15 ms·
Russian Hackers Stole NSA Data on U.S. Cyber Defense
- uptown 9y agoAccess via Facebook: https://www.facebook.com/flx/warn/?u=https%3A%2F%2Fwww.wsj.com%2Farticles%2Frussian-hackers-stole-nsa-data-on-u-s-cyber-defense-1507222108&h=ATOgadigjpkHQL03AMcyhCHrXLBfAd6WUqXLQPOYEGXvFHFBlJiM_ba_YOKYSbu9_fwXtiH4rp6UMVDCmBhGYYmznJjDRmdxS8a7eCA&_rdr https://www.facebook.com/flx/warn/?u=https%3A%2F%2Fwww.wsj.c... Access via Archive: https://archive.fo/szjBQ https://archive.fo/szjBQ
- strictnein 9y agoThanks! A note: go incognito if it doesn't work on its first try.
- el_duderino 9y agoAccess via Outline: https://outline.com/https://www.wsj.com/articles/russian-hackers-stole-nsa-data-on-u-s-cyber-defense-1507222108 https://outline.com/https://www.wsj.com/articles/russian-hac...
- NN88 9y agoTHEY EXPLOITED KASPERSKY TO DO IT. HOLY. SHIT. Full Text: http://archive.is/szjBQ http://archive.is/szjBQ
- 1001101 9y agoInteresting. After seeing the gloves come off in the last month or so, it hit me just this morning that one could make the case for it being a bad idea to have a system with root access to thousands of US systems in Russian jurisdiction.
- mattnewton 9y agoIt boggles my mind they don’t require source files for things running with administrative privledges on government computers, so they can audit it and then compile it themselves. Though in this case it wouldn’t have helped, because apparently the information was brought home to a personal computer.
- uptown 9y agoThat's actually a recent development: http://fortune.com/2017/07/02/kaspersky-source-code-inspection/ http://fortune.com/2017/07/02/kaspersky-source-code-inspecti...
- 1001101 9y agoWouldn't the source on such a system change daily? How do you keep up with updates?
- mattnewton 9y agoBy auditing the diffs daily? Code review but by someone on the US government’s payroll.
- strictnein 9y agoThe UK has a program that does just that, especially in regards to networking/telecom hardware and software from China.
- dralley 9y agoI believe the allegation isn't that Kasperky was used to exfiltrate the data, but that Kasperky is passing information about certain files on customer computers to Russian Intelligence. In this case, they believe the presence of NSA malware samples on the contractor's computer, detected by Kasperky, was used to target him.
- mhneu 9y agoEugene Kaspersky was trained by the FSB (formerly KGB). Here's a good article (by a Democratic senator) https://www.nytimes.com/2017/09/04/opinion/kapersky-russia-cybersecurity.html https://www.nytimes.com/2017/09/04/opinion/kapersky-russia-c... "That threat is posed by antivirus and security software products created by Kaspersky Lab, a Moscow-based company with extensive ties to Russian intelligence. To close this alarming national security vulnerability, I am advancing bipartisan legislation to prohibit the federal government from using Kaspersky Lab software."
- BoiledCabbage 9y agoI also believe that they actually know more than they are willing to quote in a paper. Likely Kaspersky was used to exfiltrate the data as well, but they aren't willing to say that. I don't have any evidence of this, but considering the closeness of Kaspersky to the govt, and the built in ability to directly upload files, it seems overkill to try to find a new exploit.
- tryingagainbro 9y agoNSA /CIA and our National Security is as secure as the weakest link. They need not be traitors, just people that got too complacent...while Russia never sleeps (Like NSA does when Russians and others screw up.) It isn't easy but if tens of thousands people have access to something, it's just a matter of time. And they need access "to connect the dots" so it's a losing game.
- vkou 9y ago> Russia never sleeps (Like NSA does when Russians and others screw up.) Do you have a number of reliable sources for this, or is it just unsubstantiated us-vs-them jingoism?
- tryingagainbro 9y agoDo you have a number of reliable sources for this You want a source to back up that Russia is always looking to hack us, and USA is always looking to hack the Russians?
- toomanyrichies 9y agoI believe the author is asking for a source for your claim that "Russia never sleeps but the NSA does". That seems like an apocryphal claim unless you have high-level knowledge of the inner workings of both Russia's and America's intelligence communities (and are willing to share it here).
- bllguo 9y agoHe explicitly quoted what he wanted sources for. Don't try to be cute. In other words, what makes you say the NSA is complacent and that Russia is ahead.
- tryingagainbro 9y agowhile Russia never sleeps (Like NSA does when Russians and others screw up.) Easy there...meant to say that NSA does the same, or never sleeps. I am 100% sure that NSA is extremely effective.
- iloveluce 9y agoI hope NSA is doing the same with Russian Cyber Defense systems. This is what NSA should be focused on and not on turning its eavesdropping capabilities towards the homeland. What if an adversary where to hack the NSA warehouses were all communications swept up by their eavesdropping efforts are stored?
- comicjk 9y agoI've been thinking about writing a spy thriller based on that premise, ever since the Snowden leaks. At this point I'd assign 30% probability that it's already happened.
- mtgx 9y agoThey've already stolen a bunch of NSA's spying and mass hacking tools, so we're probably years away until stored data is stolen, too, if we'll even find out about it.
- Synaesthesia 9y agoOf course they are. They have teams of hackers and security experts working on offensive and defensive cyberwarfare. Re: Spying on the homeland, governments generally regard the domestic population as a threat and and enemy.
- white-flame 9y ago> This is what NSA should be focused on and not on turning its eavesdropping capabilities towards the homeland. Spying on Americans traditionally would be done by our allies, so we can trade info with them and have it all be "legal." The NSA is simply optimizing that chain away. :-P
- austincheney 9y agoAnother damn NSA contractor took confidential information home. Epic fail.
- mtgx 9y agoIt's of their own doing: https://www.salon.com/2013/06/11/500000_contractors_can_access_nsa_data_hoards/ https://www.salon.com/2013/06/11/500000_contractors_can_acce... Also, I believe I read a recent article about them allowing even more private companies access to this stuff, but I can't find a link right now.
- austincheney 9y agoI had trouble taking that article seriously. It was really preachy and everybody but Snowden is apparently a mindless idiot.
- mhneu 9y agoIt's partially George Bush's doing - he put a rule into place saying the government had to hire more contractors. Fits with the GOP plans to weaken the govt to enable tax cuts for the wealthy, but the increasing use of contractors has been bad for security. Full time federal employees take a different oath and generally feel more loyalty to the agency.
- 23443463453 9y agoIt does way beyond that. The origins of today's symptoms lie in the corporate elite turning the USA into a kind of private equity opportunity starting in roughly the late 60s. Ever since and with ever increasingly compounding effects and impact, the USA's capacity across all aspects has been syphoned off and drained. Worse yet, with the H1B program in the 1990s as a significant milestone or inflection point, we even totally capitulated on the desire to educate and train our own domestic capacity and population as the corporate entities draining the USA and it's people of their resources were more interested in short term gains, regardless of the consequences and long term impact. With the rise of H1Bs and other less notable laws and policies only compounding the situation, all efforts to educate the "worker of the future" was little more than lip service to placate various anxious parties as the syphoning by the corporate elite continued. Now we are left in a country and world where we have imported foreigners with foreign ideologies, interests, and loyalties, largely infected with various ideologically subversive communist memes (in a literal sense) the Soviets spread as psychological warfare during the cold war without their hosts even knowing it; who are not only taking jobs from actual invested, patriotic Americans who's ancestors built the country, but being given jobs in government through another pernicious systemic vulnerability, affirmative action that prioritizes the creation of a fantastical inverse master race planned society through "diversity", at the expense of merit, skill, and ability. It's kind of the classical mercenary problem of yesteryear. See the latter stages of the Roman Empire for details.
- mozumder 9y ago"An NSA contractor brought home documents about U.S. offensive cyber capabilities. He used Kaspersky on his home computer. Russian government hackers stole the documents." https://twitter.com/ericgeller/status/915983591737319427 https://twitter.com/ericgeller/status/915983591737319427 So, yah, avoid Kaspersky AV software.
- keda 9y agoFunny how this Cybersecurity reporter publish his PGP key using unsecured protocol. http://www.ericjgeller.com/pgp_ejg.txt http://www.ericjgeller.com/pgp_ejg.txt
- strictnein 9y agoUhmm... that's a public key. So it doesn't matter. He could put it on a billboard in Times Square.
- tlrobinson 9y agoI believe keda's point is it's served over HTTP not HTTPS so there's no way to verify you're not being MITM'd when looking at it. (A possible workaround is to check via multiple connections, check Google's cache, etc)
- strictnein 9y agoI mean, sure, but if you're sending him a PGP encrypted message, and his public key was messed with, the end result would just be his inability to open the message. I think his actual point was to try and discredit the messenger.
- tlrobinson 9y agoThe attacker would then be able to read your encrypted messsage (and possibly re-encrypt it with the original key before forwarding it) Also, PGP keys may also be used to sign software or other public messages (not a typical use-case for journalists, though)
- runesoerensen 9y agoKaspersky preempting (presumably) this story: "New conspiracy theory, anon sources media story coming. Note we make no apologies for being aggressive in the battle against cyberthreats" https://twitter.com/e_kaspersky/status/915946040561487875 https://twitter.com/e_kaspersky/status/915946040561487875 Edit: Kaspersky press release https://usa.kaspersky.com/about/press-releases/2017_kaspersky-lab-response-to-the-alleged-incident-reported-by-the-wall-street-journal-in-an-article-published-on-october-5-2017 https://usa.kaspersky.com/about/press-releases/2017_kaspersk...
- deleted 9y ago[deleted]
- tlrobinson 9y agoHeh, an extreme interpretation of that statement could be that Kaspersky considers the NSA to be a "cyberthreat"...
- benmowa 9y agowell.... https://en.wikipedia.org/wiki/Clipper_chip https://en.wikipedia.org/wiki/Clipper_chip
- thephyber 9y agoJacob Applebaum publicly claimed (at the Chaos Computer Club, Germany, in the mid-2010s) that the Five Eyes and other intelligence services, for better or worse, attack employees of network providers, SaaS providers, and likely native software providers. It's not clear to me if it matters what country they are working from. If the NSA has a credible threat in the USA, they can be authorized to assist with domestic intelligence services to infiltrate services required to get their job done. One specific attack he claimed happened was a MITM of LinkedIn connections at foreign ISPs. I don't think it's a stretch to call them a "cyberthreat", especially if you are a Russian citizen or are trying to secure computer systems outside of the USA (I'm giving Kaspersky a generous benefit of the doubt).
- 9y ago
- ericfrederich 9y agoThis came up in congress a couple weeks ago didn't it? I think Rubio had mentioned Kapersky it knowing that it was a public hearing... some speculated that this was perhaps because he was privy to some classified things he couldn't say publicly but wanted to get the word out that they can't be trusted.
- 086421357909764 9y agoThere's always been a strong narrative, but for a government to call out another commercial entity and or government for spying is a dangerous game and only played when it's a big enough issue. It's all politics, they're spying, we're spying, it's when that crosses the line and we need to slap hands that matters. Further the public disclosure of facts to support are risky in that they can give away, tools, capabilities, or accesses that may be unknown to the foreign actors. For it to hit the news and the government to ban it, took many years of balancing and finally something internal broke the camels back so to speak. I'm not sure if this was it, but I'm going to go out on a limb and say it's probably not an isolated case.
- igivanov 9y agoNo confirmation from the NSA, only "leaks" from anonymous "multiple people with knowledge of the matter." How do we know it's not another piece of fake news riding the wave of "Russia did it"?
- mozumder 9y agoBecause you trust journalists to do their job in verifying sources, which maintains their credibility. I want you to think your cunning plan through. What do you think would happen if journalists actually lied?
- pdx 9y agoYou have GOT to be fucking kidding. Have you actually been asleep for the last 6 years?
- mozumder 9y agoWere you under the impression that credible journalists are in the business of "fake news"? I want you to think about what would happen if that were actually the case.
- beepboopbeep 9y agoYou're the only one in this thread that's incredulous about a major publication posting a researched article. Clearly we are all out to get you.
