Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Perhaps I read it wrong, but the article never says Samsung didn't ship a keylogger, it just indicates that the AV software can make false positives based on a folder.

Can we get a link to an article that actually checks a Samsung laptop (and lists their methodology, not this "Duh, there were not any keyloggers") instead of anecdotal evidence and attacking the previous reseaerchers methods?

Even if the previous guy was wrong, at least he listed all his methods for review.



The article says two things:

1) The whole saga was caused by a bad antivirus alert. This story never even happens if not for that.

2) They checked a set of Samsung laptops and found no trace of keylogger software. See http://www.f-secure.com/weblog/archives/00002132.html

Is there more you'd like to see be done?


Yes (I did see the link back to the original article). Specifically, I'd like some more information about their methodology.

1) How did they verify there were no key loggers (is their AV program set to identify StarLogger instances) 2) What subset of Samsung laptops did they check 3) Did they check from more than one source 4) Did they verify that the laptops they checked haven't been wiped & reimaged with the local store's base computer image (such as with Best Buy)

With out some of this basic data, their findings are perhaps more suspect than the original article (not that I believe Samsung is doing this, I just disagree that their conclusions are as cut and dried as they, and the link title, indicate).


At this point we have no more evidence that Samsung has keyloggers than Thinkpads or MacBook Pros.

We really should be doing what you suggest for all brands and models of laptops. There's no evidence to suggest a specific issue with Samsung at this point.

Even the antivirus manufacturer who detected the problem has acknowledged they made a mistake.

http://sunbeltblog.blogspot.com/2011/03/samsung-laptops-do-n...

A pretty first class post in my opinion.

It would be like a newspaper reporting that "Falcolas kills 5 people!" And then turns out that you actually saved five people from drowning, and the newspaper prints a retraction. But then someone says, "But can you prove he didn't also kill five people at some point along the way? No one has really come out to say that he's never killed five people." Sure you may have, but at that point we have no reason to believe you have moreso than anyone else.


Sorry if I'm being unclear, but I simply have an issue with their conclusions (and the article title), particularly since their article doesn't support it.

Absence of evidence is not evidence of absence. An absence of evidence, plus noting the problem of the AV, is all that this article has.

The Ars Technica article [1] draws much better conclusions - "Samsung laptop keylogger almost certainly a false positive". It's a significantly more accurate conclusion than "Confirmed: Samsung is Not Shipping Keyloggers", given the data that we have at this point.

[1] http://arstechnica.com/hardware/news/2011/03/samsung-laptop-...


Yes.

1) What was in the SL directory? F-Secure claims the certified guy never inspected it. What about them, did they inspect it? They could have easily asked Hassan for a copy (insert appropriate caveats here about trusting sources). Sounds like they didn't even find one on their own, so how can they assert they know what it does not contain? They might not have gotten one of the laptops with the payload; that doesn't mean they don't exist.

2) How did the SL directory get there? F-Secure didn't even offer a theory.

3) Is Samsung installing keyloggers on a subset (random sample) of their machines?

4) I'd like to see it stated clearly, with no weasel words: Is F-Secure under contract with Samsung or do they have any business relationship with Samsung whatsoever? If not, are they angling for one?


Windows Live installs the SL directory for Slovenia language support. See my other post a little further down for the link.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: