US Bans Kaspersky Software
wired.com
wired.com
[1] - https://www.av-comparatives.org/test-results/
[2] - https://en.wikipedia.org/wiki/Equation_Group#Discovery
[3] - https://en.wikipedia.org/wiki/Kaspersky_bans_and_allegations...
Unless you have a reason to believe that somewhere the NSA is having a meeting where your name is getting mentioned this isn’t actually something you need to worry about.
Also worth noting that if you do happen to find yourself on a targeting list, no one brand of anti virus is going to make even the smallest bit of difference as to what the outcome of that decision was.
This angle you seem to be insinuating that this decision to ban them is somehow because “they are mad” is a child like understanding of the situation and is actively wrong.
Please explain to me what you think should be different.
The thread went like this:
- Someone: Kaspersky is arguably the best at the job, was the only one capable of detecting NSA malware at one point.
- You: NSA never targets anyone they don’t want to target, and antivirus is useless if you are a target.
- Someone: NSA malware also gets leaked into the wild and end up infecting millions.
- You: A single example?
- Me: A single example (that was arguably digital security story of the year at the time).
- You, two comments later: what should NSA do?
They don’t need to do shit. Antivirus companies should up their game. In practice though, word on the street (probably backed up by leaked documents too but I’m not sure) is they — including the targeted software vendors, notably Google and Microsoft — often just greenlight their allies’ operations, and issue a low profile patch when it’s really bad.
To me the only conversation to be had here is were there reasonable protections in place at the time and what is being done to prevent it happening in the future but just due to the fact that this is the NSA those conversations are not going to be public for obvious reasons.
What exactly do you want to see happen here?
> Unless you have a reason to believe that somewhere the NSA is having a meeting where your name is getting mentioned this isn’t actually something you need to worry about.
... unless the exploits leak (after use), which they do.
The CIA once proposed to commit terrorist attacks on American soil to create a justification for war a against Cuba. JFK turned them down but was anybody in the CIA ever punished for it? Hell no, and there is reason enough to think they may have even murdered him for that rejection. Even if you don't believe that, none of them have ever been punished for their abuses and there has never been reform.
How could you claim that without (a) having insider knowledge of the secret activities of the FISA court and (b) violating some sort of legal restriction on publicising your knowledge of said court? One of the major complaints about the US surveillance program (indeed any surveillance program) is almost nobody is allowed to know who the targets are or why.
> I think the most controversial thing on that front from memory was Angela Merkel and other EU heads of state
And I think the most controversial target to date was actually Trump.
Wasn't their plan with stuxnet "spread this as far as we can and eventually it'll hit what we want?"
Ignoring how frequently they will accidentally target the wrong people, that seems like intentionally creating something where there will be accidental victims.
>The worm initially spreads indiscriminately...
And most of the rest of the article. They made a worm that was only supposed to activate in incredibly specific circumstances, but spread indiscriminately to find that specific circumstance.
edit oh, and let's not forget those extremely specific circumstances still seemed to have hit a thousand other targets accidentally, which is the exact thing you said isn't ever going to happen.
There is an element of you are going after a very specific system or set of systems but they are all air gapped and you need to find a way to get your malware onto those systems somehow.
This part is actually how you describe it more or less. The plan was basically: spread everywhere you can but only do so if you are confident for some reason that you’re on a system belonging to the target country (I.e Iran) and if anyone ever sticks in a USB key to one of those systems you should take that as an opportunity to cross the air gap because people are sloppy and mistakes happen.
So in that sense, yeah it is somewhat true, that’s literally the strategy they used to get where they needed to go. However, the controls they had around it I think were also reasonable. I fully expect the NSA and Mossad (who would later somewhat fuck up the operation) to be doing exactly that and I think it’s consistent with their job.
The second part is the “actually malicious” payload. That had an entirely different set of checks and balances in place to make sure it wasn’t fucking up unreleated systems along the way but just using them as a launch point.
