Edit: ok, "make nice" (my words) does sound like courting, but I was thinking of it in a more neutral way.]
That being said, I really don't know whether Kaspersky deserves the treatment it's gotten... not having followed their behavior closely. It very well may, for all I know. But it's possible there is blowback from that.
That's a problem in a democracy, where we need to vote on these issues, because we rarely have other sources for secret information. But trusting an inaccurate source because you lack another, while tempting, is flawed reasoning. Better to say, 'I don't know'.
I wonder if some parts of the security establishment are more reliable than others. There are some individuals I trust more than others, at least.
That tells me that there are in fact times they would like the general public to know about their operations, and separately, those unauthorized sources seem to match the official ones a lot of the time. With that established, we can move on to trying to discern their motivations when they decide it is important we know the details of their operations, and why they would seemingly go against the very advice that they so rabidly bark to everyone else.