Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

// // //
10/25/2017
01:00 PM
Simon Marshall
Simon Marshall
Simon Marshall

Will Transparency Save Kaspersky?

Kaspersky is trying radical transparency to counter accusations that it acts as a front for Russian intelligence. Will it be enough to quiet the skeptics?

In operating room terminology, it's time to open the patient up. Kaspersky Labs, suffering under a malaise of suspicion, just announced it will present its source code for inspection, in what it calls a new Global Transparency Initiative, aimed at enabling the specialists to pronounce a diagnosis.

Kaspersky is understandably sick of accusations flying around about the security resilience of its own software, and speculation that it is acting as a collaborator or distributor for Russian or Eastern European hackers and their allies.

Founder Eugene Kaspersky, chairman and CEO of Kaspersky Lab, said in a prepared statement, "Internet balkanization benefits no one except cybercriminals. Reduced cooperation among countries helps the bad guys in their operations, and public-private partnerships don't work like they should."

Asked to defend their position, Kaspersky Lab was unequivocal. "[We do] not have inappropriate ties to any government, which is why no facts have been presented publicly by anyone or any organization to back up the false allegations made against the company," a Kaspersky spokesperson told SecurityNow.

"The only conclusion seems to be that Kaspersky Lab, a private company, is caught in the middle of a geopolitical fight, and it is being treated unfairly even though the company has never helped, nor will help, any government in the world with its cyberespionage or offensive cyber efforts," she said.

Eugene Kaspersky
Eugene Kaspersky

Challenging criticism head-on is a huge roll of the dice for the security giant. If it's successful, then Kaspersky's code is ultimately verified, maybe gets a free tweak, and critics will need to put up or shut up. How the US government would respond to that is unclear. If it fails, Kaspersky's reputation will take an insufferable blow and there will be a rush to turn the software off at every endpoint as quickly as possible. Of course, and most likely, there will be a huge grey area between these potential polar outcomes, lengthening the scandal, and also enabling both parties to continually maneuver before any conclusions are reached.

Kaspersky formed an internal cross-functional team to prepare for its Global Transparency Initiative this past summer. When asked, they were not ready to talk about who will be doing the audit. What we do know is Kaspersky plans to have its source code, updates and threat detection rules reviewed by an outside contractor(s) during Q1 2018.

Within the same timeframe, its operations will come under scrutiny, including its development lifecycle processes, its software, and its supply chain risk mitigation strategies. Kaspersky will open three geographical 'transparency' centers of excellence in Europe, the US and Asia, where trusted partners will have access to reviews of the company's code, software updates, and threat detection rules, among other metrics.

At this point, Kaspersky has been entirely banned by the US Department of Homeland Security since mid-September, following an earlier removal by the General Services Administration from an approved supplier list. So, Kaspersky is up against the clock.

"Kaspersky are in an unfortunate situation," Michela Menting, digital security research director at ABI Research told SecurityNow. "As a Russian firm, with old ties to soviet military and FSB, the public condemnation by US government agencies ties into old and continued political rivalries. [It is] not helped by alleged Russian hacking of the US presidential elections. However, no proof has been provided by the agencies and so it makes it difficult to justify the ban."

Given there are so many variables in inspecting the source code, and then pressure to make a clear truth statement at the international, governmental level, can Kaspersky's initiative really work?

"I am not sure it will work for everyone, especially in North America. If the US government says no, then those contracting with the government will follow. They don't really have much choice," said Menting. "Certainly, the US government itself is unlikely to be deterred in the short term."

There are multiple questions about how effective a source code audit and be. Right now, it's unclear how Kaspersky would react in multiple theoretical scenarios. Predicting how some of them might play out is doubly difficult because some of them would apparently occur with Kaspersky's knowledge, some would not.

For example, is the base source code "safe"? Has it recently been hacked? Who would the potential hacking agencies be? Has Kaspersky modified its own code and unintentionally opened a door to exploit? If there are active threats or actions, is Kaspersky aware of them? If they exist, are they being treated. You get the picture.

I think the main question here is about how effective a source code audit can be, since, for one, it's only ever a snapshot of the code at any particular moment in time.

"That's true, and Kaspersky can show [only] what they want," said ABI's Menting. "I think the additional audits and controls, and the transparency centers will certainly help. I don't think that they would set this all up to fail, and I believe this is a legitimate effort to really cut down on the negative publicity and rumors."

Meantime, Kaspersky wants even more transparency participants. "We want to raise the bar by working with our customers, partners, independent experts, and the broader information security community to essentially crowdsource innovative ways to validate trustworthiness," said the spokesperson.

Kaspersky has applied the principles of transaprency to its own software in the past, publishing a list of vulnerabilities in its products and giving credit to the researchers who found the issues.

Related posts:

— Simon Marshall, Technology Journalist, special to Security Now

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Machine Learning, AI & Deep Learning Improve Cybersecurity
Machine intelligence is influencing all aspects of cybersecurity. Organizations are implementing AI-based security to analyze event data using ML models that identify attack patterns and increase automation. Before security teams can take advantage of AI and ML tools, they need to know what is possible. This report covers: -How to assess the vendor's AI/ML claims -Defining success criteria for AI/ML implementations -Challenges when implementing AI
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-3349
PUBLISHED: 2022-09-28
A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readupcasetable of the component exFAT Handler. The manipulation of the argument dataLength leads to heap-based buffer overflow. It is possible to launch the attack on the physical devi...
CVE-2022-40486
PUBLISHED: 2022-09-28
TP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401 Rel. 57450(5553) was discovered to allow authenticated attackers to execute arbitrary code via a crafted backup file.
CVE-2022-2760
PUBLISHED: 2022-09-28
In affected versions of Octopus Deploy it is possible to reveal the Space ID of spaces that the user does not have access to view in an error message when a resource is part of another Space.
CVE-2022-30935
PUBLISHED: 2022-09-28
An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users, and optionally reset their password. Tested and confirmed in...
CVE-2022-32166
PUBLISHED: 2022-09-28
In ovs versions v0.90.0 through v2.5.0 are vulnerable to heap buffer over-read in flow.c. An unsafe comparison of “minimasks� function could lead access to an unmapped region of memory. This vulnerability is capable of crashing the software, memory modification...