How Antivirus Companies Handle State-Sponsored Malware
schneier.com
schneier.com
Most of all I remember that the only company not willing to sit tight was FSecure. They contacted BMG Sony and where about to go public, when Mark Russinovich publicized this atrocity. At least that's how I recall it.
It's since then that I have zero faith in security software vendors.
http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t...
Until that policy changes at Microsoft, at least 90 percent of the PC users will never be truly safe.
We're not running out to exploit the vulnerability in our competitor's system. The NSA or other malicious actors may be, sure, but I have doubts that this is what Microsoft wants to have happen. The goal is to mitigate the risk while a patch is being made. Microsoft doesn't want their software to be exploited, period.
Not to mention COFEE [4] -- I wonder how many antivirus detect that, especially since its source code was leaked...
[1] http://technet.microsoft.com/en-us/security/dn467918
[2] http://www.zdnet.com/blog/security/microsoft-kicks-chinese-c...
[3] https://www.microsoft.com/en-us/sharedsource/default.aspx
[4] https://wikileaks.org/wiki/Microsoft_COFEE_(Computer_Online_...
Not sure if I'd trust these companies more or less than the signature based companies.
We have very good relations with both the FSB cybersecurity department and the Moscow police department. They know us. They know us as people who support them when they need it.
http://www.wired.com/dangerroom/2012/07/ff_kaspersky/all/
(edit:) and the FBI:
Даже США: мы периодически консультируем ФБР.
It's like asking a politician, "Have you ever been unfaithful to your wife?"
"What's that? No? Okay, well you heard the man. Time to move on."
Glad to here we're safe.
this sounds more like an assumption than reasoning. given all we know to date about the operations of the NSA and the CIA (they collaborate closely at times), we should not be so hasty in dismissing such an important topic.
>> Understanding that the companies could certainly lie, this is the response so far: no one has admitted to doing so.
well.. they wouldn't, would they.