Live data from Hacker News

Kaspersky AV injected unique ID allowing sites to track users in incognito mode

heise.de

111–120 of 164 posts

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#111
post #8

Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender. That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing…

Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

Have you personally audited every line of every piece of code in your Debian install? The usual retort is “many eyes”. How “many eyes” were on the OpenSSL vulnerability that was in many open source distributions for a year and a half.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#112
post #91

Earlier quoted context omitted.

I was using a spinny disk for a few weeks and I upgraded back to SSD the other day. The difference is incredible. Browser used to take 10 seconds to start, now it's instant. The only good thing is, I got so frustrated waiting constantly that I optimized my software to minimize IO (eg disabled browser history) so now it's even faster.

I will blow your mind when I will tell you to use a RamDisks for fastest run times wink wink

If you use a Samsung SATA SSD, just enable RAPID mode in the Samsung Magician program. The different with and without is huge.

(Enabling RAPID mode basically creates an invisible RAM disk and uses it under the hood.)

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#113

I don't fully understand why everyone gets upset over browser leaks when in private mode - most websites interested in tracking private sessions will just associate private and non-private sessions by IP address. If you're paranoid enough to use a VPN for 'private' traffic, you should probably be running such sessions in a VM using something like the tails live CD.

Indeed. Private sessions do not make you untrackable, the only difference is nothing is saved from the session. But many people misunderstand what private/incognito mode does.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#114
post #58

Earlier quoted context omitted.

I guess I don't understand why anyone would want to leave it installed after that magnitude of trust violation (silent privacy-destroying MITM of HTTPS traffic by default). Why do you? Edit: Or maybe I'm misinterpreting?

Not everyone is able to choose what software is installed on the machine they use. Especially for AV, that may be enforced by the company one works for.

What company is using Kaspersky? Aren't they on US security blacklists?

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#116
post #114

Earlier quoted context omitted.

Not everyone is able to choose what software is installed on the machine they use. Especially for AV, that may be enforced by the company one works for.

What company is using Kaspersky? Aren't they on US security blacklists?

This may be surprising, but there's people outside the US.

In fact more than 95% of people are not presently in the US.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#117
post #47
post #30

Earlier quoted context omitted.

Getting rid of AVs is old news. If almost no one in infosec trusts using them then why bother? https://twitter.com/justinschuh/status/802491391121260544 https://robert.ocallahan.org/2017/01/disable-your-antivirus-...

Sometimes i get the feeling some are contrarian only for the sake of it. Advocating using windoze without av is like advocating not using condoms because it doesn't feel good.

Windows really isn't as bad as its reputation when it comes to security. It goes for windows as it goes for any other OS: Don't install crap you cannot trust. Don't run everything as root (UAC). Think before you give anything elevated rights.

I have seen my share of ridiculous security flaws in ALL OS'. Anyone remember when you could login on any mySQL server by simply trying enough times? That wasn't windows specific! (back in 2012!)

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#119

Earlier quoted context omitted.

I see windoze fanboys are having a leg-day today. Enjoy your ads and spying. Oh an the virii.

I haven’t ran Windows outside a VM (and only then for FPGA/ASIC programming tools) in the better part of a decade myself and loathe every second of the time I do run it in a VM, yet I still think you are out of line here. Maybe consider cooling off before posting more?

Specifically, what is bad in pointing out windows is a security liability, and a low quality os generally speaking? Along with blunt user spying though ads inside a product you paid for? Something tells me i stepped into a vicious fandom of that os.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#120
post #94

Earlier quoted context omitted.

Are you sure they don't leak any information sufficient to identify you? Let's play this through; 33 bits of information leak your identity (assuming 8 billion humans) If you set your timezone; that's already leaking 5 bits of information (37 timezones), it lets an observer narrow down your location. The times the VM is active can confirm this (by observing when the VM is more active vs not, your sleep pattern can be…

For the most part, I only use Windows VMs when I need Excel for >50MB spreadsheets. Or to test Windows VPN clients. Your analysis strikes me as implausible. Few adversaries could see all of those parameters. For example, it's typically Tor through a nested VPN chain. So it'd be nontrivial for a local observer to know that I'm using Tor. Or for a remote observer to know that I'm using VPNs. And seriously, why would I…

Windows telemetry will know it's Tor. Irregular sleep schedules are usually very regular when looked at over a long time.
Post reply on HN