U.S. Government Can’t Get Rid of Kaspersky Labs Software
thedailybeast.com
thedailybeast.com
You have to think about the motivations of each country. Even if Kaspersky were spying for the Russians, they won't give a damn about your porn, tax cheating, affairs, your padding of expense reports, or whatever they find on your computer. As an American, it's MY government that I'd have to worry about.
just at some moment in future, when you aren't some nobody like today and have become somebody meaningful, they would make you an offer you wouldn't be able to refuse - either all this collected info is sent to USG or ... Until that they would use it mostly for some innocuous stuff like what specific message to post in your feed to make you vote that specific way.
>Even if Kaspersky were spying for the Russians
when people say that "if" i'm always reminding myself that it is Western world, people have different mentality here. NSA here had to do _secret_ (or at least Google had to pretend so) tap to Google's fiber where is in Russia FSB has much better VPN into Kaspersky intranet than Kaspersky employees do :)
And even applying Western standards this is what possible to say :
https://www.theguardian.com/technology/2017/oct/11/israel-ha...
"At the time, the Department of Homeland Security said it “is concerned about the ties between certain Kaspersky officials and Russian intelligence and other government agencies, and requirements under Russian law that allow Russian intelligence agencies to request or compel assistance from Kaspersky and to intercept communications transiting Russian networks”"
Notice that Kaspersky doesn't lie :
"In an official statement about the allegations, Kaspersky Lab said: “As a private company, Kaspersky Lab does not have inappropriate ties to any government, including Russia,"
as the keyword here is "inappropriate" which the above mentioned law clearly takes care of. Again, all these fine icing-on-the-cake details, like the law and "inappropriate", etc. are only for the Western consumption, as they just don't really matter in the Russian reality if only by virtue of being dwarfed by the things what do matter there. In that reality it would be a really "inappropriate", a faux pas of the scale that is even hard to imagine, if Kaspersky refused to work with FSB :)
Edit: thanks! I do recognize that I use Western thinking. Optimism and implicit trust are great!
How can you be so sure about that? You never know what they would need from you. You write on HackerNews - you are probably a computer professional, maybe an admin somewhere, but maybe you just know someone and you'd be useful to put pressure on that person? Think about the Swiss banker from the Snowden leak:
""" The Guardian said Snowden described a “formative” incident in which he claimed CIA operatives were attempting to recruit a Swiss banker to obtain secret banking information.
The operatives purposely got the banker drunk and encouraged him to drive home in his car, he told the newspaper.
When the banker was arrested for drunk driving, an undercover agent offered to help “and a bond was formed that led to successful recruitment”. """
The American agencies don't need to blackmail you - they can get access in many other ways.
It's like Red Star OS, except it uses you!
Moreover, if your running anything that is not very niche or custom system people are probably targeting it. I am not sure I would call BSD niche enough. Also, even if you are using a niche system that does protect you against a targeted attack. If you were a government a target attack is much more likely. Honestly, unless you have 100% bug free software and hardware, and its designed with security in mind. The possibility of malware taking advantage of bugs exists.
Moreover, that excludes social engineering and getting someone to do something stupid. Even if the system normally is extremely secure.
If we are getting super serious considering all the firmware that exists in a computer. If a system ever ran code you did not audit you can never be sure that system is secure. Even if you have an AV. You would have to re-flash any firmware that could be written to by the CPU, and reinstall the OS as soon you ran code that you did not audit. I doubt there really is any system except small embedded systems that you can audit all the code that closely. Modern systems just have too many layers.
I actually do run FreeBSD. I'm not so arrogant as to believe that the system is perfect, though there are a number of factors that make it more secure than average.
Why wouldn't the Russian government seek to take your secrets if it could? Employees at even the most mundane companies, such as SendGrid (email as a service) or Salesforce, have passwords and ssh keys that could permit access to infrastructure. That infrastructure contains valuable information when mined at scale.
How do you think these campaigns happen? All 0days? The most public recent nation-state hack, of the Clinton campaign, was done by a phishing page.
Yes, we are all targets to some degree of nation states.
That said, Kaspersky software is excellent. I would just disable the cloud upload portion of it.
It would be better if one chooses their software based on trust, security audits, open source, etc.
Obviously they care about white collar crime, but I'd say committing the crimes is worse than the warrants to uncover them...
If only there was some sort of group in the government that handled information security... Some sort of security agency, if you will.
The Anti-Kaspersky stuff is likely just chest beating. I get it at the base level, and that AV software in general grants a much deeper reach that most softwares, but most likely they're not installing the same Kaspersky that anyone else is.
My current employer is a rather large non-US tech company, and we have custom branches for every product specifically made for the US Federal Government. It's all rebuilt from the ground up on US soil by US Nationals and the US Government has freedom to review the code.
It's the price you pay to play with the US Government. I would find it very hard to believe that Kaspersky doesn't have something similar.
I mean, let's just hypothetically assume for a moment that Kaspersky is compromised and doing intel gathering for the Russian government. Can you think of a more perfect weapon than a compromised suite of software that is so deeply entrenched in a nation state's stack that they can't remove it, even if they wanted to?
Among the reverse engineering / exploit development crowd, I haven't heard much complaining about Symantec's detection mechanisms.
There are also bespoke anti-malware solutions marketed to the U.S. government, and they are not commercially available specifically to mitigate the risk that malware authors will test their products against anti-malware engines. These bespoke solutions are understandably far more expensive due to their smaller deployment and high quality.
It's reasonable that the U.S. government has to consider the need to have the best, reasonably affordable, commercially-available solution for the majority of its systems. This is balanced by the threat that the Russian Federation's government could interdict the software being delivered to the U.S. government client. Intermediate solutions, such as the project that Huawei set up with the UK government, or the source-code sharing that Microsoft does to get Russian contracts, seem to be optimal.
