The Canadian Communications Security Establishment -- the most secretive of Canada's spy agencies -- has released the sourcecode for Assemblyline, a "Swiss Army Knife for malware analysis" that rolls up several malware analysis tools into a single unit, which can scan files for known malware and also assign a score to files indicating the likeliness that the file has a previously unseen form of malware.
The move is most welcome, and exemplifies the ways that security services can serve the mission of national security by rooting out malware and vulnerabilities. It's a real contrast to this year's meeting in Ottawa where Australia's top spy proposed deliberately introducing vulnerabilities into commonly used tools to preserve spies' ability to hack their adversaries./
The possibility that CSE's own tool could be used to detect spy software of its own design, or that of its partners, is not lost upon the agency.
"Whatever it detects, whether it be cybercrime or [nation] states, or anybody else that are doing things — well that's a good thing, because it's made the community smarter in terms of defence," said Jones.
Nor does he believe that releasing Assemblyline to the public will make it easier for adversaries to harm the government, or understand how CSE hunts for threats — quite the opposite, in fact.
"We believe that the benefits far outweigh any risks and that we can still use this to be ahead of the threat that's out there."
Canada's 'super secret spy agency' is releasing a malware-fighting tool to the public
Many large-scale data-breaches involve attackers gaining access to administrators' database logins; from there, they can clone the whole database and plunder it at will; but leading nosql database vendor Mongodb proposes to add another layer of security it's calling "Field Level Encryption" which encrypts the data in database fields with its own key -- possibly […]
Stalkerware -- spyware sold to people as a means of keeping tabs on their romantic partners, kids, employees, etc -- is a dumpster fire of terrible security (compounded by absentee management), sleazy business practices, and gross marketing targeted at abusive men who want to spy on women.
I recently wrote about how much I enjoyed testing the OnePlus 7 Pro. One of the nicer things about it was the fact that its in-display fingerprint reader, unlike the one in the last-gen OnePlus handset, works in a timely manner. Too bad that, no matter how quickly it can read a fingerprint, it still […]
This all-in-one computing solution packs a healthy dose of processing power packed inside a 21.5″ HD LED display. It also features an Intel Core i3-2100 Dual-Core 3.1GHz CPU with 4 GB of DDR3 RAM for next-level multitasking and an impressive 250 GB SATA hard drive that can safely store your important files and media. So […]
So you cut the cord and got rid of cable? Join the steadily growing club. But while you’re out picking a streaming service, you might find one big blind spot: Local TV and sports, not to mention first-run programming from the big cable networks. Luckily, there’s a throwback way to get it for free: The […]
Even if you feel like AirPods are worth the price tag, you’ve got to admit there’s a certain anxiety that comes with using them. What if I lose them? What if they get wet in the rain? Or drenched in sweat? Or fall into the drink you dropped them into? Shiny tech is great, but […]