Live data from Hacker News

Kaspersky OS

eugene.kaspersky.com

41–50 of 290 posts

Re: Kaspersky OS

#41
post #29
post #25

Earlier quoted context omitted.

Unbreakable? From a company based in Russia? Really?

Does Russia make backdoored hardware and software? Do you have proof of that? But we do have proof USA does that. See Snowden leaks.

No leaks doesn't mean there's nothing to leak.

Re: Kaspersky OS

#42
post #26
post #16

Earlier quoted context omitted.

I guess you'll have to trust him and his friends from the FSB (former KGB) :)

Do you make the same remarks when Google, Microsoft, Apple or Palantir releases software?

I have the impression that ever since Snowden happened, yes. Any mention of a non open source OS gets accompanied by remarks about NSA, FBI and co.

Re: Kaspersky OS

#44
post #24

No word on if this is FLOSS or not in the article so I'm assuming it'll be something closed. Which essentially renders the entire exercise moot form my POV. I also don't like how they mentioned Linux. They make it sound as if (a) Linux is very insecure...I'm no expert but I'd like to see them prove their system is more secure than a Linux distro dedicated to security. (b) Linux is the only viable option. There's plen…

"Anticipating your questions: not even the slightest smell of Linux. All the popular operating systems aren’t designed with security in mind, so it’s simpler and safer to start from the ground up and do everything correctly."

It looks like a realistic assessment. General purpose operating systems ( at least the 3 most famous ones ) are built with ease of use in mind, not security. Even Torvalds admits it, saying that he sees performance as a top priority, and not security.

If Kaspersky OS is more secure or not, we will see in the future.

Re: Kaspersky OS

#45
"not even the slightest smell of Linux."

So me too I have a dream. In my dream, every shop that needs two threads running and one semaphore synchronizing, will cease porting Linux and instead will roll up the sleeves, writes their own kernel 100% matching their need, prove its validity via formal verification and then use it.

In the world where this is possible, why would one go for a non-generic OS from a third party? Does look to me like Kaspersky might have that same vision for the future and tries to leverage their assets while it is not too late.

But security-by-brand-name is not really better than security-by-verification, isn't it?

Re: Kaspersky OS

#46
post #33
post #14

> All the popular operating systems aren’t designed with security in mind Kaspy OS runs on a switch, and they're talking about popular operating systems, so in the same vein, OpenBSD wouldn't be a popular secure OS for e.g. routers? But hey, I'd be really happy if they based it on seL4 and formally verified their security concepts. That would be a real game-changer. OTOH I'm really sceptical until they provide any re…

Also, in a microkernel-based system, verifying the kernel itself is but a start. To make a verifiably secure system for network infrastructure and IoT-devices, you need, at the very least, a provably correct IP stack. Want a nice web interface? Now you need to verify the HTTP server, too. Want to talk to other devices? You probably want a DNS resolver. And so forth... Simply signing code and having the OS refuse to e…

But isn't an isolation kernel enables you to limit spread of malware between modules and to detect when a module was compromised and reset it ? Isn't that a big improvement ?

Re: Kaspersky OS

#47
post #42
post #26

Earlier quoted context omitted.

Do you make the same remarks when Google, Microsoft, Apple or Palantir releases software?

I have the impression that ever since Snowden happened, yes. Any mention of a non open source OS gets accompanied by remarks about NSA, FBI and co.

Open source projects are not shielded from this either. Plenty of paranoia, justified or not, going around these days.

https://igurublog.wordpress.com/2014/04/08/julian-assange-de...

http://www.theverge.com/2013/12/20/5231006/nsa-paid-10-milli...

https://www.quora.com/Is-there-any-backdoor-left-in-Unix-or-...

https://blog.cloudflare.com/how-the-nsa-may-have-put-a-backd...

On one hand, we've been privy to some of NSA's operations, on the other, there is still a lot left to be disclosed, most will of course, never be out in the open.

Re: Kaspersky OS

#48
post #24

No word on if this is FLOSS or not in the article so I'm assuming it'll be something closed. Which essentially renders the entire exercise moot form my POV. I also don't like how they mentioned Linux. They make it sound as if (a) Linux is very insecure...I'm no expert but I'd like to see them prove their system is more secure than a Linux distro dedicated to security. (b) Linux is the only viable option. There's plen…

Yes I would not take their mention of Linux as a personal attack on your operating system of choice.

Treat it as someone saying "I don't like pizza" when you do like pizza - it means nothing to your enjoyment of pizza.

Re: Kaspersky OS

#49
post #5

There are no real details about the OS in the article. Did anybody here work on the project?

From what I heard from people that work there, this company mistreats employees and has huge problems with management. I could provide a proof link, but it's in Russian.

RMB - Translate to English.

Re: Kaspersky OS

#50
post #29
post #25

Earlier quoted context omitted.

Unbreakable? From a company based in Russia? Really?

Does Russia make backdoored hardware and software? Do you have proof of that? But we do have proof USA does that. See Snowden leaks.

Recent Russian legislation mandates backdoors:

http://arstechnica.com/tech-policy/2016/06/russias-new-spy-l...

Post reply on HN