Live data from Hacker News

Kaspersky AV injected unique ID allowing sites to track users in incognito mode

heise.de

51–60 of 164 posts

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#51
post #47

Earlier quoted context omitted.

Sometimes i get the feeling some are contrarian only for the sake of it. Advocating using windoze without av is like advocating not using condoms because it doesn't feel good.

Windows with its built-in Windows Defender and your Common Sense 2019 Computer Professional Edition is going to be enough nowadays.

As a rare windows user (two or free times a year) i never trust a machine without an av. maybe things changed, but i see windows as so unsafe that i would not even login with to regular email, let alone make online payments. I simply see that os as a vulnerability by default.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#52
post #47

Earlier quoted context omitted.

Sometimes i get the feeling some are contrarian only for the sake of it. Advocating using windoze without av is like advocating not using condoms because it doesn't feel good.

Windows with its built-in Windows Defender and your Common Sense 2019 Computer Professional Edition is going to be enough nowadays.

Unfortunately common sense is not very common

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#53

Can anyone tell me how kaspersky is injecting a script into an HTTPS site? From the screenshot in the article, there doesn't appear to be a kaspersky browser extension in use. I guess it would have to be a MITM of some sort. Either by installing a cert or by getting the TLS keys from the browser, I suppose?

This was my immediate thought. Where is rewrite happening? All the options seems icky.

I think AV vendors used to do browser addons to provide some functionality. But since browser extensions in all popular browser are now effectively neutered versions of their former selves, they are probably resorting to stuff like this. It can be hard to even get a browser addon installed as a third party program without resorting to hacks (thanks to browsers having taken measures after the toolbar hell).

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#54
post #8

Earlier quoted context omitted.

Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

You are wrong about trusting Linux. Linux would badly need AV if it was a more popular desktop OS. Right now the user base is just too small to be a valuable target. A regular Linux distro (without SELinux or some kind of application sandboxing and a hardened setup including NOEXEC home, forbidding ptrace, ...) is very susceptible to compromise. All it takes is somehow getting the system to execute one unprivileged s…

Thanks. I do appreciate that there are vulnerabilities.

So I work only in VMs. I do nothing on host machines except to run VMs, and keep the OS up to date. And I compartmentalize rigorously. Minimally in different VMs. When it matters more, in different host machines. And when it really matters, in different host machines on different LANs. Only text files cross important security boundaries. And machines that my ~anonymous personas use never see anything about my meatspace identity.

This is, of course, just a hobby.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#55
post #51

Earlier quoted context omitted.

Windows with its built-in Windows Defender and your Common Sense 2019 Computer Professional Edition is going to be enough nowadays.

As a rare windows user (two or free times a year) i never trust a machine without an av. maybe things changed, but i see windows as so unsafe that i would not even login with to regular email, let alone make online payments. I simply see that os as a vulnerability by default.

I don't run Windows myself, but honestly: Remote exploitable Windows vulnerabilities on a default install are somewhat rare nowadays. MS has come a long way here.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#56

I don't fully understand why everyone gets upset over browser leaks when in private mode - most websites interested in tracking private sessions will just associate private and non-private sessions by IP address. If you're paranoid enough to use a VPN for 'private' traffic, you should probably be running such sessions in a VM using something like the tails live CD.

For sure.

But using Tails in VMs isn't recommended. Better is using Whonix, because it isolates the Tor client and userland in separate VMs. It also has a LiveCD mode. And for added security, you can run it in Qubes.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#57
post #51

Earlier quoted context omitted.

As a rare windows user (two or free times a year) i never trust a machine without an av. maybe things changed, but i see windows as so unsafe that i would not even login with to regular email, let alone make online payments. I simply see that os as a vulnerability by default.

I don't run Windows myself, but honestly: Remote exploitable Windows vulnerabilities on a default install are somewhat rare nowadays. MS has come a long way here.

I remember the smashing the stack for fun and profit windows days. It was so easy to inject shell code it was laughable. Btw can you still name a file smss.exe, run it, and not end the process with the task manager?

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#58
post #44

Earlier quoted context omitted.

The last paragraph of the article was particularly astounding on this point, in that it explains how to disable the script injection rather than purge all Kaspersky software from the computer. That seems to contradict everything that preceded it.

I know how to uninstall software. I probably wouldn't know where to disable a particular feature or that I could disable it at all.

I guess I don't understand why anyone would want to leave it installed after that magnitude of trust violation (silent privacy-destroying MITM of HTTPS traffic by default).

Why do you? Edit: Or maybe I'm misinterpreting?

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#59
post #57

Earlier quoted context omitted.

I don't run Windows myself, but honestly: Remote exploitable Windows vulnerabilities on a default install are somewhat rare nowadays. MS has come a long way here.

I remember the smashing the stack for fun and profit windows days. It was so easy to inject shell code it was laughable. Btw can you still name a file smss.exe, run it, and not end the process with the task manager?

I just tried this on Windows 10 1903 and had no problem ending the process with task manager.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#60
post #8

Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender. That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing…

Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

> or in trusting Debian?

From a security POV Desktop Linux is an utter disaster.

For attackers it's like going back a decade in time.

Post reply on HN