Judge Dismisses Kaspersky Suit Challenging Software Ban
wsj.com
wsj.com
The only specific thing I know is that a CIA contractor took some CIA tools home had Kaspersky installed, and had it setup to auto-submit samples, so naturally it detected the hacktools and submitted them...
But the implications have been that Kaspersky has been actively used to spy on US agencies and companies. But again no technical information has been published, which would be hugely damaging to Kaspersky's reputation.
There's three possibilities:
- They're right and Kaspersky is working for Russian intelligence (but the US aren't releasing technical information for unknown reasons).
- They're doing this to promote American and European alternatives which can be manipulated by Western intelligence (e.g. exclude state sponsored malware from definitions).
- It is just a "red scare" within the US DoD, and they aren't releasing technicals because they have no technicals. It is just playing Telephone between analysts using vague assertions and feeding off of one another (see Iraq War).
All I am asking for is "Here's a technical paper explaining exactly what we caught Kaspersky doing." If we got that and it held up, I'd be fully onboard.
Virtually none of their customers will be safer if they did the monitoring. If anything widespread actually gets released, they'll likely know from telemetry.
Without testing ground and inside knowledge that doesn't sound easy considering any detection would cause... what we have now.
A normal office near which I worked had a malware lab with isolated and logged networking, actual green/red painted sides of the room, dedicated fancy storage, etc. They would know if anything's being uploaded by the AV. NSA likely has a much tighter setup.
And again - what's Kaspersky's gain in that situation?
If it's plausible that some Western companies might cooperate with Western intelligence, then it's equally plausible that a Russian company may cooperate with its home country's intelligence. Regardless of whether it's true, the Western allies' intelligence community benefits from discouraging Kaspersky's use either way: either by driving usage to products they can influence, but their adversaries can't, or by avoiding exposure of first-party malware to an actor they can't influence.
I want to see the technical paper too, but for Huawei.
We know from the Snowden leaks that the NSA had access to (Huawei founder/CEO, and ex-Chinese intel employee) Zhengfei's email back from 2010. They also got access to Huawei's source code repository.
By 2012 US five-eyes allies were banning Huawei from critical infrastructure projects[1].
Doesn't take a lot of reading between the lines there to speculate that they really did find some stuff.
The joke here is, that the Chinese don't share intelligence with anyone else: arguably, if they do see our packets, less people see them because the NSA share with their strategic partners, and with the FBI!
The Chinese probably should.
I agree with not using foreign AV on US Government computers. Even if for no other reason than the Russian government could storm into Kaspersky HQ and demand private keys to sign a malware update (e.g. right before a conflict).
I just want to see technical explanation for the ongoing negative PR against the company, particularly as it relates to private Western businesses and individuals. Why should I, as a technical person, advise my company to move away from Kaspersky with no technical information in hand? On the face of it Kaspersky is (was?) a well reputed and effective piece of defensive software.
[0] https://www.cyberscoop.com/kaspersky-sanctions-treasury-depa...
I can understand mistrust of spy agencies.
But it seems completely obvious to me that every release of additional information must by its very nature undermine the personnel, tools and techniques used to get that information. Occasionally that might need to be done, but to not mention these pretty clear counter-arguments seems shortsighted.
In this case, there's plenty of reporting of leaked reports about what is supposed to happen. TLDR: The Israeli's had access to Kaspersky's network and saw them accessing classified US document and passed that information back[1][2].
Who knows if that is true? If it is, and the Israeli's didn't agree to the leaks I imagine they'd be pretty unhappy.
It's also interesting that some five-eyes allies like Australia haven't[3] yet[4] banned Kaspersky, but other NATO allies have[5].
[1] https://arstechnica.com/information-technology/2017/10/russi...
[2] https://www.haaretz.com/israel-news/israel-s-kaspersky-hack-...
[3] http://www.abc.net.au/news/2017-10-12/no-ban-for-lobbyist-ba...
[4] https://www.itnews.com.au/news/kaspersky-makes-case-to-avoid...
[5] https://www.crn.com.au/news/dutch-govt-to-stop-using-kaspers...
https://www.kaspersky.com/blog/internal-investigation-prelim...
I just don’t buy it. Based on what I know about what kind of flimsy intel it takes to extrapolate to irrefutable proof to support what someone wants to be true, and how products in this space work (I have direct experience here, with competing products) it rings of chasing ghosts.
Personally, I think if Kaspersky is compromised, I don’t think it would be from the top down, but rogue insiders. And I don’t think they are unique in that regard.
There is indeed a catch 22 with providing proof. On one hand, you can’t burn an important intel source. On the other hand, we can’t take their word for it. Intel analysts never have the full story, and even with the best of intentions, their interpretations can be extremely wrong. According to Hayden, former Director of NSA, they were certain that Iraq had WMDs. According to him, it turns out that they were just wrong. Oops.
That's probably what they have. But imagine you're a Government Official and the Member of The Press asks you: "Do you know that your office is running software produced by Russians? The same Russians that hacked our elections?! And not just by any Russians, but Russians with links with Russian Government, which includes Russian Military, Russian Intelligence Service and controls Russian Nukes?!"
Of course, you could start explaining that doing business with Russian government (aka "links") is not weird for a Russian company, especially a major one and near-monopoly on the local market, and you can not declare every Russian a spy just because Russian spies exist and sometimes even mess with some American interests, even though nothing of the sort happened in the election - you can try to do all that and earn a headline "Government Official N. Is Soft on Russia - Idiocy or Corruption?" And God forbid it turns out you visited an industry conference in Russia 3 years ago or attended, among other 500 people, a reception which (unknowingly to you) was paid by a Russian oligarch living in New York...
