Kaspersky Lab cybersecurity firm is hacked
bbc.com
bbc.com
We already know Duqu was made by the same people who made Stuxnet. We already know Stuxnet was made by the US and/or Isreal to hurt the Iranian nuclear program. So if they have strong evidence it was the same people... we know who those people are and we should just say their names.
But we don't actually have to speculate about what the silence of the american companies means: they are quite open about their policies: http://slashdot.org/story/01/11/28/173201/symantec-will-not-...
>Symantec chief researcher Eric Chien stated that provided a hypothetical keystroke logging tool was used only by the FBI, Symantec would avoid updating its antivirus tools to detect such a Trojan, echoing a similar stance Network Associates allegedly took with its McAfee anti-virus software earlier this week. 'If it was under the control of the FBI, with appropriate technical safeguards in place to prevent possible misuse, and nobody else used it -- we wouldn't detect it,' said Chien. 'However we would detect modified versions that might be used by hackers.
I'm sure this is no surprise to them.
That's the job of Western companies. Keeps everyone honest. Western companies have as much bias as anyone, they are just good at covering it up with rhetoric... and Americans are good at deluding themselves about their own bias and Nationalism which is no different from anyone else's.
> On balance, with the current regimes in those countries, I prefer the western alternative to these regimes. It's not as if they are equivalent just with a different opinion. I truly prefer my western govt's over Russia and China's.
I do too. However, no one is as clean, just, and fair as they make themselves out to be. Everyone who plays geopolitics is dirty as shit. I like my government because it treats me well enough, ask other people and they might not have the same opinions.
what a world we got ourselves into! :)
But here, the topic was very specific - to say that picking the lesser evil is a bad thing is actually, I'm sorry to say, spoiled. Being able to pick at all is a luxury, which some do not have to this day. And let's not even go into all the other problems we no longer face today, at least in large parts of the world.
That's not to say we don't have a tonne of work ahead of us. We probably always will. And criticism is essential in making progress. But just saying that "the world" has gone bad is not helpful criticism, it's defeatist. Because, what can we do if it has indeed gone bad? Let's not throw the baby out with the bathwater.
In all honesty, I still think that western security companies have less bias than those working in less free societies.
Kaspersky early detected, nailed, and exposed an advanced nation-state attack on its network.
BBC spin - "Kaspersky Lab cybersecurity firm is hacked"
Kaspersky is also much easier to control than most AV vendors, Eugene has often been quite positive about Russia spying on its citizens more aggressively than the US does, and he has deep connections with other powerful people of Russia.
The firmware exploits are part of the attack system with Duqu 2.0, right?
[0] http://www.mcafee.com/us/security-awareness/articles/mcafee-...
[1] https://news.ycombinator.com/item?id=9685829
[2] http://www.kaspersky.com/about/news/virus/2015/equation-grou...
I'm wondering how lateral movement to non-Windows machines would have been accomplished.
[0] https://securelist.com/files/2015/06/The_Mystery_of_Duqu_2_0...
Alternatively, it could be a way of getting at the company's data or even to instigate a thorough review of their platform from the client's perspective. There's a lot of subtle information in the Kaspersky report that might be interesting to intelligence services: - Simultaneous Duqu & Equation Group infection of one victim - Feature coverage (and those omitted, like other payloads) - Red herrings detected/ignored; strings, faked compile timestamps - Noticed misspelling of "Excceeded" & lack of other linguistic errors
Kaspersky mulled this issue:
"So the targeting of security companies indicates that either they are very confident they won't get caught, or perhaps they don't care much if they are discovered and exposed. By targeting Kaspersky Lab, the Duqu attackers have probably taken a huge bet hoping they’d remain undiscovered; and lost."
However they also conceded that they aren't sure:
"The exact reason why Kaspersky Lab was targeted is still not clear – although the attackers did seem to focus on obtaining information about Kaspersky's future technologies, Secure OS, anti-APT solutions, KSN and APT research."
https://securelist.com/files/2015/06/The_Mystery_of_Duqu_2_0...
