6 ms·
Perhaps he/she had the data on a SAN while performing development from a more “secure” computer and one of his personal computers with AV installed was connecte
by joewee 9y ago
Perhaps he/she had the data on a SAN while performing development from a more “secure” computer and one of his personal computers with AV installed was connected to the same SAN. A likely scenario as far as scenarios go.
- devoply 9y agoOne other possibility is that Kaspersky stole nothing, that it found the malware on computers it was tasked with protecting. And one should wonder did they add signatures to their A/V product to find and protect against this malware or not?
- tptacek 9y agoNYT: Israeli intelligence officers informed the N.S.A. that in the course of their Kaspersky hack, they uncovered evidence that Russian government hackers were using Kaspersky’s access to aggressively scan for American government classified programs, and pulling any findings back to Russian intelligence systems. They provided their N.S.A. counterparts with solid evidence of the Kremlin campaign in the form of screenshots and other documentation, according to the people briefed on the events. As reported, this isn't incidental collection.
- indubitable 9y agoThe thing I don't understand about allegations like this is that, if true, why in the world did the US not take up Kaspersky on its offer of complete source access? Scans are executed client side using client side heuristics. And so what is or is not sent back would be contained within the client. It could be trivially verified that the source code they proffered compiles to the product at the time. And so it would also contain clear evidence whether or not the company's product was collecting and reporting data on software/documents/etc outside the nominal domain of its purpose.
- tptacek 9y agoYou need more than the source; you need the selector/signature configuration at all times the program was running, and the total state of every update ever applied to every running instance of the software. The US already has Kaspersky's source.
- seabird 9y agoThat paragraph reeks of either journalistic license or a journalist who doesn't seem to understand what antivirus does. Every antivirus program aggressively scans for malicious programs and sends them back to the security firm for inspection and creation of fingerprints. If the collection wasn't incidental, what mechanism could the FSB exploit to non-naively identify tools that it didn't already have, and flag them for retrieval?
- tptacek 9y agoYour comment doesn't really say anything. Obviously, most AV software relays files back to the AV vendor's servers. But that's not what this graf implies. The graf suggests that Russian hackers are sending selectors down to the installed base of AV software to retrieve specific files, and that, once they obtained files that way, they passed the files on to Russian intelligence.
- seabird 9y agoYou seem to miss the part where I say >If the collection wasn't incidental, what mechanism could the FSB exploit to non-naively identify tools that it didn't already have, and flag them for retrieval? Emphasis on "non-naively." Antivirus seems like a highly ineffective tool for espionage of the sort being claimed in the article. You either have to blindly fish for something or already have a fingerprint of what you're looking for.
- tptacek 9y agoObviously, they have fingerprints of what they're looking for.
- seabird 9y agoTo have a hash of a file, you need the file (or a large portion of the file), especially in the context of antivirus, which searches for very specific files and needs to have a very low false positive and false negative rate. Consequently, they would already have to have the tool (or a large portion of the tool) to find it and retrieve it. A little non-productive, don't you think? Saying that they "obviously have fingerprints of what they're looking for" is an active attempt to make the events fit a narrative.
- codedokode 9y agoAV use other methods, except for signatures, for example running code in the sandbox or heuristics. If the malware was not obfuscated then it could be detected even without signatures. But of course if I were installing an AV product I wouldn't like it to send my files anywhere.