Live data from Hacker News

Kaspersky OS

eugene.kaspersky.com

181–190 of 290 posts

Re: Kaspersky OS

#181

Earlier quoted context omitted.

Yes, my first thought (after VMS) when he said no popular OS is designed for security. Then of course, I realized that by "Popular" he meant Mac OSX, Windows, and Linux. Linux of course, we all know is a security mess because Torvalds refuses to deal with security issues.

I don't think it's a fair statement to blame Linux's security problems on Linus. Linux provides support for lots of security options, but the project's guiding philosophy is "don't break userland". This is 99% of the time what you see Linus cursing out other kernel contributors for. All of the possible options that Linus could _enforce_ would do just that. Heck, a lot of the security problems and blame have nothing t…

Of course it's fair. He built it to just have a person UNIX that he enjoys working on. Lots of other people did the same. Security was never a priority for them. Whereas, by that time, there were already multiple OS's with strong levels of built-in security. He could've copied stuff from them. There's even more now. They're still keeping broken model for (a) their priorities that put security low and (b) avoiding rewriting anything depending on broken security architecture. All the container developments are the classic solution to (b) but their security is often similarly shoddy vs what it could've been.

So, yeah, blame Linus and others in that ecosystem who do everything but make a solid foundation. Contrast that to OpenBSD for monolithic or GenodeOS for microkernel approaches where they bake security in at various levels. MINIX 3 for reliability levels they achieved 10x faster than monolithic UNIX's did. You get what you focus on. :)

Re: Kaspersky OS

#182

Only use it if you want to send all of your information to FSB (modern KGB). Evgeniy Kasperskiy has friends in government, police and FSB. He also is apologet of state surveillance.

Although I thought the same when I saw it, I think that's unfair. You could just as easily say Symantec/Norton/Microsoft Defender/Windows/Google is CIA/NSA. Since everything's being watched, Kaspersky might be just as much FSB as it is NSA, or any other country that could get its mitts on it. Cisco was definitely completely NSA there for a while, because of the backdoor. China's got Lenovo and every smart appliance,…

> Kaspersky might be just as much FSB as it is NSA, or any other country that could get its mitts on it

No, it's not the same. Despite its flaws, the United States government is not at all the same as Russia's.

Re: Kaspersky OS

#183
post #62

Earlier quoted context omitted.

"Anticipating your questions: not even the slightest smell of Linux. All the popular operating systems aren’t designed with security in mind, so it’s simpler and safer to start from the ground up and do everything correctly." It looks like a realistic assessment. General purpose operating systems ( at least the 3 most famous ones ) are built with ease of use in mind, not security. Even Torvalds admits it, saying that…

Which is funny, because they say that popular operating systems are not designed with security in mind. They give this as a reason to start from the ground up. I am from the camp saying that currently sole kernel does not an OS make. With this in mind network equipment OSes are certainly not popular ones. Nevertheless there are probably lots of less popular OSes with less popular kernels that are designed with securi…

To support your point, the company below did a clean-slate OS tightly integrated with hardware protection features of Itanium CPU's to give people hell trying to compromise their DNS servers. Also re-did the networking stack to assume a hostile instead of benign network. Way over due there. The OS is available for licensing IIRC but OEM's don't give a shit about security if dollars are on the line. ;)

http://www.secure64.com/secure-operating-system

An older one that was pentested by the NSA with positive results reduced attack surface by using PPC embedded board, INTEGRITY microkernel, and carefully-coded state machines. That a small team made this shows both the big companies and startups could be doing way better if they cared.

http://www.sentinelsecurity.us/HYDRA/hydra.html

Re: Kaspersky OS

#184

Earlier quoted context omitted.

I don't think it's a fair statement to blame Linux's security problems on Linus. Linux provides support for lots of security options, but the project's guiding philosophy is "don't break userland". This is 99% of the time what you see Linus cursing out other kernel contributors for. All of the possible options that Linus could _enforce_ would do just that. Heck, a lot of the security problems and blame have nothing t…

Of course it's fair. He built it to just have a person UNIX that he enjoys working on. Lots of other people did the same. Security was never a priority for them. Whereas, by that time, there were already multiple OS's with strong levels of built-in security. He could've copied stuff from them. There's even more now. They're still keeping broken model for (a) their priorities that put security low and (b) avoiding rew…

Right. I'm saying give up on expecting the project to change. The project isn't for what you want it to be for and never will be.

You should be shouting at companies who use it for applications where security is a must. That's where the madness lies.

I use OpenBSD and so should you :)

Re: Kaspersky OS

#185

Earlier quoted context omitted.

Linux is very insecure. Maybe you have not been following the news lately.

There's plenty of great quotes from Torvalds about why it's like that. He places functionality over security, and assumes security will just 'happen' with code quality. I tend to disagree - but I am typing this from a Linux box, not an OpenBSD box. Because Linux is more functional as a desktop - the irony there isn't lost on me.