That full context I think still firmly fits my original definition that unless you’re actively on a target list for some reason you have no reason to view NSA malware as something you should have on your threat model. Not sure if you agree or not?
And that's forgetting that no matter how specific the NSA supposedly was, after launching their malware other groups will copy it, so an AV provider will need to view NSA malware as a threat model.
Plus, your original definition assumes the NSA either doesn't make mistakes, or an AV company shouldn't try to clean up their mistakes, both of which are nonsense
1000s of computers did indeed have malware on them. That’s true.
The malware was intentionally designed to do nothing other than trying to cross the airgap to where it was actively trying to go.
This is the entire reason I just explained why when you say “stuxnet infected thousands of machines” that you’re actually talking about a couple of different things here as though they were one.
The nuance in this particular debate matters quite a lot and I don’t think ignoring it for the sake of convenience is helpful.
If it only damaged the one system it was supposed to be targeting, why would we ever have heard of it?
I.e here is an example of what we consider to be legitimate use to compare and contrast with say North Korea’s Sony hack.
But also it lost a lot of its value as a secret once it was already done.
These rogue pieces of software do occasionally escape their intended target and do measurable damage to infrastructure. Many such cases.
The idea that "I don't need quality antivirus, because I have nothing to fear from such threats" has similar energy to "I don't care about my privacy, I have nothing to hide."
Malware is a real thing that people need to worry about.
Being targeted by the NSA doesn’t happen by mistake.
As some others have pointed out, there was an incident a few years ago where NSA lost a whole bunch of their malware thanks to I believe again it was a leaker in that case (Joshua Schulte if I remember correctly).
That did in turn end up getting used in a North Korean operation shortly thereafter which by contrast didn’t seem to have good controls in place and absolutely spread like wild fire.
But as far as I know it happened once, was an anomaly and just isn’t a thing that is likely to ever impact you which is why I’m making the argument that what the OP was saying that Kaspersky is the best anti virus just isn’t a good argument and people shouldn’t feel like they are missing out on anything in this instance.
Let me make another point.
Having access to multiple computer security firms is good, and the services Kaspersky provides do not end with their antivirus software. Security firms regularly publish their work and work with each other.
Perhaps I'm wrong here, but if memory serves, Kaspersky was one of the first firms to detect stuxnet and publish it's structure (I could be wrong here, trust but verify). Using this data, Symantec was able to begin studying the virus as well.
Walling off security research will lead to more parallel research, rather than international collaboration in computer security. Whether or not this is a good or a bad thing is arguable - but I believe international efforts are a net good while the Internet is an international affair.
Who knows, siloing of development might allow creativity and novel solutions in computer security like what happened with the USA/antibiotics and the USSR/phage theory - but I might be coping here.
Of course not. Only the criminals are punished. /s
also, it's not like the american-based companies will not do that with european data to america. :D
It'd be pretty easy to see if the software was missing Russian state malware both by inspecting the code, or simply installing it on a test machine and then running the scan. If this were the case, it's highly likely the news would be repeating it 24/7. So it seems safe to assume it's doing its job well.
[1] - https://www.kaspersky.com/about/press-releases/2020_kaspersk...
So what, exactly, is this press release supposed to prove?
And they asked for it just to be sure. /s
Without press freedom you don’t have free speech.
But yeah, it is a pretty bad comparison.
Banning foreign agents from a hostile regime in a time of war is not an attack on free speech. Kapersky is free to speak -- and he has, through public statements from his company. He is not free to do business with the Western world while living in a sanctioned country.
The number of times I've seen HN posters rejoice that people are not allowed to even communicate their political ideas because they are x-ist (it's a private company, bigot!) is too many to count. But the minute there's an actual genocidal war being waged by one of the most wicked nations on earth, people are very concerned about the Constitutional right to commercially sell antivirus software from the enemy's borders. Absurd.
To be fair, western third parties like Japan refer to the conflict as the "Invasion of Ukraine" (ウクライナ侵攻, ukuraina shinkou) and such.
