Live data from Hacker News

Kaspersky AV injected unique ID allowing sites to track users in incognito mode

heise.de

121–130 of 164 posts

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#122
post #89

Earlier quoted context omitted.

Every single company I worked for installed AV on our work computers, which was a huge resource hog and made the highest-specced MacBook Pros feel like cheap netbook. I suspect it is mandated by some sort of compliance requirement, and the IT departments are just ticking a box. Maybe that's how this industry is still alive.

Reading sibling comments I have an idea for a startup. Make an AV, that does not really do anything, but can be used by thoughtful companies to "tick the box". Sell licenses and then do only the minimum required for compliance. It could be described that it uses Windows Defender service to provide the basis of AV solution.

An AV that alarmed on unpatched vulnerabilities might be better. Attackers will resignature their code to evade everything on VT, then spam the world to hit whoever hasn't patched.

For ransomware anyway. If they're targeting you specifically they'll find out what you're running and customize against it.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#123

Do we even need A/V for windows ? I think Microsoft Defender along with "proper digital hygeine" obviates the need for dedicated A/V solutions.

They use Mcaffee where I work, and have done for more than 10 years - it's an absolutely horrible resource hog, and keeps my laptop's fans permanently whining like it's about to explode. Things got better after the switch from mechanical disks to solid state, but the 12 or so processes it has permanently running (yes, really) still use more CPU combined that anything else. And it's never found a virus, as we catch everything at the email server, and I know what not to open in any case.

I'm not sure why anyone would use any other than Defender TBH. I wonder if perhaps it's licensed separately for enterprises?

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#124

Shock! Russian (and Chinese) companies cannot be trusted, neither can American ones, but we have this messy thing called "Democracy" and "rule of law" that gives us recourse and hope. They have none.

Agree with the first half of your sentence. Did you vote for NSA tracking?

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#125
post #79
post #65

Earlier quoted context omitted.

>By default, there are no services listening. Desktop linux , not "the Linux kernel". The kernel isn't amazing, but on the desktop side you regularly see downright absurd stuff like this https://scarybeastsecurity.blogspot.com/2016/11/0day-exploit... and less surprising bugs like this https://donncha.is/2016/12/compromising-ubuntu-desktop/ The quality of software outside of some widely deployed server software tends…

> you regularly see downright absurd stuff like this That's a bug which only occurs on five year old distributions and which was fixed years before any exploit was ever found. Honestly if that's being brought up as a bad example Linux is looking pretty good compared to other operating systems.

Yeah. The first article he linked to specifically called out Windows for doing fonts in kernel-space, to put that gstreamer vulnerability in context.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#126

Can anyone tell me how kaspersky is injecting a script into an HTTPS site? From the screenshot in the article, there doesn't appear to be a kaspersky browser extension in use. I guess it would have to be a MITM of some sort. Either by installing a cert or by getting the TLS keys from the browser, I suppose?

This was my immediate thought. Where is rewrite happening? All the options seems icky.

Windows AV software is notoriously "icky". Microsoft had been making a effort to push AV vendors towards more"official" means of real-time hooking, but many still use DLL injection, kernel hooking etc.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#127
post #79
post #65

Earlier quoted context omitted.

>By default, there are no services listening. Desktop linux , not "the Linux kernel". The kernel isn't amazing, but on the desktop side you regularly see downright absurd stuff like this https://scarybeastsecurity.blogspot.com/2016/11/0day-exploit... and less surprising bugs like this https://donncha.is/2016/12/compromising-ubuntu-desktop/ The quality of software outside of some widely deployed server software tends…

> you regularly see downright absurd stuff like this That's a bug which only occurs on five year old distributions and which was fixed years before any exploit was ever found. Honestly if that's being brought up as a bad example Linux is looking pretty good compared to other operating systems.

An attacker can trivial phish to sudo password and execute arbitrary commands every time you open the terminal.

shellrc and profile as well as almost all core unix tools allow running arbitrary code.

You can even bend the paths of bashrc and friends so the user can't trivially inspect them without dropping to root first (at which point, arbitrary code can trivially obtain root access too)

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#129
post #114

Earlier quoted context omitted.

What company is using Kaspersky? Aren't they on US security blacklists?

This may be surprising, but there's people outside the US. In fact more than 95% of people are not presently in the US.

It would be surprising if 95% of businesses outside of the US use Kaspersky. It would be surprising for any large company using them.

Most installs are from individual people in and outside of the US.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#130
post #51

Earlier quoted context omitted.

As a rare windows user (two or free times a year) i never trust a machine without an av. maybe things changed, but i see windows as so unsafe that i would not even login with to regular email, let alone make online payments. I simply see that os as a vulnerability by default.

Mate, seriously? Windows itself has come a long way to be considered stable. The real risk is user-space applications, like.. AV's.

*AVs
Post reply on HN