Live data from Hacker News

Kaspersky OS

eugene.kaspersky.com

61–70 of 290 posts

Re: Kaspersky OS

#62
post #24

No word on if this is FLOSS or not in the article so I'm assuming it'll be something closed. Which essentially renders the entire exercise moot form my POV. I also don't like how they mentioned Linux. They make it sound as if (a) Linux is very insecure...I'm no expert but I'd like to see them prove their system is more secure than a Linux distro dedicated to security. (b) Linux is the only viable option. There's plen…

"Anticipating your questions: not even the slightest smell of Linux. All the popular operating systems aren’t designed with security in mind, so it’s simpler and safer to start from the ground up and do everything correctly." It looks like a realistic assessment. General purpose operating systems ( at least the 3 most famous ones ) are built with ease of use in mind, not security. Even Torvalds admits it, saying that…

Which is funny, because they say that popular operating systems are not designed with security in mind. They give this as a reason to start from the ground up. I am from the camp saying that currently sole kernel does not an OS make. With this in mind network equipment OSes are certainly not popular ones. Nevertheless there are probably lots of less popular OSes with less popular kernels that are designed with security in mind. Some of them are probably good tries at such a goal. They could be used and extended and it would be probably better securitywise, because of years of bug fixes, that no new OS can have.

Re: Kaspersky OS

#63

Earlier quoted context omitted.

"Anticipating your questions: not even the slightest smell of Linux. All the popular operating systems aren’t designed with security in mind, so it’s simpler and safer to start from the ground up and do everything correctly." It looks like a realistic assessment. General purpose operating systems ( at least the 3 most famous ones ) are built with ease of use in mind, not security. Even Torvalds admits it, saying that…

OpenBSD is pretty popular in the security community , and is as FLOSS as it gets.

Yet it's not widely used as embedded OS. I never saw any router with OpenBSD or web camera.

The underlying problem, IMO, is people. They just don't care about security, they want to deliver working device.

Also it's not clear how many vulnerabilities, used in real life attacks (like DDOS from IoT devices) are in latest Linux kernel? May be problem not with Linux, but with custom software or lack of updates.

Re: Kaspersky OS

#64
Security through obscurity. I thought we all have learned that it doesn't work. Well, good riddance, KasperskyOS!

"And then there are some details that will remain for certain customers’ eyes only forever, to ward off cyber-terrorist abuses."

https://eugene.kaspersky.com/2012/10/16/kl-developing-its-ow...

Re: Kaspersky OS

#65
post #56
post #43

Closed source OS from an anti virus company with a dodgy history? I will pass.

Could you expand on the "dodgy history"? I always thought that Kaspersky was one of the "good guys"

Kaspersky had a history of working with Russian security agencies, has a lot of buddies there and a lot of people have throughout their careers moved from Kaspersky to these agencies and vice versa. If Russia will need somerhing from Kaspersky, government won't even need a warrant - he'll be happy to help.

Re: Kaspersky OS

#66
post #26
post #16

Earlier quoted context omitted.

I guess you'll have to trust him and his friends from the FSB (former KGB) :)

Do you make the same remarks when Google, Microsoft, Apple or Palantir releases software?

They don't have this kind of history with security agencies though.

Re: Kaspersky OS

#67

Earlier quoted context omitted.

OpenBSD is pretty popular in the security community , and is as FLOSS as it gets.

Yet it's not widely used as embedded OS. I never saw any router with OpenBSD or web camera. The underlying problem, IMO, is people. They just don't care about security, they want to deliver working device. Also it's not clear how many vulnerabilities, used in real life attacks (like DDOS from IoT devices) are in latest Linux kernel? May be problem not with Linux, but with custom software or lack of updates.

These two statements contradict each other:

> The underlying problem, IMO, is people. They just don't care about security, they want to deliver working device.

> This unassuming black box is [...] designed for networks with extreme requirements for data security.

You can claim that nobody will buy Kaspersky's device, or that they did poor market research. But you can't claim that they don't care about security.

Re: Kaspersky OS

#68
post #6

No mention of verification like seL4 or CertiKOS?

I understand CertiKOS used Coq so the verification was at least half-automated? How L4 was certified -- what were the tools available at the time? Verification still remains huge work but sounds less heroic nowadays. Now that we have tools and methodologies for verification, the announce of yet another secure OS suddenly sounds much less impressive.

Here is seL4 proof: https://github.com/seL4/l4v

To quote, "Most proofs in this repository are conducted in the interactive proof assistant Isabelle/HOL".

Re: Kaspersky OS

#69

Security through obscurity. I thought we all have learned that it doesn't work. Well, good riddance, KasperskyOS! "And then there are some details that will remain for certain customers’ eyes only forever, to ward off cyber-terrorist abuses." https://eugene.kaspersky.com/2012/10/16/kl-developing-its-ow...

I agree. What I find interesting is that real world security is also a function of popularity. You won't get many outside hackers to attack a platform, if it's hardly used.

So any new platform would first need broad adoption, then a few years of maturity in able for the outside world to assess if it's more secure than current systems.

Obviously, security centric design helps a lot, but on the other hand Kaspersky is a relatively small player in comparison with the other OS-movements (whether capitalist or FOSS).

Re: Kaspersky OS

#70
post #21

My suspicion is that most attempts to create a better OS for IoT will fail for political reasons. AFIAKT, one really important characteristic of Linux (and JavaScript also) for large tech companies is that they can control their own stacks, without having to license tech from another corporation, but still have the benefit of network effects. Samsung have Tizen, Google have ChromeOS etc. etc. At the component level,…

Speaking of OS's for IoT - I think http://www.contiki-os.org/ deserves a mention.
Post reply on HN