Samsung blames security software false positive for StarLogger issue.
tgdaily.com
tgdaily.com
// Samsung gave an authoritative answer via their senior support personnel corroborating the [false] positive report of an installed key-logger from a previously trustworthy system analysis tool. I'd say that was diligent.
I don't think Samsung can win a libel case against someone who published what they themselves confirmed to be the truth (despite this revelation that they in fact lied).
This does leave the possibility that the report that it was confirmed by senior support was fabricated; in which case a libel suit would be back on.
// What good will that do, so I see that it's C:\Windows\SL\WinSL.exe how do I tell without decompiling it that it's a keylogger? Certainly one could go further to test it but if the company that installed the drive image confirms it's a keylogger it seems reasonable to me to not check further.
If they denied it then yes it needs further corroboration but practically ...
You might have to ask an, uh, security consultant.
Someone working in Security firm (NetSec Consulting) should have idea of they are saying.
Did he actually look in the Windows/SL directory? Did he compare the contents to those that StarLogger actually installs (a trial version is available for download)? This seems like pretty basic stuff. Did he ask Microsoft what a Windows/SL directory might be?
The Age article does note:
"Network World said it contacted three public relations officers at Samsung for comment and gave them a week to send back their comments. 'No one from the company replied,' it said."
Not impressed.
Best thing about that site: he charges $60 flat rate for virus removal.
http://www.nesecc.com/Flyer.htm
Damaging his reputation, that of his friend the writer, and of NetworkWorld: free.
To be fair to him, Samsung did turn around and say, "Yeah we're keylogging, problem?" or words to that effect. If he's not a technical security consultant then that might be enough for him to go to the press (especially if he felt stiffed by Samsung).
Not all security roles are technical, not all consultants are either, it's entirely possible that he's a policy or risk kind of guy.
May I observe that the only reason we think that Samsung confirmed this is from the words of a source that is now appearing not to be trustworthy in the first place? If this "security consultant" couldn't verify the actual existence of a key logger in the first place, why do we trust him to accurately relay a conversation with support? I don't really accept it as fact that Samsung confirmed anything in particular at any point; the possibility that this guy heard what he wanted to hear is too significant to ignore.
I would suggest that wading through a corporate customer service call center's escalation process is reasonable evidence of due diligence. And I find it somewhat more likely that a call center employee affirmed the SL directory was for keylogging to clear the case than that Mr. Hassan fabricated a story about the call and Samsung's confirmation.
Hassan's allegation has all the marks of a mistake due to inexperience rather than fabrication because it is just too easy to disprove.
First off, if I even remotely sense that there is malware on my machine it gets an immediate format. Second, why in Thor's name would you buy from Samsung again? I get the impression he's a guy with a little knowledge that thinks he has this whole computer thing figured out. If you are going to make these types of allegations and publish them, you have to approach it scientifically and verify your results.
Because I agree - if you were going to tend to make a big fuss about this (as I would) and I had determined it looked like Samsung installed the first one (as he claimed) in no way would I ever get samsung laptop #2. Not to mention, not even checking the contents of the directory before reporting it widely.
Pretty decent approach to tarnish their reputation too, if it happened that way. To get an estimate of reach, the HN story "Samsung installs keyloggers" currently has 477 votes - it seems quite unlikely the retraction will get that much exposure.
http://www.f-secure.com/weblog/archives/00002133.html http://news.ycombinator.com/item?id=2391289
It's even getting triggered by an empty SL folder apparently. Looks a lot like some sort of poor taste april fool's prank to me. Come on! A security warning from a folder name... _Really?_
To go public with such questionable supporting evidence seems unfathomable from someone who is, ostensibly, qualified enough to know better.
I sincerely hope any forthcoming apology and subsequent abjuration is given an equal amount of publicity.
Samsung may choose to magnanimous and not sue, with a bit of cleverness they can spin this such that they get more out of that than any lawsuit they could possibly file... but it will be their choice, and if they do sue I won't hold it against them. It'd be fair.
I've had plenty of nonsense spouted to me when a tech support person doesn't understand my problem or how to deal with it.
In the report it was second line and they consulted some other authority (manual, person, we don't know; could have lied) in order to provide an answer to the question of whether the keylogger was installed by Samsung.
Why do they want him off the phone, don't they get paid according to customer contact time? The longer he's on the phone the more money the company makes.
For tier 1 or 2 support, they are also working off a script, and very few reps actually know what's happening outside of that script. Forcing them off script is the quickest way to get bad information and for them to likely get punished.
The only times I've had to ring support have been to get recovery disks or initiate a return or what have you. However on those occasions they always wanted to walk me through the whole script ("yes I turned it off and on again, send me the disc please, yes I checked my network cable, ... could you ..., yes I ran check disk, ..., etc., etc.").
But then at €1.70 or whatever a minute I kinda expect that.
How do you lose money when they're billing at sort of rate? How do you make more money by completing calls quickly?
Prepaid support obviously different.
The scripts are designed for solving issues that novice users have. That said, you are putting the rep in a position of possibly getting disciplined if you try to force them off script. At least at some of the places I've worked in the past. (I don't do support now, this was several years ago.)
"The findings are false-positive proof since I have used the tool that discovered it for six years now and I am yet to see it misidentify an item throughout the years."
At least it reminds us why the underdog sometimes has the upper hand, I suppose.