Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Two weeks ago, the NSA accused the Russian SVR (intelligence agency) of exploiting vulnerabilities in US networks and suggesting that they were behind the SolarWinds compromise[1].

Now, Kaspersky (which is suspected to be affiliated with Russian intelligence - possibly unwillingly) claims to have found CIA malware (effectively "burning" it, if it's real).

The timing does not seem to be a coincidence. Tit-for-tat?

[1] https://www.nsa.gov/News-Features/Feature-Stories/Article-Vi...



> which is suspected to be affiliated with Russian intelligence - possibly unwillingly

I have yet to see actually compelling evidence that this is the case.



The Bloomberg articles are definitely the closest I've seen coming to substantive evidence, that is for sure.

I do, however, think that there is a big difference between being "affiliated with Russian intelligence" and providing an anti-DDOS service to the FSB, which is what this article is discussing, and really all it gives evidence for. Kapersky also provided services to the US intelligence services, I don't think it would be described as "affiliated with American intelligence."


Have you ever been in a wildly corrupt and centralised country? That frame of reference changes everything about what you just said - ie there are no “FSB contractors” that could possibly be independent under an authoritarian frame of reference.



This is not compelling evidence - the contractor had the "upload suspicious files" flag on and it uploaded flagged malware - this is consistent with pretty much every AV I've ever heard of and not evidence of a "Russian plot."


But CIA developing malware isn't news to anyone. How is this a tit-for-tat then?


Well, at least for once the general public wins. Let's hope they fight more this exact way, and less on every other way.


The tit-for-tat goes the other way:

1. expose malware the CIA doesn't want exposed

2. get accused by the CIA of being in bed with the Russians

"working for the Russians" is the go to baseless political smear these days


I would like to point out that a russian security company almost certainly has ties with the russian government. Particularly a very large, well respected one. It would be like accusing oracle or amazon of having ties with the US government.


Kaspersky himself is a 1987 KGB school alumni. The naïveté of Westerners is sometimes astonishing.


This is a very good point, and stands in stark contrast with no management or employees of FireEye or CrowdStrike ever being associated with FVEY intelligence services.

Nope, it's ONLY the evil Russians. The naïveté of non-Westerners is sometimes astonishing.


Kaspersky is the ever-presiding CEO and the founder of the company. Was CrowdStrike founded by a CIA alumni?

And I hope you realize your whole retort amounts to "Kaspersky is as bad as CIA shell companies".


The "well respected" part of that has partly to do with no evidence of them being partial.

If they were known as a kremlin puppet, they wouldn't be respected.


Ok you're right. I didn't know they were based in moscow. I tend to dismiss "The Russians" claim out of hand now.


Interesting. But if you had cited "my ass" as a source it would be more reliable, because the NSA is probably better at lying.


The parent commenter was sourcing "the NSA accused..." with the accusation, not making a claim as to whether the accusation was true.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: