Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

09 September 2015

Kaspersky Paranoia or Somethig More ??


Several months ago (March 2015), I wrote the below article elsewhere.  It references a Reuters and Daily Facts article.  Some found it to sound somewhat paranoid while others found it to be intriguing.

[March 2015] 

"Russian researchers expose breakthrough U.S. spying program" and "Kaspersky links US to spread of PC spyware across 30 countries"

Both titles are referring to the same article, with the first being affiliated with Reuters[1] and the second with the Daily Facts.[2]

I find this article interesting due to the allegations in the article where the NSA and or the CIA are considered responsible for the altering of hard drive firmware for purposes of spying.  I would not doubt whatsoever that this speculation is true or partially true considering a similarity between Stuxnet and this attack.

What I find incredibly fascinating is that once again, Kaspersky Labs has made the discovery of an incredibly brilliant and complex "malware" spying tool.  It really is amazing that Kaspersky Labs is known for most high profile discoveries involving complex malware and shedding light on hacking incidents where other companies seem to be ignorant.

Please follow the bouncing ball for one moment in an effort to entertain me as I don my tinfoil hat and begin to profess my long time belief about Kaspersky Labs, specifically Eugene Kaspersky. 

Wired Magazine conducted an interview[3] with Mr. Kaspersky a few years ago that was rather enlightening.  This interview was the king pin in what I believe to be part of a larger master plan... you still with me and my tinfoil hat?

Apparently, Mr. Kaspersky was a bright cryptologist recruited and sponsored by the KGB of that time and graduated from a five year program in 1987.

Knowing the past history with the former Soviet Union (USSR) and knowing that those in the KGB never leave - ever hear of Comrade "J"? 

Is it plausible that the plan all along was for Mr. Kaspersky to start his well respected anti-virus company as a mechanism into many of the U.S.A.'s companies and government systems?

I will take it a step further... what better foothold to establish for the day when the cyberwar begins... a foothold into the core economy, core infrastructure and other critical infrastructure components?  After all and unbeknownst to many, Kaspersky products are found within other products being used by everyday Americans.

What better way to amass needed information that could allow for a collaborative effort to hijack and destroy the U.S. economy and infrastructure?

One last thought before I remove this itchy tin hat... how does one lab (Kaspersky) consistently find the most sophisticated malware on the face of the planet before any others in the security realm? 

Are they really that good or could this be a case of Spy VS. Spy?  My guess is the latter of the two.

I would like to ask Mr. Kaspersky for the Powerball winning numbers since the odds of that prediction are approximately the same as Kaspersky Labs being on the forefront and discovery of every global cyber event.

MT>

1 http://www.reuters.com/article/2015/02/16/us-usa-cyberspying-idUSKBN0LK1QV20150216
2 http://daily-facts.net/kaspersky-links-us-to-spread-of-pc-spyware-across-30-countries-financial-times/ 
3 http://www.wired.com/2012/07/ff_kaspersky/


Now I fast forward to information and questions from David Vincenzetti of HackingTeam and a recent Reuters article found here.

Both are asking similar questions and pointing to anomalies similar to those I have pointed out in my March 2015 ranting about Kaspersky Labs and their incredible ability to ferret out the root cause of breaches as well as being the first on scene like an arsonist to a fire.

Just my crazy rants or is this a case of where there's smoke there's fire?

05 October 2014

Mitnick - Security Expert or Security Whore?

Rarely blogging, it's hard to be taken seriously - I know, enough said.

Kevin  Mitnick started his foray into "hacking" well before most reading this (if there is anyone reading this) were even born, as I doubt many over the age of forty-something read these types of articles.

If you are reading this, chances are that you already know who Mitnick is and why he has received so much notoriety - good and bad.
If you do not know of him, I'd recommend reading the Wikipedia page HERE before reading the rest of the post, else it really won't mean that much.

Kevin started into the computer age just a few years before I had.  It was a wonderful new world whereby many geeks were freed and came together to share in their geekdom.
The major differences between Kevin and those like Kevin and myself and those like myself was, and still is, integrity and respect for others.

In 1982ish, I too performed some low level "hacking" on a DEC that allowed me to access the neighboring rival school's system.  Of course their geeks thought that our geeks were not up to the challenge and "we" needed to disprove that misguided thought - no matter the cost.

It wasn't long before I and another were called to the principal's office and were asked a series of questions regarding the incident that had been discovered some two weeks later.  Only after listening to this voice of reason for what seemed to be an hour, I was sent on my way... fortunately with no real penalties.
I gave the interaction a bit of thought and realized that the geeky"new toys" that we had access to were not to be used to make people's lives more difficult but to enhance and assist lives - everywhere. That's not to say that "fun" and "pranks" don't have their place - we wrote many pieces of code that today would be deemed "viruses" or "malware".

That stated, Kevin had his fun and proved his points many times in the past - we all get it! Additionally, he made money with his nefarious doings, past and present.
Yes, he "did his time" for the wrong doings of the past, but now it seems that being away from the spotlight just isn't doing it for him.

I had read where Kevin was taking his consulting firm to the next level - at least in his eyes.  Kevin decided that "Zero Day" exploits could be a lucrative business and that his business model needed a shift.

Welcome the Kevin Mitnick 0-day exploit for hire business model!  Have a look HERE.

Knowing that we live in the United States of America, considered to the "freest" country in the world, I can understand how Kevin thinks this could be "good" idea.

Sadly and pathetically, this is far from a good idea and begs the question, "Was Kevin ever anything less than a 'whore' within the computer and security field?"
In my opinion, Kevin has "jumped the shark" with this business endeavor and has lost what little respect I had in reserve.

Mr. Mitnick has once again decided that "criminal type" behavior is where he likes to live.  I use the term "criminal type" because he's engaging in behavior that is not clearly criminal, just looks, walks and acts like that type of behavior... anyone remember the duck analogy?

This is really nothing less than old school pirate or mercenary behavior - period.

Plausible deniability has its roll here as you may be able to infer on his website.

Okay, so Kevin is the broker of "wrong-doing" but not the actual "wrong-doer"... that makes it so much better, right?

I am sure that every transaction will be throughly investigated so that the 0-days do not fall into the hands of the Devil.  Certainly these 0-days cannot be traced, certainly the buyers will abide by any type of professional Terms of Use, and the buyers would never pass it on to an insidious user of the 0-day - anyone every hear the term "straw purchase"?
After all, Kevin has never been known to do anything that would be deemed inappropriate or nefarious himself, right?

Regardless of the outcome of this "business", why would anyone consider Kevin Mitnick a security professional?
From this moment on, I hereby propose the title - Kevin Mitnick, Security Whore.