Closed source OS from an anti virus company with a dodgy history? I will pass.
Kaspersky OS
61–70 of 290 posts
Re: Kaspersky OS
#62No word on if this is FLOSS or not in the article so I'm assuming it'll be something closed. Which essentially renders the entire exercise moot form my POV. I also don't like how they mentioned Linux. They make it sound as if (a) Linux is very insecure...I'm no expert but I'd like to see them prove their system is more secure than a Linux distro dedicated to security. (b) Linux is the only viable option. There's plen…
"Anticipating your questions: not even the slightest smell of Linux. All the popular operating systems aren’t designed with security in mind, so it’s simpler and safer to start from the ground up and do everything correctly." It looks like a realistic assessment. General purpose operating systems ( at least the 3 most famous ones ) are built with ease of use in mind, not security. Even Torvalds admits it, saying that…
Re: Kaspersky OS
#63Earlier quoted context omitted.
"Anticipating your questions: not even the slightest smell of Linux. All the popular operating systems aren’t designed with security in mind, so it’s simpler and safer to start from the ground up and do everything correctly." It looks like a realistic assessment. General purpose operating systems ( at least the 3 most famous ones ) are built with ease of use in mind, not security. Even Torvalds admits it, saying that…
OpenBSD is pretty popular in the security community , and is as FLOSS as it gets.
The underlying problem, IMO, is people. They just don't care about security, they want to deliver working device.
Also it's not clear how many vulnerabilities, used in real life attacks (like DDOS from IoT devices) are in latest Linux kernel? May be problem not with Linux, but with custom software or lack of updates.
Re: Kaspersky OS
#64"And then there are some details that will remain for certain customers’ eyes only forever, to ward off cyber-terrorist abuses."
https://eugene.kaspersky.com/2012/10/16/kl-developing-its-ow...
Re: Kaspersky OS
#65Closed source OS from an anti virus company with a dodgy history? I will pass.
Could you expand on the "dodgy history"? I always thought that Kaspersky was one of the "good guys"
Re: Kaspersky OS
#66Re: Kaspersky OS
#67Earlier quoted context omitted.
OpenBSD is pretty popular in the security community , and is as FLOSS as it gets.
Yet it's not widely used as embedded OS. I never saw any router with OpenBSD or web camera. The underlying problem, IMO, is people. They just don't care about security, they want to deliver working device. Also it's not clear how many vulnerabilities, used in real life attacks (like DDOS from IoT devices) are in latest Linux kernel? May be problem not with Linux, but with custom software or lack of updates.
> The underlying problem, IMO, is people. They just don't care about security, they want to deliver working device.
> This unassuming black box is [...] designed for networks with extreme requirements for data security.
You can claim that nobody will buy Kaspersky's device, or that they did poor market research. But you can't claim that they don't care about security.
Re: Kaspersky OS
#68No mention of verification like seL4 or CertiKOS?
I understand CertiKOS used Coq so the verification was at least half-automated? How L4 was certified -- what were the tools available at the time? Verification still remains huge work but sounds less heroic nowadays. Now that we have tools and methodologies for verification, the announce of yet another secure OS suddenly sounds much less impressive.
To quote, "Most proofs in this repository are conducted in the interactive proof assistant Isabelle/HOL".
Re: Kaspersky OS
#69Security through obscurity. I thought we all have learned that it doesn't work. Well, good riddance, KasperskyOS! "And then there are some details that will remain for certain customers’ eyes only forever, to ward off cyber-terrorist abuses." https://eugene.kaspersky.com/2012/10/16/kl-developing-its-ow...
So any new platform would first need broad adoption, then a few years of maturity in able for the outside world to assess if it's more secure than current systems.
Obviously, security centric design helps a lot, but on the other hand Kaspersky is a relatively small player in comparison with the other OS-movements (whether capitalist or FOSS).
Re: Kaspersky OS
#70My suspicion is that most attempts to create a better OS for IoT will fail for political reasons. AFIAKT, one really important characteristic of Linux (and JavaScript also) for large tech companies is that they can control their own stacks, without having to license tech from another corporation, but still have the benefit of network effects. Samsung have Tizen, Google have ChromeOS etc. etc. At the component level,…