9 ms·
Kaspersky has been known to collaborate with the Russian government and promote Russian interest. They've actively pursued state actors that are hostile to Russ
by _m96l 9y ago
Kaspersky has been known to collaborate with the Russian government and promote Russian interest. They've actively pursued state actors that are hostile to Russian interest, for example The Equation Group (https://en.wikipedia.org/wiki/Equation_Group https://en.wikipedia.org/wiki/Equation_Group), which wouldn't be an organic part of the function or activities of a normal civilian cyber-security company. Such an "innocent" company would have no reason to get involved in cyberwarfare between state-actors, while Kaspersky is heavily involved in such activities and pouring considerable resources into them. This is especially damning since they are clearly targeting state-actors that are antagonistic to Russian interest, such as the US (Equation Group) and its allies (Israel), yet are totally silent on pro-Russian activity.
For anyone who's been at all aware of its history, it is clear that Kaspersky is at the very least actively collaborating with the Russian government, most likely doing its bidding, and possibly can be described as a cyber-security arm of Russian security forces.
I'm honestly surprised their products aren't already banned across all US government agencies.
- carvalho 9y agoWay down this thread, so time to ask the question: Do American anti-virus, social media, and search companies do exactly the same, but for the US military? I've always found it suspicious that Russia and China created their own social networks, email providers, and search engines. Almost like they know the power of a capable search engine or social network for intelligence gathering purposes. Google and US anti-virus companies must work closely with the NSA too. > Kuok repeatedly expressed fears that he might be dealing with an NSA, CIA or FBI agent, but continued to negotiate with the undercover officer, even cautioning him to avoid referencing the items by model number in e-mail, because "your country has this system to analyze" e-mail for keywords. https://www.wired.com/2010/05/kuok https://www.wired.com/2010/05/kuok Also after the "theft" and premature release of Stuxnet by Israel, I wonder how strong the collaboration between the US and Israel is. > A 43-year-old former Akamai employee has pleaded guilty to espionage charges after offering to hand over confidential information about the Web acceleration company to an agent posing as an Israeli consular official in Boston. https://www.pcworld.com/article/239187/akamai_employee_tried_to_sell_secrets_to_israel.amp.html https://www.pcworld.com/article/239187/akamai_employee_tried... > Facebook, for example, previously announced its DeepFace facial recognition system is capable of determining with 97 percent accuracy whether two images are of the same person. The company, which itself is accustomed to criticism that it views users as guinea pigs, is able is make such accurate identifications because of the network of images from which it draws, something that could take police agencies a decade or more to build up. Snowden worked for Dell as a cover for his intelligence work. Russia told their military to move off Linkedin the moment it got acquired by Microsoft. Do Dell and Microsoft work closely with the DoD and should this concern non-US citizens that rely on their software and hardware? https://techcrunch.com/2016/08/15/mapping-israels-marketing-technology-industry/ https://techcrunch.com/2016/08/15/mapping-israels-marketing-...
- dunpeal 9y ago> Do American anti-virus, social media, and search companies do exactly the same, but for the US military? Doubtful. Keep in mind that in Russia / China the state has a lot more leverage against commercial companies. It's very easy for the state to effectively shut any non-complying company, not to mention far worse (Russia and China have thrown businessowners into jail for no reason before). > Almost like they know the power of a capable search engine or social network for intelligence gathering purposes. Absolutely, the typical pattern is that some dominant foreign provider refuses to comply with say, Chinese Firewall rules, so the Chinese block it and instate a friendly domestic provider instead.
- wu-ikkyu 9y ago>It's very easy for the state to effectively shut any non-complying company https://en.wikipedia.org/wiki/Lavabit https://en.wikipedia.org/wiki/Lavabit
- mizzack 9y ago> Doubtful. Keep in mind that in Russia / China the state has a lot more leverage against commercial companies. It's very easy for the state to effectively shut any non-complying company, not to mention far worse (Russia and China have thrown businessowners into jail for no reason before). That is pretty disingenuous. Noncompliance with an NSL is a quick route to contempt charges. On top of that, the gag order prevents you from explaining your position to shareholders or customers. This coercion makes it much more straightforward for most businesses to simply comply with US demands, unless you voluntarily shutter your company, e.g. Lavabit.
