49 comments

[ 3.0 ms ] story [ 121 ms ] thread
> Congress didn’t give anyone money to replace these devices,

Seems more like the U.S. Government doesn't want to get rid of Kaspersky. They choose not to replace compromised devices. Doesn't seem like it is a hard technical challenge at all, rather the lack of action seems more intentional.

Surely we can all agree this is an issue of National Security. And if the task is to be done with no Federal assistance or financial help whatsoever, it seems clear that the government is compromised.

This seems more like a Pointy-Haired Boss-type move to me. Bosses in actual IT businesses often don't understand what's involved with a large IT project; what hope does a 79-year-old senator have of understanding what removing Kaspersky software from the entirety of the United States government's systems would take?
They don’t. But starting Monday, we’ll find out.
I'm rather surprised the United States government would be using foreign software for information security. Really, I'm surprised that they're using outside software for it at all. As much as I'm a fan of the free market, that isn't the sort of thing I'd trust to an outside company.

If only there was some sort of group in the government that handled information security... Some sort of security agency, if you will.

I'm not sure which is worse, Kaspersky/Russia spying on everyone in the Fed or the NSA.
This makes sense for the US Government. But at the same time, it makes more sense for me - as a US citizen - to use Kaspersky. The Russian gov't doesn't care about me at all, so I have little to fear from them. But I do fear the NSA because I am subject to the whims of the US government.
What if your PC gets enlisted in a state sponsored attack against the US? Or is used as a proxy for an intrusion? Or... so many other possible scenarios...
(And if you have an American-branded anti-virus) What if your PC gets enlisted in a state sponsored attack by the US? Or is used as a proxy for an intrusion? Or... so many other possible scenarios...
It's not that surprising. Typically when you work with Governments, everything is specially done, doubly so for the US Government. Custom Federal forks of the main product (with feature parity), heavily customized SLAs, full access to the source code for review, and lots more to ensure that it meets the US Federal standards.

The Anti-Kaspersky stuff is likely just chest beating. I get it at the base level, and that AV software in general grants a much deeper reach that most softwares, but most likely they're not installing the same Kaspersky that anyone else is.

My current employer is a rather large non-US tech company, and we have custom branches for every product specifically made for the US Federal Government. It's all rebuilt from the ground up on US soil by US Nationals and the US Government has freedom to review the code.

It's the price you pay to play with the US Government. I would find it very hard to believe that Kaspersky doesn't have something similar.

For the vast majority of COTS software the US Government uses the same software versions as everyone else. This holds true for anti-virus software.
FWIW, the anti-Kaspersky train has been rolling for over three years.

Since the time that Kaspersky revealed (after Symantec) global co-ordinated state sponsored malware programs such as Reign, created by the NSA and GCHQ. https://www.theregister.co.uk/2014/12/05/regin_kaspersky/ https://en.wikipedia.org/wiki/Regin_(malware)

Or the time that Kaspersky publicly humiliated the NSA by revealing their hacking of hard drive firmware. https://www.dailykos.com/stories/2015/2/17/1364910/-Breaking... https://www.scmagazineuk.com/is-nsa-worlds-most-advanced-thr...

Since then, congressional hearings, committees, and US intel agencies' warnings of "security threats" from Kaspersky had been rolling out with regular frequency. Last year's ban was just a culmination of other efforts already underway.

Kaspersky's role of tracking nation-state malware inflitrations gives them a position as a quasi-intelligence agency. US intelligence agencies hate Kaspersky because they out every program the US has going on, and because they operate out of Moscow.

Literally every US intelligence agency has testified before Congress about how they specifically don't trust Kaspersky. https://www.npr.org/sections/parallels/2017/07/05/535651597/... So the US and its allies infiltrated their network and reverse engineered its software in order to find whatever dirt they could. https://www.observeit.com/blog/kaspersky-lab-nation-state-at... https://theintercept.com/2015/06/22/nsa-gchq-targeted-kasper...

The information they have on global intelligence operations, their location outside of an ally's control, their insistence on embarrassing nation states' covert operations and exploits, and the fact that their software isn't the most secure (https://www.forbes.com/sites/thomasbrewster/2015/09/23/googl...) has given the US government enough reason to want them out of their infrastructure. It's just politically untenable.

What makes you think the NSA employees felt humiliated?

Maybe they were proud that their work was publicly recognized.

Higher-ups understandably felt frustration that they needed to replace the program, but what makes you think that the employees didn't already anticipate that exploits and campaigns would get burned?

Is there a difference between a vendor issuing a patch or an organization's security response team cutting off access, and a anti-malware company doing its job to research campaigns?

If the NSA employees responsible were proud of the public exposure of their clandestine work, while it was still viable, the NSA hired the wrong people.
Everyone occasionally hires the wrong people.
* > Basically, Kaspersky's role of tracking nation-state malware inflitrations gives them a position as a quasi-intelligence agency. The US government didn't like that, because they constantly out the various programs going on, and because they operate out of Moscow. So the US and/or its allies infiltrated their network and reverse engineered its software in order to find whatever dirt they could. https://www.observeit.com/blog/kaspersky-lab-nation-state-at... https://theintercept.com/2015/06/22/nsa-gchq-targeted-kasper...

Is revenge the only motive to do this, if indeed it was the NSA (it's likely it is)? Wasn't there an allegation that Kaspersky software had exfiltrated NSA employees' and contractors inappropriately-stored classified material? Or wouldn't it makes sense for the NSA, an intelligence agency, to spy on a foreign company with good access to information about foreign officials?

Kaspersky didn't exfiltrate anything. An NSA contractor brought home classified files and put them on a machine on the internet that had Kaspersky AV. The AV tagged the files as malware and uploaded it to Kaspersky's servers to be analyzed. It's another ridiculous screw-up by the NSA that they had to cover for. https://www.nbcnews.com/news/investigations/russian-hackers-... Quote:

  "Not only is the work of the NSA and CIA increasingly visible, there is
  a certain aggression implied by this," he said. "It's a 'game-on' moment."
  
  Kaspersky, he said, should be treated as a hostile actor.
Israel was inside Kaspersky's network, found the Russians looking for US files (or so they claim) which had been just hanging around on their servers for a year, and so they notified the NSA about the breach. https://www.nytimes.com/2017/10/10/technology/kaspersky-lab-...

I don't believe any agency operates based on revenge. They operate based on politics. Can they really continue to fund this organization that is constantly pulling their pants down? Kaspersky's biggest flaw here is just having shit security.

Considering that non-malware related documents were reportedly taken, you're not telling the full story.

You make some good points.

That said, the politics of the NSA and the politics of Congress are often quite orthogonal and shouldn't be equated.

From the article:

"However, the anti-Kaspersky train picked up steam following revelations last year of a bizarre incident in which the company slurped up classified documents and source code from the home computer of a National Security Agency contractor running Kaspersky Internet Security software. That contractor, Nghia Hoang Pho, pleaded guilty last year to willfully mishandling classified material by taking it home.

"Kaspersky claimed the incident was an unintended byproduct of its routine malware scanning. The source code was for an NSA hacking tool, which Kaspersky’s product properly flagged for analysis by malware researchers. But because the code was bundled in a ZIP archive with the classified documents, Kaspersky’s software uploaded the entire thing. When Eugene Kaspersky realized what had happened, he ordered his researchers to immediately delete their copy of the documents and code, the company asserted in a blog post last year. “The archive was not shared with any third parties,” the company wrote."

Presumably, it was an isolated incident and we can trust Kaspersky's statement about their actions. No?

That was more than an allegation, Kaspersky has admitted it happened, and the person with the inappropriately stored classified material was found guilty.

The important thing to note that is the way it happened makes me comfortable in saying that all the big anti-virus products have received similar breaches of classified material and we just don't know about it. Any antivirus company that isn't sending unknown but suspicious code back for analysis is completely incompetent (this should be a setting for privacy reasons, but they need to make sure it is on where possible). You can accuse the various vendors of problems, but none are that incompetent.

You missed

"Even less hawkish U.S. officials worry that the company could be compelled under Russian law to weaponize their code to spy on U.S. government networks. The company works so closely with Russia’s Federal Security Service, or FSB, that agents are sometimes embedded in the firm’s Moscow headquarters."

("Agents" is likely an incorrect term (I hope) and is uselessly vague.)

I didn't miss it, I completely ignored it. It's well known that former FSB agents work at Kaspersky. But the insinuation that Russian agents could be working at Kaspersky isn't even speculation, it's just a hand-wavey allusion to some dastardly-yet-unknown plot.

Former NSA and other intelligence agents work at US AV companies, too. And the US regularly uses National Security Letters to covertly compel US companies to do their bidding. But they don't even have to.

The FBI uses its own signals intelligence branch when working with US companies, such as telcos and technology companies, on national security investigations. This sigint group then shares its information with other US intelligence agencies. So companies can claim they never passed information to the NSA, because they were only passing it to the FBI.

If we use the same rule to compare Russian and US antivirus companies, nobody should use either of them, because they have the same biases, the same ex-intelligence officers, and they can pass off information in a variety of ways and still maintain plausible deniability.

This should be fairly alarming to all parties, not the least of which being the government.

I mean, let's just hypothetically assume for a moment that Kaspersky is compromised and doing intel gathering for the Russian government. Can you think of a more perfect weapon than a compromised suite of software that is so deeply entrenched in a nation state's stack that they can't remove it, even if they wanted to?

On the contrary, as an American not involved in government work, Kaspersky is one few AV products I'd trust. American antivirus makers like Symantec, Comodo, McAfee, Microsoft (Defender), Webroot, and CheckPoint are all subject to secret warrants and infiltration by the US government. Others, like the UK's Sophos, would be subject to US influence as well.

You have to think about the motivations of each country. Even if Kaspersky were spying for the Russians, they won't give a damn about your porn, tax cheating, affairs, your padding of expense reports, or whatever they find on your computer. As an American, it's MY government that I'd have to worry about.

>they won't give a damn about your porn, tax cheating, affairs, your padding of expense reports, or whatever they find on your computer.

just at some moment in future, when you aren't some nobody like today and have become somebody meaningful, they would make you an offer you wouldn't be able to refuse - either all this collected info is sent to USG or ... Until that they would use it mostly for some innocuous stuff like what specific message to post in your feed to make you vote that specific way.

>Even if Kaspersky were spying for the Russians

when people say that "if" i'm always reminding myself that it is Western world, people have different mentality here. NSA here had to do _secret_ (or at least Google had to pretend so) tap to Google's fiber where is in Russia FSB has much better VPN into Kaspersky intranet than Kaspersky employees do :)

What's the basis of your accusation that FSB has overt access into Kaspersky's infrastructure?
It isn't accusation :) You're trying to apply Western standards in the domain of completely different standards.

And even applying Western standards this is what possible to say :

https://www.theguardian.com/technology/2017/oct/11/israel-ha...

"At the time, the Department of Homeland Security said it “is concerned about the ties between certain Kaspersky officials and Russian intelligence and other government agencies, and requirements under Russian law that allow Russian intelligence agencies to request or compel assistance from Kaspersky and to intercept communications transiting Russian networks”"

Notice that Kaspersky doesn't lie :

"In an official statement about the allegations, Kaspersky Lab said: “As a private company, Kaspersky Lab does not have inappropriate ties to any government, including Russia,"

as the keyword here is "inappropriate" which the above mentioned law clearly takes care of. Again, all these fine icing-on-the-cake details, like the law and "inappropriate", etc. are only for the Western consumption, as they just don't really matter in the Russian reality if only by virtue of being dwarfed by the things what do matter there. In that reality it would be a really "inappropriate", a faux pas of the scale that is even hard to imagine, if Kaspersky refused to work with FSB :)

Please share the sources or your reasoning.

Edit: thanks! I do recognize that I use Western thinking. Optimism and implicit trust are great!

"Even if Kaspersky were spying for the Russians, they won't give a damn about your porn, tax cheating, affairs, your padding of expense reports, or whatever they find on your computer"

How can you be so sure about that? You never know what they would need from you. You write on HackerNews - you are probably a computer professional, maybe an admin somewhere, but maybe you just know someone and you'd be useful to put pressure on that person? Think about the Swiss banker from the Snowden leak:

""" The Guardian said Snowden described a “formative” incident in which he claimed CIA operatives were attempting to recruit a Swiss banker to obtain secret banking information.

The operatives purposely got the banker drunk and encouraged him to drive home in his car, he told the newspaper.

When the banker was arrested for drunk driving, an undercover agent offered to help “and a bond was formed that led to successful recruitment”. """

The American agencies don't need to blackmail you - they can get access in many other ways.

True, there is that danger. However I have to trust somebody - I don't write anti-virus software. I suppose I could, but it takes time to get expertise in that, time that I wouldn't get to spend with my kids. Not to mention working alone I couldn't fight all the attacks on my computer in a timely manor without help, and thus I still have to depend on other people who might or might not be trustworthy.
You could use a platform that doesn't require anti-virus.
Platforms don't require AV software: people do. A security-minded user could live in Windows and never catch a virus. On the other hand, I've seen careless individuals become infected with the worst malware by downloading the wrong thing to their Mac.
By choosing Apple or Microsoft products, you are still going with a company under US jurisdiction, which is silly if you wanted to avoid US AV companies for that reason.
Oh, certainly! I'd even go as far as call irresponsible the use of any closed source software in situations that call for tight security. In this sense, choosing Mac, Windows or PutinOS (oh, how I wish such a thing existed!) carries exactly identical consequences.
> PutinOS

It's like Red Star OS, except it uses you!

