Confirmed: Samsung is not shipping keyloggers
f-secure.com
f-secure.com
Mohamed Hassan [MSIA, CISSP, CISA and graduate of the Master of Science in Information Assurance (MSIA) program from Norwich University in 2009 as the original article prominently states], on the other hand, is probably not so lucky. Any Google search on his name from now on will probably reveal this whole debacle. Furthermore, I wouldn't be surprised if he just opened himself up to legal action by Samsung.
If they're going to pass him off as an expert, then he better be doing analysis that a normal lay-man can't do. If he has the credentials, then why is he basing his claim off of a conversation with low-level customer support?
They have experienced difficulty regarding the rates at which students receiving Federal Financial Aid graduate - i.e. their issues are based on low graduation rates and not based on being a diploma mill.
Disclosure: my spouse teaches for UoP part time.
UoP had about 400,000 students at the time the Frontline piece was produced - that's seven Ohio State Columbus's [http://www.osu.edu/osutoday/stuinfo.php] so number of schools is not perhaps the best measure.
Rightly or wrongly, because UoP has open enrollment they admit more students who are eligible for Federal Financial Aid than most schools because of the population they enroll.
And nothing in the Frontline piece accused UoP of being a diploma mill as was implied by the prior comment to which I responded. A criticism of their business model is a different indictment altogether.
Wait, so just like a real university?
The money quote:
>The findings are false-positive proof since I have used the tool that discovered it for six years now and I am yet to see it misidentify an item throughout the years.
It boggles the mind how a founder of security consulting company can be so clueless. But most of HN and the tech news site like Slashdot fell for this with completely knee-jerk reactions, so I guess I am not surprised and the people behind his fiasco got the publicity they wanted. And remember HB Gary?
I am sure this hoopla would've cost Samsung some real damage in sales and they might be considering legal action. As Churchill said:
"A lie gets halfway around the world before the truth has a chance to get its pants on."
Well, atleast I can say I called it, even after the so called Samsung confirmation. http://news.ycombinator.com/item?id=2389141
I've heard the same kind of reasoning from people who forward on those "Microsoft will send a prize for the most emails sent!"-type emails.
The problem is: there has to be a minimum level of credibility, otherwise we'd be swamped with every man and his dog making claims like these.
Extraordinary claims require extraordinary evidence. Especially when the person making claims is the founder of a security company. His due diligence consisted of things like "The software I used is false-positive proof since I am using it from 6 years". "I have done this on two different laptops with same results, so it must be Samsung's fault". Huh?
I hope this guy has it coming to him. If he's going to put his creds up like that, he's putting himself out there as an informed source. You expect that sort of sensationalism from journalists, not from a security "expert". Shameful work, overall.
Actually, he has a sufficiently common name that those results will be relegated to the 2nd or 3rd page of search results within a few weeks:
Overall in that item I think HN did better than you imply, unless you mean the upvotes the item received.
Reddit fared much worse, IMO, in that people continued to upvote the wrong story after the truth was out. The correction has been posted but isn't anywhere near the front page.
Meanwhile, the shitty media outlets that irresponsibly spread this got all the ad impressions they wanted. The problem with truth is that its not as profitable as BS. How many people will ever read the corrections?
Of course, these guys are not even trying.
That said, "security appliances" and other magical solutions tend to be rather imperfect. tptacek (of http://insecure.org/stf/secnet_ids/secnet_ids.pdf) may have something to say about that, too.
It stinks of proprietary crap and I wonder what it would look like if they took a more OSS approach? When you can't even talk about XSS testing without a bit of prodding as if it's something exceptional it really makes me wonder what on earth these guys are selling.
Don't forget that lots of "programmers" are barely-skilled and working on VBA macros - one label can cover a wide range of skill.
Nice laptop you have here; would be a shame if something would happen to it!
You'll have thousands of quotes from a so-called "Samsung supervisor" who "said it's used to "monitor the performance of the machine and to find out how it is being used."
What is this bullshit ? From where did the quote come from ?
Amazing how most are just copy-paste. It just prove that very few online news websites verify their source if the keylogger claim is false.
Mohamed's lesson: Just because you were unable to prove a false-positive with the same program for 6 years doesn't mean there weren't any.
