diabolus
Executive Member
Then again, who will you trust more with protecting us from this? Americans or Russians?
https://en.wikipedia.org/wiki/Equation_Group
EDIT: The more i read about this, the more scary it gets:
Read more: http://www.digitaltrends.com/comput...s-the-sledgehammer-is-unneeded/#ixzz3ihEqgbwq
..and then this :
https://www.schneier.com/blog/archives/2013/12/how_antivirus_c.html
...
leading into:
http://securityaffairs.co/wordpress/20648/intelligence/nsa-rsa-encryption-backdoor.html
and even more:
https://en.wikipedia.org/wiki/Magic_Lantern_(software)#Antivirus_vendor_cooperation
Now suddenly it sounds to me the USA based companies are much more dodgy when it comes to opening up backdoors for the USA spies/government... would you still trust Symantec?
https://en.wikipedia.org/wiki/Equation_Group
The Equation Group is a highly advanced secretive computer espionage group, identified by discoverers Kaspersky Labs as one of the most advanced (if not the most advanced) in the world as of 2015, and suspected by security expert Claudio Guarnieri[2] and unnamed former intelligence operatives[3] of being tied to the United States National Security Agency (NSA). Because of the group's predilection for strong encryption methods in their operations, the name Equation Group was chosen by Kaspersky Lab, who also documented 500 malware infections by the group's tools in at least 42 countries over many years.[4][5]
They also identified that the platform had at times been spread by interdiction (interception of legitimate CDs sent by a scientific conference organizer by mail),[1]:15 and that the platform had the "unprecedented" ability to infect and be transmitted through the hard drive firmware of several of the major hard drive manufacturers, and create and use hidden disk areas and virtual disk systems for its purposes, a feat demanding access to the manufacturer's source code of each to achieve,[1]:16-18 and that the tool was designed for surgical precision, going so far as to exclude specific countries by IP and allow targeting of specific usernames on discussion forums.[1]:23-26 The techniques and knowledge used by the Equation Group were considered in summary to be "out of the reach of most advanced threat groups in the world except [this group].[1]:31
EDIT: The more i read about this, the more scary it gets:
Read more: http://www.digitaltrends.com/comput...s-the-sledgehammer-is-unneeded/#ixzz3ihEqgbwq
The world woke up one morning in June of 2010 to discover the United States and Israel had been cooperating on a new form of malware, labeled Stuxnet. Targeted at Iranian uranium enrichment facilities, it upset the country’s centrifuges so discreetly that the country’s engineers didn’t realize there was a problem until it was too late.
Related: How Stuxnet crippled Iran’s nuclear dreams
While nation-state attacks weren’t unheard of, this was the first time a nation was caught actively harassing outside countries with a state-sponsored virus that could cause real, physical damage. It was widely speculated that the methods used were invented by the attacker that deployed Stuxnet, but it turns out the Group was behind it all along.
..and then this :
https://www.schneier.com/blog/archives/2013/12/how_antivirus_c.html
Even so, I joined a group of security experts to ask antivirus companies explicitly if they were ignoring malware at the behest of a government. Understanding that the companies could certainly lie, this is the response so far: no one has admitted to doing so.
Up until this moment, only a handful of the vendors have replied ESET, F-Secure, Norman Shark, Kaspersky, Panda and Trend Micro. All of the responding companies have confirmed the detection of state sponsored malware, e.g. R2D2 and FinFisher. Furthermore, they claim they have never received a request to not detect malware. And if they were asked by any government to do so in the future, they said they would not comply. All the aforementioned companies believe there is no such thing as harmless malware.
...
leading into:
http://securityaffairs.co/wordpress/20648/intelligence/nsa-rsa-encryption-backdoor.html
NSA paid 10M$ to RSA to insert an encryption backdoor in its solution
Last revelation based on the documents leaked by Edward Snowden is related to the allegedly encryption backdoor inserted by RSA in the BSafe software.
and even more:
https://en.wikipedia.org/wiki/Magic_Lantern_(software)#Antivirus_vendor_cooperation
Antivirus vendor cooperation
The public disclosure of the existence of Magic Lantern sparked a debate as to whether anti-virus companies could or should detect the FBI's keystroke logger.
Concerns include uncertainties about Magic Lantern's full potential and whether hackers could subvert it for purposes outside the jurisdiction of the law.[7][8]
Bridis reported that Network Associates (maker of McAfee anti-virus products), had contacted the FBI following the press reports about Magic Lantern to ensure their anti-virus software would not detect the program.[citation needed] Network Associates issued a denial, fueling speculation as to which anti-virus products might or might not detect government trojans.[9]
CNET News has surveyed 13 security companies about their contacts with and level of cooperation with law enforcement authorities.[10]
Graham Cluley, a technology consultant from Sophos, said "We have no way of knowing if it was written by the FBI, and even if we did, we wouldn’t know whether it was being used by the FBI or if it had been commandeered by a third party".[11] Another reaction from this came from Marc Maiffret, chief technology officer and cofounder of eEye Digital Security who states: "Our customers are paying us for a service, to protect them from all forms of malicious code. It is not up to us to do law enforcement's job for them so we do not, and will not, make any exceptions for law enforcement malware or other tools."[12]
When asked if Magic Lantern would need a court order to deploy, FBI spokesman Paul Bresson would not comment, stating: "Like all technology projects or tools deployed by the FBI it would be used pursuant to the appropriate legal process."[13][14] Proponents of Magic Lantern argue the technology would allow law enforcement to efficiently and quickly decrypt messages protected by encryption schemes. Implementing Magic Lantern does not require physical access to a suspect's computer, unlike Carnivore, a predecessor to Magic Lantern, since physical access to a computer would require a court order.[15]
Following the media coverage of Magic Lantern, F-Secure (a Finnish anti-virus company), announced their policy on detecting government spying programs: "F-Secure Corporation would like to make known that we will not leave such backdoors to our F-Secure Anti-Virus products, regardless of the source of such tools. We have to draw a line with every sample we get regarding whether to detect it or not. This decision-making is influenced only by technical factors, and nothing else, but within the applicable laws and regulations, in our case meaning EU laws.
We will also be adding detection of any program we see that might be used for terrorist activity or to benefit organized crime. We would like to state this for the record, as we have received queries regarding whether we would have the guts to detect something obviously made by a known violent mafia or terrorist organization. Yes we would."[16]
Now suddenly it sounds to me the USA based companies are much more dodgy when it comes to opening up backdoors for the USA spies/government... would you still trust Symantec?
Last edited: