Live data from Hacker News

Kaspersky AV injected unique ID allowing sites to track users in incognito mode

heise.de

81–90 of 164 posts

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#81
post #47

Earlier quoted context omitted.

Sometimes i get the feeling some are contrarian only for the sake of it. Advocating using windoze without av is like advocating not using condoms because it doesn't feel good.

Windows with its built-in Windows Defender and your Common Sense 2019 Computer Professional Edition is going to be enough nowadays.

Just to clarify, does Common Sense 2019 Pro come with an ad-blocker for protection against malvertising? I still run into a lot of people who think malvertising isn't a thing. It was worse back when flash adverts were common, but it's still really bad

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#83
post #8

Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender. That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing…

Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

[1] (Debian had a weak PRNG for ~2 years in ~2006-2008) teaches us every distribution or OS vendor can make huge mistakes, with very simple actions (ie. the systems are complicated).

(I'm not saying you should not trust Debian though.)

I do wonder if a stateful OS such as nixOS can help mitigate the threat of malware easier (sans extradition of data, for that we'd need capability-based security, or something like pledge). If it'd be user-friendly, like TimeMachine, that is.

[1] https://www.schneier.com/blog/archives/2008/05/random_number...

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#84
post #75
post #38

Earlier quoted context omitted.

Microsoft can collect anything it wants from those VMs. Because they contain nothing that I don't want them to know. In particular, they don't contain anything about my meatspace identity. Sometimes I do need to put data on VMs that I want kept private. For that, I clone a Windows VM, add a virtual disk containing the data, and then start it with no network connectivity. When I'm done, I detach the data disk, and del…

Not meaning to come across as mean, but could you explain your reasoning behind such precautions, and why they seem worth the extra effort to you? It would seem to me that if you just need to occasionally run an exe that you could most likely get it working with WINE.

That setup doesn’t work with games, too - unless you’re willing to turn off your GPU in the main OS so that it could be used in the other guest.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#85
post #8

Earlier quoted context omitted.

Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

The reason the Windows Defender is so good these days is https://docs.microsoft.com/en-us/graph/security-concept-over... The idea is everyone pools their threat data and immunity to new threats can be rapidly disseminated via Azure. The time window any new malware has to exploit Windows 10 anywhere in the world is measured in 10s of minutes now. It’s impressive stuff. The ISG can spread immunity much faster than malw…

How does it help against new threats exactly, if they are not auto-detected in the first place?

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#86
post #77

Earlier quoted context omitted.

Android AVs are data hoarding goldminers. The Android ecosystem is replete with AVs with questionable privacy policy. To me, it seems like most utilities on Android (like AVs) solely exist to compromise user's privacy. Some even bundle in free VPNs (and you can straight away guess why it's free). One of India's largest telecom networks, known for self enforced censorship via deep packet inspection, has an AV on PlayS…

They don’t sell it or rent it, they give it away! That’s some pro-level weasel wording.

They're saying they sell your information, but not your personal information. And then they say that any information they get isn't personal.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#87
post #75
post #38

Earlier quoted context omitted.

Microsoft can collect anything it wants from those VMs. Because they contain nothing that I don't want them to know. In particular, they don't contain anything about my meatspace identity. Sometimes I do need to put data on VMs that I want kept private. For that, I clone a Windows VM, add a virtual disk containing the data, and then start it with no network connectivity. When I'm done, I detach the data disk, and del…

Not meaning to come across as mean, but could you explain your reasoning behind such precautions, and why they seem worth the extra effort to you? It would seem to me that if you just need to occasionally run an exe that you could most likely get it working with WINE.

Once I have a Windows VM that's stable, with the apps that I usually need, the rest of it takes little time. Mainly it's Excel that I need. And I need it to use all available CPU cores. I suppose that might work in Wine, but that seems like an iffy approach.

Why do I take such precautions? Well, I've been an anonymous coward for a couple decades. I've corresponded with many people, and played with many projects. I honestly have no idea who might be after me, or for what. Ideally, nobody, for nothing. But ...

Given that, I take whatever precautions I practically can.

And it's also a hobby. Perhaps like building little ships in glass bottles. But hopefully maybe useful to someone.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#88
post #75

Earlier quoted context omitted.

Not meaning to come across as mean, but could you explain your reasoning behind such precautions, and why they seem worth the extra effort to you? It would seem to me that if you just need to occasionally run an exe that you could most likely get it working with WINE.

That setup doesn’t work with games, too - unless you’re willing to turn off your GPU in the main OS so that it could be used in the other guest.

I don't play games. And even if I did, I'd never pass a physical GPU to a VM. That's almost as iffy as direct access to physical storage.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#89

Honest question: what is AV even for these days? I have had some form of AV on all of my Windows machines since the 90's. I don't think I have seen a detection in at least ten years.

Every single company I worked for installed AV on our work computers, which was a huge resource hog and made the highest-specced MacBook Pros feel like cheap netbook. I suspect it is mandated by some sort of compliance requirement, and the IT departments are just ticking a box. Maybe that's how this industry is still alive.

Reading sibling comments I have an idea for a startup.

Make an AV, that does not really do anything, but can be used by thoughtful companies to "tick the box". Sell licenses and then do only the minimum required for compliance.

It could be described that it uses Windows Defender service to provide the basis of AV solution.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#90
post #8

Earlier quoted context omitted.

Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

> In Debian, I can be reasonably confident that no information leaves the system without my authorization. Only if you are not running a webbrowser > Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian? Only fools trust Microsoft (or Google, or Facebook). I slightly hoped they were turning in the right direction in win 2000 and xp and even 7. But vista and the rest shown their true…

> Only if you are not running a webbrowser

Touché. I am not hard-core enough to browse in terminal. I don't use Chrome/Chromium though.

I actually rather like systemd. Most of the time, at least. But yes, I know the controversy. So do you like Devuan?

Post reply on HN