Kaspersky Lab Has Been Working With Russian Intelligence (bloomberg.com)
An anonymous reader quotes a report from Bloomberg: Internal company emails obtained by Bloomberg Businessweek show that Kaspersky Lab has maintained a much closer working relationship with Russia's main intelligence agency, the FSB, than it has publicly admitted. It has developed security technology at the spy agency's behest and worked on joint projects the CEO knew would be embarrassing if made public. The previously unreported emails, from October 2009, are from a thread between Eugene Kaspersky and senior staff. In Russian, Kaspersky outlines a project undertaken in secret a year earlier "per a big request on the Lubyanka side," a reference to the FSB offices. Kaspersky Lab confirmed the emails are authentic.
The software that the CEO was referring to had the stated purpose of protecting clients, including the Russian government, from distributed denial-of-service (DDoS) attacks, but its scope went further. Kaspersky Lab would also cooperate with internet hosting companies to locate bad actors and block their attacks, while assisting with "active countermeasures," a capability so sensitive that Kaspersky advised his staff to keep it secret. In this case, Kaspersky may have been referring to something even more rare in the security world. A person familiar with the company's anti-DDoS system says it's made up of two parts. The first consists of traditional defensive techniques, including rerouting malicious traffic to servers that can harmlessly absorb it. The second part is more unusual: Kaspersky provides the FSB with real-time intelligence on the hackers' location and sends experts to accompany the FSB and Russian police when they conduct raids. That's what Kaspersky was referring to in the emails, says the person familiar with the system. They weren't just hacking the hackers; they were banging down the doors. Kaspersky Lab has issued a statement in response to Bloomberg's report. It reads in part: "Regardless of how the facts are misconstrued to fit in with a hypothetical, false theory, Kaspersky Lab, and its executives, do not have inappropriate ties with any government. The company does regularly work with governments and law enforcement agencies around the world with the sole purpose of fighting cybercrime. In the internal communications referenced within the recent article, the facts are once again either being misinterpreted or manipulated to fit the agenda of certain individuals desperately wanting there to be inappropriate ties between the company, its CEO and the Russian government, but no matter what communication they claim to have, the facts clearly remain there is no evidence because no such inappropriate ties exist."
The software that the CEO was referring to had the stated purpose of protecting clients, including the Russian government, from distributed denial-of-service (DDoS) attacks, but its scope went further. Kaspersky Lab would also cooperate with internet hosting companies to locate bad actors and block their attacks, while assisting with "active countermeasures," a capability so sensitive that Kaspersky advised his staff to keep it secret. In this case, Kaspersky may have been referring to something even more rare in the security world. A person familiar with the company's anti-DDoS system says it's made up of two parts. The first consists of traditional defensive techniques, including rerouting malicious traffic to servers that can harmlessly absorb it. The second part is more unusual: Kaspersky provides the FSB with real-time intelligence on the hackers' location and sends experts to accompany the FSB and Russian police when they conduct raids. That's what Kaspersky was referring to in the emails, says the person familiar with the system. They weren't just hacking the hackers; they were banging down the doors. Kaspersky Lab has issued a statement in response to Bloomberg's report. It reads in part: "Regardless of how the facts are misconstrued to fit in with a hypothetical, false theory, Kaspersky Lab, and its executives, do not have inappropriate ties with any government. The company does regularly work with governments and law enforcement agencies around the world with the sole purpose of fighting cybercrime. In the internal communications referenced within the recent article, the facts are once again either being misinterpreted or manipulated to fit the agenda of certain individuals desperately wanting there to be inappropriate ties between the company, its CEO and the Russian government, but no matter what communication they claim to have, the facts clearly remain there is no evidence because no such inappropriate ties exist."
To be fair, Eugene Kaspersky did meet with Russian intelligence, but they only discussed adoption.
You are welcome on my lawn.
What nation with a powerful central government doesn't demand indelicate acts from its major corporations?
Happiness in intelligent people is the rarest thing I know.
Ernest Hemingway
Imagine that, a Russian company working for/with the Russians. How quaint. Much like the Cripts and Bloods working for the CIA.