Personally, I don't view this as a war because there was no formal declaration(s) of war to be seen anywhere before nor after the fact. War is an act of diplomacy, but what Russia has been doing is anything but.
See also: https://en.wikipedia.org/wiki/Mariupol_theatre_airstrike
Which was done (and, judging by the choice of ordinance, signed off on at the highest levels) not despite the fact that they knew there were children present at the carefully selected target; but because of it.
Regardless, Kapersky has plenty of money. If he doesn't support his nation's mass butchering of its neighbors he could easily buy citizenship in a country like Nevis, which puts it up for sale, denounce Putin, and abandon the Russian state. As it is, he is under the control of the FSB, and every dollar he earns generates demand for the ruble and tax revenue for the Russian state.
As much as diplomacy tends to be derided (and I'm certainly among those detractors), I also want to believe diplomacy still fucking means something for the sake of a civilized world.
Yes of course, and I'm not defending it, but it's still totally different in both scale and nature from what Russia is doing in Ukraine.
At least on surface appearances the US isn't taking control of the oil and selling it on the market (the oil is owned and marketed by the autonomous Kurdish government which runs the region).
And unlike Russia, the US certainly isn't seeking to permanent annex the region.
Because if Americans kill people, it is an act of justice, of spreading democracy (see also Irak, Afganistan, Yemen, various Latin American and African countries) not a killing. /s
But the U.S. operation involves less than 1 percent as many ground troops as Russia has deployed in Ukraine.
And last I checked, hasn't resulted in entire cities razed to the ground, and 15 percent of the population displaced.
I don't understand what benefit for diplomacy is this insistence that a war without a declaration isn't a war.
If it helps clarify things for you: most wars are deeply psychological in nature; and part of how they operate is by telling people (both the perpetrators and victims) that it's not really a "war". But rather a "special operation". They will even lie right to your face, and tell you that they are there to "demilitarize" the area and to bring peace. And that to the extent that it might look like a war -- that will insist that they had no choice; it was forced on them; the other side could stop it at any time if they wanted to.
Proper declarations do have significance of course; but they are always secondary to the basic facts of what's happening on the ground.
No, what's going on in Ukraine is even worse; it's unadulterated, uncivilized baboonery that should be an embarassment to all of humanity. Russia for doing it, and the rest of us all for failing to stop it (and so far putting an end to it).
It's the 21st motherfucking century and we can't even try to be civilized about brutally murdering each other en masse. Fucking hell, man.
But I see the overall point you're making, and I've also taken the "Can we even call it a war?" perspective at times, not because of the lack of a proper declaration (which I see as insignificant), but from the sheer pointless, murderous insanity of it all.
A side note: It just so happens that the romanized version of the Russian acronym for SMO is SVO (that is, SVO = СВО and perhaps F meant "full"?) so I was temporarily confused by what you meant with that acronym. I now do see what you meant by it. But at the moment my mind was focused on the pointless insanity that we both agree is the situation in Ukraine, not math.
No, this is an unnecessary formalism. Why not define war by what is actually happening (large scale armed conflict between states or other large groups) rather than by mere words uttered by somebody?
> In his study Hostilities without Declaration of War (1883), the British scholar John Frederick Maurice showed that between 1700 and 1870 war was declared in only 10 cases, while in another 107 cases war was waged without such declaration (these figures include only wars waged in Europe and between European states and the United States, not including colonial wars in Africa and Asia).
See also e.g. Red Cross: https://casebook.icrc.org/a_to_z/glossary/declaration-war
> The principle of a compulsory declaration of war has now fallen into disuse. In practice and under customary law, a declaration of war is no longer necessary for a state of war to exist; it suffices for one of the parties to make its intentions clear by actually commencing hostilities. Similarly, a formal declaration of war is not necessary for the application of international humanitarian law.
Was it ever? Under customary law, a state of war exists between any two parties by default. What needs to be declared is peace, which is why so many ancient peace treaties survive.