That also exclude any subtle bugs that people may miss.
Since the time that Kaspersky revealed (after Symantec) global co-ordinated state sponsored malware programs such as Reign, created by the NSA and GCHQ. https://www.theregister.co.uk/2014/12/05/regin_kaspersky/ https://en.wikipedia.org/wiki/Regin_(malware)
Or the time that Kaspersky publicly humiliated the NSA by revealing their hacking of hard drive firmware. https://www.dailykos.com/stories/2015/2/17/1364910/-Breaking... https://www.scmagazineuk.com/is-nsa-worlds-most-advanced-thr...
Since then, congressional hearings, committees, and US intel agencies' warnings of "security threats" from Kaspersky had been rolling out with regular frequency. Last year's ban was just a culmination of other efforts already underway.
Kaspersky's role of tracking nation-state malware inflitrations gives them a position as a quasi-intelligence agency. US intelligence agencies hate Kaspersky because they out every program the US has going on, and because they operate out of Moscow.
Literally every US intelligence agency has testified before Congress about how they specifically don't trust Kaspersky. https://www.npr.org/sections/parallels/2017/07/05/535651597/... So the US and its allies infiltrated their network and reverse engineered its software in order to find whatever dirt they could. https://www.observeit.com/blog/kaspersky-lab-nation-state-at... https://theintercept.com/2015/06/22/nsa-gchq-targeted-kasper...
The information they have on global intelligence operations, their location outside of an ally's control, their insistence on embarrassing nation states' covert operations and exploits, and the fact that their software isn't the most secure (https://www.forbes.com/sites/thomasbrewster/2015/09/23/googl...) has given the US government enough reason to want them out of their infrastructure. It's just politically untenable.
Maybe they were proud that their work was publicly recognized.
Higher-ups understandably felt frustration that they needed to replace the program, but what makes you think that the employees didn't already anticipate that exploits and campaigns would get burned?
Is there a difference between a vendor issuing a patch or an organization's security response team cutting off access, and a anti-malware company doing its job to research campaigns?
Is revenge the only motive to do this, if indeed it was the NSA (it's likely it is)? Wasn't there an allegation that Kaspersky software had exfiltrated NSA employees' and contractors inappropriately-stored classified material? Or wouldn't it makes sense for the NSA, an intelligence agency, to spy on a foreign company with good access to information about foreign officials?
"Not only is the work of the NSA and CIA increasingly visible, there is
a certain aggression implied by this," he said. "It's a 'game-on' moment."
Kaspersky, he said, should be treated as a hostile actor.
Israel was inside Kaspersky's network, found the Russians looking for US files (or so they claim) which had been just hanging around on their servers for a year, and so they notified the NSA about the breach. https://www.nytimes.com/2017/10/10/technology/kaspersky-lab-...I don't believe any agency operates based on revenge. They operate based on politics. Can they really continue to fund this organization that is constantly pulling their pants down? Kaspersky's biggest flaw here is just having shit security.
You make some good points.
That said, the politics of the NSA and the politics of Congress are often quite orthogonal and shouldn't be equated.
"However, the anti-Kaspersky train picked up steam following revelations last year of a bizarre incident in which the company slurped up classified documents and source code from the home computer of a National Security Agency contractor running Kaspersky Internet Security software. That contractor, Nghia Hoang Pho, pleaded guilty last year to willfully mishandling classified material by taking it home.
"Kaspersky claimed the incident was an unintended byproduct of its routine malware scanning. The source code was for an NSA hacking tool, which Kaspersky’s product properly flagged for analysis by malware researchers. But because the code was bundled in a ZIP archive with the classified documents, Kaspersky’s software uploaded the entire thing. When Eugene Kaspersky realized what had happened, he ordered his researchers to immediately delete their copy of the documents and code, the company asserted in a blog post last year. “The archive was not shared with any third parties,” the company wrote."
Presumably, it was an isolated incident and we can trust Kaspersky's statement about their actions. No?
The important thing to note that is the way it happened makes me comfortable in saying that all the big anti-virus products have received similar breaches of classified material and we just don't know about it. Any antivirus company that isn't sending unknown but suspicious code back for analysis is completely incompetent (this should be a setting for privacy reasons, but they need to make sure it is on where possible). You can accuse the various vendors of problems, but none are that incompetent.
"Even less hawkish U.S. officials worry that the company could be compelled under Russian law to weaponize their code to spy on U.S. government networks. The company works so closely with Russia’s Federal Security Service, or FSB, that agents are sometimes embedded in the firm’s Moscow headquarters."
("Agents" is likely an incorrect term (I hope) and is uselessly vague.)
Former NSA and other intelligence agents work at US AV companies, too. And the US regularly uses National Security Letters to covertly compel US companies to do their bidding. But they don't even have to.
The FBI uses its own signals intelligence branch when working with US companies, such as telcos and technology companies, on national security investigations. This sigint group then shares its information with other US intelligence agencies. So companies can claim they never passed information to the NSA, because they were only passing it to the FBI.
If we use the same rule to compare Russian and US antivirus companies, nobody should use either of them, because they have the same biases, the same ex-intelligence officers, and they can pass off information in a variety of ways and still maintain plausible deniability.
Seems more like the U.S. Government doesn't want to get rid of Kaspersky. They choose not to replace compromised devices. Doesn't seem like it is a hard technical challenge at all, rather the lack of action seems more intentional.
Surely we can all agree this is an issue of National Security. And if the task is to be done with no Federal assistance or financial help whatsoever, it seems clear that the government is compromised.