Exactly. Priorities = what you get out of your work. Far as Linux vs OpenBSD box, remember also that contributors (including corporate) are partly to blame here since they chose to put their investments into a project that doesn't care about security instead of one that bakes it in. Even if Theo et al weren't pleasant, they could've forked OpenBSD keeping any of their improvements while making what changes they absolutely needed. We'd have had an OpenBSD desktop in a few years as easy as OpenSUSE at the least.

Re: Kaspersky OS

#186
post #104

Earlier quoted context omitted.

The Intel ME and and AMD PSP are still executing proprietary code on an independent processor in your CPU package all the time, with full system access. Linux cannot do anything about it.

Yeah you only FTrace your entire networking stack at watch if it ever sends/receives packets without your knowledge. Or use libpcap and accomplish the same task. Or use a user space packet stack stack and disable your default network interface. I get not everything on the system is pure FOSS. But every binary ball isn't NSA spyware. If you assume that is true, you literally cannot use ANY computer. FOSS OS's make it…

> But every binary ball isn't NSA spyware. If you assume that is true, you literally cannot use ANY computer.

You can use one, but you can expect it's exploited. It might not be a happy fact, but we shouldn't deny it if it's true.

The NSA by itself has 40,000 employees, tens of billions in budget, the best tools and tech in the world, and a track record of doing such things. I expect that if they see a valuable vulnerability, they will develop an exploit.

Re: Kaspersky OS

#187

Earlier quoted context omitted.

I don't think it's a fair statement to blame Linux's security problems on Linus. Linux provides support for lots of security options, but the project's guiding philosophy is "don't break userland". This is 99% of the time what you see Linus cursing out other kernel contributors for. All of the possible options that Linus could _enforce_ would do just that. Heck, a lot of the security problems and blame have nothing t…

Sure, but comments like: "Security people are often the black-and-white kind of people that I can't stand. I think the OpenBSD crowd is a bunch of masturbating monkeys, in that they make such a big deal about concentrating on security to the point where they pretty much admit that nothing else matters to them." "So LSM stays in. No ifs, buts, maybes or anything else. When I see the security people making sane argumen…

The market has sort of proved him right.

Companies that use Linux and need security will either get caught with their pants down or they won't. It's up to their level of preparedness and luck. I wouldn't underwrite that if I were an insurer though.

Those of us that care are already using something else.

Re: Kaspersky OS

#188

Earlier quoted context omitted.

Sure, but comments like: "Security people are often the black-and-white kind of people that I can't stand. I think the OpenBSD crowd is a bunch of masturbating monkeys, in that they make such a big deal about concentrating on security to the point where they pretty much admit that nothing else matters to them." "So LSM stays in. No ifs, buts, maybes or anything else. When I see the security people making sane argumen…

The market has sort of proved him right. Companies that use Linux and need security will either get caught with their pants down or they won't. It's up to their level of preparedness and luck. I wouldn't underwrite that if I were an insurer though. Those of us that care are already using something else.

Absolutely.

I would actually argue that security doesn't depend on any one product, but instead a mindset, methodology, and toolbox. Defense in depth, etc.

Re: Kaspersky OS

#189

Earlier quoted context omitted.

Of course it's fair. He built it to just have a person UNIX that he enjoys working on. Lots of other people did the same. Security was never a priority for them. Whereas, by that time, there were already multiple OS's with strong levels of built-in security. He could've copied stuff from them. There's even more now. They're still keeping broken model for (a) their priorities that put security low and (b) avoiding rew…

Right. I'm saying give up on expecting the project to change. The project isn't for what you want it to be for and never will be. You should be shouting at companies who use it for applications where security is a must. That's where the madness lies. I use OpenBSD and so should you :)

I also use OpenBSD (and donate to it, since I have more money than time right now)... but damn, they do need a VM that I can use, so that it can be my regular desktop.

Re: Kaspersky OS

#190

Earlier quoted context omitted.

There's plenty of great quotes from Torvalds about why it's like that. He places functionality over security, and assumes security will just 'happen' with code quality. I tend to disagree - but I am typing this from a Linux box, not an OpenBSD box. Because Linux is more functional as a desktop - the irony there isn't lost on me.

Exactly. Priorities = what you get out of your work. Far as Linux vs OpenBSD box, remember also that contributors (including corporate) are partly to blame here since they chose to put their investments into a project that doesn't care about security instead of one that bakes it in. Even if Theo et al weren't pleasant, they could've forked OpenBSD keeping any of their improvements while making what changes they absol…

A very valid point. IBM contributes a TON of code to Linux. They could easily have worked to improve security if they cared.

Or, improved BSD, and avoided all that GPL stuff if they wanted.

Post reply on HN