8 ms·
Canada's 'secret spy agency' is releasing a malware-fighting tool to the public
- stephengillie 9y ago> Assemblyline is described by CSE as akin to a conveyor belt: files go in, and a handful of small helper applications automatically comb through each one in search of malicious clues. On the way out, every file is given a score... This sounds like it could sit nicely between Github and CI (Jenkins/Travis/Circle/etc), and be a pre-integration security scan. Can we name it Sherlock?
- KGIII 9y agoMountie might be better.
- mberger 9y agoHow about Canadian Shield? CanShield?
- 52-6F-62 9y agoChad Kroeger. Nobody would ever come near it again.
- SuperPaintMan 9y agoRude.
- excalibur 9y agoHogline
- etblg 9y agoMurdoch, it'd be have to be
- bonestamp2 9y agoYa, looking at npm repos.
- jordigh 9y agoThe main repo seems to be here: https://bitbucket.org/cse-assemblyline/assemblyline/src https://bitbucket.org/cse-assemblyline/assemblyline/src Released under the MIT license with crown copyright. Looks like a plain ol' Flask application. I don't know what I was expecting from the government. Maybe more Microsoft and more Oracle, more "enterprise". And the git history goes back ten months with an initial commit of December 21, 2016. I'm actually surprised to learn that CSE would be in charge of such a thing. I would have thought that this fell under the role of Canadian Security Intelligence Services. We definitely don't hear a lot about CSIS or CSE in the news to the point that I think most Canadians might have a hard time expanding those acronyms or know what they mean. It's good to see a little more transparency from them and to not have to wait for NSA leaks to figure out what their Canadian counterparts are up to.
- 52-6F-62 9y agoCSE is comparable to America's NSA in general function and scope. While CSIS does intelligence work with computers and hires a lot of programmers and analysts, CSE is traditionally the more technologically-focused of the two. You also hear significantly less about it than even CSIS. They're good at their jobs. edit: Spelling. They changed it from CSEC to CSE
- canistr 9y agoMore like they changed it "back" to CSE. :)
- deleted 9y ago[deleted]
- revelation 9y agoCitation needed.
- 52-6F-62 9y agohttps://www.cse-cst.gc.ca/en/about-apropos/faq https://www.cse-cst.gc.ca/en/about-apropos/faq
- danesparza 9y agoIs it just me, or is it amazing that they're releasing this for free? Even Canadian SPY organizations are friendly!
- nerdshoe 9y agoAnd it didn't even come by way of Russia.
- rphlx 9y agoA cynic, and, perhaps, a realist could consider their motivation to be fairly similar to that of a private blackhat attempting to purge foreign malware on hosts that they own, or may want to own. Exclusive control being always preferable to competing control. I'd be far more impressed and grateful if these state services released disclosures and actual patches for complex zero-day vulns, particularly in unmaintained, widely deployed closed-source products such as WinXP. 8-Ball says that is 'Unlikely' though.
- kaybe 9y agoI don't think I trust foreign intelligence agencies enough to install their software on my devices. Sure, they probably also release stuff not under their name and not open, but still.
- EGreg 9y agoInteresting, Kaspersky is constantly maligned for simply being USED by Russian spy agencies, or "having associations with" them. Russia and China now demand audits of security software from the USA. Countries build their own national Linuxes now that Windows phones home all your passwords, for the CIA and NSA to easily backdoor or get via an order. So, why would anyone trust a spy agency's software? Only if it's all open source.
- e1ven 9y agoIt's MIT license, and the repo seems to have full history.
- mtgx 9y agoShould we be reminded that bugs such as Apple's GoTo Fail can exist? Or like Heartbleed, which actually was in open source software? If they were to put a backdoor in it, whoever would find it would probably just take it for some error they made in coding.
- bfred_it 9y agoThat doesn’t mean that the binaries match the repo content.
- gnode 9y agoDoes it even have binaries? It's a Python app, isn't it?
- cyberattacknow 9y agoNot really. Some software just can't be profitable open source.
- dmix 9y agoThis one even includes a Kaspersky interface: https://bitbucket.org/cse-assemblyline/alsvc_kaspersky https://bitbucket.org/cse-assemblyline/alsvc_kaspersky An interesting inclusion but it makes sense as it seems to work by hitting up all possible scanners (both remote and local). The consensus from security people seems to be use multiple AV products, if you insist on using them at all... This tool will get extra scrutiny given it's coming from a spy agency and is OSS. That's not usually how spy agencies operate, too overt. Besides, they seem to have no problem quietly hacking your browser remotely with the click of a button with Quantum anyway. I'm still not going to use it but I wouldn't personally be overly worried vs any other mainstream antivirus.
- lpgauth 9y agoBillangual README!
- jagger27 9y agoBilingual
- ape4 9y agoIts a Canadian government rule that even URLs have to be bilingual. eg You can't have http://host.ca/news http://host.ca/news (with bilingual text on the page) it has to be http://host.ca/news_nouvelles http://host.ca/news_nouvelles This is only for fed government sites.
