Live data from Hacker News

Kaspersky OS

eugene.kaspersky.com

171–180 of 290 posts

Re: Kaspersky OS

#171
post #24

No word on if this is FLOSS or not in the article so I'm assuming it'll be something closed. Which essentially renders the entire exercise moot form my POV. I also don't like how they mentioned Linux. They make it sound as if (a) Linux is very insecure...I'm no expert but I'd like to see them prove their system is more secure than a Linux distro dedicated to security. (b) Linux is the only viable option. There's plen…

> I also don't like how they mentioned Linux

I do. Every time I read an article on a new "operating system" someone has released, it turns out to basically just be another Linux distribution, or a new gui/runtime environment running on top of the Linux kernel. Kaspersky took a step back and thought about their requirements, and decided to go with a microkernel architecture because they felt that was a better approach for security (a choice I agree with).

It's refreshing to see genuinely new OSs built from the ground up (open source or not), because it shows that not everyone is stuck in the mindset of Linux when they want to innovate in the OS space. That's not to say that Linux is necessarily a bad choice for many scenarios, just that it's great to see projects that don't restrict themselves based on the design of Linux (and, more generally, Unix).

Re: Kaspersky OS

#172
post #124

Earlier quoted context omitted.

Although I thought the same when I saw it, I think that's unfair. You could just as easily say Symantec/Norton/Microsoft Defender/Windows/Google is CIA/NSA. Since everything's being watched, Kaspersky might be just as much FSB as it is NSA, or any other country that could get its mitts on it. Cisco was definitely completely NSA there for a while, because of the backdoor. China's got Lenovo and every smart appliance,…

You could just as easily say Symantec/Norton/Microsoft Defender/Windows/Google is CIA/NSA. Isn't it, though? Apple seems to be the only company that has stood up to the three letter agencies. (I'm a US citizen.)

Apple only kind of stood up to the feds, they happily handed over the terrorists icloud account and all things associated, they only refused to be compelled to write software knowing full well that the FBI already easily had the capability to break into the iphone. I would say that the government having some sort of restricted access to this data could be useful and important to society IF, and only if, there were better civil liberties protections in place. DHS has way too much power, and we heard from Edward Snowden that our data is often irresponsibly used.

Re: Kaspersky OS

#173

Earlier quoted context omitted.

um... except they do. That's what the snowden documents showed us

No. Snowden documents didn't show that Larry and Sergei are childhood buddies with FBI, NSA or CIA chiefs. That's the problem with intellectual americans - you guys know how bad things are in your country, but not realize how worse they are everywhere else.

No, I'll concede the specifics, but the impact is the same. They show that Google, FB, etc are all sending their data to the NSA and others.

> That's the problem with intellectual americans - you guys know how bad things are in your country, but not realize how worse they are everywhere else.

What? Just because some situations are worse in other countries means the US can't be doing anything wrong?

Re: Kaspersky OS

#174

Earlier quoted context omitted.

OpenBSD is pretty popular in the security community , and is as FLOSS as it gets.

Yet it's not widely used as embedded OS. I never saw any router with OpenBSD or web camera. The underlying problem, IMO, is people. They just don't care about security, they want to deliver working device. Also it's not clear how many vulnerabilities, used in real life attacks (like DDOS from IoT devices) are in latest Linux kernel? May be problem not with Linux, but with custom software or lack of updates.

This defense contractor builds their stuff on OpenBSD:

https://www.genua.de/en/solutions.html

One can always strip out what's not necessary. One can also put it in user-mode on top of a secure microkernel with some services running directly on microkernel and some running in OpenBSD. That Kaspersky thought the choices were Linux-based or purely clean-slate shows limited knowledge of what's out there or a personal preference.

Re: Kaspersky OS

#175

Earlier quoted context omitted.

Ahem http://rationalviews.com/t/presentation-on-fully-open-source... You could go into that rabbit hole. I'd recommend against it... I lost days reading all the docs and playing with this

POWER8/9 isn't fully open. Read the license agreements. While you get access to a lot of stuff, there is a lot of fine print you are ignoring. A lot of the deep docs are behind paywalls. To get access to POWER8/9 literature you sign away your rights to OPEN-POWER. Also if you make anything for POWER8/9, under a public license (what license you can/can't use are dictated by the license agreement), using docs obtained…

Yeah, I went down that rabbit hole a bit.

