Kaspersky believes it found new CIA malware
therecord.media
therecord.media
The fact that they can determine all this from some binary is amazing. Security researchers really are techno-archaeologists.
But when someone accuses the US we never add any salt. Not that I don’t think it’s false, it’s just that the lack of consistent skepticism is interesting.
Hell, I've seen malware from countries in Africa that lack food. These societies have a lot of kurtosis.
They have a lot less money than South Korea, and their political system is...what it is...but I don't see any reason a North Korean can't study just as hard as a South Korean and achieve similar results.
I think people confuse North Korea's suffering with weakness. I'll grant that there is a lot of hunger, but the mission from the beginning, of the guerrilla fighters who now run the country, was sovereignty at all costs. And I'd say purely in terms of sovereignty North Korea is doing remarkably well.
There's absolutely no morals or ethics at the means level. That's not a judgement. The fact is, the driver is the ends. Meet the objective by (nearly) any means necessary.
The CIA, NSA, etc. will - and have - say pretty much anything. That's their job. But why people liken them to some holy higher power is beyond me. Maybe it's a result of the IC's own disinformation? Ironic but fitting.
Let's not pretend the FSB and MSS don't also lie constantly. That you're more familiar with the CIA lying is a testament to the free press of the US, not the other way around.
The point of the previous post is that it could easily be another security agency.
You don't know everything there is to know about the CIA. All it means that that they can't lie about what you do know.
Who is pretending? The discussion is about the CIA.
When I discuss cats, there is no reason I should have to always qualify it by saying "yes, and dogs are cute, too."
This advice makes no sense to me.
Honestly, yes.
> Then when the CIA denies they lied about the foreign government was doing something bad
When have they done this? A few times probably, but not really a high percentage.
At any rate, P(CIA telling the truth about a foreign govt|foreign govt is doing something bad) is much higher than P(CIA lying about foreign govt|foreign govt is not doing something bad). The rational thing is to put higher weight on such statements than when the CIA is trying to cover their own ass.
99 reports could be truthful but the 1 lie that leads to war is enough to ruin their reputation.
Anyway, the point is that I don’t think you have to dig very deep these days to find plenty of instances of geopolitical power X doing bad things, so I’m not sure why the CIA would bother lying to stir up shit against them when they could tell the truth just as easily, with the same result. This assumes their purpose in releasing any information at all is to influence public opinion, not increase transparency, as the latter would probably mean divulging uncomfortable truths. The former does not—they can release exactly what they want, and no more.
On the other hand, flatly denying you’ve done a bad thing is a form response for governments and corporations (and politicians) at this point, even when it’s risible on its face. If you’re the guy responsible for putting those comms together and you admit wrongdoing, you’re never working in this town again. Simple as that. Deny, deny, deny. Deny everything. (Isn’t that a one-off X-Files title card?)
Has the CIA lied? Absolutely, though I’d guess far more often (orders of magnitude?) by omission than by outright explicit falsehood. The latter goes against the same ass-covering impulse that drives the bullshit denials. My brief comment above is meant to be a general observation on the sorts of public communication games the CIA and similar organizations tend to play, not an absolute truth or bible for living your life.
That’s... not how that works at all. Disinformation campaigns very frequently include publicly signaling you’ve come to a different conclusion than the real one you’ve come to.
I'm not sure why you think what I said is incompatible with this. Often the best "lie" is a carefully cut-out corner of a larger truth.
Because it’s literally the opposite. Misattribution is disinformation 101 if you have a solid source you need to protect.
US finds out China severely compromised a system while pretending to be Russia. The US found this out via a compromised Chinese government asset.
They need to fix the system but don’t want to let on they knew it was China and risk compromising their insider knowledge. Best course is to just say, “we found this that looks like Russia and we fixed it”.
There is no reason to assume a public attribution from an intelligence agency is correct. There are far too many reasons for it to be helpful to lie.
In your scenario, that's not a lie.
https://definitions.uslegal.com/a/admission-against-interest...
https://en.wikipedia.org/wiki/Declaration_against_interest
that is to say, when making a statement is personally detrimental to someone, and they make it anyway, that statement should generally be given a higher degree of belief than one that is self-interested.
so in other words, if the CIA denies that they did something bad, you don't necessarily believe that straightaway, because of course they would say that. On the other hand if they do admit they did something bad, then it's OK to believe them in that instance even if they've lied in other instances.
