Live data from Hacker News

Kaspersky AV injected unique ID allowing sites to track users in incognito mode

heise.de

71–80 of 164 posts

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#71
post #42

Can anyone tell me how kaspersky is injecting a script into an HTTPS site? From the screenshot in the article, there doesn't appear to be a kaspersky browser extension in use. I guess it would have to be a MITM of some sort. Either by installing a cert or by getting the TLS keys from the browser, I suppose?

Many antivirus applications install a local certificate authority so they can MITM HTTPS. From my experience most fail to check the original CA meaning anyone can intercept your traffic...

They should generate that certificate along with private key on your local machine, so it does not allow anyone else to intercept your traffic. Even seemingly harmless applications can do that. For example Blizzard Battle.net Launcher (used for all games) does that.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#72

Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender. That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing…

Android AVs are data hoarding goldminers. The Android ecosystem is replete with AVs with questionable privacy policy. To me, it seems like most utilities on Android (like AVs) solely exist to compromise user's privacy. Some even bundle in free VPNs (and you can straight away guess why it's free).

One of India's largest telecom networks, known for self enforced censorship via deep packet inspection, has an AV on PlayStore with 10m installs.

Some excerpts from their privacy policy [0]:

> Reliance Jio does not sell or rent any Personal Information.

Followed by:

> Reliance Jio may provide your information or data to its partners, associates, service providers and third parties as necessary or appropriate

> Any personally identifiable information provided by you will not be considered as sensitive if it is freely available and / or accessible in the public domain.

[0] https://www.jio.com/en-in/jio-security-privacy-policy

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#73
post #8

Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender. That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing…

Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

> In Debian, I can be reasonably confident that no information leaves the system without my authorization.

Only if you are not running a webbrowser

> Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

Only fools trust Microsoft (or Google, or Facebook). I slightly hoped they were turning in the right direction in win 2000 and xp and even 7. But vista and the rest shown their true nature. About Debian i have mixed feelings. On one hand they are a very respectable distribution, on the other hand - systemd.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#74
post #64
post #57

Earlier quoted context omitted.

I remember the smashing the stack for fun and profit windows days. It was so easy to inject shell code it was laughable. Btw can you still name a file smss.exe, run it, and not end the process with the task manager?

You live in the XP days.

The majority of the Windows haters I come across seem to be the same.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#75
post #38

Earlier quoted context omitted.

So all the telemetry that Windows collects from the VM's you're running are sent to Microsoft through nested VPNs over TOR? I don't think Microsoft minds or cares that your Windows VM telemetry gets send to them that way or any other way? How are your VPNs and TOR helping you with the Microsoft you don't trust?

Microsoft can collect anything it wants from those VMs. Because they contain nothing that I don't want them to know. In particular, they don't contain anything about my meatspace identity. Sometimes I do need to put data on VMs that I want kept private. For that, I clone a Windows VM, add a virtual disk containing the data, and then start it with no network connectivity. When I'm done, I detach the data disk, and del…

Not meaning to come across as mean, but could you explain your reasoning behind such precautions, and why they seem worth the extra effort to you? It would seem to me that if you just need to occasionally run an exe that you could most likely get it working with WINE.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#76
post #56

Earlier quoted context omitted.

For sure. But using Tails in VMs isn't recommended. Better is using Whonix, because it isolates the Tor client and userland in separate VMs. It also has a LiveCD mode. And for added security, you can run it in Qubes.

Funny that you namedrop like three security products but fail to evaluate which hypervisor should be used, which is probably the most important part of a secure environment if unauthorized code execution fits in your threat model.

Sorry. Whonix, by default for non-expert users, runs in VirtualBox. You can also use KVM. And Qubes basically uses Xen.

My threat model is mainly about preventing potential adversaries from learning my ISP-assigned IP address. I don't care all that much if a VM, or even a host machine, gets pwned. My stuff is well enough compartmentalized that I'd at most lose some work. But not my privacy.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#77

Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender. That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing…

Android AVs are data hoarding goldminers. The Android ecosystem is replete with AVs with questionable privacy policy. To me, it seems like most utilities on Android (like AVs) solely exist to compromise user's privacy. Some even bundle in free VPNs (and you can straight away guess why it's free). One of India's largest telecom networks, known for self enforced censorship via deep packet inspection, has an AV on PlayS…

They don’t sell it or rent it, they give it away! That’s some pro-level weasel wording.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#78
post #67

Anti-virus here means anti-privacy. What shocks me most is that this is in the paid versions as well. I run Linux and have ClamAV installed for some compliance thingy, yet I have never run it (the compliance thingy tells me to have AV installed, not to actually run it). I can totally recommend some up-to-date Linux distro in case you want to steer clear of "virusses (etc)".

I used to run ClamAV for a few years, both on Linux and macOS. The only thing it ever detected were Windows viruses in my spam mailbox. Every time I received a spam email, ClamAV would complain and I'd have to go delete the email that was already not in my inbox.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#79
post #65
post #62

Earlier quoted context omitted.

Please explain. Security from what? By default, there are no services listening. And what malware runs on Linux?

>By default, there are no services listening. Desktop linux , not "the Linux kernel". The kernel isn't amazing, but on the desktop side you regularly see downright absurd stuff like this https://scarybeastsecurity.blogspot.com/2016/11/0day-exploit... and less surprising bugs like this https://donncha.is/2016/12/compromising-ubuntu-desktop/ The quality of software outside of some widely deployed server software tends…

> you regularly see downright absurd stuff like this

That's a bug which only occurs on five year old distributions and which was fixed years before any exploit was ever found. Honestly if that's being brought up as a bad example Linux is looking pretty good compared to other operating systems.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#80
post #58

Earlier quoted context omitted.

I know how to uninstall software. I probably wouldn't know where to disable a particular feature or that I could disable it at all.

I guess I don't understand why anyone would want to leave it installed after that magnitude of trust violation (silent privacy-destroying MITM of HTTPS traffic by default). Why do you? Edit: Or maybe I'm misinterpreting?

Not everyone is able to choose what software is installed on the machine they use. Especially for AV, that may be enforced by the company one works for.
Post reply on HN