Do antivirus companies whitelist NSA malware?

Mathew J. Schwartz writes: Dear antivirus vendors: Are you aiding and abetting National Security Agency (NSA) spying?

That’s the subject of an open letter, sent in October to leading antivirus vendors, from 25 different privacy information security experts and organizations. The letter asks the vendors to detail whether they’ve ever detected state-sponsored malware or received a government request to whitelist state-sponsored malware, and how they would respond to any such requests in the future.

The letter, sent from Dutch digital rights foundation Bits of Freedom, requested that the firms respond by November 15. “Please let us know if you feel that you cannot, or cannot fully, answer any of the above questions because of legal constraints imposed upon you by any government,” it said.

“Since we learned that the NSA has surreptitiously weakened Internet security so it could more easily eavesdrop, we’ve been wondering if it’s done anything to antivirus products,” letter signatory Bruce Schneier, chief security technology officer of BT, said in a blog post. “Given that it engages in offensive cyberattacks — and launches cyberweapons like Stuxnet and Flame — it’s reasonable to assume that it’s asked antivirus companies to ignore its malware. We know that antivirus companies have previously done this for corporate malware.”

As of two weeks ago, however, only six security vendors — ESET, F-Secure, Kaspersky Lab, Norman Shark, Panda, and Trend Micro — had responded to the request for information. [Continue reading…]

Print Friendly, PDF & Email
Facebooktwittermail