Live data from Hacker News

Kaspersky OS

eugene.kaspersky.com

11–20 of 290 posts

Re: Kaspersky OS

#12
post #5

There are no real details about the OS in the article. Did anybody here work on the project?

From what I heard from people that work there, this company mistreats employees and has huge problems with management. I could provide a proof link, but it's in Russian.

Go ahead and provide it, Russian or not.

Re: Kaspersky OS

#13
It sounds very interesting, for sure, but the announcement is a little thin on details. The OS is apparently based around a microkernel. Which sounds good, but AFAIK, microkernels are comparatively popular in the embedded space (think QNX, L4) - so that choice is not in itself revolutionary.

They mention signatures, and it kind of sounds as if the OS will refuse to execute any non-signed code. Again, sounds like a good idea in principle, but remember how Stuxnet came with - IIRC - two valid signatures created with stolen keys. It might be better than nothing, but to an attacker with sufficiently deep pockets, no quantum computers are needed.

Of course, those are just random thoughts popping into my head. I should wait for more details before passing judgment. A (verifiably?) secure OS for embedded and "IoT" devices would be very desirable, that much is certain.

Re: Kaspersky OS

#14
> All the popular operating systems aren’t designed with security in mind

Kaspy OS runs on a switch, and they're talking about popular operating systems, so in the same vein, OpenBSD wouldn't be a popular secure OS for e.g. routers?

But hey, I'd be really happy if they based it on seL4 and formally verified their security concepts. That would be a real game-changer. OTOH I'm really sceptical until they provide any relevant details.

Re: Kaspersky OS

#15

Haha! I am curious how long will it take to have it completely cracked.

On the basis that the grander the announcement, the greater the motivation to break it, I reckon about 20 minutes.

Re: Kaspersky OS

#16

Will this be open source, or will we have to trust Kapersky that it is secure?

I guess you'll have to trust him and his friends from the FSB (former KGB) :)

Re: Kaspersky OS

#17
How is this more secure than any other L3 switch with an out of band (or otherwise hardened) management interface?

I'm not going to say no one is attacking switches, but that's definitely not where I'd start.

Re: Kaspersky OS

#18
Given that there's not only software bugs, but the hardware ones, I wonder how secure it would be. I personally hate their software, but still, it would be nice to know.

P.S. Security without open-sourcing is impossible. Although, dunno how for other countries, but here in Russia some people have a different point of view.

Some people believe that “opensource is insecure by design, because everyone can see the code”. Probably Kaspersky has the same point.

Re: Kaspersky OS

#19
post #15

Haha! I am curious how long will it take to have it completely cracked.

On the basis that the grander the announcement, the greater the motivation to break it, I reckon about 20 minutes.

Correct! Kaspersky has just placed a MASSIVE TARGET on his back.

Understandably, investors do want catchy stories and media buzz... :)

Re: Kaspersky OS

#20
My thoughts went as follows - Interesting..., Hmmm Not much real information..., hope its open source..., is this for network appliances or for general use..., again if isn't open source I really don't care.
Post reply on HN