Or you can ban Kaspersky software - which has a bunch of viable local alternatives anyway - and earn a headline "Government Official N. is Exercising Reasonable Prudence in the Face of the Red Threat". Which one would you choose?
> They're doing this to promote American and European alternatives which can be manipulated by Western intelligence
Could be but more likely they are just opportunist and doing CYAing.
> It is just a "red scare" within the US DoD, and they aren't releasing technicals because they have no technicals.
Rem acu tetigisti.
> All I am asking for is "Here's a technical paper explaining exactly what we caught Kaspersky doing
Don't hold your breath.
In that case we even know, that US companies are be forced to cooperate and are legally barred from reporting it. Any foreign government using commercial US software for sensitive information is at least reckless.
Secondly only if their dependence on Google is as critical and as potentially damaging as their dependence on operating system security software.
you seem very certain of that, which appears to be at odds with the Mueller investigation and investigations undertaken on FB, Twitter and Reddit posts/ads from russian based accounts. So what exactly are you saying did not occur?
> Mueller investigation and investigations undertaken on FB, Twitter and Reddit posts/ads from russian based accounts
Ads most definitely happened. Though the valiant effort by Mueller's team is mostly wasted because a) publicly speaking about US politics while being Russian is not a crime, neither is astroturfing or failing to disclose vested interest (both are routinely done in advertising and politics), and trying to imply otherwise would run straight into the 1st amendment, which SCOTUS still has pretty healthy respect for; and b) even minor financial irregularities, that are crimes, which Mueller inevitably discovered (I mean, can you imagine a campaign run by thoroughly corrupt Russian government that won't have financial irregularities? even many US campaigns are full of them if you look close enough...) are not prosecutable since none of the perpetrators are anywhere US law can reach them.
However, the ads definitely existed. Moreover, it is also a definite fact that there were multiple hacks of both DNC and RNC computer systems, some of them might have been perpetrated by Russian groups. As a result of those, some dirty laundry definitely got aired.
> what exactly are you saying did not occur?
"hacking elections". Which is a commonly used phrase, and it is both vague and misleading. There is no indication that any component of electoral system per se was hacked, so direct meaning - implying the genuine voting preferences of Americans were subverted - is definitely false. We may only talk about persuasive effects of the Russian actions, but even then there's not much.
There is no indication that a minuscule-budgeted and hamfistedly-executed (I mean, have you seen them? they are hilariously bad) Russian ads changed anything in relation to the elections. The airing of dirty laundry that followed the email hacks may have had some influence, but it is in line of long-standing tradition of leaks and whistleblowing that has existed in US politics since forever - a lot of secret things become public eventually, to the major embarrassment of people who would rather not have them published. I haven't heard any of the leaks referred to as "hacking the election" - in fact, many are lauded as valiant efforts in informing public about the misdeeds of the powerful.
So summarily, nothing is left from the claim that "Russians hacked the elections" in any meaningful sense. The most one could claim is "Russians tried to influence the elections, mostly without success, but it is possible they uncovered some dirt on some of the politicians that may have influenced some voters".
At the same time releasing what exactly they know might itself seem problematic. Telling the other guy exactly what you know about his methods might not be the right choice as far as being an intelligence service goes.
But even all that aside, do you take a chance on a company like Kaspersky who operates inside an oppressive state where you know the government can assert some a powerful influence on its people with no recourse for their people to push back or go public (heck if they leave the country the outcomes don't look so good).... and pretend they're just like any other software company and proceed to install it on sensitive systems?
I think if there were no action the common response would be "OMG how can you play dumb and install that stuff at the DOD (or wherever)?"
That evidence is still missing.
The burden to prove a negative has been shifted to Kaspersky. Good luck with that.
I don't think they much care whether the median HN commenter buys the narrative that Kaspersky has been suborned by Russian intelligence. The people whose opinions about this really matter --- from what I can tell, uniformly --- do buy that narrative.
So Assad was winning with non chemical weapons but every time he basically heard Obama or Trump was gonna leave him alone he gassed his own people just to invite retaliation.
And Russia made a long shot bet against the favorite candidate that all the polls said would win because, in the likely event that she won and found out, they would have a pissed off US President and public.
It’s WMDs all over again!
Pretty obvious reasons to me.
It would reveal the sources and methods they used to obtain it in the first place.
You do not have to be onboard. Those that banned them, know what you're asking and then some. But let's ask this question: If Russia wanted, could they pressure Kaspersky to do Russia's dirty work? Fraud charges, tax fines...and outright assassinating a C level exec so the next one learns. Russians play by different rules, let's accept it, and software that could be controlled by them has no place in US Govt computers.
Of course that is if this is true, I don't know. It could well be a scare tactic.
I have lived under a totalitarian regime (not Russia) and I can tell you that the security apparatus doesn’t fuck around. There is no asking, only cooperation, or else...
The Russians are also good at spook games, I mean, the dude is KGB trained. They don’t need to compromise the source code with backdoors that someone can find, they just ask Kaspersky to be a tiny bit more aggressive in their sample vacuuming for example. Or they just don’t do anything and sit on it, knowing that one day they can call to collect.
I personally believe Kaspersky is compromised, IMHO. I just don’t see a way that it can’t be.
The entire thing is a fairly transparent attempt to gin up some anti-russian sentiment in the wake of a growing presidential scandal under active investigation that keeps turning up damning evidence. At best it pulls the administration out of the fire for a few days but frankly all its doing is insisting the US is open for business until we find a big enough bus to throw you under for our own political gain.
Same with Huawei. Its difficult to cast an outright ban on import as anything less than telecom players waving their hands and crying red-scare to an audience of congressmen that are either old enough to remember duck-and-cover drills or ancient enough to have actually participated in some of the clandestine blacklisting and CIA funded government overthrow in central America.