- jakelarkin 9y agohow Kaspersky was ever thought to be "okay" in the US enterprise/government market has always been perplexing to me. Antivirus, something which literally inspects all of your files and network activity, made in the country that's a hotbed of blackhat activity and home one of the most aggressive cyber-espionage militaries outside the US. yea okay great, sign me up.
- deleted 9y ago[deleted]
- joe_the_user 9y agoWell, at this point, which anti-virus product you use is gradually devolving to "which state do you want to spy on you?". And the problem is, the answer may not be "the state I live in", since that state is the most likely to tax and otherwise regulate you.
- lallysingh 9y agohttps://www.clamav.net/ https://www.clamav.net/ ?
- gooftop 9y agoIn this day and age of FUD, what are the odds that said open source software has a vulnerability or malicious code inserted by some state actor (ours included)?
- lallysingh 9y agoProbably low.
- dreamfactored 9y agoMaybe rather than playing cat and mouse over taxes, a person who avoids taxes should be more fairly and simply designated as a foreign national or stateless?
- 9y ago
- pasbesoin 9y agoSorry. I have a point -- towards the end. Even if it's one that gets me downvoted: In my personal life, I've been wrestling with the decision to "do the right thing" and, for example, pay for digital media I consume. Help a friend in need, who doesn't really reciprocate (because, "the children", among other things). Purchase the health care insurance that takes away money I could otherwise spend on immediate treatment. In each area, I've felt increasingly screwed over. Shrinking catalogs, and money I paid spent on lawyers ensuring ever-greater rent-seeking as opposed to actual access to content. My friend's health on the rebound, while mine has suffered, including from the depression induced by their abandonment of our friendship once I was, apparently, no longer necessary. A health care system that keeps jacking prices and trying also by legislative manipulation to push me out the door of coverage, regardless of my best efforts to work with it. In all these matters, I'm coming to think that part of my failed response comes down to a simple matter: Don't pay. Stop paying the very systems and people that or who are screwing you over. So, here we have the NSA, that is (who are) ever more showing themselves to be incompetent with regard to what we hope they would accomplish, and outright aggressive and abusive with regard to us and matters that we consider commercial contract law, not their business, distracting rather than helpful, etc. Helping prop up private IP rights and rent-seeking. Domestic spying. Accumulating so much data on everything that they can't see the needle for the haystack -- so, grow the haystack! I'm hardly one of these bullsh-t "Conservative" (that's with a big "C", to differentiate from the actual noun/adjective, "conservative"), "shrink/starve the government" types. Government plays an essential role: It is the definition of our collective organization and governance. But in some areas, I really want to say, let's simply stop paying for this shit. Because when we pay for it, we only make it stronger. Not the effective governance we aspire to. Instead, this incompetence that also threatens aggression against its own society.
- indubitable 9y agoI find these allegations are deserving of some scrutiny. The entire story is quite bizarre when you begin to consider it. The NSA is apparently leaking like a broken pipe with this information. And it's peculiar because this is information that makes our intelligence agencies look completely inept. That is a very good thing if this story is fake, but a very bad thing if its true. It is stupefying that NSA contractors/employees would be genuinely copying classified information that is heavily related to national security, and then just loading it up on their personal Windows PC with no apparent encryption or access controls. For instance why in the world wouldn't they have OS level software restricting read access of a certain secure partition (or removable media) to a specific whitelist of processes? Or why wouldn't they use an airgapped machine? Then there are issues like the NSA being so anxious and happy to leak this information, and then them indirectly 'wink wink' confirming it publicly completely destroying the purpose of we don't comment on speculation --- when you start commenting on certain speculation, it indirectly says something about other speculation that you actually choose not to comment on. They're also seemingly unconcerned that somebody is leaking information that, if true, shows the NSA to be incompetent and also exposes attack vectors for enemy actors. There are also things like Kaspersky previously volunteering to provide complete source access to the government. Our government declined the offer. How does this make sense? Since Iraq I have become much more critical of pretty much everything. Our media and our government lied to generate a case for war. And I feel lately that they are now trying to build a case for some sort of conflict, presumably cold, against Russia. Or at the minimum start Red Scare 3.0. I have no idea why they would want to do this, but I tend to abide Occam's razor, and this all being true requires a lot more effort than this just being "Yellowcake 2.0."