It sucks that it's so hard to trust anybody's software (or hardware) today.
The obvious distinctions that spring to my (uninformed) mind are: active (mitm, injection) vs passive (snooping, traffic analysis), targeted/opportunistic (maybe insider/outsider too?), and perhaps level of available resources (on the s'kiddie - lone hacker - collective - governmental spectrum, or something)
I guess the biggest problem with not having a coherent threat model is that you can end up putting too much effort into the wrong things and have a false confidence in your security. Weakest links, and all that.
Spoofing Spoofing is attempting to gain access to a system by using a false identity. This can be accomplished using stolen user credentials or a false IP address. After the attacker successfully gains access as a legitimate user or host, elevation of privileges or abuse using authorization can begin.
Tampering Tampering is the unauthorized modification of data, for example as it flows over a network between two computers.
Repudiation Repudiation is the ability of users (legitimate or otherwise) to deny that they performed specific actions or transactions. Without adequate auditing, repudiation attacks are difficult to prove.
Information disclosure Information disclosure is the unwanted exposure of private data. For example, a user views the contents of a table or file he or she is not authorized to open, or monitors data passed in plaintext over a network. Some examples of information disclosure vulnerabilities include the use of hidden form fields, comments embedded in Web pages that contain database connection strings and connection details, and weak exception handling that can lead to internal system level details being revealed to the client. Any of this information can be very useful to the attacker.
Denial of service Denial of service is the process of making a system or application unavailable. For example, a denial of service attack might be accomplished by bombarding a server with requests to consume all available system resources or by passing it malformed input data that can crash an application process.
Elevation of privilege Elevation of privilege occurs when a user with limited privileges assumes the identity of a privileged user to gain privileged access to an application. For example, an attacker with limited privileges might elevate his or her privilege level to compromise and take control of a highly privileged and trusted process or account.
They use the DREAD model to calculate threat impact (risk). You can get the risk rating for a given threat by asking the following questions:
Damage potential How great is the damage if the vulnerability is exploited?
Reproducibility How easy is it to reproduce the attack?
Exploitability How easy is it to launch an attack?
Affected users As a rough percentage, how many users are affected?
Discoverability How easy is it to find the vulnerability?
Therese's more detail in chapter 3 [1] (threat modelling) of the book Improving Web Application Security: Threats and Countermeasures [2] Note the book was published 12 years ago.
[1] https://msdn.microsoft.com/en-us/library/ff648644.aspx#c0361...
Your AV company's infrastructure is probably a lot more secure than the infrastructure of browser plugins you use and games you play.
But we don't. Our workstations are actually fairly dumb in this regard. Why is that?
Note: Newer Windows an Mac systems might have this with their stores, I don't know. But a store isn't a requirement for this, so why have we had to wait so long?
Well I'm not a security expert and I'm using Linux, so I don't use a Windows antivirus obviously. A quick test trying to download free or trial Windows antivirus software (I'm not willing to pay for this simple experiment):
Kaspersky:
- google Kaspersky
- google result leads to http site, all the way to the download of the trial version it's http (I'm sure at least 80% of users don't notice this)
- try to type in manually https://www.kaspersky.com
- it redirects to http://www.kaspersky.com !!!!
Ok let's try Avast, it's popular, isn't it? - ok it's all https, http redirects to https, it could even have HSTS, didn't check.
- download links to http CNET site ...
- I have to allow half the World's third party js to get to the download.
- It's of course http,
- Manually rewrite it to https (not straightforward, it's behind a redirection), invalid certificate (issued to a248.e.akamai.net instead of software-files-a.cnet.com
- Its installer is probably loaded with CNET crapware anyway
Downloading Avira worked fine though, I only tried these three. These companies are supposed to be security vendors, this is freaking ridiculous.Certainly not everyone will do this. Although it is probably no longer considered part of the maniac fringe, I don't think it's going to be mainstream any time soon. However, the benefits are not imaginary.