Do you still trust Kaspersky AV?

Then again, who will you trust more with protecting us from this? Americans or Russians?

https://en.wikipedia.org/wiki/Equation_Group
The Equation Group is a highly advanced secretive computer espionage group, identified by discoverers Kaspersky Labs as one of the most advanced (if not the most advanced) in the world as of 2015, and suspected by security expert Claudio Guarnieri[2] and unnamed former intelligence operatives[3] of being tied to the United States National Security Agency (NSA). Because of the group's predilection for strong encryption methods in their operations, the name Equation Group was chosen by Kaspersky Lab, who also documented 500 malware infections by the group's tools in at least 42 countries over many years.[4][5]

They also identified that the platform had at times been spread by interdiction (interception of legitimate CDs sent by a scientific conference organizer by mail),[1]:15 and that the platform had the "unprecedented" ability to infect and be transmitted through the hard drive firmware of several of the major hard drive manufacturers, and create and use hidden disk areas and virtual disk systems for its purposes, a feat demanding access to the manufacturer's source code of each to achieve,[1]:16-18 and that the tool was designed for surgical precision, going so far as to exclude specific countries by IP and allow targeting of specific usernames on discussion forums.[1]:23-26 The techniques and knowledge used by the Equation Group were considered in summary to be "out of the reach of most advanced threat groups in the world except [this group].[1]:31


EDIT: The more i read about this, the more scary it gets:
Read more: http://www.digitaltrends.com/comput...s-the-sledgehammer-is-unneeded/#ixzz3ihEqgbwq

The world woke up one morning in June of 2010 to discover the United States and Israel had been cooperating on a new form of malware, labeled Stuxnet. Targeted at Iranian uranium enrichment facilities, it upset the country’s centrifuges so discreetly that the country’s engineers didn’t realize there was a problem until it was too late.

Related: How Stuxnet crippled Iran’s nuclear dreams

While nation-state attacks weren’t unheard of, this was the first time a nation was caught actively harassing outside countries with a state-sponsored virus that could cause real, physical damage. It was widely speculated that the methods used were invented by the attacker that deployed Stuxnet, but it turns out the Group was behind it all along.


..and then this :

https://www.schneier.com/blog/archives/2013/12/how_antivirus_c.html
Even so, I joined a group of security experts to ask antivirus companies explicitly if they were ignoring malware at the behest of a government. Understanding that the companies could certainly lie, this is the response so far: no one has admitted to doing so.

Up until this moment, only a handful of the vendors have replied ESET, F-Secure, Norman Shark, Kaspersky, Panda and Trend Micro. All of the responding companies have confirmed the detection of state sponsored malware, e.g. R2D2 and FinFisher. Furthermore, they claim they have never received a request to not detect malware. And if they were asked by any government to do so in the future, they said they would not comply. All the aforementioned companies believe there is no such thing as harmless malware.

...


leading into:
http://securityaffairs.co/wordpress/20648/intelligence/nsa-rsa-encryption-backdoor.html
NSA paid 10M$ to RSA to insert an encryption backdoor in its solution

Last revelation based on the documents leaked by Edward Snowden is related to the allegedly encryption backdoor inserted by RSA in the BSafe software.



and even more:

https://en.wikipedia.org/wiki/Magic_Lantern_(software)#Antivirus_vendor_cooperation
Antivirus vendor cooperation

The public disclosure of the existence of Magic Lantern sparked a debate as to whether anti-virus companies could or should detect the FBI's keystroke logger.

Concerns include uncertainties about Magic Lantern's full potential and whether hackers could subvert it for purposes outside the jurisdiction of the law.[7][8]

Bridis reported that Network Associates (maker of McAfee anti-virus products), had contacted the FBI following the press reports about Magic Lantern to ensure their anti-virus software would not detect the program.[citation needed] Network Associates issued a denial, fueling speculation as to which anti-virus products might or might not detect government trojans.[9]

CNET News has surveyed 13 security companies about their contacts with and level of cooperation with law enforcement authorities.[10]

Graham Cluley, a technology consultant from Sophos, said "We have no way of knowing if it was written by the FBI, and even if we did, we wouldn’t know whether it was being used by the FBI or if it had been commandeered by a third party".[11] Another reaction from this came from Marc Maiffret, chief technology officer and cofounder of eEye Digital Security who states: "Our customers are paying us for a service, to protect them from all forms of malicious code. It is not up to us to do law enforcement's job for them so we do not, and will not, make any exceptions for law enforcement malware or other tools."[12]

When asked if Magic Lantern would need a court order to deploy, FBI spokesman Paul Bresson would not comment, stating: "Like all technology projects or tools deployed by the FBI it would be used pursuant to the appropriate legal process."[13][14] Proponents of Magic Lantern argue the technology would allow law enforcement to efficiently and quickly decrypt messages protected by encryption schemes. Implementing Magic Lantern does not require physical access to a suspect's computer, unlike Carnivore, a predecessor to Magic Lantern, since physical access to a computer would require a court order.[15]

Following the media coverage of Magic Lantern, F-Secure (a Finnish anti-virus company), announced their policy on detecting government spying programs: "F-Secure Corporation would like to make known that we will not leave such backdoors to our F-Secure Anti-Virus products, regardless of the source of such tools. We have to draw a line with every sample we get regarding whether to detect it or not. This decision-making is influenced only by technical factors, and nothing else, but within the applicable laws and regulations, in our case meaning EU laws.

We will also be adding detection of any program we see that might be used for terrorist activity or to benefit organized crime. We would like to state this for the record, as we have received queries regarding whether we would have the guts to detect something obviously made by a known violent mafia or terrorist organization. Yes we would."[16]

Now suddenly it sounds to me the USA based companies are much more dodgy when it comes to opening up backdoors for the USA spies/government... would you still trust Symantec?
 
Last edited:
Nothing I would care to talk about.
Good! (was actually joking in general ;))

Just spotted this to add some perspective to what I was saying earlier:
http://www.valuewalk.com/2015/08/russia-vs-china-vs-us-cyber-war/

The perception of which of the countries is most likely to be in the wrong certainly differs greatly depending on your geographical location. Naturally, in the United States it is frequently reported that both China and Russia pose a significant threat to American security. But reporting in the two Eastern nations can be significantly different, and fairly recently Russian publications suggested that indeed the United States had already unleashed a form of cyber warfare against both Russia and China.
 
Kaspersky Lab deliberately fed bogus malware to its rivals to sabotage their antivirus products, two anonymous former employees allege. Kaspersky says the accusations are false.

Reuters reported today that two ex-Kaspersky engineers claim they were tasked with tricking competing antivirus into classifying benign executables and other files as malicious. Anti-malware tools from Microsoft, AVG and Avast were targeted, apparently.

http://www.theregister.co.uk/2015/08/14/kasperskygate/
 
When my ESET expires I'm going back to Kaspersky. They are simply the most secure in the business. Also, ESET's crappy firewall has driven me up the wall too often to warrant a renewal.
 
Here we go with yet another anti-Russia hysterical post from Ghoti and his clones.

There is no evidence Kaspersky has any links to FSB. Note that in his OP he uses the more emotive KGB to stir the pot. Anyone can see he's just spouting troll propaganga once more.

In a cyber world where Window 10 is allegedly collecting yoiur info, Facebook is allegedly doing something similar (yes, US companies) he wants to continue the US v Russia cold war in the business context.

Perhaps I could suggest we ignore his well-known paranoia.

Here's the Kaspersky response, which he's ignored (of course, since it doesn't fit his agenda).

--
Eugene Kaspersky, founder and CEO of the multibillion dollar private software security group, slammed the recent Bloomberg article as “sensationalist” and “false,” asking whether it could be linked to Equation Group revelations by his firm.

The Bloomberg article, with the catchy headline “The Company Securing Your Internet Has Close Ties to Russian Spies” was published on Thursday.

