Live data from Hacker News

Kaspersky is declared a US national security threat and is banned by the FCC

hothardware.com

131–140 of 435 posts

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#131

Earlier quoted context omitted.

It’s a thing in big orgs, where macros are enabled in excel and employees can be tricked into opening mail attachments. Windows defender should suffice, but like you said, from a compliance/insurance perspective it may me valuable to say “look, we scanned for signatures according to the latest knowledge of [insert vendor]”. Personally I think that it’s ridiculous that these huge orgs fail to address the actual underl…

I have personally watched Windows Defender fail to notice a real virus infection from a USB flash drive. The USB flash drive was plugged in and instantly Windows was infected - Windows Defender did nothing. You could then manually run a Windows Defender scan and it would find the infection but it would not prevent the infection. I think one's need for a security product should match one's exposure to issues - it depe…

Would one of the commercial antivirus products have caught it, though? Did you check?

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#133
post #48

Is there any point in using antivirus these days anyway? I'm open to being wrong here, but I'm under the impression that antivirus exists only to tick boxes in outdated security compliance checklists. How big of a threat are viruses compared to, say, rogue antivirus products themselves?

> rogue antivirus products themselves? It's not just rogue AV software. Buggy, insecure AVs are a big problem too. They're attack surface! Especially when running parsers and interpreters for untrusted inputs in kernel space.

Even when they don't expose any security holes, they bog the computer down so much that I'd almost rather have a virus - at least a command-and-control virus might take steps to make me unaware of its presence.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#134

Is there any point in using antivirus these days anyway? I'm open to being wrong here, but I'm under the impression that antivirus exists only to tick boxes in outdated security compliance checklists. How big of a threat are viruses compared to, say, rogue antivirus products themselves?

I assume it is a cover your ass thing for executives to point to when malware happens on systems they are responsible for.

More than that. It's still required by cert standard bodies such as PCI and SOC2 .

Even if you as an exec know they are security theater you are forced to comply due to these certifications.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#135

Ok, let's cut the crap. Is Kaspersky a dirtbag or not? I suspect not, but it is an unfortunate accident he was born in and runs his company from Russia, the government of which is a dirtbag, so, correct me if I am wrong, Kaspersky must be a dirtbag by association, but especially for discovering Stuxnet. Believable, but I think the real reasons Kaspersky is persona non grata is due to having discovered Stuxnet, and Ka…

The problem is: how do you run a business that has offices and physical assets in Russia, without being at least partially beholden to the Russian government? They have demonstrated that they are not shy about using gangster tactics. One could say that the same is true in the US, but I believe the degree matters. Although the US government and intelligence agencies will and do try to overreach, there is a strong lega…

No post body was provided.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#136

Ok, let's cut the crap. Is Kaspersky a dirtbag or not? I suspect not, but it is an unfortunate accident he was born in and runs his company from Russia, the government of which is a dirtbag, so, correct me if I am wrong, Kaspersky must be a dirtbag by association, but especially for discovering Stuxnet. Believable, but I think the real reasons Kaspersky is persona non grata is due to having discovered Stuxnet, and Ka…

The problem is: how do you run a business that has offices and physical assets in Russia, without being at least partially beholden to the Russian government? They have demonstrated that they are not shy about using gangster tactics. One could say that the same is true in the US, but I believe the degree matters. Although the US government and intelligence agencies will and do try to overreach, there is a strong lega…

> The problem is: how do you run a business that has offices and physical assets > in Russia, without being at least partially beholden to the Russian government? > They have demonstrated that they are not shy about using gangster tactics.

To be fair, the US government has used gangster tactics to get US companies to install backdoors and allow encryption breakers.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#137
Kaspersky has a very good research team which uncovered a lot of APT hacking groups including Russian ones so I don't see a reason why would they be a threat. But on the other hand Russian state can force them to snoop files and traffic from their clients but I doubt that will happen because everyone would stop using them and they would go bankrupt. Imo US government should use domestic antivirus solutions.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#138
post #61
post #32

Earlier quoted context omitted.

> Telegram vs Whatsapp in terms of security. The 3-letter US agencies do not have direct access to Telegram's servers, they do have when it comes to Whatsapp (or to any other US-based company). The same goes if you're a Russian doing anti-government stuff in, well, Russia, it's better to put your fate in Whatsapp's (and Meta's) hands, presumably the US agencies won't come after you for being against the Russian gover…

I agree with your logic, though a paranoid person might point out that they don't need access to telegram's servers; access to the app store or to automatic OS updates would be enough.

You agree to the logic based on a false premise that the 3-letter US agencies do not have direct access to Telegram's servers which are located in the US (among other places).

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#139

Earlier quoted context omitted.

I have also been amused by the number of technical people that prefer anything vs Signal in terms of security.

Signal requires a phone number and doesn't allow anonymous usage as I understand.

Signal is designed for privacy, not for anonymity.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#140

Is there any point in using antivirus these days anyway? I'm open to being wrong here, but I'm under the impression that antivirus exists only to tick boxes in outdated security compliance checklists. How big of a threat are viruses compared to, say, rogue antivirus products themselves?

I don't think you're wrong at all. Considering symantec is mining with your computer on top of all the other terrible things anti-virus companies do to your computer, at this point a virus might be less intrusive.
Post reply on HN