https://en.wikipedia.org/wiki/Kaspersky_bans_and_allegations...
Whatever the case, it's probably wise to take their statements with some skepticism of bias in this regard.
When it comes to US crafted malware, I trust the Russians in detecting it and telling the world more than I would any US-based company.
FTFY.
That isn't true. This "without evidence" shit is rather silly when it comes to top-secret sources and methods. Blow decades of work and risk getting people killed to Prove that an ex-KGB officer helps an authoritative regime thats known to poison its enemies. People said the same shit about Huawei, then all the KPN shit.
Link: https://www.bloomberg.com/news/articles/2017-07-11/kaspersky...
That said, I think the safest default assumption is both that any large national intelligence agency lies all the time, and also that any entity that a national intelligence agency has the means and motive to compromise is probably compromised. So Kaspersky is probably an FSB asset (but so too is Amazon a CIA/NSA asset) but the CIA is probably lying 99% of the time too.
"We lie, we cheat, we steal". Literally from the mouth of the guy who ran it to your ears.
I'm not sure how you find these source legitimate sans evidence, other than possibly they are you team.
PS. Doesn't make the other jerks legitimate either.
You're talking about an entity with the ability to fake any evidence that they would be able to provide you. So no matter what "evidence" they provide you would still need to make a choice to believe them.
Personally, I don't know how closely they coordinate with Russian intelligence services, but some of the samples they get and the background/context they get can only be obtained if you are very close to the investigation. The way they phrase things like "we found this in a multi-engine scanner" raise the hair on the back of my neck, since I work in malware analysis and you don't just run across these types of samples by chance. They are either doing IR for organizations that were targeted (which you would just mention), or they are getting tipped off on where to look.
Whether or not this is intentional, or just happens to be a coincidence, it is something to be aware of.
Examples of suspicious timing: Flame paper released while there were massive protests in Russia around 2012, Regin/Equation Group/Duqu 2.0 paper released during Ukranian invasion circa 2014/15, and now this paper also released while tensions in Ukraine are ramping up and after the fallout from the SolarWinds stuff.
I think it would be less suspicious if places like Sputnik (a known propaganda arm of Russia) didn't immediately start pushing a specific narrative when Kaspersky has these malware releases.
It's definitely reasonable to be sceptical here, but that goes both ways.
[meta] I would REALLY love for people down-voting something to explain why they do this. Maybe as HN feature for the first 200 downvotes, you have to reply to the post or upvote one below that explains it...
You might as well say they are an AV firm and there is a conflict of interest just by saying there is some x malware.
Either way they need to proof it.
TBH, one should be happy that US possess such power. US might be biased, but the country is at least rational.
I don't follow that logic:
> >1: The US is the single most powerful cyber warfare practitioner
> >2: Successful operations in Iran, China and Russia
> >3: But those countries won't disclose such incidents
So how you can be so sure about point 1?
But you should take both these statements with a grain of salt when either side of the field stands to gain (or lose) something.
IQT funds a ton of different companies, it doesn't make them fronts for the CIA. Cloudera, FireEye and a ton of others have taken money from IQT, it doesn't make them propaganda.
Though I won't say for sure that Recorded Future is CIA propaganda, there are obvious reasons why the CIA would fund a software development or computer security company besides propaganda. For what other reason would they fund a media company?
TheRecord is essentially their blog/news site, just like ThreatPost is Kasperskys blog/news site. Just like I wouldn't consider Kaspersky a media company, just like I wouldn't consider Recorded Future to be a media company.