Antivirus Companies Shouldn’t Have Hidden What They Knew About Regin
technologyreview.com
technologyreview.com
Sure, they could just go ahead and disclose it against the customers express wishes, but how many would hire their services in the future if there's no expectation of customer confidentiality?
Edit: There likely is an NDA in place even before externals are allowed in, so breaching it might invite some additional problems than just image issues.
But I don't know this particular contract, so that may not be in play.
EDIT: also, it's not like antivirus companies publicise everything they do. From what I've seen (admittedly not much, so maybe I'm wrong) most releases are simply summarised as "added protection against 100 new threats".
When they 'release a new version', that behaviour can be spotted by the AV companies, and that new version can then be added to the signature list as well.
For Prins, the reason is completely different.
"We didn't want to interfere with NSA/GCHQ operations," he told Mashable, explaining that everyone seemed to be waiting for someone else to disclose details of Regin first, not wanting to impede legitimate operations related to "global security."
You have to carefully monitor and learn everything you can about the malicious actor, and discover all the infections. Then produce a plan to remove it and prevent further infection. This is all implemented at a single instant.
However, it doesn't end there, you then have to monitor very carefully to see if it comes back. If this can all be done in secret it is much easier, especially if the malicious actor doesn't know you know they are there.
If you immediately reported everything you knew it would greatly assist the malicious actor - keeping it secret is part of trying to stay ahead in the game. Even after the first incident keeping it secret helps with future incidents.
And the only way to clean up a compromised computer is a full reinstall. You can't possibly know what has happened on the compromised computer during the compromise. This is what the desktop support jockeys and most companies get wrong - obviously it's probably because of the cost associated with a full reinstall, but it doesn't make it any less valid. If it costs too much, companies should then focus on preventing machines getting compromised in the first place.
Think about it, if I ask you to hand over your laptop for say, an hour, during which I have completely free reign over it, can you tell me everything I've done during that hour and all the backdoors installed, if any?
And to nitpick, obviously these days not even a full reinstall might do it when there's BIOS viruses and even hard drive firmwares can be compromised etc. of course.
As long as the attacker has at least one route into the organization at anyone time, the possibility of reinfection exists. So I guess it's wise to take a coordinated approach.
So, it means what you mean by 'externally' and how sophisticated you expect the malware to be.
After you get the infected machine, you pull out the drive and scan it externally, looking for bad hashes and files that shouldn't be there.
Yes, I can. Read up on modern digital forensics. Everything you do on a machine leaves a trace and there are ways to recover those traces and put together exactly what you did. That is exactly what Incident Response/Digital Forensics Firms do. An IR firm would never tell you to just reimage a machine when you're dealing with an advanced attacker. They'd want to go through, use the tools they have to identify exactly what happened on the machine and what other machines were compromised before they even started talking remediation. Wiping the one machine that you got an alert on would do absolutely nothing to solve the problem.
As a followup, both you and GP should read up on digital forensics from someplace OTHER than their marketing material...
> An IR firm would never tell you to just reimage a machine when you're dealing with an advanced attacker. They'd want to go through, use the tools they have to identify exactly what happened on the machine
Yes, I was talking more in the run-of-the-mill case sense, not regarding thorough forensic investigations. If you're actually going to investigate the incident deeper, you should at least get memory dumps, process dumps and an image of the machine and such. In my experience though, at most companies the SOP is just monitoring standard antivirus stuff and then when an infection comes up, it either gets automatically cleaned or someone goes over and fixes it with a manual scan or whatever. Which is completely inadequate.
Even working within the system, I'd say many attackers can remove traces such that many investigators won't find them, by doing things like deleting created logs, restoring file metadata to its original state, and writing over the erased evidence multiple times. (This perhaps assumes root access and a consumer-grade OS in default configuration.) It might lead to a suspicious state where the system has been running for hours with no artifacts that would routinely be left, but the investigator might not be able to determine much of what was done. It might be as simple as using a browser the investigators don't check: http://www.cbsnews.com/news/casey-anthony-detectives-overloo...
edit: clarification
To borrow a phrase from the /g/ community, I run Common Sense 2014 platinum edition. I.e. I don't download stuff from sketchy websites in general, I don't click email attachments, I don't use the Java web plugin, I do use things like Adblock and Noscript, etc.
If I do end up with a possibly suspicious file it gets sent off to a multi-scanner environment like VirusTotal or Jotti where I can get about 30 different opinions simultaneously.
The last few infections I've gotten were due to doing something boneheaded. Running something from a torrent without checking it first, or turning my browser security off temporarily and forgetting to reenable it.
However, I'd also run EMET to make it a bit harder for an exploit getting past NoScript to operate correctly.
I know, security is all about layers, but the usability and performance tradeoff gained for this paper tiger protection is not worth it, in my mind.
http://www.av-test.org/en/antivirus/home-windows/windows-7/
http://www.av-test.org/en/antivirus/home-windows/windows-8/
How old is your PC that modern antivirus software noticeably slows it down?
On the other hand, my work laptop is Red Hat 6 and Linux, Mac, or Windows, we're required to run Symantec by corporate policy. Then again I work for a security company, so...
That's ridiculous. It has been a hell of a long time since antivirus applications affected the performance of a machine that way. The performance impact on any remotely modern machine is negligible.
