No word on if this is FLOSS or not in the article so I'm assuming it'll be something closed. Which essentially renders the entire exercise moot form my POV. I also don't like how they mentioned Linux. They make it sound as if (a) Linux is very insecure...I'm no expert but I'd like to see them prove their system is more secure than a Linux distro dedicated to security. (b) Linux is the only viable option. There's plen…
Linux is very insecure. Maybe you have not been following the news lately.
Kaspersky OS
121–130 of 290 posts
Re: Kaspersky OS
#122Earlier quoted context omitted.
Agree, I'd like exactly to look closer inside "hard enough". First, it depends on each specification -- what if the hardware is much-much smaller (IoT) and task to perform is well defined? It is hard today primarily because the required skill set becomes less and less current, but it is all demand-driven, it was not so some time ago. Secondly, it could be replicated to some extent only -- for example, verified librar…
> what if the hardware is much-much smaller (IoT) and task to perform is well defined? Anything IoT needs a full network stack at least, and usually a set of radio drivers for WiFi, 6lowpan, Zigbee, Bluetooth or whatever. That usually amounts to quite a lot of software, which in the case of the radio stuff is often proprietary and patent-encumbered. Asking the hardware vendors is a dead end. You might as well ask for…
> Anything IoT needs a full network stack at least ...
My point really is, every IoT device would need only its part of the full network stack, not all the protocols currently implemented in, say, Linux, and chances are, some device will require extremely reduced subset of the network stack, especially at the lower layers and with respect to kernel interaction.
I am not a verification expert, but verifying a very reduced subset of a well-defined specs seems at least feasible -- how would we verify something open-ended? Those pesky little theorems would become much more general and would come in even greater numbers?
Verifying a generic OS, good for all devices and all application, if at all doable from theoretical standpoint, looks too much of work for no particular profit for the verifier (very similar to the validation of the Linux kernel which is relayed on to the distro builders).
I wouldn't be as pessimistic either about the hardware vendors. After all, (some of them) already use formal verification in (some of) the silicon design, and verifying closer to the silicon seems simpler -- the closer to the metal the less genericity (assuming the verified silicon underneath).
Re: Kaspersky OS
#123Only use it if you want to send all of your information to FSB (modern KGB). Evgeniy Kasperskiy has friends in government, police and FSB. He also is apologet of state surveillance.
Even your anti-virus companies has worked with the govt to allow some govt sponsored malware through.
Would be great if Kaspersky OS will be free and open source.
Re: Kaspersky OS
#124Only use it if you want to send all of your information to FSB (modern KGB). Evgeniy Kasperskiy has friends in government, police and FSB. He also is apologet of state surveillance.
Although I thought the same when I saw it, I think that's unfair. You could just as easily say Symantec/Norton/Microsoft Defender/Windows/Google is CIA/NSA. Since everything's being watched, Kaspersky might be just as much FSB as it is NSA, or any other country that could get its mitts on it. Cisco was definitely completely NSA there for a while, because of the backdoor. China's got Lenovo and every smart appliance,…
Isn't it, though? Apple seems to be the only company that has stood up to the three letter agencies. (I'm a US citizen.)
Re: Kaspersky OS
#125Earlier quoted context omitted.
What choice do we have? All other operating systems send your information either to NSA or China. State surveillance reigns supreme.
Great sweeping accusations require citations to back them up. Without any citations, the above statement is meaningless hyperbole. There are quite a few open source operating systems that you can personally verify that they protect your information appropriately.
That's basically what I was always telling myself in the back of my mind during the latest US election, every time I heard that the Wikileaks DNC email leaks were originating from Russia :D
Re: Kaspersky OS
#126Earlier quoted context omitted.
What choice do we have? All other operating systems send your information either to NSA or China. State surveillance reigns supreme.
That's a bizarre accusation and very easy to fact-check for yourself. It's trivial to run a packet sniffer and see all the information being sent out of your network. I know for sure that my apple and my linux boxes aren't making any network connections that I don't understand.
It's turtles all the way down.
Re: Kaspersky OS
#127Earlier quoted context omitted.
"Anticipating your questions: not even the slightest smell of Linux. All the popular operating systems aren’t designed with security in mind, so it’s simpler and safer to start from the ground up and do everything correctly." It looks like a realistic assessment. General purpose operating systems ( at least the 3 most famous ones ) are built with ease of use in mind, not security. Even Torvalds admits it, saying that…
OpenBSD is pretty popular in the security community , and is as FLOSS as it gets.
Then of course, I realized that by "Popular" he meant Mac OSX, Windows, and Linux.
Linux of course, we all know is a security mess because Torvalds refuses to deal with security issues.
Re: Kaspersky OS
#128Only use it if you want to send all of your information to FSB (modern KGB). Evgeniy Kasperskiy has friends in government, police and FSB. He also is apologet of state surveillance.
Iran and other SCO countries will be customers since they are friendly with Russia. I wonder if they are running it on Elbrus chips. That would make it extra super secure and Russian.
Re: Kaspersky OS
#129Re: Kaspersky OS
#130No word on if this is FLOSS or not in the article so I'm assuming it'll be something closed. Which essentially renders the entire exercise moot form my POV. I also don't like how they mentioned Linux. They make it sound as if (a) Linux is very insecure...I'm no expert but I'd like to see them prove their system is more secure than a Linux distro dedicated to security. (b) Linux is the only viable option. There's plen…
Linux is very insecure. Maybe you have not been following the news lately.
He places functionality over security, and assumes security will just 'happen' with code quality. I tend to disagree - but I am typing this from a Linux box, not an OpenBSD box. Because Linux is more functional as a desktop - the irony there isn't lost on me.