Israeli Spies 'Watched Russian Agents Breach Kaspersky Software' (bbc.com)
Israeli spies looked on as Russian hackers breached Kaspersky cyber-security software two years ago, according to reports. From a report: The Russians were allegedly attempting to gather data on US intelligence programs, according to the New York Times and Washington Post. Israeli agents made the discovery after breaching the software themselves. Kaspersky has said it was neither involved in nor aware of the situation and denies collusion with authorities. Last month, the US government decided to stop using the Russian firm's software on its computers. The Israelis are said to have notified the US, which led to the ban on Kaspersky programs. The New York Times said that the situation had been described by "multiple people who have been briefed on the matter."
yeah, just stood there im sure
NPR had some significant advertising for Kapersky today
So Israel was spying on the US and saw that Russia was spying on the US.
Great. Wish they'd both die in a fire.
Bullshit
If Kaspersky did not know. Its not like Russia has a free press to investigate those things. Oh crap.
Part of the reason I've always felt nervous installing AV or anything else that wanted to run at or near kernel is exactly this: at least one third party is "in" my system...and if that third party goes sideways then the rest of my defenses aren't worth much. (e.g. is your IDS really going to flag a 10% traffic increase to your AV vendor from your AV software?)
Here's an old story you might find apolitically interesting. We knew way before the election that Kaspersky was KGB trained and a Putin loyalist. You can read my comment history of you're an actual skeptic rather than a Russian botnik. But I also recommend anyone who doubts Putin's viciousness to hear the story of how he murdered his way into office from this PBS Documentary.
As a sidenote, I'm a slashdot reader from more than a decade ago, and I've been really disappointed to see the amount of denialism present on this issue. I remember this as a place for pragmatic, intelligent, realistic people. And here's the reality: Putin is at war with you, he doesn't give a shit about you or your family or even his own citizens' families, and he actively hopes that you are confused about what he is doing, or denying it entirely.
Seriously, if something like this came up in a cheesy 80s action show I'd switch channel.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
Kaspersky's AV solutions scan files, and transmit data back to their servers if found to be malware. If nothing else, they can send back lists of files on machines that are scanned, etc.
The transmission is done thru TLS-encrypted channels.
The Russian Government, like most major governments, do their best to monitor all of the traffic they can. See the recent Wikileaks documents on "Peter-Service" for some details.
If the Russian gov't has obtained, one way or another, copies of Kaspersky's TLS keys, then they really don't need cooperation to see everything that's coming down the pipe. They can also probably MITM the connection and take control of the AV application, without Kaspersky's knowledge.
It is called "plausible deniability" for Kaspersky and fairly trivial in a country where the use of strong encryption requires a license from the gov't.
There are numerous current news articles about our (American) Justice Department is salivating over the possibility of that being possible in the U.S.
Learning HOW to think is more important than learning WHAT to think.
I trust(ed) Kaspersky more than the Senators bad-mouthing them. They look pretty bad in this light, though. Not because of collusion with the KGB but because their software can't, apparently, protect their own systems. So who can we trust, then? Symantec? McAfee? Windows Defender? Please. It looks like we either have to swallow the fact we're going to be entertaining uninvited guests or we'll have to try to live without our security blankets. It isn't so bad for /. readers but what about those friends and family who are more-and-more at risk? What a stinkhole we've made of the Internet.
Is there anyone in this break-in who's NOT a spy?
No matter how you spin this there is no way for Kapersky to come out of this whole mess OK.
The best way to be protected is to ignore the problems... so says the Symantec CEO https://yro.slashdot.org/story...
If it is breached, that means that they are not working together with them. It means it NEEDS to be breached to be available to them.
Why are they not caught breaching the others? My guess is because they found the loophole the NSA put in there. and everybody is using that already.
It also shows that the Israelis where looking to breach it (most likely while working with/for the NSA) and that means they where not yet able to breach it either.
Of all of them, the safest bet is still them. Worst case is that only the Russians read your things. Best case is that a new version makes it that nobody has hacked them.
Don't fight for your country, if your country does not fight for you.
Are you sure it wasnâ(TM)t Israeli agents? Easy to watch them if youâ(TM)re standing in the same room.
It isn't so bad for /. readers but what about those friends and family who are more-and-more at risk?
This comment is just bizarre and completely backwards. The only people who care about this stuff are people on places like Slashdot. Friends and family who don't work in IT are not losing any sleep over this at all. I can give you my complete guarantee on that. The people who actually do care are few in number.
It seems rather disingenuous that the U.S. would complain about a proprietary piece of Russian software with a backdoor installed in a proprietary OS which also has backdoors that the U.S. intentionally installed.
In fact, one article down from this headline reads: "Justice Department To Be More Aggressive In Seeking Encrypted Data From Tech Companies". I seem to remember an Israeli firm cracking the encryption on the San Bernadino shooter's iPhone.
So the lesson to be learned is, you can't trust governments not to spy and you can't trust proprietary software. The only option left is free/libre open source software that is able to be audited and patched by anyone.