Now of course - in the specific case of the CIA they are a government apparatus, not an independent actor, so the fact that they say (eg) Russia did a bad thing isn't necessarily against their interest, it is in their interest for the US Government to look good and truthful. But as a general rule, it's important to look at the interests in a specific instance to determine rather than just assuming that because an actor lied once that everything they say is suspect.
1. https://en.wikipedia.org/wiki/Eugene_Kaspersky#Early_life
That was news to me, so I went looking for some context.
https://en.wikipedia.org/wiki/Kaspersky_bans_and_allegations...
Hey, I don't even believe the CIA quite always lies: I'm sure it has sometimes said "The FSB is lying", and I believe that too. Because the FSB is pretty much always lying... Just like the CIA.
Somebody says people are skeptical of attribution to governments outside the US, but not the US. Specifically he says that he does not doubt it was the US.
So yeah, the discussion you're replying to is not just about CIA.
How do you go from reading "the CIA is lying" to "the FSB is telling the truth"? Do you understand the difference between those statements? Reminds me of a stand up bit, "are you a Jew or an antisemite?"
The link is a Kaspersky press release, so there’s potential for an FSB connection:
https://www.bloomberg.com/news/articles/2017-07-11/kaspersky...
A whole lot of these outfits are started by former NSA employees, and they love having people that previously worked in US national security on their rooster for the marketing value.
Yet whenever one of these outfits accuses China/Russia/Iran of being responsible for the latest "cyber incident"/"misinformation campaign" these accusations are widely regurgitated without any doubt like some kind of definitive factual truth.
"There is no such thing, at this date of the world’s history, as an independent press. You know it and I know it. There is not one of you who dares to write your honest opinions, and if you did, you know beforehand that it would never appear in print. I am paid weekly for keeping my honest opinions out of the paper I am connected with. Others of you are paid similar salaries for similar things, and any of you who would be so foolish as to write honest opinions would be out on the streets looking for another job.
If I allowed my honest opinions to appear in one issue of my paper, before twenty-four hours my occupation would be gone. The business of the journalist is to destroy the truth; to lie outright; to pervert; to vilify; to fawn at the feet of Mammon, and to sell the country for his daily bread. You know it and I know it and what folly is this toasting an independent press. We are the tools and vassals of the rich men behind the scenes. We are the jumping jacks, they pull the strings and we dance. Our talents, our possibilities and our lives are all the property of other men. We are intellectual prostitutes." - John Swinton, the former Chief of Staff at the New York Sun, at a toast before the prestigious New York Press Club in 1880
[1] https://www.washingtonpost.com/politics/2019/03/22/iraq-war-...
[2] https://www.washingtonpost.com/archive/opinions/2003/11/28/m...
Folks inside the CIA knew that the yellow cake uranium was a lie and at best, did not make any of this knowledge public as the justification for war was coming together. That silence resulted in the loss of at least one hundred and fifty thousand human beings needlessly and a war that has lasted decades.
> I have witnessed the CIA justify those wars
to
> the CIA knew that the yellow cake uranium was a lie and at best, did not make any of this knowledge public
?
Isn't that a bit of a... large jump?
Also, do/should intelligence agencies generally come out and make public announcements of intelligence at all? I mean, maybe you can argue they should do that (for the public good), but unless they already do this in similar situations (or are normally instructed to), to show they actually acted in bad faith is going to need a lot more than arguing they didn't explicitly go out of their way to do so.
Btw, here's what I'm reading they apparently reported: https://fas.org/irp/cia/product/iraq-wmd.html
> Moderate Confidence: Iraq does not yet have a nuclear weapon or sufficient material to make one but is likely to have a weapon by 2007 to 2009. (See INR alternative view, page 84).
> We cannot confirm whether Iraq succeeded in acquiring uranium ore and/or yellowcake from these sources. [...] Intelligence information on whether nuclear-related phosphate mining and/or processing has been reestablished is inconclusive, however.
(To be clear: none of this is to suggest I'm a fan of the entities involved...)
> Also, do/should intelligence agencies generally come out and make public announcements of intelligence at all?
They did so pretty frequently during the Trump administration. Whistleblowers spoke up when someone came in claiming to want to end the war on terror, they didn't feel the need to do so in 2001 when that war was getting started.
As they say, technically correct, the best kind of correct.
Just gonna point out that non-Americans are human beings as well, and millions have died - directly as a result of this silence.
