Live data from Hacker News

Kaspersky AV injected unique ID allowing sites to track users in incognito mode

heise.de

151–160 of 164 posts

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#151

Earlier quoted context omitted.

If nothing else, herd immunity. That said, I don't know if there's any compelling reason to use something beyond what the OS vendor already provides.

Agree with you, on Windows. But when you go into Linux and Mac territory, there really isn't any OS Vendor specific security solution that does what many people need. AV is still super important to have for people who don't understand that downloading a fake flash player to watch the newest game of thrones episode isn't the best idea. And there's a lot of those people out there.

Apple does actually have malware protection built in to macOS. It's not nearly as extensive as something like Windows Defender and is pretty much invisible to the user, but it does exist.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#152
post #79
post #65

Earlier quoted context omitted.

>By default, there are no services listening. Desktop linux , not "the Linux kernel". The kernel isn't amazing, but on the desktop side you regularly see downright absurd stuff like this https://scarybeastsecurity.blogspot.com/2016/11/0day-exploit... and less surprising bugs like this https://donncha.is/2016/12/compromising-ubuntu-desktop/ The quality of software outside of some widely deployed server software tends…

> you regularly see downright absurd stuff like this That's a bug which only occurs on five year old distributions and which was fixed years before any exploit was ever found. Honestly if that's being brought up as a bad example Linux is looking pretty good compared to other operating systems.

> That's a bug which only occurs on five year old distributions and which was fixed years before any exploit was ever found

I don't think we're reading the same post unless you got confused by the part where he discusses the exploit not the bug.

> Honestly if that's being brought up as a bad example Linux is looking pretty good compared to other operating systems.

Compared to what? FreeBSD? Certainly not any modern desktop OS.

MSFT is investing heavily in exploit mitigations while Linux distros are probably still struggling with ASLR. https://www.blackhat.com/docs/us-16/materials/us-16-Weston-W...

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#153

Earlier quoted context omitted.

For the most part, I only use Windows VMs when I need Excel for >50MB spreadsheets. Or to test Windows VPN clients. Your analysis strikes me as implausible. Few adversaries could see all of those parameters. For example, it's typically Tor through a nested VPN chain. So it'd be nontrivial for a local observer to know that I'm using Tor. Or for a remote observer to know that I'm using VPNs. And seriously, why would I…

It turns out that people's irregular sleep patterns are in fact not quite as irregular when you actually measure them. On the other hand, I believe HN posting history just says "X days ago" for posts older than a day, so you can't get fine grained schedules from that (I might have graphed yours, otherwise, just to see).

Right, you'd need to scrape HN real-time to get a detailed posting history.

About sleep schedule. I really don't have one. I work and sleep when I feel like it. And I nap. And I have modafinil and zolpidem available. And coffee.

If you charted my waking and sleeping times long-term, you'd find pretty much a random walk. I can be up as much as 30-40 hours, or as little as ~1 hour. And I can be sleeping for anywhere from ~1 hour to maybe 15 hours or more.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#154
post #120

Earlier quoted context omitted.

For the most part, I only use Windows VMs when I need Excel for >50MB spreadsheets. Or to test Windows VPN clients. Your analysis strikes me as implausible. Few adversaries could see all of those parameters. For example, it's typically Tor through a nested VPN chain. So it'd be nontrivial for a local observer to know that I'm using Tor. Or for a remote observer to know that I'm using VPNs. And seriously, why would I…

Windows telemetry will know it's Tor. Irregular sleep schedules are usually very regular when looked at over a long time.

OK, Microsoft knows that some persona uses Tor. So what?

Sure, mine is "regular". In the sense of regularly random.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#155
post #8

Earlier quoted context omitted.

Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

Is that so? Chromium browser, distributed in Debian repositories, sends a signal to Google (with cookies) every time you open new tab if you use Google as default search engine (you can easily verify this by opening a new tab, running developer tools and refreshing the tab. The URL is https://www.google.ru/_/chrome/newtab?ie=UTF-8 and it has headers preventing caching).

No sane person would use Chrome/Chromium and Google, and expect privacy.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#156
post #120

Earlier quoted context omitted.

Windows telemetry will know it's Tor. Irregular sleep schedules are usually very regular when looked at over a long time.

OK, Microsoft knows that some persona uses Tor. So what? Sure, mine is "regular". In the sense of regularly random.

As mentioned, this lets microsoft single you out as an individual that is using Tor, among other signals. That makes you quite identifiable.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#157
post #156

Earlier quoted context omitted.

OK, Microsoft knows that some persona uses Tor. So what? Sure, mine is "regular". In the sense of regularly random.

As mentioned, this lets microsoft single you out as an individual that is using Tor, among other signals. That makes you quite identifiable.

Sure, "identifiable".

But they still have no clue who I am. Which is all that concerns me.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#158

Earlier quoted context omitted.

It turns out that people's irregular sleep patterns are in fact not quite as irregular when you actually measure them. On the other hand, I believe HN posting history just says "X days ago" for posts older than a day, so you can't get fine grained schedules from that (I might have graphed yours, otherwise, just to see).

Right, you'd need to scrape HN real-time to get a detailed posting history. About sleep schedule. I really don't have one. I work and sleep when I feel like it. And I nap. And I have modafinil and zolpidem available. And coffee. If you charted my waking and sleeping times long-term, you'd find pretty much a random walk. I can be up as much as 30-40 hours, or as little as ~1 hour. And I can be sleeping for anywhere fr…

You're more likely to sleep at night than not, that's sufficient to establish your timezone with good accuracy.

Fefe, a german blogger, had this analysis done using his posting history on his blog, allowing readers to not only determine his timezone, but when he was travelling and where.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#159
post #156

Earlier quoted context omitted.

As mentioned, this lets microsoft single you out as an individual that is using Tor, among other signals. That makes you quite identifiable.

Sure, "identifiable". But they still have no clue who I am. Which is all that concerns me.

Are you sure? Because the step between "identifiable" and "your personal identity" is short. Recent studies found that social graphs between social networks for the same person almost perfectly match. If you have a social network account (Facebook/Twitter/Netflix/Amazon/etc.) and you also have a social network account in the VM (HN) then someone can match those identities.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#160
post #66

There's lots of 'Do we need Kaspersky' type questions in here already. The more pertinent question is whether AV is actually effective, or if stronger countermeasures like application whitelisting are needed? https://www.youtube.com/watch?v=gvcgHkeZ1i4&list=PLqz80p7f6d...

You would need a document whitelist since many programs can be hijacked using buffer overflow attacks or outright support execution of arbritrary scripts.

I'll also point out that defending against buffer overflows which are considered vulnerabilities is a far saner boundary than a blacklist of files which grows infinitely.
Post reply on HN