Virus protection for the masses.
However, you still can get a virus from an exploit one without a patch deployed or a zero day. This require no action of your own. Although keeping your system up to date lessens the risk. It's not zero though.

Moreover, if your running anything that is not very niche or custom system people are probably targeting it. I am not sure I would call BSD niche enough. Also, even if you are using a niche system that does protect you against a targeted attack. If you were a government a target attack is much more likely. Honestly, unless you have 100% bug free software and hardware, and its designed with security in mind. The possibility of malware taking advantage of bugs exists.

Moreover, that excludes social engineering and getting someone to do something stupid. Even if the system normally is extremely secure.

If we are getting super serious considering all the firmware that exists in a computer. If a system ever ran code you did not audit you can never be sure that system is secure. Even if you have an AV. You would have to re-flash any firmware that could be written to by the CPU, and reinstall the OS as soon you ran code that you did not audit. I doubt there really is any system except small embedded systems that you can audit all the code that closely. Modern systems just have too many layers.

That isn't perfect. Viruses have been written for linux. It is harder to get them to spread, but they still are possible. There have been numerous vulnerabilities in various parts of the ecosystem - X is a nightmare for example.

I actually do run FreeBSD. I'm not so arrogant as to believe that the system is perfect, though there are a number of factors that make it more secure than average.

This is an absurd argument.

Why wouldn't the Russian government seek to take your secrets if it could? Employees at even the most mundane companies, such as SendGrid (email as a service) or Salesforce, have passwords and ssh keys that could permit access to infrastructure. That infrastructure contains valuable information when mined at scale.

How do you think these campaigns happen? All 0days? The most public recent nation-state hack, of the Clinton campaign, was done by a phishing page.

Yes, we are all targets to some degree of nation states.

That said, Kaspersky software is excellent. I would just disable the cloud upload portion of it.

Great point, I cannot stand when the argument is made: "I'd rather have Russian or Chinese backdoors in my software, than allow the possibilty of US authorities to have jurisdiction".

It would be better if one chooses their software based on trust, security audits, open source, etc.

FWIIW I use yandex instead of google for exactly the same reasons. The Russians are no doubt scoundrels, but I don't live there.
are the search results good? i feel like you can get the same results as google without the privacy violation by using a VPN or a search engine proxy like searx.
They vary over time (I assume they test different algos), but are mostly comparable to google. Qwant isn't bad either.
You think the American government cares about your porn and affairs?

Obviously they care about white collar crime, but I'd say committing the crimes is worse than the warrants to uncover them...

Kaspersky AV is an excellent product. For years it was the unrivaled market leader for non-signature-based malware detection in Windows operating systems. Its competitors are closing the gap, however. Qihoo 360 is also a good product.

Among the reverse engineering / exploit development crowd, I haven't heard much complaining about Symantec's detection mechanisms.

There are also bespoke anti-malware solutions marketed to the U.S. government, and they are not commercially available specifically to mitigate the risk that malware authors will test their products against anti-malware engines. These bespoke solutions are understandably far more expensive due to their smaller deployment and high quality.

It's reasonable that the U.S. government has to consider the need to have the best, reasonably affordable, commercially-available solution for the majority of its systems. This is balanced by the threat that the Russian Federation's government could interdict the software being delivered to the U.S. government client. Intermediate solutions, such as the project that Huawei set up with the UK government, or the source-code sharing that Microsoft does to get Russian contracts, seem to be optimal.

The U.S. Government doesn't want us using Kaspersky because Kaspersky blows the whistle on the back doors the gov't has installed in various software.
ClamAV is ripe for creating a FOSS disruption in this arena. If I were in a position of governmental power I would be pushing for foss solutions instead of proprietary black boxes that can't be audited.
Security today is very much about blind trust, certifications and not paying too much attention to the man behind the curtain. If your security software is open source anyone can point out its weaknesses.
Even then we still have the issue of binary blobs of firmware. Also hardware it's self may be exploitable. For a truly secure system everything would have to be audit-able. Also as soon as you run or insert anything into system you did not audit that whole system might as be treated as un-audited as well. Since what ever that was may have modified firmware or software.

That also exclude any subtle bugs that people may miss.