The fact that Biden played a key part in enforcing this silence at various stages is particularly galling, and it's beyond fucked-up that he isn't held to account for it.
150k is the most conservative estimate I could find for Iraq. US and Iraqi deaths included. Some estimates are in the millions but I try to be as generous as possible to the other side of a argument I am making.
It is the lowest I could find. It also has quite a list of criticisms attached to it. The Iraq body count project counts more just from reported deaths alone.
I wouldn't be surprised if the ORB study showing in excess of 1.2 million is closest to the truth. especially since it ended in 2006 i think and it's not like people stopped dying since then.
There's been a bunch of opinions since then that they were actually just misrepresented, but their own words from 2002 speak for themselves, IMO.
https://www.scribd.com/doc/259216899/Iraq-October-2002-NIE-o...
> Iraq is continuing. and in some areas expanding, its chemical, biological, nuclear and missile programs contrary to UN resolutions.
> If left unchecked, [Iraq] probably will have a nuclear weapon during this decade. (See INR alternative view at the end of these Key Judgments.)
> [State/INR Alternative View] The activities we have detected do not, however, add up to a compelling case that Iraq is currently pursuing what INR would consider to be an integrated and comprehensive approach to acquire nuclear weapons. Iraq may be doing so, but INR considers the available evidence inadequate to support such a judgment.
So basically the CIA is saying:
- The INR (separate agency) doesn't believe this is enough to start a war over.
- The other agencies (presumably including CIA) do.
However, their justifications in the bullet points seem to rely on a fair bit of speculation about motivations behind things, not as much actual concrete evidence as you'd hope. Whereas the INR evaluated the same evidence and said they aren't confident enough in this yet.
OK, so I'm with you here so far. Now the question to me is: did the CIA really lie here, or did they (and other agencies) really fail at their job? If it was a lie, are we using that to mean a falsehood, or does it refer to omission of critical information that they were reasonably confident about? On the face of it, it looks like they really just failed spectacularly, not that there was malice per se, but I don't have more details. (Though I guess that means we should listen more to the INR in the future?)
[1] https://nsarchive2.gwu.edu/NSAEBB/NSAEBB129/nie.pdf#page=13
The US has been at war for most it’s existence.
Someone made a search tool to see how many years the US had been at war for, and then ran it on Wikipedia.
Interestingly, France performed worse (assuming one doesn’t like war), though being involved in things like ‘The 100 years war’ skews things a little.
[0]: https://en.wikipedia.org/wiki/1939_Nazi_rally_at_Madison_Squ...
We'd then "steal" those supplies, thus allowing the US to avoid breaking non-aggression treaties, and (as you mentioned) the ire of some of its citizenry.
Not much profit in theft.
Even if Roosevelt's goal wasn't to sit back and make a profit, he ran on that platform as the country did want that.
Not wanting to spill their blood, not wanting to enter a conflict which (at the time) seemed only to aid old, dying empires (eg France, UK), means the goal in not entering the conflict, was all about profit?
What a twisted viewpoint.
Meanwhile, if the US does enter a conflict, the goal is always claimed by some, to be exploitation.
Thus, whatever the US does, the goal is selfish, evil, cruel? Sure, that sound reasonable, fair.
I cannot find an easy source for the history lesson I learned in school. Take it or leave it as it stands.
>Thus, whatever the US does, the goal is selfish, evil, cruel? Sure, that sound reasonable, fair.
That is what it means to be an empire. There's no "good" empire, they all exist to prop themselves up to greater heights.
Even if Roosevelt's goal wasn't to sit back and make a profit, he ran on that platform as the country did want that.
You've actually claimed that Roosevelt ran on a platform of "Let's sit back and not do anything, so we can make a profit". Come on! Give it a rest, please!
Further, the average American (re: the voter) didn't give a rat's ass about some corp they worked for, turning a profit thanks to war profiteering. And many Americans even wanted to enter the war! You know how voting works.
On to your other comment.
If there is no "good" empire, then there is no "evil" empire. You cannot remove moral labels on only one side, yet leave them on the other. Ergo, you've essentially stated that Nazi Germany has no justified, negative moral connotation to it?
Sorry, there are empires that revolve around a negative, evil premise. And those which revolve around a positive, good premise. But let's step back from this a bit, and do what some might find sensible.
Look at historical empires, comparatively, and assess the US against them.