And under no circumstance is it 'better off with the virus instead'.
Really, look at what they do. They pre-emptively scan every executable program you run at the least. Unless you're on an SSD, and probably not even then, this is a blocking operation that is impossible to not notice.
I think the main problem with antivirus on modern hardware is that commercial entities selling antivirus have to add bells and whistles. Few people would be willing to pay $x a year for a program they aren't even aware of running. So, that $x program makes sure you see it frequently by adding progress displays, toolbars, task bar items, etc. they also make sure they have stuff to report, even if that includes meaningless stuff such as registry keys on Windows. Detecting that meaningless stuff takes time, too.
I think you're spot on, but from the scope of a user who knows 90% of that stuff is BS, it's just another bullet point in the list of why I don't run AV software.
Earlier this year my Windows 7 machine with a Xeon W3565 (3.20 GHz) and 6GB RAM was slowing down noticeably every time Symantec Endpoint Protection 12 downloaded new definitions--something it did twice a day. I would consider this a reasonably powerful machine, and the slowdown had an effect on my ability to work.
Sense the tone. My tongue is clearly planted firmly in my cheek, and if you're too literal to recognise that, at least err on the side of not downvoting.
For the record, it's been about 4 years since I used antivirus software on Windows, maybe things have improved since then.
Do you have the benchmarks to support this claim? Unless things have improved considerably in the last year, simply doing a "git clone" took measurably longer even on a machine with an SSD. Microsoft Security Essentials had by far the lowest impact but it was still easily visible.
Keep in mind that when New York Times was hacked a while back that 50 kinds of malware was found, and only one of them was detected by multiple AV products.
So depending upon AV to protect you is fraught with peril.
Consider the possibility that adding AV to your system increases the attack surface. Does anyone remember the Michelangelo Virus from a while back? A well-known firm' AV software caused more damage than the virus itself. (It wiped out the boot sector.)
Don't count on AV to protect you.
I worked for 5 years in the trenches in the anti-malware industry and countless times I've seen antivirus software completely hose up computers and worse: having its own insecurity and hooks into the Windows API used directly to infect a system (I'm looking at you, AVG circa fall'09).
Most importantly, no antivirus seems to do a very good job of dealing with emerging threats and malware is rapidly getting more sophisticated than the AV vendors can cope with. The major problems these days all seem to come down to an insufficiently secured operating system.
The only real, effective antivirus is user education.
1. i.e. not Outlook managed by an enterprise IT department
As long as linux isn't too mainstream, it will be less a problem. But you could still use ClamAV if you share some files with other computers.
edit: Also, i'm not sure i agree with you that Windows being the most widely used OS is the reason for the proliferation of viruses for that platform. As i understand it (not wanting to start a flamewar here, i genuinely don't know), it also suffers from some poor security architecture -- but maybe my information is outdated. But sure, the fact that "everyone" uses it makes it a more valuable target, of course.
The single best advice to not getting infected is to not do stupid stuff.
As for Windows being unsafe, sure, it's easier to propagate stuff since you have root access. But like I said, viruses on OSX do exist.
I also stated i do not run external-facing services. That applies to the Samba example, too (although i was fibbing: i allow keypair-only login via sshd).
yes, that's what I meant.
I don't do much locally other than write code. I use Web IDE's, Web Editors, Online Markup, Stream via HTML5... Not much to download now-a-days.
[0] https://hn.algolia.com/?q=tptacek+antivirus#!/comment/foreve...
Obviously these companies failed miserably to meet any reasonable person's timeline of disclosure. One question is whether the extra time researching this malware reasonably would have produced additional worthwhile intelligence about its function and targets. If so, then the delay was "worthwhile". Another question is whether it's not better to simply release an incomplete picture to the security community (perhaps selectively) and let the larger hive mind go to work on finding and corroborating additional clues.
It seems like the firms chose the former; many HN readers would advocate the latter. So finally, the question remains whether such a forced disclosure would be perceived as an irresponsible "leak" based only upon the disagreement in methodology and interpretation of "responsible"? Would its withholding be considered likewise irresponsible? Can a single firm, a collection of firms, or the security research community at large meaningfully stay ahead of a dedicated state-funded attacker? (Probably, Probably, Probably not).
If a nation-state is producing malware, it logically will also be monitoring the channels of disclosure for evidence of its release and detection in the wild. But that's no reason to limit the resources being dedicated to protecting the public; it's egotism at best and collusion at worst.
Psychologists will tell you that you shouldn't put too much faith in what people tell you about their reasons. Both because people are bad at introspection and/or try to put a spin on things, and because for most things a single reason doesn't even exist. (See also "Why did you buy product X", a question subject to much study).
Frankly, I'm not sure how many of their clients (being one myself) care if they publicize anything, as long as they protect against it.
Well, that's a Catch-22 and a half if there ever was one. Absence of detection doesn't mean absence of malware, it just means you haven't found out how badly you've been infected. The paid-for guys are halfways in the pockets of people who've paid more and the free guys are lagging behind.
I'm very disappointed by Kaspersky : I chose them specifically because they were Russians, I though they would not be susceptible to NSA pressures.
At least, that's what I understand from "all the companies had added signatures for Regin to their detection database".