US officials: Kaspersky “Slingshot” report burned anti-terror operation(arstechnica.com)
arstechnica.com
US officials: Kaspersky “Slingshot” report burned anti-terror operation
https://arstechnica.com/information-technology/2018/03/kaspersky-slingshot-report-apparently-exposed-us-military-cyber-ops/
35 コメント
I'm not sure what's particularly newsworthy about this - an anti-malware tool/outfit found malware. It's not as though Kaspersky could, or arguably should, know the source was the US military. It'd probably be a bigger story if Kaspersky was overlooking government sanctioned malware.
It seems odd that there’s coverage that “this put US lives in danger.”
Is there any action that Kaspersky or the general public should take to mitigate this risk? Is the suggestion that we shouldn’t work to eliminate malware in case it serves some higher purpose.
Will there be a new US law requiring checking with a secret government agency before publishing and patching exploits? Will it matter to non-US firms?
Maybe this secretly currently happens. No way to confirm, currently, and not productive to speculate.
Is there any action that Kaspersky or the general public should take to mitigate this risk? Is the suggestion that we shouldn’t work to eliminate malware in case it serves some higher purpose.
Will there be a new US law requiring checking with a secret government agency before publishing and patching exploits? Will it matter to non-US firms?
Maybe this secretly currently happens. No way to confirm, currently, and not productive to speculate.
Indeed, it's a very strange line that hasn't been called-out sufficiently in rhetoric.
What does "put lives in danger" really mean? It seems to be a deliberate blurring of the lines of culpability.
Most things "put lives in danger," in some sense (a just war, the invention of the automobile, rock climbing). Obviously the benchmark for what is acceptable must be much stricter than "put lives in danger," particularly when it's the lives militants.
What does "put lives in danger" really mean? It seems to be a deliberate blurring of the lines of culpability.
Most things "put lives in danger," in some sense (a just war, the invention of the automobile, rock climbing). Obviously the benchmark for what is acceptable must be much stricter than "put lives in danger," particularly when it's the lives militants.
Yup, it sounds like Kaspersky was doing their job. It seems incredibly disingenuous to say that they endangered people by doing so.
> It seems incredibly disingenuous to say that they endangered people by doing so.
Not really, it could be a fact based on knowledge. Although I’d agree it would be disingenuous to say it was intentional.
Not really, it could be a fact based on knowledge. Although I’d agree it would be disingenuous to say it was intentional.
[deleted]
Kaspersky, as both an security firm and an agent of the Russian state, certainly has the capacity to identify the probable source of APTs.
As Slingshot is a US-originated APT deployed against ISIS in Syria and Iraq, and the US is in conflict with the Russian state in Syria, it's a newsworthy question as to what aspect of Kaspersky's job is most relevant here.
As Slingshot is a US-originated APT deployed against ISIS in Syria and Iraq, and the US is in conflict with the Russian state in Syria, it's a newsworthy question as to what aspect of Kaspersky's job is most relevant here.
Unless the US Military is being extremely careless, attribution of malware is extremely difficult and, aside from leaks, almost impossible to accurately attribute.
A large security company or a nation state can absolutely attribute malware originating from nation-states (APTs) with a high degree of confidence.
We are not talking about some recombinant script kiddie malware: Slingshot is attributable, Stuxnet was attributable, the DNC penetration was attributable.
Nation-states with mature cyberwarfare capabilities, and their appendages such as Kaspersky, are routinely capable of identifying the authors of novel malware.
We are not talking about some recombinant script kiddie malware: Slingshot is attributable, Stuxnet was attributable, the DNC penetration was attributable.
Nation-states with mature cyberwarfare capabilities, and their appendages such as Kaspersky, are routinely capable of identifying the authors of novel malware.
> It's not as though Kaspersky could, or arguably should, know the source was the US military.
Indeed. Often a primary goal of operations such as that is to conceal and make attribution as difficult as possible.
Indeed. Often a primary goal of operations such as that is to conceal and make attribution as difficult as possible.
The final paragraph of the article is weird.
"Kaspersky's exposure of the program will likely not win the company any points in its battle to get off a US federal government blacklist."