- barsonme 9y agoje ne savais pas !
- 8note 9y agoI'm surprised there isn't a separate copy of all the code in French, or at least the code comments
- 52-6F-62 9y ago// En français, s'il vous plaît fonction commencer(état) { si (état !== nonDéfini) { laisser nouveauChaîne = `Bonjour, ${état}`; faire { console.journal(nouveauChaîne); piraterTousLesSystèmes(); } tandisQue (systèmesSontDébloqués()) } autre { merde(`partout`); } } // Commencer! commencer(`L'état du Brésil`); // Bon.
- eslachance 9y agoWe're sorry we didn't come up with it sooner, eh?
- deleted 9y ago[deleted]
- BenoitEssiambre 9y agoIs this just a pond or do they have an actual moat around the building?
- 3pt14159 9y agoThis is the first major commit where they pulled in the existing codebase almost a year ago: https://bitbucket.org/cse-assemblyline/assemblyline/commits/ef004b6bd7d24ee5a2664e62251092817db7eec2?at=master#chg-al/common/security.py https://bitbucket.org/cse-assemblyline/assemblyline/commits/... Couple interesting bits: 1. Bcrypt looks trusted. I guessed as much given that I've seen it used in other GC projects that were "Protected B" (think Revenue Canada / similar). 2. It doesn't look like they enabled HSTS by default until a couple months later in the repo: https://bitbucket.org/cse-assemblyline/assemblyline/commits/d874f39dd46185bc61680076e226acd555c1ffbd https://bitbucket.org/cse-assemblyline/assemblyline/commits/... Again, unsurprising since the CSE / CST main page doesn't have HSTS. 3. This part of the original version of the README is interesting: <README SNIPPET> #### License (or lack thereof) and Conditions of use As is fairly evident, we haven't selected a license for this project as of yet. As discussed when members were first granted read access to the repository, dissemination is based on the premise of originator controlled. If you feel there are other partners that would benefit from an early view and would be able to contribute, please contact the project leads and we should be able to sort it out. We will soon be splitting the platform and services into two separate repo's, so please treat the services as slightly more sensitive than the platform itself, ie: release it and perish!!! ... but seriously, we do not grant anyone the right to do anything other than deploy the platform and use it. No sharing, presenting, etc without our knowledge. We hope to have a clear release plan soon. </README SNIPPET> So it looks like they passed it around a bit either internally in the CSE or to a wider audience that may have included other departments. Probably getting more eyes on it to stop something stupid from going out. 4. There are some fun little commits like this: https://bitbucket.org/cse-assemblyline/assemblyline/commits/7907b5c217cfea5627d9dcf69d1080b7c2d66c30?at=master https://bitbucket.org/cse-assemblyline/assemblyline/commits/... Or this (adding the French version is always one of the last steps before something goes public): https://bitbucket.org/cse-assemblyline/assemblyline/commits/f51059f010bb2a87682112ea7d6817e957bcf029 https://bitbucket.org/cse-assemblyline/assemblyline/commits/... Or this (we've all been there): https://bitbucket.org/cse-assemblyline/assemblyline/commits/fe8d98795939aaa29fe60aad9aa1bcb4dc3ad957 https://bitbucket.org/cse-assemblyline/assemblyline/commits/...
- 52-6F-62 9y agoLol. I don't know if you clicked the username, but it's appropriate: https://bitbucket.org/sgaron-cse/ https://bitbucket.org/sgaron-cse/
- dddddaviddddd 9y agoWhat does it actually do?
- hk__2 9y agoThe article says: > … files go in, and a handful of small helper applications automatically comb through each one in search of malicious clues. On the way out, every file is given a score, which lets analysts sort old, familiar threats from the new and novel attacks that typically require a closer, more manual approach to analysis.
- ktta 9y agoLooks like they use Binary Ninja too. https://bitbucket.org/cse-assemblyline/alsvc_binja https://bitbucket.org/cse-assemblyline/alsvc_binja
- a1371 9y agoI don't find my answer, I just have one question: does it send any "usage stats" or "unknown files" back to them? If your computer establishes any kind of connection with their center it wouldn't be only something for the public, they'd also benefit. That isn't necessarily a bad thing but seems important enough to be discussed.
- crimsonalucard 9y agoDoubt it. That'd be too obvious.
- bane 9y agoHow's this compare with things like Laika BOSS or mitre's multiscanner?
- crimsonalucard 9y agoChances are there's some really really obscure security hole in the app that they hope to exploit sometime in the far future. I'm telling you.
- bonestamp2 9y agoOr hoping someone will fix and submit a pull request.
- ulises314 9y agoFirst OpenBSD and then this, Canada is like the promised land for security minded people!
- rootw0rm 9y agolol, upx unpacker