Live data from Hacker News

Kaspersky AV injected unique ID allowing sites to track users in incognito mode

heise.de

41–50 of 164 posts

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#41

Can anyone tell me how kaspersky is injecting a script into an HTTPS site? From the screenshot in the article, there doesn't appear to be a kaspersky browser extension in use. I guess it would have to be a MITM of some sort. Either by installing a cert or by getting the TLS keys from the browser, I suppose?

This was my immediate thought. Where is rewrite happening? All the options seems icky.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#42

Can anyone tell me how kaspersky is injecting a script into an HTTPS site? From the screenshot in the article, there doesn't appear to be a kaspersky browser extension in use. I guess it would have to be a MITM of some sort. Either by installing a cert or by getting the TLS keys from the browser, I suppose?

Many antivirus applications install a local certificate authority so they can MITM HTTPS.

From my experience most fail to check the original CA meaning anyone can intercept your traffic...

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#44

Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender. That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing…

The last paragraph of the article was particularly astounding on this point, in that it explains how to disable the script injection rather than purge all Kaspersky software from the computer. That seems to contradict everything that preceded it.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#45
post #8

Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender. That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing…

Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

You are wrong about trusting Linux.

Linux would badly need AV if it was a more popular desktop OS. Right now the user base is just too small to be a valuable target.

A regular Linux distro (without SELinux or some kind of application sandboxing and a hardened setup including NOEXEC home, forbidding ptrace, ...) is very susceptible to compromise.

All it takes is somehow getting the system to execute one unprivileged shell script and your user is permanently hosed.

An attacker can spy on everything, including other applications memory, unless they prevent it. Browsers are also easily compromised by just injecting a extension that can spy on everything.

Also he lack of dynamic firewalls makes it hard to monitor/prevent unwanted network traffic. (which could often be easily circumvented, though)

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#47
post #30

Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender. That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing…

Getting rid of AVs is old news. If almost no one in infosec trusts using them then why bother? https://twitter.com/justinschuh/status/802491391121260544 https://robert.ocallahan.org/2017/01/disable-your-antivirus-...

Sometimes i get the feeling some are contrarian only for the sake of it. Advocating using windoze without av is like advocating not using condoms because it doesn't feel good.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#48
post #47
post #30

Earlier quoted context omitted.

Getting rid of AVs is old news. If almost no one in infosec trusts using them then why bother? https://twitter.com/justinschuh/status/802491391121260544 https://robert.ocallahan.org/2017/01/disable-your-antivirus-...

Sometimes i get the feeling some are contrarian only for the sake of it. Advocating using windoze without av is like advocating not using condoms because it doesn't feel good.

Windows with its built-in Windows Defender and your Common Sense 2019 Computer Professional Edition is going to be enough nowadays.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#49
I don't fully understand why everyone gets upset over browser leaks when in private mode - most websites interested in tracking private sessions will just associate private and non-private sessions by IP address.

If you're paranoid enough to use a VPN for 'private' traffic, you should probably be running such sessions in a VM using something like the tails live CD.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#50
post #44

Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender. That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing…

The last paragraph of the article was particularly astounding on this point, in that it explains how to disable the script injection rather than purge all Kaspersky software from the computer. That seems to contradict everything that preceded it.

I know how to uninstall software. I probably wouldn't know where to disable a particular feature or that I could disable it at all.
Post reply on HN