Is the US perfect? Certainly not! However, are you? I? Nope.
Yet compare the US to other empires. Especially world spanning empires. Whilst the UK, France, all the way back to Rome, Greece, were not superpowers, they were "known world" spanning. World impacting.
Now assess the policies of these empires. Comparatively? The US is the most benign empire ever. EVER. Assess its strength, versus countries it invades. If the US behaved as the UK, the entire planet would be under its boot! If it behaved as Nazi Germany, can you even imagine?
It sickens me to have to defend the US, for I do indeed know it is not perfect. The US rolls over in its sleep, and crushes parts of Canada's economy. Yet I don't seem to recall post WWII US threatening to invade Canada, if we didn't pass copyright laws it likes. I don't recall the US capturing Iraq, and hauling off "undesirables* to concentration camps by the millions. I don't recall the US invading countries, and maintaining control after the fact -- for hundreds of years.
Oh sure, yes "Well, the US did this, corporate that, it's all for this and that" so what. We're comparing empires here.
So please, show me a world spanning empire, ever, which behaved with as much restraint as the US has. And bear in mind, the US literally could overthrow 90% of the planet in a matter of 20 years.
Just... it sickens me to see the US's own citizens, denigrate her so.
Now... do I respect your desire to reign in the US? Keep it restrained? Under control?
YES! By God yes, I do. But why on Earth make up contrived stuff, like the US was a land of profiteering, sniveling, hand wringing people, staying out of a war because PROFIT.
Please stop! Please!
Our first century of nonintervention was unquestionably based on the thought that entangling ourselves in European wars would drain us dry. Saying an element of that doesn't still remain is just incorrect, it is broadly the same idea as "Make America Great Again."
"Much of America" supported it, I never said all.
>If there is no "good" empire, then there is no "evil" empire. You cannot remove moral labels on only one side, yet leave them on the other
Trying to be an empire in itself is evil. Being the "least evil" empire is not something to be proud of.
>Yet I don't seem to recall post WWII US threatening to invade Canada, if we didn't pass copyright laws it likes.
Yet they have done basically that with Mexico and many other South American countries.
>. I don't recall the US capturing Iraq, and hauling off "undesirables* to concentration camps by the millions
Only thousands, while killing many many more.
>. I don't recall the US invading countries, and maintaining control after the fact -- for hundreds of years.
Literally all of America, Puerto Rico, and this ignores that setting up puppet governments and economic domination are also methods of empire building.
>Please stop! Please
No. I see your point of view as accepting the blatant propaganda taught to us our entire life. The US denigrated itself, and just tries to make people think it's noble.
There is a vast difference between "drain america dry" and "stay out of the war to profiteer". Vast. Immense. The motives are entirely different.
I cannot continue this conversation, when you keep making these sorts of assertions. There's no common ground. Nothing we can realistically discuss, for, you aren't even discussing the same things when you reply.
Outside of all of this, bear in mind I'm a Canuck. No, I'm not all "rah-rah America', nor is my viewpoint skewed by propaganda. You guys drive me nuts at times. I frankly view your country as a brother, one I wish well for, yet often sit gobsmacked, and even sad, when you I see how my brother is behaving.
I think you're trying to discuss things, with the view that I'm going to respond to US political talking points. Or perhaps culture viewpoints.
Anyhow.
Have a good one. We're not going to agree here, so there's no point.
Besides the political reason stated for doing so, name one difference. Both involve profiting by staying out of the war, and using that money to further your own ambitions.
We are discussing the same things, you just label them differently than I and think that justifies them. Like claiming the US has never invaded and occupied a country for centuries, as if the First Nations somehow wouldn't count.
I hope you also have a nice day.
See also: https://en.wikipedia.org/wiki/Afghanistan_Oil_Pipeline
This has been an unfortunate truth for the US and USSR before it (and other empires before that). For a depressing insight into how little we have learned, Boys in Zinc by Svetlana Alexievich is a good read.
Wilson ran for reelection promising not to enter WWI. Upon winning, he immediately broke that promise. When USA entered the war, it had already ground to a stalemate after three years of carnage. The various warring parties had been open to a negotiated peace. As soon as American lives were on the line, France, Britain, and Italy discovered a determination to see the war to its bitter end, which took another 1.5 brutal years and millions more human lives.
Wilson claimed to prefer reconciliation to punishment of Germany, and initially during peace negotiations he reined in the worst French and British excesses. Then he got Spanish Flu, suffered severe mental decline, and functioned as a doormat for the remaining "negotiations". The French and British somehow concocted such draconian penalties that they created brutal fascist dictatorships not only in their enemy Germany but also in their ally Italy. Hitler's and Mussolini's empowerment, not to mention the transfer of Germany's Chinese colony to Japan, guaranteed a conflict like WWII.
https://www.history.com/news/woodrow-wilson-1918-pandemic-wo...
It is a complex topic that for some reason we don't talk about much. I find the theory really interesting because hind sight we haven't had major wars like we did in the past. But clearly this leaves the US wanting to use its military (though that's the basis of the theory in the first place).
If an idea is reasonably feasible, I just assume someone, somewhere is already doing it.
The practical benefit is lowering my cognitive overhead, transaction costs.
Instead of guarding against every possible attack vector, I take basic precautionary measures, and then decide if any action is worth the risk, knowing full well it'll likely go terribly wrong.
So I always wear a mask, use a password wallet, drive just under the speed limit. Etc. It's habit, routine. Then when I step outside my personal safety bubble, it's an affirmative choice.
"CNN" is a recursive acronym, modeled after "GNU".
https://www.wsj.com/articles/russian-backed-facebook-account...
We also know that hundreds of thousands of foreign-sponsored accounts on Twitter, Reddit, Facebook, etc, have been banned over the years. (Please fact check by googling!)
Here's an example that in major parts contributed to a civil war going on to this day: The existence of a US military operation that manipulates social media trough sock-puppet accounts [0] was revealed around the same time Syrians were riled up to regime change trough.. social media [1].
Said social media presence kept announcing "Days of Rage" protests in Syria which initially no Syrian even showed up to.
These operations predate anything noteworthy Russia did on the same front, as most of that only started in the wake of the Ukraine revolution, which also saw plenty of blatant US interference [2]. Back then Russia was diplomatically very vocal about how unprecedented the foreign interference in Ukraine was.
What followed was St. Petersburg troll farms heavily targeting the US.
> We also know that hundreds of thousands of foreign-sponsored accounts on Twitter, Reddit, Facebook, etc, have been banned over the years. (Please fact check by googling!)
How many domestic sponsored accounts have been banned? Zero, which means that on US based social media these kind of outfits are fighting with a heavy home game advantage [3], yet in most of these places that never comes up, it's always "Look out for the Russian/Chinese propagandist!", just like you are doing here. Which usually ends up targeting skeptical people not wholeheartedly endorsing the "Good vs Evil" narrative and not any actual propagandists.
[0] http://www.theguardian.com/technology/2011/mar/17/us-spy-ope...
[1] https://www.france24.com/en/20110203-syria-democracy-protest...
[2] https://www.theguardian.com/world/2013/dec/15/john-mccain-uk...
[3] https://www.reddit.com/r/Blackout2015/comments/4ylml3/reddit...
The Smith–Mundt Act makes it illegal to distribute propaganda where it may be consumed by a primarily US audience.
Also from just a practical investment perspective, creating a bunch of sock puppets on Reddit to try and influence the opinion of Putin doesn't make sense. r/Russia for example only has 150k subscribers and most of the posts are in English.
You would need to ask WeChat, VK, Weibo, Douyin, and OK for transparency reports on how many state-sponsored accounts they have terminated.
That hasn't been true for nearly a decade as the Smith-Mundt act was "modernized" in 2012 to allow for exactly that [0].
Even when it was in effect, I doubt anybody was seriously trying to abide by that. The closest thing to practically doing that would have been to completely skip on the English language, which I seriously doubt they did.
I put that denial into the very same camp as the NSA denying spying on American citizens: They say it because they are supposed to say that and admitting to it would put them in a world of trouble trough open admission of guilt.
> Also from just a practical investment perspective, creating a bunch of sock puppets on Reddit to try and influence the opinion of Putin doesn't make sense.
It makes a lot of sense, not just to manufacture consent, but also trough the fact how the US is the literally largest culture exporter on the planet. US social media isn't just populated by Americans: Facebook, Reddit, Twitter and whatnot are by now overwhelmingly used by international audiences.
Sure, there are countries that try to ban these platforms, but that doesn't stop the USG from still trying to get something going [1]
> You would need to ask WeChat, VK, Weibo, Douyin, and OK for transparency reports on how many state-sponsored accounts they have terminated.
But none of these are in any way widely used outside of their respective countries, their very limited reach and lack of language diversity, makes them inherently inferior to the globally dominating US social media platforms.
Yet that's where the "opinion wars" are won, where the international Overton window is defined: On the global stage, not on comparatively obscure domestic platforms.
[0] https://foreignpolicy.com/2013/07/14/u-s-repeals-propaganda-...
[1] https://www.theguardian.com/world/2014/apr/03/us-cuban-twitt...
The "opinion wars" in the US are won on what you consider to be the dominant social media networks. Again, if you want to convince a bunch of people to overthrow Putin, those daily active users are on VK - not Facebook.
But you literally can't use a lack of evidence of US influence on US social networks as proof that it is happening. Your second link plainly states that the US created an entirely new social network to try and influence Cuba, they didn't do it on Instagram. Hold yourself to a higher standard.
0. https://www.politifact.com/factchecks/2019/aug/23/facebook-p...
They agree on a very different question. Even if we want to reframe it as an allegedly completely harmless "VoA can now broadcast to Americans!", the embezzles the fact that outlets like VoA/Radio Liberty&co. are very much the US equivalent to a Russia Today.
With the difference how their US versions have been broadcasting globally, completely unopposed, for literally decades. Yet whenever RT is linked anywhere it doesn't take long for somebody to go "That's Russia bad/propaganda/all lies!", usually derailing the discussion from the actual topic.
> Again, if you want to convince a bunch of people to overthrow Putin, those daily active users are on VK - not Facebook.
You also want to dampen any criticism, propaganda is not just a game of offense, it's also one of defense [0] That's where it's really helpful to have more than just two eyes, like Five Eyes [1]
> Your second link plainly states that the US created an entirely new social network to try and influence Cuba, they didn't do it on Instagram.
Cuba actively blocks Internet traffic when it's convenient to them [2], Instagram can't sidestep that, SMS can [3], it can even reach people that still only have dumb phones, something quite relevant back in 2012.
[0] https://en.wikipedia.org/wiki/Falsehood_in_War-Time#Summary
[1] https://theintercept.com/2014/02/24/jtrig-manipulation/
[2] https://twitter.com/netblocks/status/1333495221712265217
China on the other hand not so much. I might go trough the effort of finding them again but someone here shared some American studies that showed china initially didn't really have such a presence of bots and the like on twitter, fb, etc like Russia at that point (i think around 2016 or 2017) but there were notable networks of bots targeting chinese people with anti china stuff.
A second study showed that i think 3 years later China had also gotten into this but that it was comparatively small scale and notably incompetent.
That said - it ABSOLUTELY BOGGLES MY MIND that, if these are not leaked, but rather recovered from attempted attacks, how are _any_ valid timestamps and strings not randomized as part of the build process!? I'm not saying it refutes or confirms, I'm just wondering - how difficult is it to read an ELF | PE and remove / change those things, and if it's as easy as I'm thinking, why would you not do so? Or replace with preprocessor directives that you could setup to random values for production builds to use strings and timestamps that indicate some other entity? All of this seems straightforward to me, like, could do via shell scripting or python. Is there a valid reason to leave this stuff in? Are we seeing some low priority work that the TLA wants to leak to show that they're out there and capable?
They do, except they're not random. Check out the CIA Vault 7 leaks from a few years ago. They purposefully leave trails that point to other countries including using foreign languages for variable names/comments.
> “[D]esigned to allow for flexible and easy-to-use obfuscation” as “string obfuscation algorithms (especially those that are unique) are often used to link malware to a specific developer or development shop.”
> The source code shows that Marble has test examples not just in English but also in Chinese, Russian, Korean, Arabic and Farsi. This would permit a forensic attribution double game, for example by pretending that the spoken language of the malware creator was not American English, but Chinese, but then showing attempts to conceal the use of Chinese, drawing forensic investigators even more strongly to the wrong conclusion, — but there are other possibilities, such as hiding fake error messages.
https://www.mintpressnews.com/wikileaks-reveals-marble-proof...
And Broadcom _does_ note that they associate with Vault7 group via the whole picture, but it's weird they present the strings and dates data without noting that it would be trivial to fake, and don't give any specificity to the other data points.
I guess for this type of work the only thing you _really_ have is the code's intent, if you can figure that out.