The point is - it's about the only way to do a real actual code audit on what your processor is doing.

Re: Kaspersky OS

#176
post #87
post #40

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/L4_microkernel_family#Commerci... > OKL4 shipments exceeded 1.5 billion in early 2012, mostly on Qualcomm wireless modem chips. Other deployments include automotive infotainment systems. > Apple mobile application processors beginning with the A7 contain a Secure Enclave coprocessor running an L4 operating system. This implies that L4 is now shipping on all iOS devices, the total shipmen…

So we have 2-3 very niche deployments. Does it really make L4 popular in embedded systems? Also, OKL4, specially the version claimed to run on qualcomm is very different from the original L4 (I say claimed since multiple attempts to reverse engineer qualcomm baseband firmware showed no traces of OKL4) edit: if you think this is incorrect please provide a valid counterpoint. downvoting a post this way to hide its pres…

It will also help you to remember that embedded space is extremely fragmented with many RTOS's & non-RTOS's to choose from. Developers also do custom stuff or just run on bare metal with runtimes. It's an interesting field due to diversity of solutions they use. That one product hits a billion installs with a bunch of vendors in a space that exclusively use Win Mobile, Symbian, and Android is significant.

It's popularity was just relative, though. In mobile phones, one microkernel was more popular than others. vxWorks and QNX were more popular in embedded space in general than L4's. I don't know the exact distribution.

Re: Kaspersky OS

#177
post #151

Earlier quoted context omitted.

> Russia is super paranoid, and increasingly isolationist And they have good reason to be. The US has really shot itself in the foot by intentionally compromising the systems we create. Hopefully we can use this (and similar actions by other countries) to turn that around.

Let's cautiously assume that China also does this. Open-source hardware would be great at counteracting this (and for other reasons), but it's harder than open-source software.

That's why China built their own OS on top of an open-source BSD. :)

https://en.wikipedia.org/wiki/Kylin_(operating_system)

Re: Kaspersky OS

#178
post #56
post #43

Closed source OS from an anti virus company with a dodgy history? I will pass.

Could you expand on the "dodgy history"? I always thought that Kaspersky was one of the "good guys"

Someone deep downthread had these links. I haven't vetted them so much as bringing them higher in thread to put more substance in discussion:

https://news.ycombinator.com/item?id=12986906

Re: Kaspersky OS

#179
post #162

Earlier quoted context omitted.

The biggest issue with Windows isn't its inherent security, it's the way it's used. Most users run everything with super admin rights. Most developers require that for installs. OSX is right behind it, with a culture of laxness that undoes most of the benefits the designers tried to give them.

I've run into "security software" for domain computers that required every computer to have the same local admin password... and for it to be enabled on every computer.

Exactly. That's ridiculous thinking far beyond what the OS designer is responsible for.

Re: Kaspersky OS

#180

Earlier quoted context omitted.

Yes, my first thought (after VMS) when he said no popular OS is designed for security. Then of course, I realized that by "Popular" he meant Mac OSX, Windows, and Linux. Linux of course, we all know is a security mess because Torvalds refuses to deal with security issues.

I don't think it's a fair statement to blame Linux's security problems on Linus. Linux provides support for lots of security options, but the project's guiding philosophy is "don't break userland". This is 99% of the time what you see Linus cursing out other kernel contributors for. All of the possible options that Linus could _enforce_ would do just that. Heck, a lot of the security problems and blame have nothing t…

Sure, but comments like: "Security people are often the black-and-white kind of people that I can't stand. I think the OpenBSD crowd is a bunch of masturbating monkeys, in that they make such a big deal about concentrating on security to the point where they pretty much admit that nothing else matters to them."

"So LSM stays in. No ifs, buts, maybes or anything else. When I see the security people making sane arguments and agreeing on something, that will change. Quite frankly, I expect hell to freeze over before that happens, and pigs will be nesting in trees. But hey, I can hope."

He's typically very critical of security-related changes unless they are a massive improvement. I think characterizing him as "functionality over security" is entirely fair. He's not even wrong necessarily.

Post reply on HN