I don't expect Kaspersky (the person) to play hero under these circumstances.
I don't expect Kaspersky (the person) to play hero under these circumstances.
If you're a valuable target, it's basically choosing if you want to be spied on by the russians or the americans. (or installing linux, and hoping for the best).
Those companies often actually have people scan the hardware they receive to check for alterations. There was a whole thing about this a decade ago where a reporter (wrongly, IIRC) accused Facebook and Google of having compromised motherboards, and people from those companies were commenting here about how they are actually very careful with their supply lines and have people vet what they receive with scanning electron microscopes in some instances. (I'll try to find some of the submissions here and edit them as links on the bottom shortly).
I also have it on good authority (a good friend that worked at Google at the time) that Google found out that someone (the NSA) was tapping their inter-datacenter links and that's one of the reasons they made sure all data between datacenters was encrypted, and that was prior to the Snowden leaks.
So yes, agencies are constantly attempting to infiltrate large tech companies for their own purposes. That doesn't mean they always succeed, or that those companies just give up and accept that it happens. They all fight it quite actively.
It's also not a theory.
It's true that any any software that allows auto-updating can be used to load arbitrary code onto a system, limited only by whatever additional safeguards are in place. In the case of the OS vendor, that can't really be guarded against, but it exists farther up the stack as well. Chrome and Firefox can just as easily load nefarious code onto your computer, limited only by what the OS prevents (which is generally more on a mobile platform, thankfully) and what their own reputation can sustain if they were found doing so.
Its interesting to note that not many people remember (maybe a generational thing?) Kevin Poulsen found multiple government listening devices installed on Pac Bell networks that were listening to foreign embassy phone traffic which was highly illegal at the time.
It doesn't surprise me the extent the NSA and other three letter agencies have gone to get at information they deem valuable or important.
FTC should follow a fair and evidence based process for arriving at a decision like this.
There should be punitive measures only after it has been established that there is wrongdoing.