This thread also isn't full of calls for sanctions against the US or talk of overthrowing the government.
I don't actually doubt many of the reports claiming North Korea or whoever were behind some attack, I know they are likely engaging in such activities. I just don't think the evidence is convincing enough to use as a casus belli or similar reason to take our own malicious actions. I would take a similar stance with this CIA malware, but nobody here is calling for punishment based on it.
This is a case of a third party saying "we think it was probably X". You can't rule out other motivations here either, but there's a fair bit more room for it to be less politically motivated.
Likewise, Kaspersky is more believable than if the FSB came out with this story, even if we must be cautious that it could be an FSB story.
The NSA and CIA, on the hand, are always assumed to have some of the best hackers in the world. So when I read that some huge exploit with multiple complex 0-days chained together has been discovered, and it's being attributed to the USA and/or Israel, I usually assume that's true because very few other countries have the ability to pull it off.
As a result they operate units completely overseas. North Korean students launch attacks from Indian Universities. They have networks of individuals that spend all day cashing out ATMs in Malta. The Chilbosan Hotel in Shenyang, China is a front used by the RGB as a forward base for cyber operations.
It's not genuine skepticism. It's people on social media wanting Internet points for pointing something out. It's devil's advocates and "well akshully..." people just saying something to make a point. People don't do it on CIA stories because it's not honest skepticism in the first place. It's not fun when the sarcastic and cynical responses make you even more jaded about your own country.
<--- Now, kindly do the needful, dear reader.
I think Occam's razor is often misapplied in this way. It's for explaining natural phenomena, not for surmising the intent of an intelligent entity with an incentive to deceive.
* CIA malware is discovered by a (Russian) Security company and they release a report about it.
* CIA malware discovered a year or more ago by a (Russian) security company and they tell the CIA about it and the CIA asks them to wait 1y+ to release the report, and they obliged.
Reminiscent of how cipher decoders knew their German operators well enough that it assisted in the decipher process.
for plausible deniability and to be able to reuse the same attack vector over and over, it's cheaper to just intercept shipments and install/modify what they need:
https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...
impossible to reproduce unless you have the exact same equipment.
Isn't this exactly what Intel's "Management Engine" and AMD's "Platform Security" is?
Bonus question, does apples new MX chips have an equivalent backdoor?
Or will you claim that all machines that are capable of such tasks are already compromised?
Admittedly it's absurdly complicated to do that at global level, but let's say someone in the right place manages to do that, the next level would be doing the same at iron level on computers, so that each subsystem can talk with others and the external world without administration tools noticing, because it's all done through a covert channel set up by closed software. That would be the perfect weapon to build pervasive surveillance that no security software at any privilege level, not even debuggers, would detect.
The only way to find something fishy is going on would be to sniff inter-chip communications locally and set digital analyzers on network cables with appropriate software. Network analyzers could fail if they use the same network chipsets, as would do a normal packet monitor.
Now, Kaspersky (which is suspected to be affiliated with Russian intelligence - possibly unwillingly) claims to have found CIA malware (effectively "burning" it, if it's real).
The timing does not seem to be a coincidence. Tit-for-tat?
[1] https://www.nsa.gov/News-Features/Feature-Stories/Article-Vi...
1. expose malware the CIA doesn't want exposed
2. get accused by the CIA of being in bed with the Russians
"working for the Russians" is the go to baseless political smear these days
Nope, it's ONLY the evil Russians. The naïveté of non-Westerners is sometimes astonishing.
And I hope you realize your whole retort amounts to "Kaspersky is as bad as CIA shell companies".
If they were known as a kremlin puppet, they wouldn't be respected.
I have yet to see actually compelling evidence that this is the case.
I do, however, think that there is a big difference between being "affiliated with Russian intelligence" and providing an anti-DDOS service to the FSB, which is what this article is discussing, and really all it gives evidence for. Kapersky also provided services to the US intelligence services, I don't think it would be described as "affiliated with American intelligence."
So it was possible then to analyze the metadata of the files and determine when the malware was made/compiled? That seems like bad OPSEC. If I was CIA I would be rigorous in modifying and faking when certain files were last modified or created, and possibly stripping other damaging metadata (if it's incriminating enough). This is basic metadata hygiene employed by journalists, whistleblowers etc
Often it's a massive team with people of very varied programming skills. The core exploit might be some super high tech, hand coded in assembly rootkit, but then the remote control stuff might ends up being some badly written powershell script or multi-megabyte dot-net, java or python binary pulling in every library under the sun.
