Live data from Hacker News

German Government Agency warns about using Kaspersky

bsi.bund.de

11–20 of 147 posts

Re: German Government Agency warns about using Kaspersky

#11

Google translate: https://www-bsi-bund-de.translate.goog/DE/Service-Navi/Press... (For the none German speakers)

The DeepL translation (deepl.com) seems to be a bit better:

# BSI warns against the use of Kaspersky antivirus products

The Federal Office for Information Security (BSI) warns against the use of antivirus software from the Russian manufacturer Kaspersky in accordance with §7 of the BSI Act. The BSI recommends replacing applications from Kaspersky's portfolio of antivirus software with alternative products.

Antivirus software, including the associated real-time cloud services, has extensive system permissions and must maintain a permanent, encrypted and unauditable connection to the manufacturer's servers for system-related reasons (at least for updates). Therefore, trust in a manufacturer's reliability and self-protection, as well as its authentic ability to act, is critical to the secure use of such systems. If there are doubts about the manufacturer's reliability, antivirus software poses a particular risk to an IT infrastructure that is to be protected.

The actions of military and/or intelligence forces in Russia, as well as the threats made by the Russian side against the EU, NATO and the Federal Republic of Germany in the course of the current armed conflict, are associated with a considerable risk of a successful IT attack. A Russian IT manufacturer may itself carry out offensive operations, be forced to attack target systems against its will, or itself be spied upon as a victim of a cyber operation without its knowledge, or be misused as a tool for attacks against its own customers.

All users of antivirus software can be affected by such operations. Companies and public authorities with special security interests and operators of critical infrastructures are particularly at risk. They have the option of seeking advice from the BSI or the relevant constitutional protection authorities.

Companies and other organizations should carefully plan and implement the replacement of essential components of their IT security infrastructure. If IT security products and, in particular, antivirus software were to be switched off without preparation, they might be left defenseless against attacks from the Internet. Switching to other products involves temporary losses in convenience, functionality and security. The BSI recommends that an individual evaluation and consideration of the current situation be carried out and, if necessary, that BSI-certified IT security service providers be consulted.

Press contact: Federal Office for Information Security Press Office Tel.: 0228-999582-5777 E-mail: presse@bsi.bund.de Website: www.bsi.bund.de

Twitter: @BSI_Federation #GermanyDigitallySecureBSI

Re: German Government Agency warns about using Kaspersky

#12

This is interesting news, but submitted content must be in English on HN. Edit: Take it from dang, not me: https://news.ycombinator.com/item?id=27571809

Language isn't mentioned anywhere in the submission guidelines [0].

[0] https://news.ycombinator.com/newsguidelines.html

Re: German Government Agency warns about using Kaspersky

#13
This is interesting news but I think it's more about sanctions/politial pressure than an actual threat to general businesses and people.

Once a zero day or backdoor has been used its burnt forever, nation state intelligent services need to be incredibly careful about when and where they use them. If one was to be placed in a Kaspersky product and used, that's Kaspersky burnt as a business forever, and with it the ability to use it as a vector for high value targets. They are not going to use a backdoor in a Kaspersky product for a general attack on people and business, at least not at this point. Realistically any high value target in the west isn't using Kaspersky anyway.

Re: German Government Agency warns about using Kaspersky

#15

This is interesting news, but submitted content must be in English on HN. Edit: Take it from dang, not me: https://news.ycombinator.com/item?id=27571809

Language isn't mentioned anywhere in the submission guidelines [0]. [0] https://news.ycombinator.com/newsguidelines.html

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

Re: German Government Agency warns about using Kaspersky

#16

This is interesting news but I think it's more about sanctions/politial pressure than an actual threat to general businesses and people. Once a zero day or backdoor has been used its burnt forever, nation state intelligent services need to be incredibly careful about when and where they use them. If one was to be placed in a Kaspersky product and used, that's Kaspersky burnt as a business forever, and with it the abi…

> more about sanctions/politial pressure than an actual threat

I think this would be one of their hybrid warfare steps (well) before actually going nuclear.

Re: German Government Agency warns about using Kaspersky

#17
I will go on the record here and one-up them, warning against the use of any antivirus product. SO many vulns and gaping, smoking holes in that kind of software over the years, it's not even funny. Faux-security is what most vendors are peddling.

https://twitter.com/GossiTheDog/status/1427935182200492039 is one of my favourite bugs from recent years. I acknowledge this bug is not specific to an antivirus product (but of course, Fortigate offers that as an optional component for traffic inspection - and I keep wondering what that sub-component's code quality is like 8-)), but anyone who tries WILL find examples for grave problems aplenty.

Re: German Government Agency warns about using Kaspersky

#18
post #2

Little bit worried about Jetbrains products as well. I think they have development centers in Russia? Not worried about company, but rather some disgruntled employee, for example put this USB stick to your computer or otherwise we will prosecute you or your close one for participating in protests or some fabricated accusation.

Jetbrains was already banned at the department of defense and many other companies in the wake of previous hacks where they were suspected as the entry point.

Re: German Government Agency warns about using Kaspersky

#19

This is interesting news but I think it's more about sanctions/politial pressure than an actual threat to general businesses and people. Once a zero day or backdoor has been used its burnt forever, nation state intelligent services need to be incredibly careful about when and where they use them. If one was to be placed in a Kaspersky product and used, that's Kaspersky burnt as a business forever, and with it the abi…

You seem to be assuming a lot of things, like that Kaspersky couldn't deploy certain updates to targeted customers? That malware will leave behind trails of how it got on the computer? That plausible deniability is impossible?

What happens when a definition update "reduces false positives" but actually lets in a Russian cyberweapon that is delivered independently?

Re: German Government Agency warns about using Kaspersky

#20
It's curious to look on at this situation from Linux. Perhaps I shouldn't be too comfortable but it's really a different world. I suppose that one should take care which distribution one uses as that is also an effective entry point for software from the outside but at least a bit more obvious and open than some AV company.
Post reply on HN