Surveillance and servility: is the AV industry a puppet of statecraft?


Samir Mody

K7 Computing, India
Editor: Helen Martin


‘Surveillance has been an instrument of statecraft for millennia.' Samir Mody, K7 Computing

Table of contents

(The views expressed herein are the author’s own. They do not reflect the policies or opinions of the author’s current employer or any other party.)

In a paper I submitted for the 2011 AVAR conference I stated the following: ‘There can be little doubt that the military and intelligence establishments of various nations have wings dedicated to cyber warfare ... Given the enormous resources involved and the high-profile, targeted nature of cyber attacks, it is difficult to predict the security responses of commercial anti-virus companies and the general public at large. It is likely that standard civilian bodies would largely be bystanders in these events.’ [1]

My opinion, forged on the anvil of revelations surrounding Stuxnet, Flame, Duqu and their ilk, has not changed over the past couple of years, notwithstanding an article [2] which landed in my inbox recently. The article refers to an open letter to the AV industry, which seeks clarification on the possible tacit collusion of the industry within the ambit of global statecraft, whether ratified in a partisan manner or not. I agree with Kurt Wismer, who points out that resourceful intelligence agencies ought to be at least as proficient as the common, albeit professional, cybercriminal in routinely bypassing modern security software, thus obviating the need to recruit AV industry partners. No strings being pulled here.

What about the concept of surveillance in the era of cyber warriorism? Surveillance has been an instrument of statecraft for millennia. 2,300 years ago, in his magnum opus Arthashastra, the Indian philosopher and statesman Kautilya described and, in fact, prescribed spying as an essential aspect of government policy in maintaining the security of the realm. In a democracy, it is the extent to and premise on which the denuded citizen is subjected to government voyeurism that raises concerns and generates heated debate.

Interestingly, survey findings revealed during Andrew Lee’s keynote address at this year’s VB Conference [3] suggest that a majority of the US public would support, or at any rate be indifferent to government surveillance if it were done in a transparent manner for the public good. The respondents’ views must reflect their threat perception and trust in governance at any given point in time. Therefore, the geographical location of the respondent, influenced by the narratives of history, is very important.

Let’s look at a brief case study. In August 2012, a mass exodus of Indian citizens of north-eastern origin (from various other parts of the country) was orchestrated via crude but effective misinformation propaganda, involving doctored visuals and threatening messages disseminated via various forms of social media. The context of ethnic skirmishes immediately preceding these events meant that the attack was sufficiently potent to effect a mass movement of people who believed themselves to be vulnerable. It took several days for the former status quo to prevail, providing a stark demonstration of the threat potential inherent in social networking. Perhaps a timely intervention by a vigilant agency could have nipped this attack in the bud. Indeed, in the context of national security, section 69(1 and A1) of the Indian IT Act authorizes designated government agencies to ‘intercept, monitor, decrypt…’ and ‘block for access…’ any computer-related data. If nothing else, at least the intent has been communicated transparently in the public domain. (Certain intrusive activities require a court warrant.) Nevertheless, concerns about the security of the collected data and its potential abuse are justified. (IT-related legislation across many democracies probably contains similar provisions in relation to national security.)

The Act, perforce, makes no mention of clandestine monitoring activity, or the need for private entities to enter into an insidious partnership with intelligence agencies. Let us not be naïve, however. Should these agencies wish to snoop, they don’t require the cooperation of AV vendors.



Latest articles:

EternalBlue: a prominent threat actor of 2017–2018

At the centre of last year's infamous WannaCry ransomware attack was an NSA exploit leaked by the Shadow Brokers hacker group, known as ‘EternalBlue’. The worm-like functionality of the exploit made a deadly impact by propagating to interconnected…

VB99 paper: Giving the EICAR test file some teeth

There are situations that warrant the use of live viruses. There are also situations where the use of live viruses is unwarranted. Specifically, live viruses should not be used when safer and equally effective methods can be used to obtain the…

Powering the distribution of Tesla stealer with PowerShell and VBA macros

Since their return more than four years ago, Office macros have been one of the most common ways to spread malware. In this paper, Aditya K Sood and Rohit Bansal analyse a campaign in which VBA macros are used to execute PowerShell code, which in…

VB2017 paper: Android reverse engineering tools: not the usual suspects

In the Android security field, all reverse engineers will probably have used some of the most well-known analysis tools such as apktool, smali, baksmali, dex2jar, etc. These tools are indeed must‑haves for Android application analysis. However, there…

VB2017 paper: Exploring the virtual worlds of advergaming

As adverts in gaming (‘advergaming’) ecosystems continue to become more sophisticated, so the potential complications grow for parents, children and gamers, who just want to play without having to worry about where their data is going (and how it is…

Bulletin Archive

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.