- 0xfeba 9y agoI'm so skeptical now of skeptical Russia posts. A 25 day old account who's first comment [0] was about media and divisiveness. 0 - https://news.ycombinator.com/item?id=15336362 https://news.ycombinator.com/item?id=15336362
- mythrwy 9y agoMaybe that's the first part of the evil plan? Make people see Russians everywhere. I try to look at content and don't care much who the poster might be. Because everyone has motive even if it's just boredom or attention.
- random023987 9y agoGovernment drone copies NSA malware onto a system with Kaspersky security software installed for the purpose of detecting malware. Brilliant
- NN88 9y agoPutin is screwed the minute Trump leaves.
- 52-6F-62 9y agoIs it just me, or is this possibly related to the Vault 7 materials on Wikileaks, and thus the WannaCry attacks that brought the NHS to its knees this past year?
- killjoywashere 9y agoI'm going to go out on a limb and propose a hypothesis: The DoD's hyper-innefficient contracting system rewards DC insiders and effectively limits the department's ability to invest where investment is needed while draining the public coffers of unfathomable amounts of money. The DoD's hyper-ineffective personnel system inhibits personal development while at the same time making it nearly impossible to move laterally within the organzation, thus preventing thousands of experts in many fields (that is, many thousands of experts) from self-organizing into effective functional units. These two issues have made the DoD ripe for attack in the digital domain, an area that has nothing to do with their other core missions areas which are all organized around delivering kinetic energy to adversaries.
- SomeStupidPoint 9y agoContracting instead of developing in-house capabilities is completely destroying the DoD and American military effectiveness. The corruption around that is posing a real, impactful threat to national security. Fuck these people and their "free market" lies as a cover for outright theft of public funds. It's not just in the cyber domain that this is a problem, but the cyber domain is one in which the corner-cutting, half-assed nature of the corruption is most visible because the damage is most easily exploited by foreign powers.
- rdtsc 9y agoWas selling to the DoD before and agree with you. We just sold a product but interacted with contractors and various agencies. It's a hot mess, the corruption, nepotism, stuff like request for quotes for a project and specs made to meet exactly only one vendor and nobody else and so on.
- zghst 9y agoThe power on the inside is more of a effective deterrent and great asset than a deficit for the DoD. Economically how it works is that the DoD secures assets and locations around the world relating to the means of production of consumer components. American interests, especially the interests of the American consumer are definitely protected and represented for. Where this model has failed for us is put a huge deficit in our self reliance with regards to consumer production. Due to globalization, American politicians have no urgent need to educate the workforce more than they already have, they can provide security and investment to produce a source of worldwide talent, all thanks to the contractors playing their crucial role in the ecosystem of American security. What people fail to understand is that no organization or system is perfect. The DoD isn't organized for the new kinds of warfare being performed. The main job of the DoD is to protect American interests abroad, not operate in the background on American soil against hundreds, thousands of nation-state and criminal organizations. The FBI does this job, they successfully work with hundreds of private contractors. You'd be surprised by the scale on which they are resourceful and helpful.
- codedokode 9y agoI remember that Kaspersky helped to investigate some of cyberattacks perfromed allegedly by western agencies. Could not these articles be a part of revenge campaign to punish them? And another thought, if we cannot trust foreign AV software, does it mean that every country must have at list one national AV product? Or maybe it would make sence to make some special API for AV software so that it can check files and processes but cannot send data to the Internet?
- dreamfactored 9y ago> if we cannot trust foreign AV software, does it mean that every country must have at list one national AV product That also goes for pretty much every online platform from search to shopping to social. N.B. The Russians and Chinese are already doing precisely this
- beagle3 9y agoAlso, every country needs their own operating system; and in fact, also CPU and fab facilities.
- mhkool 9y agoRemember the Chinese network equipment allegations? The agencies said hey had backdoors. That was never proven but what we know is that the agencies had access over nearly all Cisco equipment. Now Kaspersky is the next 'unsafe' non-American company... There are only allegations from an unreliable source: the agencies have lied regularly. I am convinced that there is an anti-Kaspersky campaign since the agencies 'like' the American antivirus vendors a lot more. I bet the agencies have ways to spy on users of American antivirus vendors.
