Live data from Hacker News

Kaspersky OS

eugene.kaspersky.com

161–170 of 290 posts

Re: Kaspersky OS

#161

Earlier quoted context omitted.

But comparatively speaking is still more secure than Windows or OS X?

Depends on who you ask, for example, taking the top 50 products with new vulnerabilities discovered in 2016[1], Windows 10 got less vulnerabilities than the Linux Kernel and OS X. This could either mean that Windows 10 has become more secure than its most popular competitors, or that researchers hadn't invested enough resources to audit Windows 10 properly. Taking into account the results from previous years and prev…

Well, there's also how serious the vulnerabilities are. Linux kernel had 4 code execution vulns, Windows 10 had 44. Linux had 44 gain privilege vulns, Windows 10 had 79. Linux seemed to have mostly DoS vulns, which is admittedly not great, but I'd rather a server go down then get compromised and used to take over the rest of the network. Then there's the fun stuff, like mimikatz, that's been around since windows XP and still can pull passwords from windows 10...

Re: Kaspersky OS

#162

Earlier quoted context omitted.

But comparatively speaking is still more secure than Windows or OS X?

The biggest issue with Windows isn't its inherent security, it's the way it's used. Most users run everything with super admin rights. Most developers require that for installs. OSX is right behind it, with a culture of laxness that undoes most of the benefits the designers tried to give them.

I've run into "security software" for domain computers that required every computer to have the same local admin password... and for it to be enabled on every computer.

Re: Kaspersky OS

#163
post #21

My suspicion is that most attempts to create a better OS for IoT will fail for political reasons. AFIAKT, one really important characteristic of Linux (and JavaScript also) for large tech companies is that they can control their own stacks, without having to license tech from another corporation, but still have the benefit of network effects. Samsung have Tizen, Google have ChromeOS etc. etc. At the component level,…

Linux doesn't scale down very well though. I really don't need the full Linux API for a lightbulb. Most embedded OSs are microkernels for this reason. If any mega-trend has a chance of unseating Linux and generally disrupting the OS space it's IoT.

Re: Kaspersky OS

#164

Only use it if you want to send all of your information to FSB (modern KGB). Evgeniy Kasperskiy has friends in government, police and FSB. He also is apologet of state surveillance.

Although I thought the same when I saw it, I think that's unfair. You could just as easily say Symantec/Norton/Microsoft Defender/Windows/Google is CIA/NSA. Since everything's being watched, Kaspersky might be just as much FSB as it is NSA, or any other country that could get its mitts on it. Cisco was definitely completely NSA there for a while, because of the backdoor. China's got Lenovo and every smart appliance,…

No, there's difference when companies are doing it hidden and when leader of the company publicly declares that surveillance is a must-have thing.

Re: Kaspersky OS

#165

Earlier quoted context omitted.

They don't have this kind of history with security agencies though.

um... except they do. That's what the snowden documents showed us

No. Snowden documents didn't show that Larry and Sergei are childhood buddies with FBI, NSA or CIA chiefs.

That's the problem with intellectual americans - you guys know how bad things are in your country, but not realize how worse they are everywhere else.

Re: Kaspersky OS

#166

Earlier quoted context omitted.

Kaspersky had a history of working with Russian security agencies, has a lot of buddies there and a lot of people have throughout their careers moved from Kaspersky to these agencies and vice versa. If Russia will need somerhing from Kaspersky, government won't even need a warrant - he'll be happy to help.

Are there any news articles to substantiate the claim that Kaspersky readily gives information to the Russian government?

Don't have links at hand because for me personally it's firsthand knowlesge from friends and classmates working there. It's not a big secret though.

Re: Kaspersky OS

#167

Earlier quoted context omitted.

OpenBSD is pretty popular in the security community , and is as FLOSS as it gets.

Yes, my first thought (after VMS) when he said no popular OS is designed for security. Then of course, I realized that by "Popular" he meant Mac OSX, Windows, and Linux. Linux of course, we all know is a security mess because Torvalds refuses to deal with security issues.

I don't think it's a fair statement to blame Linux's security problems on Linus.

Linux provides support for lots of security options, but the project's guiding philosophy is "don't break userland". This is 99% of the time what you see Linus cursing out other kernel contributors for. All of the possible options that Linus could _enforce_ would do just that. Heck, a lot of the security problems and blame have nothing to do with the kernel at all and lie squarely with systemd and how it's implemented. If these are dealbreaker features that you must have, Linux is not the tool for you. Your efforts are better spent working to improve OpenBSD.

Re: Kaspersky OS

#168

Earlier quoted context omitted.

It runs on billions of baseband processors. It's popular by any sane definition of the word.

Following that logic, iOS is also popular in the embedded space.

That's not the embedded space; an iPhone is a full (small) computer.

iOS is quite popular, but embedded ≠ “runs on ARM”.

Re: Kaspersky OS

#170
post #24

No word on if this is FLOSS or not in the article so I'm assuming it'll be something closed. Which essentially renders the entire exercise moot form my POV. I also don't like how they mentioned Linux. They make it sound as if (a) Linux is very insecure...I'm no expert but I'd like to see them prove their system is more secure than a Linux distro dedicated to security. (b) Linux is the only viable option. There's plen…

The article is light on details, but based on the way they talked about it ("impossible to hack in principle") it's likely that they actually can _prove_ that it's more secure than a Linux distro dedicated to security insofar as they're able to prove anything at all. Since the Linux APIs are not formally specified, or verified, it's essentially impossible to _prove_ anything at all (again, in a formal sense). Formal…

There's a difference between "we show you the proof, and you trust us as a service provider that the assumptions are correct" - namely that non-OSS software is loaded in the form it is shown in the proof - and "we show you the proof, and give you all information needed to audit it." Some people will buy based on only the first statement and the brand of the company.

Now, we're looking at a top-notch team of OS programmers; presumably, they all have access to do that audit themselves, and at least some of them must be ethical and proficient enough to notice and refuse to ship a backdoor, right? But the influence of a state actor given 14 years to compromise a team shouldn't be dismissed out of hand.

https://en.wikipedia.org/wiki/Kaspersky_Lab#Controversy

Post reply on HN