- jsmthrowaway 9y agoNSL is a statutory authority document issued directly by the executive without judicial involvement. It is not a legal proceeding nor a warrant, nor is it even on court letterhead. There are no statutory penalties for noncompliance set out in the law defining NSLs, but it has provisions to request a court order to enforce if the recipient does not comply. That requires filing a federal case, bringing the intelligence operation to the attention of the judiciary, and probable argument with an opportunity for the target to argue. This is where you hear about folks like EFF defending an NSL, since replying to an NSL usually does nothing. After a court issues an order, contempt of court is a possibility. Just clarifying that the route to contempt is not quick. It’s also largely untested. Writing an NSL is two pages in a Microsoft Word template, while arguing a federal case to get your way is a much bigger prospect; if the investigation is small enough, or they’re not totally legal in how they got intelligence, etc., etc., they might not wish to argue and calling the bluff might be smart. The gagging facility of NSLs actually has a non-coercive purpose: as designed, an NSL basically invites an unknown third party into a sensitive intelligence or counterintelligence operation. Tipping off the target or anyone else could lead to a collapse of the investigation, burning other sources that were used before you got your NSL, diplomatic repercussions, and so on. That’s the thinking that went into it, and it’s actually understandable. Two problems are that (a) the gag is indefinite, with no circling back once the operation concludes and (b) NSL is horrifically abused for stuff it shouldn’t be, since FBI realized the gagging lets them mostly get away with it. Source: Have held more than one and read the citations.
- Tech-Noir 9y ago> Kaspersky has [...] actively pursued state actors that are hostile to Russian interest, for example The Equation Group (https://en.wikipedia.org/wiki/Equation_Group https://en.wikipedia.org/wiki/Equation_Group), which wouldn't be an organic part of the function or activities of a normal civilian cyber-security company. According to that Wikipedia page, The Equation Group refers to "a collection of tools used for hacking". Targeting hacking tools seems to me exactly what a security software company should be doing. >Such an "innocent" company would have no reason to get involved in cyberwarfare between state-actors, while Kaspersky is heavily involved in such activities and pouring considerable resources into them. Even if we assume these tools can only target governments and not businesses or individuals, perhaps Kaspersky wishes to obtain contracts with the governments targeted. I don't see how this is particularly sinister or illegitimate. > This is especially damning since they are clearly targeting state-actors that are antagonistic to Russian interest, such as the US (Equation Group) and its allies (Israel) Your Wikipedia link states: "The Shadow Brokers announced that it had stolen malware code from the Equation Group [...] Exploits against Cisco Adaptive Security Appliances and Fortinet's firewalls were featured in some malware samples released by The Shadow Brokers [...] Juniper also confirmed that its NetScreen firewalls were affected. The EternalBlue exploit was used to conduct the damaging worldwide WannaCry ransomware attack." Three American companies and vast numbers of individual users and civil government institutions around the world (including the UK Health Service). Are they all Russian interests?
- dunpeal 9y ago> According to that Wikipedia page, The Equation Group refers to "a collection of tools used for hacking" Are we reading the same Wikipedia page? Here's what mine says: > The Equation Group, classified as an advanced persistent threat, is a highly sophisticated threat actor suspected of being tied to the United States National Security Agency (NSA). Kaspersky Labs describes them as one of the most sophisticated cyber attack groups in the world and "the most advanced ... we have seen", operating alongside but always from a position of superiority with the creators of Stuxnet and Flame. Most of their targets have been in Iran, Russia, Pakistan, Afghanistan, India, Syria, and Mali. Kaspersky is preoccupied with this group, that by their own description, targets state actors that are hostile to the US. They've obsessively documented 500 of their alleged attacks worldwide, which would be negligible blip on the radar for any normal, purely commercial cyber-security company. Doesn't it strike you as odd? > Even if we assume these tools can only target governments and not businesses or individuals, perhaps Kaspersky wishes to obtain contracts with the governments targeted. I'm going to take a wild guess that none of the targets of the Equation Group like Afghanistan or Syria will trust Kaspersky enough to hire them for a sensitive project. These countries are very busy with ground wars and have no attention or money to spend on cyber security. The only government that may and probably does employ Kaspersky is the Russian one. Which of itself hints at heavy collusion between these two.
- Bendingo 9y ago> Kaspersky has been known to collaborate with the Russian government and promote Russian interest I would like to see some actual evidence of this, instead of just allegations.