The original article was so poorly fact checked. It really reflects poorly on Mohamed Hassan (and all his fancy yet meaningless credentials) and M. E. Kabay (who apparently worships Mr Hassan unquestioningly). I will not hold my breath out for a public apology from either of those two, although they are the ones who owe Samsung one.
And the irony is in fact delicious. A security expert finds a virus using an anti-virus scanner tool, and confirms it with some call center employee with the company. What does being a "security expert" have to do with any of that? My 10 year old nephew could have done that!
EDIT: I mean, this is the only tech news site I read. I don't know if I'm in the same boat so to speak.
> [UPDATE 3/31/11: Mich Kabay writes: A Samsung executive personally flew from Newark, N.J., to Burlington, Vt., carrying two unopened boxes containing new R540 laptop computers. These units were immediately put under seal and details recorded for chain-of-custody records. At 17:40, Dr Peter Stephenson, Director of the Norwich University Center for Advanced Computing and Digital Forensics, began the detailed forensic analysis of the disks. We expect results by Monday.]
http://www.networkworld.com/newsletters/sec/2011/040411sec1....
Can we get a link to an article that actually checks a Samsung laptop (and lists their methodology, not this "Duh, there were not any keyloggers") instead of anecdotal evidence and attacking the previous reseaerchers methods?
Even if the previous guy was wrong, at least he listed all his methods for review.
1) The whole saga was caused by a bad antivirus alert. This story never even happens if not for that.
2) They checked a set of Samsung laptops and found no trace of keylogger software. See http://www.f-secure.com/weblog/archives/00002132.html
Is there more you'd like to see be done?
1) How did they verify there were no key loggers (is their AV program set to identify StarLogger instances) 2) What subset of Samsung laptops did they check 3) Did they check from more than one source 4) Did they verify that the laptops they checked haven't been wiped & reimaged with the local store's base computer image (such as with Best Buy)
With out some of this basic data, their findings are perhaps more suspect than the original article (not that I believe Samsung is doing this, I just disagree that their conclusions are as cut and dried as they, and the link title, indicate).
We really should be doing what you suggest for all brands and models of laptops. There's no evidence to suggest a specific issue with Samsung at this point.
Even the antivirus manufacturer who detected the problem has acknowledged they made a mistake.
http://sunbeltblog.blogspot.com/2011/03/samsung-laptops-do-n...
A pretty first class post in my opinion.
It would be like a newspaper reporting that "Falcolas kills 5 people!" And then turns out that you actually saved five people from drowning, and the newspaper prints a retraction. But then someone says, "But can you prove he didn't also kill five people at some point along the way? No one has really come out to say that he's never killed five people." Sure you may have, but at that point we have no reason to believe you have moreso than anyone else.
Absence of evidence is not evidence of absence. An absence of evidence, plus noting the problem of the AV, is all that this article has.
The Ars Technica article [1] draws much better conclusions - "Samsung laptop keylogger almost certainly a false positive". It's a significantly more accurate conclusion than "Confirmed: Samsung is Not Shipping Keyloggers", given the data that we have at this point.
[1] http://arstechnica.com/hardware/news/2011/03/samsung-laptop-...
1) What was in the SL directory? F-Secure claims the certified guy never inspected it. What about them, did they inspect it? They could have easily asked Hassan for a copy (insert appropriate caveats here about trusting sources). Sounds like they didn't even find one on their own, so how can they assert they know what it does not contain? They might not have gotten one of the laptops with the payload; that doesn't mean they don't exist.
2) How did the SL directory get there? F-Secure didn't even offer a theory.
3) Is Samsung installing keyloggers on a subset (random sample) of their machines?
4) I'd like to see it stated clearly, with no weasel words: Is F-Secure under contract with Samsung or do they have any business relationship with Samsung whatsoever? If not, are they angling for one?
"After an in-depth analysis of the laptop, my conclusion was that this software was installed by the manufacturer, Samsung. I removed the keylogger software, cleaned up the laptop, and continued using the computer."
So, the author, Mohamed Hassan was able to uninstall a software which was never installed? I think he would have deleted the folder in question and called that un-installing!!
https://secure.wikimedia.org/wikipedia/en/wiki/Filesystem_Hi... Not a single 2 letter directory name.
Read the article - that's Microsoft's work, not Samsung's.