Live data from Hacker News

Kaspersky AV injected unique ID allowing sites to track users in incognito mode

heise.de

101–110 of 164 posts

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#101
post #74
post #64

Earlier quoted context omitted.

You live in the XP days.

The majority of the Windows haters I come across seem to be the same.

I see windoze fanboys are having a leg-day today. Enjoy your ads and spying. Oh an the virii.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#102

Honest question: what is AV even for these days? I have had some form of AV on all of my Windows machines since the 90's. I don't think I have seen a detection in at least ten years.

Every single company I worked for installed AV on our work computers, which was a huge resource hog and made the highest-specced MacBook Pros feel like cheap netbook. I suspect it is mandated by some sort of compliance requirement, and the IT departments are just ticking a box. Maybe that's how this industry is still alive.

PCI DSS Requirement 5 demands AV. Many financial industry standards, and auditors that verify the same, will demand an AV installation.

The AV needs to be up to date, pervasive, and with central reporting. Here is where simply having Windows Defender installed falls flat -- when it finds some malware on Betty's computer, you can't be sure what the scope was until you investigate yet standalone Windows Defender won't give you that information. So you need the enterprise version with the reporting console, alerts, etc.

AV is a nuisance for most of us, and I've gone sans it for many years, but it's critical in most workplaces because there are a lot of people who will happily run that program, etc, and you can't catch everything at the edge.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#103
post #94
post #38

Earlier quoted context omitted.

Microsoft can collect anything it wants from those VMs. Because they contain nothing that I don't want them to know. In particular, they don't contain anything about my meatspace identity. Sometimes I do need to put data on VMs that I want kept private. For that, I clone a Windows VM, add a virtual disk containing the data, and then start it with no network connectivity. When I'm done, I detach the data disk, and del…

Are you sure they don't leak any information sufficient to identify you? Let's play this through; 33 bits of information leak your identity (assuming 8 billion humans) If you set your timezone; that's already leaking 5 bits of information (37 timezones), it lets an observer narrow down your location. The times the VM is active can confirm this (by observing when the VM is more active vs not, your sleep pattern can be…

I'm not sure about timezones but there live about 6 times as many people on the northern hemisphere than the southern, so that's not one bit of information.

I know (and have known, unfortunately) multiple people over 60 that use Tor. Aha but such people are even rarer and therefore must be even easier to identify ... or are they? :)

In fact I know a handful of kids younger than 14 who have on occasion used Tor as well.

If you already (reasonably) assume the gender is most likely male, then you should know that is also less than one bit of information.

Etc. You need to try a bit harder :)

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#105
post #94

Earlier quoted context omitted.

Are you sure they don't leak any information sufficient to identify you? Let's play this through; 33 bits of information leak your identity (assuming 8 billion humans) If you set your timezone; that's already leaking 5 bits of information (37 timezones), it lets an observer narrow down your location. The times the VM is active can confirm this (by observing when the VM is more active vs not, your sleep pattern can be…

For the most part, I only use Windows VMs when I need Excel for >50MB spreadsheets. Or to test Windows VPN clients. Your analysis strikes me as implausible. Few adversaries could see all of those parameters. For example, it's typically Tor through a nested VPN chain. So it'd be nontrivial for a local observer to know that I'm using Tor. Or for a remote observer to know that I'm using VPNs. And seriously, why would I…

It turns out that people's irregular sleep patterns are in fact not quite as irregular when you actually measure them. On the other hand, I believe HN posting history just says "X days ago" for posts older than a day, so you can't get fine grained schedules from that (I might have graphed yours, otherwise, just to see).

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#106
post #51

Earlier quoted context omitted.

Windows with its built-in Windows Defender and your Common Sense 2019 Computer Professional Edition is going to be enough nowadays.

As a rare windows user (two or free times a year) i never trust a machine without an av. maybe things changed, but i see windows as so unsafe that i would not even login with to regular email, let alone make online payments. I simply see that os as a vulnerability by default.

Mate, seriously? Windows itself has come a long way to be considered stable. The real risk is user-space applications, like.. AV's.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#107
post #7

Earlier quoted context omitted.

Does that somehow make it OK?

Without knowing anything about the specifics here... yes, I can confidently say that transmitting information between two companies with the same owner is "ok" and should be expected.

Why is the data even being collected?

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#108
post #74

Earlier quoted context omitted.

The majority of the Windows haters I come across seem to be the same.

I see windoze fanboys are having a leg-day today. Enjoy your ads and spying. Oh an the virii.

I haven’t ran Windows outside a VM (and only then for FPGA/ASIC programming tools) in the better part of a decade myself and loathe every second of the time I do run it in a VM, yet I still think you are out of line here.

Maybe consider cooling off before posting more?

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#109
post #94
post #38

Earlier quoted context omitted.

Microsoft can collect anything it wants from those VMs. Because they contain nothing that I don't want them to know. In particular, they don't contain anything about my meatspace identity. Sometimes I do need to put data on VMs that I want kept private. For that, I clone a Windows VM, add a virtual disk containing the data, and then start it with no network connectivity. When I'm done, I detach the data disk, and del…

Are you sure they don't leak any information sufficient to identify you? Let's play this through; 33 bits of information leak your identity (assuming 8 billion humans) If you set your timezone; that's already leaking 5 bits of information (37 timezones), it lets an observer narrow down your location. The times the VM is active can confirm this (by observing when the VM is more active vs not, your sleep pattern can be…

But changing the timezone to a different value or providing a few false flags would cripple this line of thinking.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#110
post #78
post #67

Anti-virus here means anti-privacy. What shocks me most is that this is in the paid versions as well. I run Linux and have ClamAV installed for some compliance thingy, yet I have never run it (the compliance thingy tells me to have AV installed, not to actually run it). I can totally recommend some up-to-date Linux distro in case you want to steer clear of "virusses (etc)".

I used to run ClamAV for a few years, both on Linux and macOS. The only thing it ever detected were Windows viruses in my spam mailbox. Every time I received a spam email, ClamAV would complain and I'd have to go delete the email that was already not in my inbox.

This is ironically one of the ways using any AV can increase the attack surface of a device, leading to its compromise. I don't know if ClamAV has ever had an issue, but it seems lots of people here have forgotten the zoo of not-that-long-ago Windows Defender exploits that could be triggered by it scanning various files, like in a spam email the user never even looked at but their client downloaded a copy of anyway. The issues are often made worse by the AV processes that get owned already having root privileges.
Post reply on HN