Live data from Hacker News

Kaspersky is declared a US national security threat and is banned by the FCC

hothardware.com

371–380 of 435 posts

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#371
No source code publicly available? Available on millions of US computers?

That should automatically qualify it, and any other malware/proprietary software that's used by more than a handful of people, across a handful of US states as a national security threat.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#372
post #63

Earlier quoted context omitted.

Plenty of legit potential concerns.. Russian govt could "nationalize" Kaspersky at any moment and push rogue updates.

Shouldnt i have the same concerns with software from the US? You dont really have to nationalize to force devs to push malicious code (looking at you Australia)

This kind of comment isn't my favorite, but I do understand where you're coming from. I personally think that it's better the devil you know than the devil you don't.

I'm American. My country is the US. Yes, they're spying on me. Yes, they do naughty things. But I assume that at the end of the day, the US has my interests at heart more than China does. Or the UK, or Russia, or Turkey, or anyone else. I happen to live on the land that they'll protect even while filling their pockets.

My feedback to you would be to do the same. You don't have to trust your own government but assume your government will keep you around longer than any other government will.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#373
post #63

Earlier quoted context omitted.

Plenty of legit potential concerns.. Russian govt could "nationalize" Kaspersky at any moment and push rogue updates.

Shouldnt i have the same concerns with software from the US? You dont really have to nationalize to force devs to push malicious code (looking at you Australia)

The FTC isn't telling non-Americans what to do, only Americans. Russian software, outside the jurisdiction of the American legal system and under the control of Putin, is a threat to American infrastructure. American software is not.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#374

Ok, let's cut the crap. Is Kaspersky a dirtbag or not? I suspect not, but it is an unfortunate accident he was born in and runs his company from Russia, the government of which is a dirtbag, so, correct me if I am wrong, Kaspersky must be a dirtbag by association, but especially for discovering Stuxnet. Believable, but I think the real reasons Kaspersky is persona non grata is due to having discovered Stuxnet, and Ka…

> Is Kaspersky a dirtbag or not? I suspect not, but it is an unfortunate accident he was born in and runs his company from Russia, the government of which is a dirtbag, so, correct me if I am wrong, Kaspersky must be a dirtbag by association [...].

Even if he is not a dirtbag, being in Russia means Putin has power to use Kaspersky technology in war.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#375

Why do we accept the risk of intrusion from antivirus software at all? All antivirus software developers should open-source their traversal software and thus guarantee that no harm can be done. The scanning doesn't need write access and doesn't need network access.

While I understand the intent behind your comment, the only thing that would achieve is to allow people to reverse engineer and discover more vulnerabilities

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#376

Earlier quoted context omitted.

> One could say that the same is true in the US, but I believe the degree matters. Although the US government and intelligence agencies will and do try to overreach, there is a strong legal and cultural tradition of exposing, resisting, and fighting these overreaches in the US. That point would be a lot stronger if the US government hadn't demonstrated shocking callousness and disregard for international law in their…

Hold up. Downed a plane is different from grounded a plane. I don't know the Belarusian case, but either you misused the word or they are very different.

They forced the plane to land in Belarus by threatening it with fighter jets while it was nearly out of their airspace.

IIRC they pretended there was a bomb threat or some other nonsense.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#377

Earlier quoted context omitted.

> One could say that the same is true in the US, but I believe the degree matters. Although the US government and intelligence agencies will and do try to overreach, there is a strong legal and cultural tradition of exposing, resisting, and fighting these overreaches in the US. That point would be a lot stronger if the US government hadn't demonstrated shocking callousness and disregard for international law in their…

Hold up. Downed a plane is different from grounded a plane. I don't know the Belarusian case, but either you misused the word or they are very different.

[deleted]

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#378
post #102

Earlier quoted context omitted.

The class of risky employees should perhaps be limited to Chromebooks only.

The software we develop should have better interfaces too. A security expert should also review stuff created by UX. Back when “I love you” virus started, we had pointed out something simple as “open for read” vs “open as in run/execute” should not have had the same interface. All the new security enhancements we have today - don’t run as admin, alerts to request privileged access, sandboxing - all of them existed fo…

Microsoft has done more damage than anybody by hiding known extensions by default.

Even the script kiddies fall into that trap, my old school got infected by a .pdf.js.js ...

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#379

Earlier quoted context omitted.

It surprises me how much many posters on Hacker News seem to be against using any sort of AV software - not even the built in Defender solution in Windows, if you have to use the OS for whatever reason, but i often see the sentiment expressed that supposedly the entire class of software is useless. What happened to defense in depth with all of the layers you can introduce? Surely if you run a Linux server, you might…

For Windows one of the best things you can do, AV or not, is to NOT make your daily driver account an administrator. Create an admin account with a secure password and then another standard user account for yourself and use that standard user for everything. When installing something you will need to put in your admin password but it is really not a big deal to do so. Massively reduces your chance of ransomware and a…

The last point is probably the more important one. Basically all data people care about is not protected by UAC.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#380

Earlier quoted context omitted.

No. You need to understand what you are comparing to. The question is comparing US and Russia. No. It’s not the same. But you turned this question into comparing US to perfection. Yes, you are right. US is not perfection. But there is a big difference between 70 to 10, even both are not 100. What Snowden revealed does not make 70 to 10. If you think that way, you don’t understand how bad an authoritarian regime is.

Putting a numeric value on this is silly. The fact is that the United States government can compel companies to aid in its surveillance (just recall when they forced Snowden's email provider to install a backdoor). Even if a company does not want to participate or is not compelled to do so, the US government has very significant capacity to break into and co-opt systems (all the way from targeted surveillance of indi…

Yeah, I remember when the US government took Apple to court to get them to allow FBI to have a backdoor through the encryption and Apple did not capitulate, though the cases were eventually dropped. While US agencies certainly do crooked things, they do not have the capacity to force companies to do stuff under threat of violence and otherwise that Russia does with Kaspersky.
Post reply on HN