4 ms·
It's easy to say it should be publicised, but I'm not sure how someone can do that if the infected organisation specifically asks the antivirus company not to p
by wmt 12y ago
It's easy to say it should be publicised, but I'm not sure how someone can do that if the infected organisation specifically asks the antivirus company not to publicly discuss the malware, like what appears to have been the case with F-Secure. (https://mobile.twitter.com/mikko/status/536959936476221440 https://mobile.twitter.com/mikko/status/536959936476221440)
Sure, they could just go ahead and disclose it against the customers express wishes, but how many would hire their services in the future if there's no expectation of customer confidentiality?
Edit: There likely is an NDA in place even before externals are allowed in, so breaching it might invite some additional problems than just image issues.
- higherpurpose 12y agoBut that doesn't seem to have been the case with Kaspersky. So what's their excuse? Other than being pro-surveillance that is: https://twitter.com/csoghoian/status/505376361268400128 https://twitter.com/csoghoian/status/505376361268400128
- wmt 12y agoThat is a good point, some companies had very different motivations for not discussing it, e.g. Ronald Prins from Fox IT had this to say to Mashable: For Prins, the reason is completely different. "We didn't want to interfere with NSA/GCHQ operations," he told Mashable, explaining that everyone seemed to be waiting for someone else to disclose details of Regin first, not wanting to impede legitimate operations related to "global security." http://mashable.com/2014/11/25/regin-spy-malware-nsa-gchq/ http://mashable.com/2014/11/25/regin-spy-malware-nsa-gchq/
- gordaco 12y agoTo add something: I think that it makes a lot of sense for an infected organisation to ask for confidentiality about something like this; any public communication in the opposite sense would be an immediate signal for the attackers to release a new version of the malware. Although, depending on what the malware does, the attackers may realize immediately that it has been protected against. EDIT: also, it's not like antivirus companies publicise everything they do. From what I've seen (admittedly not much, so maybe I'm wrong) most releases are simply summarised as "added protection against 100 new threats".
- jamez1 12y agoAre you suggesting that it shouldn't be added to the signature list? Forget the news - that will be the tip off more than anything for the virus makers. When they 'release a new version', that behaviour can be spotted by the AV companies, and that new version can then be added to the signature list as well.
- lvs 12y agoIt would be possible to discuss the find publicly without disclosing the source. I'm pretty sure that's how all national security journalism functions today.
- freehunter 12y agoEven that may be against the contract. I've worked with companies where their NDA said their security troubles can't be disclosed even if the information was completely sanitized. Even saying "One company in the US was impacted by Malware X" would be inviting the lawyers. But I don't know this particular contract, so that may not be in play.