Which is say to say, no one yet come up with an approach that combines "fast to write, fast to run, and easy to maintain".
The linked article's url is https://securelist.com/apt-trends-report-q1-2021/101967/ , which is from a site called "SECURELIST by Kaspersky".
https://en.wikipedia.org/wiki/War_Is_a_Racket (1935).
History doesn't repeat but it does rhyme.
It seems to be the natural state that centres of power co-operate with each other lest they lose their power.
Churches with Kings, Corporations with Government.
I'll see if I can find the slide that articulated the issue.
The other part was "Do what we tell you, or you'll be Joe Nacchioed"
In a 2013 interview, Marissa Meyer made it abundantly clear this is why Yahoo "voluntarily" joined PRISM. One can assume the rest were similarly influenced.
[0] https://en.wikipedia.org/wiki/National_security_letter
[1] https://en.wikipedia.org/wiki/PRISM_(surveillance_program)
However, these large firms have enterprise-wide security and too many people would notice the vacuuming of data for this to be done by single agents. So that would require secret court order and secret laws, as we know existed a few years ago.
So no doubt you have some level of secret agency access but exactly how much is difficult to say. Remember these are companies operating globally and it's in their interests to not be seen as mere extension of US intelligence and foreign policy but at the same time these agencies can very persuasive, etc. etc.
While I appreciate the heads up, Can anyone offer suggestions on how to mitigate this malware? What do I do? Do I have to rely on Kaspersky?
You don’t do anything because you are not the target. It’s never been seen in the wild.
So pick your poison.
If there's something you can do, then they've failed at their job, and it's time for hiring the next batch of developers (yes these are developers with a paid day job - to make malware for the CIA).
In university, most computer science or computer engineering students had to make a choice whether to work for the country's security agencies and/or the military industries (via internships, being recruited, or just plain applying to government/pentagon/fbi/cia/nsa/csis jobs, etc), and that's their choice to make.
From the government's point of view, it's no different than recruiting soldiers for the Army/Navy/Marines. If they couldn't train you to their standards for basic fitness and basic shooting skills, they've failed and you'd probably wash out from infantry school.
The other thing you could do is to contribute to initiatives that do specific research into looking for vulnerabilities. It's no guarantee that you'll find the same vulnerabilities that the CIA is exploiting though, or you might find entirely other ones that they've been using for other exploits.
Even then there will almost always be evidence if you log network traffic. But obviously this is very difficult.
You'd need to know what to look for though. It was shown that the CIA can hide its communication in metadata of legitimate traffic which is then recovered at intermediate hops to the target. So, do you know precisely what an innocent DNS packet looks like to detect this anomaly?
Wouldn't an abnormal amount of DNS data also stand out? I assume for this to work they'd still have to send a lot of data unless they're willing to wait for half an eternity.
Just curious, since I hadn't heard of this before.
So is EU really that ethical to not engage in these kinds of moves? Or they are smart enough not to get discovered? Or somebody here will point out that I'm just not up to date?
-- [1] https://apt.thaicert.or.th/cgi-bin/showcard.cgi?g=Snowglobe%...
E.g. on this "legalized" end of the spectrum Netherlands, Italy, UK, Germany, Switzerland, France, all have _very_ active companies and strong talent pool for offsec skills and what is "legal malware" (Bundestrojaner varieties like Mini/Mega-Panzer, etc).
ETSI in France works hard so that the term "malware" doesn't even enter language (instead it's middleboxes like eTLS or standards covering the framework of Lawful Interception). The countries listed have strong relation between offsec vendors and consultants and the IC. E.g. Kudelski Security in Geneve prides itself on breaking phones, supplying tooling and a lab to Europol. HackingTeam, Gamma International, EncroChat, Sky ECC, Vupen, ... = all European.
The EU countries which have (some) talent but lack the jobs are often "painted as corrupt" backwaters where "everyone is a criminal[1]", usually cover the rest.
[1] e.g. see this PR/FUD video produced by the ghouls at Norton pretending to be journalists: https://www.youtube.com/watch?v=un_XI4MM6QI
To the writers of these things:
In the future, would you kindly NOT name your malware after terms in Physics:
1. https://twitter.com/campuscodi/status/1387026165597151234
2. https://twitter.com/riskybusiness/status/1387194016790323200