Is that just rhetorical flourish? Or is Kaspersky actually going to be penalized for doing their jobs? Is there an implication that other security companies have been "recruited" by the government to turn a blind eye towards government-sponsored malware?
"Kaspersky's exposure of the program will likely not win the company any points in its battle to get off a US federal government blacklist."
Is that just rhetorical flourish? Or is Kaspersky actually going to be penalized for doing their jobs? Is there an implication that other security companies have been "recruited" by the government to turn a blind eye towards government-sponsored malware?
Six months ago I speculated (https://news.ycombinator.com/item?id=15242367) that Kaspersky was banned from US Govt use due to not playing ball with a political entity in the government. Now we know that simply by pursuing their normal business objectives, Kaspersky has hurt the government's counterterrorism efforts.
This could've happened by accident, but the way they were treated over several years by the intelligence services, military and Congress to me says Government knew this would eventually happen and tried (and failed) to get them to not flag this kind of malware. It's possible that by not agreeing to curtail research of certain malware, they were punished by having their contracts taken away.
This could've happened by accident, but the way they were treated over several years by the intelligence services, military and Congress to me says Government knew this would eventually happen and tried (and failed) to get them to not flag this kind of malware. It's possible that by not agreeing to curtail research of certain malware, they were punished by having their contracts taken away.
Makes you wonder if American antivirus companies are instructed not to reveal American military malware.
To guard against that you could theoretically scan using a wide range of international antivirus companies. But the problem with that is that the militaries are using the antivirus software themselves as an attack vector. Kaspersky was recently caught stealing American government secrets via its software. It's impossible to know who to trust.
To guard against that you could theoretically scan using a wide range of international antivirus companies. But the problem with that is that the militaries are using the antivirus software themselves as an attack vector. Kaspersky was recently caught stealing American government secrets via its software. It's impossible to know who to trust.
Remember that most windows antivirus (except perhaps Microsoft's own) patches into the operating system somewhat similar to malware itself to do all the things it does.
Malware programs patching the same parts of the OS are likely to trip over each other.
Such a combination would be highly unstable, not to speak of incredible slow.
Malware programs patching the same parts of the OS are likely to trip over each other.
Such a combination would be highly unstable, not to speak of incredible slow.
The amercian government secrets Kapsersky was "stealing" turned out to be US sponsored malware. Which is exactly what a good anti-virus is supposed to do. But if you want something more NSA friendly, you can always use McAffee who announced a few years ago that they will happily turn a blind eye on NSA&FBI malware.
You don't know that. Nobody knows anything because this is all spy vs spy stuff so it's impossible to know what news reports are real or propaganda or disinformation. But fwiw:
- WSJ: Russian Hackers Stole NSA Data on U.S. Cyber Defense: https://www.wsj.com/articles/russian-hackers-stole-nsa-data-...
- NYT: Israelis hacked into Kapersky and caught them using their software as "a sort of Google search for sensitive information" https://www.nytimes.com/2017/10/10/technology/kaspersky-lab-...
- WSJ: Russian Hackers Stole NSA Data on U.S. Cyber Defense: https://www.wsj.com/articles/russian-hackers-stole-nsa-data-...
- NYT: Israelis hacked into Kapersky and caught them using their software as "a sort of Google search for sensitive information" https://www.nytimes.com/2017/10/10/technology/kaspersky-lab-...
> McAffee who announced a few years ago that they will happily turn a blind eye on NSA&FBI malware.
Source?
Source?
Note that as the military themselves said, this is just their "cost of doing business".
This highlights the need for independent security organizations located in mutually unfriendly political jurisdictions.
To use an analogy, this would be like blaming the developer of an antibiotic or anticholinergic for rendering your weaponized anthrax or nerve gas ineffective. Cyberweapons can easily fall into the hands of criminals (especially given their low-bar for deployment) and the marginal cost of using them is almost nothing. For an example, see WannaCry, which used the EternalBlue vector also developed by the US.
[deleted]
When the FSB exposes NSA/CIA hacking, that's an NSA/CIA failure. Their (very technically difficult) job includes not allowing enemy agencies to expose their activities.
Cold War 2.0 rages on.
Cold War 2.0 rages on.