- dunpeal 9y agoHow else can you explain their obsessive occupation with The Equation Group, which they themselves claim to be a (US) state actor, targeting other (US-unfriendly) state actors? https://en.wikipedia.org/wiki/Equation_Group https://en.wikipedia.org/wiki/Equation_Group An ordinary anti-virus company would never get involved in state-vs-state cyber warfare, let alone pour tons of money into researching it. How does that support their business model? Do you think it's normal for a commercial company to spend so much time, money, and effort researching areas that have nothing to do with their core business, and will likely get them in trouble with their customers and antagonistic governments?
- mtgx 9y agoI could make the very same argument against CrowdStrike, which has been focusing on uncovering Russian cyber attacks. Also here's some "damning evidence", too: “There’s a Balkanization of cyberspace that’s occurring, and companies need to choose which side they’re on,” said Dmitri Alperovich, co-founder of U.S. security firm CrowdStrike. http://www.reuters.com/article/us-media-tech-summit-flame/some-flame-code-found-in-stuxnet-virus-experts-idUSBRE85A0TN20120612 http://www.reuters.com/article/us-media-tech-summit-flame/so... Sounds to me like they've "chosen a side", like you're implying Kaspersky has.
- lqdc13 9y agoAre you saying state sponsored malware should not be looked into? It seems like American companies tend to find Russian state-sponsored malware and Russian ones keep finding US/US allies-sponsored malware.
- frabbit 9y agoAnd in addition Israeli hackers keep on finding malware in locations they've hacked into..... hmmmmm
- nl 9y agofor example The Equation Group (https://en.wikipedia.org/wiki/Equation_Group https://en.wikipedia.org/wiki/Equation_Group), which wouldn't be an organic part of the function or activities of a normal civilian cyber-security company. While your basic point might be correct, this part is absolutely false. All major security groups actively research all APT groups, no matter where they are from. For example, here's a 2015 report from (US Company) FireEye[1]. Page 11 talks about the Equation Group (as well as the UK-based Regin group). It is worth acknowledging that Kaspersky was the first company to identify and name the Equation Group. However, this is likely to be because of the geographical overlap of activities: Kaspersky provides defensive support in Russia and the Middle East where the Equation Group is most active. This is exactly the same as how Mandiant/Fireeye identified ATP-1 and Cozy Bear/Fancy Bear: they get called in to investigate breaches in the US where those state-supported groups are most active. [1] https://www.fireeye.com/content/dam/fireeye-www/company/events/infosec/threat-landscape-overview-fireeye-summit-paris.pdf https://www.fireeye.com/content/dam/fireeye-www/company/even...
- lawnchair_larry 9y agoThis is a lot of BS. Kaspersky have also documented Russian government malware, so that is one nail in a very weak argument. Having a lot of experience in this space, no loyalties to Russia, and all loyalties to the US, if anywhere, I strongly disagree that there has ever been any meaningful current or historical link between Kaspersky and the Russian government. Posts like this do not seem to be informed by actual industry experience and those speculations are not even agreeable to those who are suspicious of Kaspersky. You're sharing a lot of FUD.
- mtgx 9y agoYou could argue exactly the same way against US security firms such as CrowdStrike, and a few others, which seem to focus on uncovering Russian malware.
- Dolores12 9y agoFailing to find Equation Group tells alot about american antivirus companies as well. Who else they are hiding? Kaspersky, Snowden, Positive Technologies(which are also russian) are doing great service to community. Cyber weapon is still weapon and people should know about it.
- jonathanstrange 9y agoWell, it makes perfect sense to use Kaspersky then, if you're worried about the NSA. If you're more worried about Russian industrial espionage, on the other hand, e.g. as a US company with trade-secrets, you should probably better go with a US product. For most private citizens that aren't of particular interest to the Russian government (e.g. aren't politicians, activists, dissidents), Kaspersky seems like an excellent choice. Every AV product will be defeated by a targeted attack anyway.
- cwyers 9y agoEven if Kaspersky still fits your threat model (and it might), this revelation is still an existential threat, and if you use Kaspersky for an institution it's probably a good time to explore alternatives and have a plan for what to use if Kaspersky goes under.
- codedokode 9y agoEquation Group were making hacking tools so opposing them is what any decent AV company should do. Doing so they protect all their users around the world.