Live data from Hacker News

Kaspersky is declared a US national security threat and is banned by the FCC

hothardware.com

101–110 of 435 posts

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#101
post #66

Ok, let's cut the crap. Is Kaspersky a dirtbag or not? I suspect not, but it is an unfortunate accident he was born in and runs his company from Russia, the government of which is a dirtbag, so, correct me if I am wrong, Kaspersky must be a dirtbag by association, but especially for discovering Stuxnet. Believable, but I think the real reasons Kaspersky is persona non grata is due to having discovered Stuxnet, and Ka…

Kaspersky graduated from The Technical Faculty of the KGB Higher School in 1987. That was a definition of a dirtbag in Soviet time.

What he could have done then at that time? To not study? To remain illiterate?

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#102

Earlier quoted context omitted.

It’s a thing in big orgs, where macros are enabled in excel and employees can be tricked into opening mail attachments. Windows defender should suffice, but like you said, from a compliance/insurance perspective it may me valuable to say “look, we scanned for signatures according to the latest knowledge of [insert vendor]”. Personally I think that it’s ridiculous that these huge orgs fail to address the actual underl…

The class of risky employees should perhaps be limited to Chromebooks only.

The software we develop should have better interfaces too. A security expert should also review stuff created by UX.

Back when “I love you” virus started, we had pointed out something simple as “open for read” vs “open as in run/execute” should not have had the same interface.

All the new security enhancements we have today - don’t run as admin, alerts to request privileged access, sandboxing - all of them existed for a decade, but the software vendors never had the guts to weigh security higher than UX

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#103
post #63

Earlier quoted context omitted.

Plenty of legit potential concerns.. Russian govt could "nationalize" Kaspersky at any moment and push rogue updates.

Shouldnt i have the same concerns with software from the US? You dont really have to nationalize to force devs to push malicious code (looking at you Australia)

I've worked in multiple European environments (gov & private sector) that mandated usage of European anti-virus & firewalls.

In finance I had a client that didn't trust any vendor and asked me to reverse engineer VPN appliances (they negotiate a special clause with the vendor), which makes more sense then trusting based on country of origin.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#104

Earlier quoted context omitted.

The class of risky employees should perhaps be limited to Chromebooks only.

This may work some of the time, but expect "I need $windows_program" to foul your chances of this. It may not always be legitimate, but telling heavy-duty transport mechanics they can't have Cummins or Bendix software (for engines and brakes) to help them diagnose, when that's the only output for troubleshooting supported by the OEM, will not end well.

This makes me thing: When we are going to see those Windows software directly on the web?

For me makes a lot of sense being able to sell a software subscription instead of a one time product sell, and for the other hand making available to use in any device in the world with internet connection.

This also can be done like Chrome apps (like Docs) or some Electron apps (like Spotify), where you can use content without Internet for some time without any problem.

For a mechanic who is looking for the amount of torque needed on a bolt this could be perfectly viable, for example.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#105

Earlier quoted context omitted.

As a US citizen you still have some semblance of rights under the constitution that dictate what the government can do.

That's nice for some people, but is cf141q5325 even a US citizen? I'm not, so from that point of view US companies cannot offer many guarantees to me

[deleted]

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#106
post #63

Earlier quoted context omitted.

Plenty of legit potential concerns.. Russian govt could "nationalize" Kaspersky at any moment and push rogue updates.

Shouldnt i have the same concerns with software from the US? You dont really have to nationalize to force devs to push malicious code (looking at you Australia)

> Shouldnt i have the same concerns with software from the US? You dont really have to nationalize to force devs to push malicious code (looking at you Australia)

You should have the same concerns about software from anywhere, including the US. I believe it's a couple orders of magnitude more likely I'd be harmed by Russian government malicious code than any other nation.

Russia is in crisis, striking indiscriminately, and has no reputation left to lose. So that's where my concern lies.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#107

Earlier quoted context omitted.

I have also been amused by the number of technical people that prefer Telegram vs Whatsapp in terms of security.

I have also been amused by the number of technical people that prefer anything vs Signal in terms of security.

Signal requires a phone number and doesn't allow anonymous usage as I understand.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#108
post #87
post #83

Earlier quoted context omitted.

Snowden, for a thing.

What about Snowden? How he would prevent US 3-letter agencies from having access to servers located in the US or in London?

Sorry, I had mis-read the question, thought you were talking about WhatsApp. That’s news to me, the US server thing for Telegram.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#109
post #65

Earlier quoted context omitted.

I think your last sentence is what Putin counts on, that the West won’t risk “hurting the business environment” to respond to his military campaign. I think one of the flaws of Western culture is how much business efficiency is put on a pedestal above all other priorities. Because of that type of mindset, the West can’t even manufacture simple cloth or paper masks during a healthcare crisis (as an example).

Devils advocate: that efficiency is one important reason why we're rich enough to be able to afford so much else. Like, CO2 emissions are best controlled by societies who are able to shoulder the greater expense of avoiding coal and such. If we can't count on these efficiencies, we're going to lose a huge amount of positives. This sounds to me kind of like the fallacy of "if it saves even one life, it's worth it". Th…

To be clear I’m not saying to move to the extreme end of the spectrum.

My point is that the West often seems to consider low costs and efficiency above long-term implications.

I’m not saying the West should pull an Argentina [1], but the West also shouldn’t always be metaphorically choosing the lowest bidder.

[1] https://www.npr.org/sections/money/2017/02/17/515850029/epis...

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#110

Earlier quoted context omitted.

I'm curious, can you tell me why Windows Defender is inadequate? I also gather that Microsoft sells an enhanced version for businesses with needs beyond local machine antivirus.

I can't speak to its inadequacy, but I can point out that it is obviously unethical for Microsoft to sell a broken operating system and then separately profit from a product that mitigates part of what is broken in Windows. Microsoft now has no incentive to fix Windows, and, in fact, benefits from not fixing it. Seems to me that is a job for Linux, anyway, and this one time Linux fell down on the job and failed utter…

That's not really a fair critique. Maybe if this was the year 2000. But modern 'antivirus' isn't about fixing a poorly designed OS. It looks for known malware signatures, detects suspicious activity in other software, and so forth. You need that kind of thing on any platform, especially ones that run a web browser and/or let users install the software of their choice.

All of that functionality is available in the free version. The paid version is for managing the security of entire large networks of devices from things like ransomware and advanced persistent threats.

Post reply on HN