The mind conceives, the body achieves, the spirit manifests.
Why is our media trying so hard to start a war between the U.S. and Russia?
"His name was James Damore."
But I'm not really feeling the outrage here, at least with regard to what was reported.
#DeleteChrome
I noticed last week or so "Russia this, Russia that" hysteria, rumours and manipulations appeared here, something strange, as they don't contain any credible information, even anything interesting for geek, just gossips - and it's trending in traditionally geeky website.
Slashdot was safe harbor for me for more than a decade from filthy political news and "news for housewives".
Seems its time to put dot and say bye bye?
P.S. Yes i'm russian, and i hate politics and propaganda. Peace!
I guess everyone's forgotten all about RSA Security's cozy relationship with those friendly NSA folks. -PCP
So, it is being claimed that Kaspersky's is trying to take down cyber-criminals? If they were accused of using their anti-virus software to spy that would be a different story.
and Pence in. Trump is unpredictable. He's come out in favor and against single payer health care, restrictions on work visas, tariffs and a whole host of populist ideas that the folks that actually own the media aren't too keen on. Now, it's not that they expect Trump to actually _do_ any of that (he's still one of them after all) but they don't want folks to even know a progressive agenda is a possibility. So Trump's out, Pence is in and the mega-corp status quo is maintained. Maybe with a tad more religious furor but that doesn't affect them personally. Nothing much ever does...
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
and older folks are worried about politics. We're getting old enough to worry about pensions, medicare, our kid's job prospects, etc, etc. Politics affects _everything_. Like the internet? Then you better pay attention to politics. Remember, it's not just news for nerds, it's also stuff that matters. The President getting impeached and replaced with a far right, intensely religious VP? Yeah. That Matters.
Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
Even if Kaspersky doesn't want to do anything bad, I can't imagine that Russian intelligence doesn't have someone on the inside. Just as I can't imaging the CIA or NSA doesn't have someone inside MS and Google.
I don't know why this is such a big deal - they are a Russian company, which means they are (whether they like it or not) somewhat under the influence of the Russian government. Just as (again) MS and Google are somewhat under the influence of the US government.
Stop freaking out about it already, and if you consider their products just make sure you think about the ways this could be a problem for you or not.
And frankly if Kaspersky is helping the intelligence guys kick down the doors of DOS script kiddies, more power to them. It's not like the guys who do DOS attacks are generally all that smart or useful, they're just damned annoying to the rest of us.
A thousand pounds of wood moving at 300 feet per minute. Don't get in the way.
Somebody doesn't know what the first D in DDoS stands for evidently (No, Kapersky was not identifying the hacker's location. That is not even within the realm of possibility.)
Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
Pretty funny considering it's well known that nearly ALL top tech companies in the USA have cooperated extensively with multiple American intelligence and law enforcement agencies with details of actual incidents now in the public domain.
Meanwhile we're supposed to give a fuck about vague insinuations with one Russian software company???
Really?
Last time checked, Apple refused to decrypt an iPhone for the FBI. Google, and Amazon also force the government to subpoena them for information. It's bad business to give up your customer's data, and America is capatalist.
When you protest in Russia, you get killed one way another, possibly by polonium laced water. What happens in America? At worst a civil infraction.
To illustrate my point further: when was the last time you bribed a police officer? After all the stuff I've seen, I actually like police officers now.
All of these Americans who have never visited Russia have no idea how good we have it. Obama as far as i know did not have a bank account in Panama, but both Putin and Poroshenko did.
It's disappointing to see how we've lost faith in our own country, which has spread freedom across the world, for which other coubtries thank us for having done so. I never trusted Kaspersky, and now I have a reason to.
Sure disagree with me. America sucks, right? Well when Putin surreptitiously takes over America in 2020 (next time via democratic candidate because no one is suspecting it, and that's what a troll does), I bet you'll be begging for old America: where people take pride in their jobs. Ambulances show up to your house in minutes, not hours, and you don't need to bribe people to get things you want.