Live data from Hacker News

Kaspersky AV injected unique ID allowing sites to track users in incognito mode

heise.de

21–30 of 164 posts

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#21
post #8

Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender. That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing…

Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

Certain companies pay microsoft ridiculous amounts of enterprise software; you can probably trust ms not to do anything that would piss off those companies, simply because they act in their own self-interest. Beyond that, not really.

Debian and openbsd are probably as close as it gets to having an actually secure system, and if I had to pick an os for a very critical application, it would definitely be one of those. But really, honestly, any of debian, ubuntu, fedora, alpine, arch, gentoo, slackware; freebsd, openbsd, netbsd, dragonflybsd are probably more than sufficient for any practical need you might have for privacy and security.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#22
post #8

Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender. That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing…

Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

The reason the Windows Defender is so good these days is https://docs.microsoft.com/en-us/graph/security-concept-over...

The idea is everyone pools their threat data and immunity to new threats can be rapidly disseminated via Azure. The time window any new malware has to exploit Windows 10 anywhere in the world is measured in 10s of minutes now. It’s impressive stuff. The ISG can spread immunity much faster than malware can spread itself.

Of course wearing my cynics hat, they never bothered to backport it to Windows XP and that’s why the NHS was hit with WannaCry. But the other side is that they had plenty of time to upgrade...

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#23
post #8

Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender. That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing…

Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

If you are using Windows, I recommend using defender over any other AV option[0]. Understand, if you are already using Windows, you are already trusting Microsoft. If you don't trust Microsoft you probably shouldn't be using Windows.

[0] There are enterprise solutions that may be better for centralized control in a mixed environment (osx/Linux/windows). Please consult your CISO

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#24

Honest question: what is AV even for these days? I have had some form of AV on all of my Windows machines since the 90's. I don't think I have seen a detection in at least ten years.

Every single company I worked for installed AV on our work computers, which was a huge resource hog and made the highest-specced MacBook Pros feel like cheap netbook.

I suspect it is mandated by some sort of compliance requirement, and the IT departments are just ticking a box. Maybe that's how this industry is still alive.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#25

Honest question: what is AV even for these days? I have had some form of AV on all of my Windows machines since the 90's. I don't think I have seen a detection in at least ten years.

If nothing else, herd immunity. That said, I don't know if there's any compelling reason to use something beyond what the OS vendor already provides.

Agree with you, on Windows. But when you go into Linux and Mac territory, there really isn't any OS Vendor specific security solution that does what many people need.

AV is still super important to have for people who don't understand that downloading a fake flash player to watch the newest game of thrones episode isn't the best idea. And there's a lot of those people out there.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#26
There's lots of 'Do we need Kaspersky' type questions in here already. The more pertinent question is whether AV is actually effective, or if stronger countermeasures like application whitelisting are needed?

https://www.youtube.com/watch?v=gvcgHkeZ1i4&list=PLqz80p7f6d...

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#27
post #23
post #8

Earlier quoted context omitted.

Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

If you are using Windows, I recommend using defender over any other AV option[0]. Understand, if you are already using Windows, you are already trusting Microsoft. If you don't trust Microsoft you probably shouldn't be using Windows. [0] There are enterprise solutions that may be better for centralized control in a mixed environment (osx/Linux/windows). Please consult your CISO

I do agree with that.

Except that I do use Windows without trusting Microsoft. I use install disks that I've purchased ~anonymously for cash. And I only run VMs, which hit the Internet via nested VPN chains, and sometimes Tor.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#28
Can anyone tell me how kaspersky is injecting a script into an HTTPS site?

From the screenshot in the article, there doesn't appear to be a kaspersky browser extension in use.

I guess it would have to be a MITM of some sort. Either by installing a cert or by getting the TLS keys from the browser, I suppose?

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#29

Honest question: what is AV even for these days? I have had some form of AV on all of my Windows machines since the 90's. I don't think I have seen a detection in at least ten years.

Every single company I worked for installed AV on our work computers, which was a huge resource hog and made the highest-specced MacBook Pros feel like cheap netbook. I suspect it is mandated by some sort of compliance requirement, and the IT departments are just ticking a box. Maybe that's how this industry is still alive.

ISO 27001.

It doesn't mandate it explicitly, but your auditor may get fussy if you can't answer questions about the relevant controls with a clear answer.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#30

Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender. That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing…

Getting rid of AVs is old news. If almost no one in infosec trusts using them then why bother?

https://twitter.com/justinschuh/status/802491391121260544

https://robert.ocallahan.org/2017/01/disable-your-antivirus-...

Post reply on HN