Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

End of Bibblio RCM includes -->
10/25/2017
01:00 PM
Simon Marshall
Simon Marshall
Simon Marshall

Will Transparency Save Kaspersky?

Kaspersky is trying radical transparency to counter accusations that it acts as a front for Russian intelligence. Will it be enough to quiet the skeptics?

In operating room terminology, it's time to open the patient up. Kaspersky Labs, suffering under a malaise of suspicion, just announced it will present its source code for inspection, in what it calls a new Global Transparency Initiative, aimed at enabling the specialists to pronounce a diagnosis.

Kaspersky is understandably sick of accusations flying around about the security resilience of its own software, and speculation that it is acting as a collaborator or distributor for Russian or Eastern European hackers and their allies.

Founder Eugene Kaspersky, chairman and CEO of Kaspersky Lab, said in a prepared statement, "Internet balkanization benefits no one except cybercriminals. Reduced cooperation among countries helps the bad guys in their operations, and public-private partnerships don't work like they should."

Asked to defend their position, Kaspersky Lab was unequivocal. "[We do] not have inappropriate ties to any government, which is why no facts have been presented publicly by anyone or any organization to back up the false allegations made against the company," a Kaspersky spokesperson told SecurityNow.

"The only conclusion seems to be that Kaspersky Lab, a private company, is caught in the middle of a geopolitical fight, and it is being treated unfairly even though the company has never helped, nor will help, any government in the world with its cyberespionage or offensive cyber efforts," she said.

Eugene Kaspersky
Eugene Kaspersky

Challenging criticism head-on is a huge roll of the dice for the security giant. If it's successful, then Kaspersky's code is ultimately verified, maybe gets a free tweak, and critics will need to put up or shut up. How the US government would respond to that is unclear. If it fails, Kaspersky's reputation will take an insufferable blow and there will be a rush to turn the software off at every endpoint as quickly as possible. Of course, and most likely, there will be a huge grey area between these potential polar outcomes, lengthening the scandal, and also enabling both parties to continually maneuver before any conclusions are reached.

Kaspersky formed an internal cross-functional team to prepare for its Global Transparency Initiative this past summer. When asked, they were not ready to talk about who will be doing the audit. What we do know is Kaspersky plans to have its source code, updates and threat detection rules reviewed by an outside contractor(s) during Q1 2018.

Within the same timeframe, its operations will come under scrutiny, including its development lifecycle processes, its software, and its supply chain risk mitigation strategies. Kaspersky will open three geographical 'transparency' centers of excellence in Europe, the US and Asia, where trusted partners will have access to reviews of the company's code, software updates, and threat detection rules, among other metrics.

At this point, Kaspersky has been entirely banned by the US Department of Homeland Security since mid-September, following an earlier removal by the General Services Administration from an approved supplier list. So, Kaspersky is up against the clock.

"Kaspersky are in an unfortunate situation," Michela Menting, digital security research director at ABI Research told SecurityNow. "As a Russian firm, with old ties to soviet military and FSB, the public condemnation by US government agencies ties into old and continued political rivalries. [It is] not helped by alleged Russian hacking of the US presidential elections. However, no proof has been provided by the agencies and so it makes it difficult to justify the ban."

Given there are so many variables in inspecting the source code, and then pressure to make a clear truth statement at the international, governmental level, can Kaspersky's initiative really work?

"I am not sure it will work for everyone, especially in North America. If the US government says no, then those contracting with the government will follow. They don't really have much choice," said Menting. "Certainly, the US government itself is unlikely to be deterred in the short term."

There are multiple questions about how effective a source code audit and be. Right now, it's unclear how Kaspersky would react in multiple theoretical scenarios. Predicting how some of them might play out is doubly difficult because some of them would apparently occur with Kaspersky's knowledge, some would not.

For example, is the base source code "safe"? Has it recently been hacked? Who would the potential hacking agencies be? Has Kaspersky modified its own code and unintentionally opened a door to exploit? If there are active threats or actions, is Kaspersky aware of them? If they exist, are they being treated. You get the picture.

I think the main question here is about how effective a source code audit can be, since, for one, it's only ever a snapshot of the code at any particular moment in time.

"That's true, and Kaspersky can show [only] what they want," said ABI's Menting. "I think the additional audits and controls, and the transparency centers will certainly help. I don't think that they would set this all up to fail, and I believe this is a legitimate effort to really cut down on the negative publicity and rumors."

Meantime, Kaspersky wants even more transparency participants. "We want to raise the bar by working with our customers, partners, independent experts, and the broader information security community to essentially crowdsource innovative ways to validate trustworthiness," said the spokesperson.

Kaspersky has applied the principles of transaprency to its own software in the past, publishing a list of vulnerabilities in its products and giving credit to the researchers who found the issues.

Related posts:

— Simon Marshall, Technology Journalist, special to Security Now

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Improving Enterprise Cybersecurity With XDR
Enterprises are looking at eXtended Detection and Response technologies to improve their abilities to detect, and respond to, threats. While endpoint detection and response is not new to enterprise security, organizations have to improve network visibility, expand data collection and expand threat hunting capabilites if they want their XDR deployments to succeed. This issue of Tech Insights also includes: a market overview for XDR from Omdia, questions to ask before deploying XDR, and an XDR primer.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-28200
PUBLISHED: 2022-07-02
NVIDIA DGX A100 contains a vulnerability in SBIOS in the BiosCfgTool, where a local user with elevated privileges can read and write beyond intended bounds in SMRAM, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can ext...
CVE-2022-32551
PUBLISHED: 2022-07-02
Zoho ManageEngine ServiceDesk Plus MSP before 10604 allows path traversal (to WEBINF/web.xml from sample/WEB-INF/web.xml or sample/META-INF/web.xml).
CVE-2022-32411
PUBLISHED: 2022-07-01
An issue in the languages config file of HongCMS v3.0 allows attackers to getshell.
CVE-2022-32412
PUBLISHED: 2022-07-01
An issue in the /template/edit component of HongCMS v3.0 allows attackers to getshell.
CVE-2022-34903
PUBLISHED: 2022-07-01
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.