It alleges that Kaspersky Lab, a private software security company owned by Russian national Eugene Kaspersky, ignores Russian electronic espionage cases , while only unveils cybercrimes in the “US , Israel, and the EU.”

On Friday, Kaspersky published a response to these accusations saying they are “false”.

“It’s been a long time since I read an article so inaccurate from the get-go – literally from the title and the article’s subheading. So it came as little surprise that a large part of the rest of the article is simply false. Speculations, assumptions and unfair conclusions based on incorrect facts,” he wrote.

“The journalists don’t mention that we are impartial in our fight against cybercrime, no matter where it strikes. A warning, dear readers: don’t believe everything you read!”


More ...
http://www.rt.com/news/242725-report-russian-bloomberg-kaspersky/
 
Conniving, underhanded posers who resort to discrediting their junior peers for validation. Wait, isn't that what the State department does.
Russia is a very large country with a huge base of well-educated people with software skills. We can expect hackers (black and white hat).
 
Kaspersky faked malware to harm rivals, ex-employees claim

Beginning more than a decade ago, one of the largest security companies in the world, Moscow-based Kaspersky Lab, tried to damage rivals in the marketplace by tricking their antivirus software programs into classifying benign files as malicious, according to two former employees.
They said the secret campaign targeted Microsoft, AVG, Avast and other rivals, fooling some of them into deleting or disabling important files on their customers' PCs.
Some of the attacks were ordered by Kaspersky Lab's co-founder, Eugene Kaspersky, in part to retaliate against smaller rivals that he felt were aping his software instead of developing their own technology, they said.


"Eugene considered this stealing," said one of the former employees. Both sources requested anonymity and said they were among a small group of people who knew about the operation.
Kaspersky Lab strongly denied that it had tricked competitors into categorising clean files as malicious, so-called false positives.
"Our company has never conducted any secret campaign to trick competitors into generating false positives to damage their market standing," Kaspersky said in a statement to Reuters. "Such actions are unethical, dishonest and their legality is at least questionable."

Executives at Microsoft, AVG and Avast previously told Reuters that unknown parties had tried to induce false positives in recent years. When contacted this week, they had no comment on the allegation that Kaspersky Lab had targeted them.

The Russian company is one of the most popular antivirus software makers, boasting 400 million users and 270,000 corporate clients. Kaspersky has won wide respect in the industry for its research on sophisticated Western spying programs and the Stuxnet computer worm that sabotaged Iran's nuclear program in 2009 and 2010.

The two former Kaspersky Lab employees said the desire to build market share also factored into Kaspersky's selection of competitors to sabotage.
"It was decided to provide some problems" for rivals, said one ex-employee. "It is not only damaging for a competing company but also damaging for users' computers."

The former Kaspersky employees said company researchers were assigned to work for weeks or months at a time on the sabotage projects.
Their chief task was to reverse-engineer competitors' virus detection software to figure out how to fool them into flagging good files as malicious, the former employees said.

The opportunity for such trickery has increased over the past decade and a half as the soaring number of harmful computer programs have prompted security companies to share more information with each other, industry experts said. They licensed each other's virus-detection engines, swapped samples of malware, and sent suspicious files to third-party aggregators such as Google's VirusTotal.

By sharing all this data, security companies could more quickly identify new viruses and other malicious content. But the collaboration also allowed companies to borrow heavily from each other's work instead of finding bad files on their own.

Kaspersky Lab in 2010 complained openly about copycats, calling for greater respect for intellectual property as data-sharing became more prevalent.

In an effort to prove that other companies were ripping off its work, Kaspersky said it ran an experiment: It created 10 harmless files and told VirusTotal that it regarded them as malicious. VirusTotal aggregates information on suspicious files and shares them with security companies.
Within a week and a half, all 10 files were declared dangerous by as many as 14 security companies that had blindly followed Kaspersky's lead, according to a media presentation given by senior Kaspersky analyst Magnus Kalkuhl in Moscow in January 2010.
When Kaspersky's complaints did not lead to significant change, the former employees said, it stepped up the sabotage.

Injecting bad code

In one technique, Kaspersky's engineers would take an important piece of software commonly found in PCs and inject bad code into it so that the file looked like it was infected, the ex-employees said. They would send the doctored file anonymously to VirusTotal.
Then, when competitors ran this doctored file through their virus detection engines, the file would be flagged as potentially malicious. If the doctored file looked close enough to the original, Kaspersky could fool rival companies into thinking the clean file was problematic as well.
VirusTotal had no immediate comment.

In its response to written questions from Reuters, Kaspersky denied using this technique. It said it too had been a victim of such an attack in November 2012, when an "unknown third party" manipulated Kaspersky into misclassifying files from Tencent , Mail.ru and the Steam gaming platform as malicious.

The extent of the damage from such attacks is hard to assess because antivirus software can throw off false positives for a variety of reasons, and many incidents get caught after a small number of customers are affected, security executives said.

The former Kaspersky employees said Microsoft was one of the rivals that were targeted because many smaller security companies followed the Redmond, Washington-based company's lead in detecting malicious files. They declined to give a detailed account of any specific attack.
Microsoft's antimalware research director, Dennis Batchelder, told Reuters in April that he recalled a time in March 2013 when many customers called to complain that a printer code had been deemed dangerous by its antivirus program and placed in "quarantine."

Batchelder said it took him roughly six hours to figure out that the printer code looked a lot like another piece of code that Microsoft had previously ruled malicious. Someone had taken a legitimate file and jammed a wad of bad code into it, he said. Because the normal printer code looked so much like the altered code, the antivirus program quarantined that as well.

Over the next few months, Batchelder's team found hundreds, and eventually thousands, of good files that had been altered to look bad. Batchelder told his staff not to try to identify the culprit.

"It doesn't really matter who it was," he said. "All of us in the industry had a vulnerability, in that our systems were based on trust. We wanted to get that fixed."

In a subsequent interview last week, Batchelder declined to comment on any role Kaspersky may have played in the 2013 printer code problems or any other attacks. Reuters has no evidence linking Kaspersky to the printer code attack.

As word spread in the security industry about the induced false positives found by Microsoft, other companies said they tried to figure out what went wrong in their own systems and what to do differently, but no one identified those responsible.

At Avast, a largely free antivirus software maker with the biggest market share in many European and South American countries, employees found a large range of doctored network drivers, duplicated for different language versions.

Avast Chief Operating Officer Ondrej Vlcek told Reuters in April that he suspected the offenders were well-equipped malware writers and "wanted to have some fun" at the industry's expense. He did not respond to a request for comment on the allegation that Kaspersky had induced false positives.
Waves of attacks

The former employees said Kaspersky Lab manipulated false positives off and on for more than 10 years, with the peak period between 2009 and 2013.

It is not clear if the attacks have ended, though security executives say false positives are much less of a problem today.
That is in part because security companies have grown less likely to accept a competitor's determinations as gospel and are spending more to weed out false positives.

AVG's former chief technology officer, Yuval Ben-Itzhak, said the company suffered from troves of bad samples that stopped after it set up special filters to screen for them and improved its detection engine.

"There were several waves of these samples, usually four times per year. This crippled-sample generation lasted for about four years. The last wave was received at the beginning of the year 2013," he told Reuters in April.

AVG's chief strategy officer, Todd Simpson, declined to comment.

Kaspersky said it had also improved its algorithms to defend against false virus samples. It added that it believed no antivirus company conducted the attacks "as it would have a very bad effect on the whole industry."

"Although the security market is very competitive, trusted threat-data exchange is definitely part of the overall security of the entire IT ecosystem, and this exchange must not be compromised or corrupted," Kaspersky said.


Read more: http://www.theage.com.au/it-pro/sec...yees-claim-20150817-gj0joh.html#ixzz3j3Fk9jvP
 
When my ESET expires I'm going back to Kaspersky. They are simply the most secure in the business. Also, ESET's crappy firewall has driven me up the wall too often to warrant a renewal.

