Live data from Hacker News

Kaspersky is declared a US national security threat and is banned by the FCC

hothardware.com

91–100 of 435 posts

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#91

Earlier quoted context omitted.

Shouldnt i have the same concerns with software from the US? You dont really have to nationalize to force devs to push malicious code (looking at you Australia)

As a US citizen you still have some semblance of rights under the constitution that dictate what the government can do.

Snowden's leaks showed that the NSA was simply ignoring the 4th Amendment, and that the secret FISA court was letting the NSA do so.

Theoretically, the Constitution protects you. In reality, the intelligence community acts largely in secret, and there's very little preventing them from violating the Bill of Rights. Citizens don't even know what rights they've given up until someone like Snowden spills the beans.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#92

Earlier quoted context omitted.

Shouldnt i have the same concerns with software from the US? You dont really have to nationalize to force devs to push malicious code (looking at you Australia)

As a US citizen you still have some semblance of rights under the constitution that dictate what the government can do.

That's nice for some people, but is cf141q5325 even a US citizen?

I'm not, so from that point of view US companies cannot offer many guarantees to me

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#93

Earlier quoted context omitted.

It’s a thing in big orgs, where macros are enabled in excel and employees can be tricked into opening mail attachments. Windows defender should suffice, but like you said, from a compliance/insurance perspective it may me valuable to say “look, we scanned for signatures according to the latest knowledge of [insert vendor]”. Personally I think that it’s ridiculous that these huge orgs fail to address the actual underl…

The class of risky employees should perhaps be limited to Chromebooks only.

This may work some of the time, but expect "I need $windows_program" to foul your chances of this. It may not always be legitimate, but telling heavy-duty transport mechanics they can't have Cummins or Bendix software (for engines and brakes) to help them diagnose, when that's the only output for troubleshooting supported by the OEM, will not end well.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#94
post #26

> Kaspersky also maintains that it “doesn’t have any ties with any government, including Russia’s This take is either naive in the extreme, or disingenuous. For a security company trying to maintain a trusted reputation, neither of those two options is good. While possibly technically accurate, it is a dodge or a flub that overlooks the fact that their autonomy can be usurped by the governments where they are based a…

Exactly. They're one OMON or FSB visit away from 'having ties to the Russian government.' Refusing to acknowledge that is just downright disingenuous.

The same can be said about any vendor in the world, though.

Any of them is one NSL away from becoming a spy, wrecker or saboteur.

If your threat model includes foreign governments, don't use foreign closed source software. If your threat model includes your government, don't use domestic closed source software.

Or do, but either be ready to mitigate the harm, or be willing to live with it.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#95

Earlier quoted context omitted.

It’s a thing in big orgs, where macros are enabled in excel and employees can be tricked into opening mail attachments. Windows defender should suffice, but like you said, from a compliance/insurance perspective it may me valuable to say “look, we scanned for signatures according to the latest knowledge of [insert vendor]”. Personally I think that it’s ridiculous that these huge orgs fail to address the actual underl…

The class of risky employees should perhaps be limited to Chromebooks only.

This is why people don't like IT staff a lot of time. They think their needs of making their own jobs easier outweigh those of the organization and getting stuff done.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#96

Earlier quoted context omitted.

When was Kasepersky ever considered a dirtbag? That company has written a lot of technically in-depth security reports over various threats for a long time. AFAIK it's a (relatively) honest business, though sadly the target of American russophobia

Unsure of reason for downvotes, but this was my observation as well, and my experience is that Kaspersky Labs scanning software successfully sanitizes its targets and does so without giving the uncanny feeling of wasting one's time. Putin and friends are moronic for bullying and harassing and mugging Ukraine. But if I were him, I would definitely declare apple pie a security threat in response.

Yeah, it was my preferred AV for a while, til I switched to a local company

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#97

Is there any point in using antivirus these days anyway? I'm open to being wrong here, but I'm under the impression that antivirus exists only to tick boxes in outdated security compliance checklists. How big of a threat are viruses compared to, say, rogue antivirus products themselves?

It’s a thing in big orgs, where macros are enabled in excel and employees can be tricked into opening mail attachments. Windows defender should suffice, but like you said, from a compliance/insurance perspective it may me valuable to say “look, we scanned for signatures according to the latest knowledge of [insert vendor]”. Personally I think that it’s ridiculous that these huge orgs fail to address the actual underl…

I think if Excel macros were banned in finance, trading volume would drop by several hundred billion dollars per day.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#98

I spent Sunday researching alternatives, then uninstalling KIS and trying to install BitDefender. From this I conclude that the current state of AV/Security apps is dismal. Researching alternatives is difficult, it falls directly into the cesspool that is web product recommendation in 2022. Trying to weed out the garbage articles, I find a handful of apps that are consistently rated that the top. I discarded the reco…

I'm curious, can you tell me why Windows Defender is inadequate? I also gather that Microsoft sells an enhanced version for businesses with needs beyond local machine antivirus.

I can't speak to its inadequacy, but I can point out that it is obviously unethical for Microsoft to sell a broken operating system and then separately profit from a product that mitigates part of what is broken in Windows. Microsoft now has no incentive to fix Windows, and, in fact, benefits from not fixing it. Seems to me that is a job for Linux, anyway, and this one time Linux fell down on the job and failed utterly, iow, not even Linux can make Windows secure. Does anyone else see the irony of the FCC banning Kaspersky? It is as silly and ineffective as banning viruses and malware. If they had any concern for security as opposed to security theater, they'd ban Windows.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#99
post #57

Earlier quoted context omitted.

I found it always fishy that telegram applauds itself for being a secure messenger but decided against encryption by default. With the flick of a switch every doubt would go away but alas.

End-to-end encrypted by default doesn't mean much if you don't trust the third party providing the software that does the encryption. One automatic app update can enable leaking of encrypted communication.

The bigger problems for me would be the appstores because they could implement a mitm. Telegram and Signal have their client sources open so you at least can check and compile them yourself but if I would handle data that was so sensitive that I can't trust any other entity I would just self host matrix or xmpp and chat with myself...

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#100

Earlier quoted context omitted.

Shouldnt i have the same concerns with software from the US? You dont really have to nationalize to force devs to push malicious code (looking at you Australia)

Depends on the country. Unlike Russia, the government in the USA is not all powerful.

except when it comes to force companies out of the USA because of "security reasons".

I think Russia is using similar tactics, does it?

Post reply on HN