GCHQ and NSA broke antivirus software so that they could spy on people, leaks indicate
Spy agencies intercepted emails about vulnerabilities so that they could use them, according to reports
Your support helps us to tell the story
From reproductive rights to climate change to Big Tech, The Independent is on the ground when the story is developing. Whether it's investigating the financials of Elon Musk's pro-Trump PAC or producing our latest documentary, 'The A Word', which shines a light on the American women fighting for reproductive rights, we know how important it is to parse out the facts from the messaging.
At such a critical moment in US history, we need reporters on the ground. Your donation allows us to keep sending journalists to speak to both sides of the story.
The Independent is trusted by Americans across the entire political spectrum. And unlike many other quality news outlets, we choose not to lock Americans out of our reporting and analysis with paywalls. We believe quality journalism should be available to everyone, paid for by those who can afford it.
Your support makes all the difference.The British and American spy agencies deliberately broke anti-virus software so that they could read the messages of their citizens, according to new leaks.
Both the NSA and GCHQ have long been said to have deliberately reversed engineer software so that they could find weaknesses in software and exploit them to read communications. But new documents show that the agencies did so to some of the most popular antivirus software, potentially exposing hundreds of millions of people to dangerous viruses, according to a report from The Intercept.
The agencies reverse engineered Kaspersky antivirus software so that they could see how it worked and ensure that it didn’t keep them from looking through computers, according to the report. They also looked through emails that had been sent to the company flagging up viruses and vulnerabilities, the Intercept reported.
Antivirus software picks up dangerous code of various kinds, including malware that looks what people are typing and doing that is often made by states as well as criminals. Attacking such software may have allowed the agencies to keep it from recognising threats from governments, as well as exploiting known vulnerabilities to get in.
Software like Kaspersky also runs with higher privileges on a computer — because it must have access to the whole system to ensure that it is kept safe, another person like a criminal or a government having access to it could use that to infiltrate the computer at a deep and dangerous level.
GCHQ obtained a warrant for the reverse engineering because it might otherwise be considered “unlawful”, according to The Intercept, which saw the details of the request for permission in files leaked by Edward Snowden. The Intercept says that the warrant is “legally questionable on several grounds”.
Join our commenting forum
Join thought-provoking conversations, follow other Independent readers and see their replies
Comments