An argument could be made that the US government should try to make nice with Kaspersky, instead of provoking them to be an enemy. Then maybe this would have played out differently, with a bit more sensitivity to US concerns.
I think the military simply needs to do a better job. After all plenty of covert operations have been exposed in the pass due to innocent civilian observation, thus the military does a better job of hiding things.
And indeed, if kaspersky could find something than various sophisticated adversaries certainly could too. So why bother to court that one private company?
And indeed, if kaspersky could find something than various sophisticated adversaries certainly could too. So why bother to court that one private company?
Well I wasn't saying court them... there is a spectrum of ways to treat companies. Courting is at the far end, right now the US is at the opposite end of that spectrum with respect to its treatment of Kaspersky. Being more toward the middle of the spectrum would also be a possibility.
[Edit: ok, "make nice" (my words) does sound like courting, but I was thinking of it in a more neutral way.]
That being said, I really don't know whether Kaspersky deserves the treatment it's gotten... not having followed their behavior closely. It very well may, for all I know. But it's possible there is blowback from that.
[Edit: ok, "make nice" (my words) does sound like courting, but I was thinking of it in a more neutral way.]
That being said, I really don't know whether Kaspersky deserves the treatment it's gotten... not having followed their behavior closely. It very well may, for all I know. But it's possible there is blowback from that.
> So why bother to court that one private company?
Because they've seemingly been the leading antivirus company for years? In terms of vulnerabilities found, at least.
Because they've seemingly been the leading antivirus company for years? In terms of vulnerabilities found, at least.
Sounds like an argument that's probably constantly being made. And constantly being weighed against perceptions of Kaspersky's actions, priorities and good-vs-bad faith mix.
Good work by Kaspersky. This doesn't look good for their competitors. Either they didn't know about the attacks, or they permitted it to happen.
If it is your goal to prevent your enemies from learning about your activities, and then someone stumbles upon those activities in the course of their normal work, but doesn't realize who is responsible for said activities, then your huffing and puffing about your absolute dire need to operate in secrecy is revealed to all as pure theater when you fill in those very details yourself to reporters you summoned.
I have zero pity for the US anti-terror operation. Digital weapons are dangerous and must be rendered ineffective through security patches, no matter who made them and who used them.
But the last guys that made big bad weapons with unforeseen consequences weren't as smart as we are. Trust us, this time is different.
The US security establishment unfortunately is an unreliable source for such claims. For example, off the top of my head consider the original stories about Jessica Lynch, Pat Tillman, the people imprisoned in Guantanamo (who originally were identified as all serious threats, but turned out to be mostly otherwise), testimony on NSA activities, exaggerations of the consequences of Snowden's leaks (IIRC), and many more. They seem to claim what suits them until proven otherwise, and like to attack leakers and journalism.
That's a problem in a democracy, where we need to vote on these issues, because we rarely have other sources for secret information. But trusting an inaccurate source because you lack another, while tempting, is flawed reasoning. Better to say, 'I don't know'.
I wonder if some parts of the security establishment are more reliable than others. There are some individuals I trust more than others, at least.
That's a problem in a democracy, where we need to vote on these issues, because we rarely have other sources for secret information. But trusting an inaccurate source because you lack another, while tempting, is flawed reasoning. Better to say, 'I don't know'.
I wonder if some parts of the security establishment are more reliable than others. There are some individuals I trust more than others, at least.
I agree. You can't maintain credibility by telling everyone that you are the only legal source of information about a subject, even if that subject is yourself. Because in situations like these, the facts of the case look indistinguishable from an operation that was revealed by an unofficial, unauthorized source.
That tells me that there are in fact times they would like the general public to know about their operations, and separately, those unauthorized sources seem to match the official ones a lot of the time. With that established, we can move on to trying to discern their motivations when they decide it is important we know the details of their operations, and why they would seemingly go against the very advice that they so rabidly bark to everyone else.
That tells me that there are in fact times they would like the general public to know about their operations, and separately, those unauthorized sources seem to match the official ones a lot of the time. With that established, we can move on to trying to discern their motivations when they decide it is important we know the details of their operations, and why they would seemingly go against the very advice that they so rabidly bark to everyone else.