Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender. That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing…
Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?
Kaspersky AV injected unique ID allowing sites to track users in incognito mode
111–120 of 164 posts
Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode
#112Earlier quoted context omitted.
I was using a spinny disk for a few weeks and I upgraded back to SSD the other day. The difference is incredible. Browser used to take 10 seconds to start, now it's instant. The only good thing is, I got so frustrated waiting constantly that I optimized my software to minimize IO (eg disabled browser history) so now it's even faster.
I will blow your mind when I will tell you to use a RamDisks for fastest run times wink wink
(Enabling RAPID mode basically creates an invisible RAM disk and uses it under the hood.)
Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode
#113I don't fully understand why everyone gets upset over browser leaks when in private mode - most websites interested in tracking private sessions will just associate private and non-private sessions by IP address. If you're paranoid enough to use a VPN for 'private' traffic, you should probably be running such sessions in a VM using something like the tails live CD.
Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode
#114Earlier quoted context omitted.
I guess I don't understand why anyone would want to leave it installed after that magnitude of trust violation (silent privacy-destroying MITM of HTTPS traffic by default). Why do you? Edit: Or maybe I'm misinterpreting?
Not everyone is able to choose what software is installed on the machine they use. Especially for AV, that may be enforced by the company one works for.
Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode
#115Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode
#116Earlier quoted context omitted.
Not everyone is able to choose what software is installed on the machine they use. Especially for AV, that may be enforced by the company one works for.
What company is using Kaspersky? Aren't they on US security blacklists?
In fact more than 95% of people are not presently in the US.
Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode
#117Earlier quoted context omitted.
Getting rid of AVs is old news. If almost no one in infosec trusts using them then why bother? https://twitter.com/justinschuh/status/802491391121260544 https://robert.ocallahan.org/2017/01/disable-your-antivirus-...
Sometimes i get the feeling some are contrarian only for the sake of it. Advocating using windoze without av is like advocating not using condoms because it doesn't feel good.
I have seen my share of ridiculous security flaws in ALL OS'. Anyone remember when you could login on any mySQL server by simply trying enough times? That wasn't windows specific! (back in 2012!)
Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode
#118Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode
#119Earlier quoted context omitted.
I see windoze fanboys are having a leg-day today. Enjoy your ads and spying. Oh an the virii.
I haven’t ran Windows outside a VM (and only then for FPGA/ASIC programming tools) in the better part of a decade myself and loathe every second of the time I do run it in a VM, yet I still think you are out of line here. Maybe consider cooling off before posting more?
Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode
#120Earlier quoted context omitted.
Are you sure they don't leak any information sufficient to identify you? Let's play this through; 33 bits of information leak your identity (assuming 8 billion humans) If you set your timezone; that's already leaking 5 bits of information (37 timezones), it lets an observer narrow down your location. The times the VM is active can confirm this (by observing when the VM is more active vs not, your sleep pattern can be…
For the most part, I only use Windows VMs when I need Excel for >50MB spreadsheets. Or to test Windows VPN clients. Your analysis strikes me as implausible. Few adversaries could see all of those parameters. For example, it's typically Tor through a nested VPN chain. So it'd be nontrivial for a local observer to know that I'm using Tor. Or for a remote observer to know that I'm using VPNs. And seriously, why would I…