Quite right, I for one will continue to trust Kaspersky. I've just installed FSB (think it stands for File Safe Backup) on my
laptop for extra security.
What will you guys do, now that this shoots holes in your "AMERIKKKA IS EBIL" schtick?
seriously, the more someone have an imaginary friend, the more troll the person becomes. and like the sun having too much mass becomes a black hole, if you get too much idiotic being a troll, you become a religious bastard, and people like that using security tools is dangerous. in Brazil, they use that as lobby to gather information and sell to marketing companies, support prostitution and keep your country in the third world manipulating elections.
What kind of traitor thinks its safe to join a Russian botnet under the false premise of antivirus protection?
This might be a wake up call to Mr Orangeturf to the real intentions of the Russians.
We are probably into their nests too. so.... no one is really "better" but just sneakier.
Lets just ditch windows and reduce our attack surface.
A botnet has no interest or ability to protect any single member. Since most infections don't use an host 24/7, sharing an host is doable and much cheaper than trying to be a part-time AV.
That they are in government employee makes little difference, these people are criminal hackers. And not only do they lie routinely, they are trained to do so. And they are subject to politics, because they must follow orders. Hence the only thing we know is that this story rings true (because the Israelis are very good at lying), but that is it. This may well just be a favor to the US and helping in getting rid of an AV company that refuses to bow to the NSA. This story does not add any credibility to the theory that Kaspersky is under Russian control. If anything, it makes it more plausible that they are not.
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
Hi Neighbor. As I was breaking into your house to "borrow" a few beers, I noticed someone had already broken in. You might wanna get that lock fixed. You're welcome.
Support Right To Repair Legislation.
No way they would benefit from more tensions and defense spending in the region.
Quis custodiet ipsos custodes?
Have gnu, will travel.
Things from people who still consider you an enemy like Russia and China.
You forgot the unsubstantiated claims that everyone who disagrees with you is a Russian.
"By way of deception shalt thou make war."
That is Mousad's creedo.
Taking the word of a spy that doesn't even work for you is the dumbest fucking thing you can do. Followed shortly after by taking the word of a spy who DOES work for you.
Why all the angst about Kaspersky? Every Intel based computer has the AMT hole. What does it matter what software you are running? Those with the knowledge can crack your system any time they want and you will never know.
This creimer fixation is terrible. So many butthurt ACs. Sad.
The week is not over yet, but I am fairly sure you are going to win the pretzel logic of the week award.
Congratulations, the competition is strong!
Comment removed based on user account deletion
I've reported this creimer sockpuppet
and security scanner can, and probably was at some point subverted to transmit data, so what is the big news?
Man, if you`re a nation of 350 million people who invented the Internet and have a larger security budget than the rest of the world put together, it must totally burn you to be hacked by a half-starved, half-drunk nation of 150 million.
But not as much as being told about it by a nation of 8 million.
Guys, we don`t agree with all your foreign adventurism and neo-colonialism, but if you`re going to run around the planet just making enemies hand-over-mailed-fist, you really need to up your cybersecurity game. You have WAY too many of your human IT resources trying to figure out how to out-snapchat SnapChat.
And hire Snowden back. That guy could run a computer.
Seems like a campaign to get rid of Kaspersky. Any idea's why?
Don't let yourself be manipulated by these BS stories about Kaspersky software. The BBC works for the City of London and the companion story posted by @msmash are intended to place an economic hit on Russia and the collateral damage is your online security. It's an F'd up world, and the spooks are everywhere. Don't play into their hands. Ignore this noise, it will make them crazy.
Where are your certs, Chris? How's the video business in your "home office" coming along?
At least you can sexually harass your employee as much as you want...
There you are spamming amazon affiliate links with yet another fake account, you revenue stream hogging disgusting fat sexist tube of lard, Christopher Dale Reimer!
You can be sure I will be watching this fake account too. I know this is you because you told me you were working on your freepass 11 file server and you are so dumb that you can't even masquerade yourself properly.
Now, I told you I was out of meds last week and you didn't even care to contact me you lazy fucker.
How many times do I have to express the emergency of the situation??????
The python click script you wrote for my pheromone revenue stream web site suddenly stopped to work!!!!!!
You fucking incompetent python script writer!!!
When it works, I get 4000+ clicks a day on my pheromone revenue stream web site but only 5 or 6 without it!!!!
Now, it seems like you dont care and that you have abandoned me you heartless fucking pig!
Bonus:
Here is a story that creimer told me when convincing me what a hard life he had:
The tree was him and the tree knot was his butt hole!
So, his uncle packed his fat ass with lard and with his cock! Not that it makes much of a difference but anyway, there it is!
Signed:
The girl that used to love you and now hates you, burn in hell where you belong you sexist pig!
Thank you for reiterating that snowden "fled to russia" even though everyone here knows that's a lie. It's good to know that this place is still considered worth trolling by the lying powers that be.