I have no problem with eset beyond its lower detection rate. Giving bitdefender a try on one of my PC`s and so far I am pleasantly surprised.
 
Here we go with yet another anti-Russia hysterical post from Ghoti and his clones.

Firstly I dont have clones here. Obviously there are other people kicking your ass to touch and you feel like those are me. I actually dont spend a lot of time on the forum lately due to other responsibilities taking up my time. Secondly, I have no problem with Russian people and I stated its a beautiful piece of software, my problem is with the Russian government. I dont trust them at all. They are pretty much a debase government as you can get. You should learn to separate the two.

I do follow Russia on all my news feeds as what happens there is of great interest to me. I work closely with friends in Russia and Ukraine to try help (in my own tiny way) them get back control of their respective countries. I havent posted 99% of the stuff that happens in Russia. Just about every day another ludicrous law or rule is passed there that curtails human rights and Russian freedom. Though I should start posting that stuff here more often. As it appears some people are intentionally blind to it.
 
Last edited:
I have no problem with eset beyond its lower detection rate. Giving bitdefender a try on one of my PC`s and so far I am pleasantly surprised.
Bitdefender is probably the only antivirus I won't touch with a ten foot pole. It gave me such grief that I'll never give it another go. Not even a month of correspondence with their support could solve the network issues Bitdefender gave me.

Once it was uninstalled and replaced with AVG everything returned to normal. AVG was alright but I gave Kaspersky a try after that and liked it more. Then I tried ESET, which I'm still using. It's been decent, but after this I'll go back to Kaspersky.
 
Bitdefender is probably the only antivirus I won't touch with a ten foot pole. It gave me such grief that I'll never give it another go. Not even a month of correspondence with their support could solve the network issues Bitdefender gave me.
I used to be anti-bitdefender. Had a bad experience with them around 8 years ago. Thats why I havent touched them till now, which I guess is why I was pleasantly surprised.

Once it was uninstalled and replaced with AVG everything returned to normal. AVG was alright but I gave Kaspersky a try after that and liked it more. Then I tried ESET, which I'm still using. It's been decent, but after this I'll go back to Kaspersky.

If I just had normal data I would consider it, but my data could put other people at risk so not in a rush to risk it. Even if the risk is tiny.
 
If I just had normal data I would consider it, but my data could put other people at risk so not in a rush to risk it. Even if the risk is tiny.

If you're not compiling your own OS right down to evaluating the BIOS in assembly code, then there is always a chance viralware can slip past. There is no reason why you can't use more than one virus software, pared with email server protection and 3rd party firewalls.

If you are scared that Kaspersky is in cahoots with Russian intelligence bent on world domination, you could get a squid proxy to limit accessible servers and record every web transaction. Then you can compare traffic with Kaspersky's update servers on a binary basis with other computers and see what the discrepancy might be. This will give you peace of mind, but ultimately the best antivirus is no antivirus and using your computer only for what it is intended. I mean how can you trust your own staff over a reputable av company?
 
Firstly I dont have clones here. Obviously there are other people kicking your ass to touch and you feel like those are me. I actually dont spend a lot of time on the forum lately due to other responsibilities taking up my time. Secondly, I have no problem with Russian people and I stated its a beautiful piece of software, my problem is with the Russian government. I dont trust them at all. They are pretty much a debase government as you can get. You should learn to separate the two.

I do follow Russia on all my news feeds as what happens there is of great interest to me. I work closely with friends in Russia and Ukraine to try help (in my own tiny way) them get back control of their respective countries. I havent posted 99% of the stuff that happens in Russia. Just about every day another ludicrous law or rule is passed there that curtails human rights and Russian freedom. Though I should start posting that stuff here more often. As it appears some people are intentionally blind to it.
You constantly post anything anti-Russia. Conjecture and no substance.

Most are single words without content, like a round of applause or jeer that adds nothing.

Given the global rhetoric surrounding Russia and its leader - and your own condition, it isn't surprising that the paranoia comes to the surface.
 
Top
Sign up to the MyBroadband newsletter
X