And the regular citizens that I interacted with are similar, for example a guy threaten me " my cousin fought in such and such Ruzzian war, he is not with the mafia and drawn a guy because X, do you want to have my cousin kill you? "
No sane goverment should run Ruzziancontrol software, even if the guy is a saint(we know is a KGB close friend ) the KGB goons will force him to install spuyweare in an update.
And what? People should say only what you want to hear?
Ban anti-virus software.
Some more discussion: https://news.ycombinator.com/item?id=40743524
Good riddance. EU should do the same.
Or are there “good” intelligence officers and “bad”?
The moment some backdoor is discovered in Kaspersky, it is done as a product all over the world. That’s the best protection about any alleged government connections exploiting the software.
The notion of open market, competition, democracy is only exercised when it is your products that should undermine the locals.
The moment it is not, you start hearing stuff like “overcapacity” (what a nice term) of china manufacturing — what a hypocrisy.
As soon as US starts loosing the positions, it wriggles just as any “dictatorship” protecting its interest by quickly dismissing the free market as it needs.
What do you mean as "backdoor"? Any anti-virus software is a backdoor.
Anti-virus software is rootkit on your system.
It can literally upload any file on your disk to the cloud.
This is by design and this is why you dont want to run Russian state-controlled company software on your system.
> We fully believe that … the Russian government is either now using Kaspersky or certainly would be willing to use Kaspersky.
“Highly likely” is a shit of an argument that is exercised quite often lately.
See the problem: there is absolutely no way to tell whatever AV software uploading your sensetive documents to it's servers for legit reasons or because it's spying on you.
Windows Defender do have automatic sample submission, but according to documentation only automatically submit files that are "safe" to not no contain PII:
https://learn.microsoft.com/en-us/defender-endpoint/specify-...
It might request user approval to submit non-executables, but again we can't know when and why Microsoft might decide to override defaults. Technically data collection pipeline is here.
I suppose in theory it could contain something that exploits an ability to sidestep the firewall, but then you're in to conspiracy theory land.
Russia is the most sanctioned country in the world. That's economically bad for everyone; just less bad for the US than Russia. The argument that this is designed to help US companies is... crazy.
Russia is no longer part of open market and it's not a democracy. There is absolutely no reason to make business with any of companies based in there just like there is no reason to work with companies from North Korea.
Companies from Russia like Jetbrains that wanted to work on global market left the country, relocated their staff and closed offices. Kaspersky choose to stay so his company can now work for local market instead and might be sell some AV to North Korea.
What about abandoning elderly fathers and mothers, etc.? Or should they relocate too?
Or stay whenever you are and sell you services to markets of "friendly countries" like North Korea.
Crucial components in the security profession are trust, and managed risk. Companies that don't pass the sniff test are simply discriminated against - regardless of circumstances.
The US is looking out at the world again and trying to influence it. And the common man is bombarded with western military exceptionalism propaganda. Why would the USA allow any avenue for its currency to flow into a Russian firm? It was only a matter of time for something like this to occur.
Two questions:
1) What is open market for you? Does USA have an open market?
2) What is democracy for you? USA is democracy or just a shade of it to spread propaganda?
> Companies from Russia like Jetbrains that wanted to work on global market left the country
No, global market is not western market - they did it only to get access to western market because they have a lot of users there.
Yes.
For context, I'm not an American or European, and my home country is allied with Russia. That being said, the US is not just like the Russia, no matter how badly Putin wants the world to believe that.
In the current world diplomacy is a joke, countries and their diplomats are unable to find a peaceful solutions. People are dying on both sides ( Ukraine-Russia, Israel-Palestine, ... ) while the world watches.
The media also spread hateful propaganda on all sides of conflicts, politicians make hateful comments. Nobody cares.
For starters US hasn't razed any cities lately to later claim them as their own.
So what's your proposal for how they should do that?
In particular: precisely which of Putin's most recently dictated terms do you think they should force Ukraine to agree to -- in order obtain this "peace" that you say is easily available?
This is unfortunately not true. Maybe only in the West. Cisco has backdoors since years. Kaspersky just uncovered an Apple backdoor, that's why US is so upset.