- willstrafach 9y ago> Remember the Chinese network equipment allegations? The agencies said hey had backdoors. That was never proven but what we know is that the agencies had access over nearly all Cisco equipment. They had exploits for both Cisco and Huawei actually. > There are only allegations from an unreliable source: the agencies have lied regularly. I don't recall that happening, do you have a few specific examples? > I am convinced that there is an anti-Kaspersky campaign since the agencies 'like' the American antivirus vendors a lot more. I bet the agencies have ways to spy on users of American antivirus vendors. Sounds like a very bold claim to make, but no substantiation.
- deleted 9y ago[deleted]
- campuscodi 9y agoHas anyone else noticed the influx of anti-Russia articles on the WSJ lately?
- dmix 9y agoIf the article contains the words 'cyber' you can pretty much be assured they've got plenty of 'authoritative' government sources who are inherently anti-Russian. From my experience it's certainly not new, even for WSJ. I've read plenty of non-fiction espionage books and it's a safe bet to expect the American ones to be dripping with Russian paranoia. Warranted or not. They never gave that up after the cold-war, unlike the public. And non-technical journalists rely heavily on their sources expertise, more so than most subjects. I prefer getting my infosec news from infosec people: https://twitter.com/matthew_d_green/status/916016499747205120 https://twitter.com/matthew_d_green/status/91601649974720512...
- peoplewindow 9y agoWSJ and any other media outlet aligned with the globalist, pro-Clinton, pro-EU world view. I knew the whole "Putin ate my election" angle was getting completely out of control when I started seeing people claim, with a straight face, that Russian interference was somehow behind Brexit. It's the same people making the same tenuous claims about any political change they hate - it's not legitimate because anyone who disagrees with me has been brainwashed by tweets.
- dragonwriter 9y ago> WSJ and any other media outlet aligned with the globalist, pro-Clinton No News Corp outlet is aligned with pro-Clinton anything.
- blackflame7000 9y agoDoes anyone really think the NSA isn't trying to hack the Kremlin as well?
- deeth_starr_v 9y agoCount me as a skeptic on this one. NSA employee/contractor takes home classified docs and I am assuming hacking tools, Kaspersky detects the hacking tools and uploads them to Kaspersky, Kaspersky determines it's NSA tools, notifies the Russian government, Russian government hacks the computer and gets all files. Then somehow NSA is able to deduce all this information. I'm not saying this is not possible, but I think their level of conviction on this is too high. A home computer is not going to have access logs. So let's say they see NSA malware in the Kaspersky quarantine folder, and there is also other malware on the computer. They of course have to assume the worst, that Russia got all the files. But they are making a couple big logical jumps without proof. This article is just to sketchy on details for me to take it credibly. Makes me think of the claim Cuba is using some kind of new radio brain weapon on US consulate workers in Cuba.
- cl289 9y agoWWCS (What would Clapper Say): Nov 15, 2017, to Congress: "I can categorically deny that there were any leaks of this nature during my tenure as Director of National Intelligence." June 22, 2020: "Well, yes, I did say at the time that I denied it. But I said 'categorically denied'- that is to say, under certain conditions, or categories, this could be denied. That is what I meant and I stand by that. I also used the word 'can,' which is a sort of conditional; look it up in your grammar books. I did not say 'I do deny,' but 'I can deny.' There are conditions that might allow one to deny this assertion: i.e. what exactly is a Russian, what does it mean to leak, or to have leaked, or to have an inadvertant leak. That is what I meant and I stand by that also."
- TempleOS 9y agocia niggers are in denial on God and going to get fuck beat out of them tests Gareth muezzins pauperizing toilet retract commercializes saltier breakthrough's barbed unifying Lemuria's shed's buffer recovery Transylvania scandals analyst undersign sugar's irony correspondence Micky's fiberglass untangles mentality Stengel's fuck's plumps soliloquize firearms holstering
- jpelecanos 9y agoFor whom do those hackers specifically work for (SVR, GRU, or Spetssvyaz)?
- open_bear 9y agoKGB, obviously.