Live data from Hacker News

German Government Agency warns about using Kaspersky

bsi.bund.de

101–110 of 147 posts

Re: German Government Agency warns about using Kaspersky

#101
post #61

Earlier quoted context omitted.

Anti virus can be very helpful in corporate environments if set up right and managed by knowledgeable people. Those people are expensive, but they're life savers when John from marketing clicks the "enable editing" button in a spreadsheet he just received from a spoofed email address. The problem with corporate security is that security vendors often try to shovel as much crap onto your network as possible, rather th…

No problem in a company, where spreadsheet not have root access to everything.

Spreadsheets don't have to have access to admin to cause serious issues. Company financials, shared drives, contact lists with hierarchy, email history, password managers, etc. live on restricted user accounts. As usual there's an XKCD for it: https://xkcd.com/1200/

Re: German Government Agency warns about using Kaspersky

#102
post #98

Earlier quoted context omitted.

Lenovo gets a lot of love from linux users for their laptops, but they've repeatedly shipped malware infested systems. Sometimes they did it in exchange for money, sometimes they wrote the malware themselves. I wouldn't recommend anyone go near them. I mean, hardware that'll play nice with linux is nice, but we're not lacking for alternatives these days. If a company who acts as horribly as Lenovo does can still be r…

They never shipped a malware that would resist a fresh install. Nobody should ever use an OEM provided OS.

> They never shipped a malware that would resist a fresh install.

Actually they did. It stored the malware in UEFI so after a format/clean reinstall of your OS you were still vulnerable.

https://www.ghacks.net/2015/08/12/lenovo-once-again-in-hot-w...

Re: German Government Agency warns about using Kaspersky

#103
post #50
post #17

I will go on the record here and one-up them, warning against the use of any antivirus product. SO many vulns and gaping, smoking holes in that kind of software over the years, it's not even funny. Faux-security is what most vendors are peddling. https://twitter.com/GossiTheDog/status/1427935182200492039 is one of my favourite bugs from recent years. I acknowledge this bug is not specific to an antivirus product (but…

Most insurances expect you to have an AV installed.

It’s also part of Windows hardening standards that are then pulled into compliance frameworks.

My company installs at least 3 antimalware/security management products that cripple, I mean, protect endpoint systems. 2 vendors. None of them are integrated with each other. So files and executables are all scanned 3x. Git runs abysmally slow because of all the processes involved and tiny files.

One of the reasons I run the paperwork gauntlet to run a Mac. Windows is crippled, Linux is banned on endpoints, so Mac it is. I have to run 1 AV, but it doesn’t do a lot. And I love apple kicking everyone out of the kernel over time (except VirtualBox, that’s annoying).

Luckily it’s mostly an application-level concern on Linux. Scanning files and such on file-servers, mail gateways, etc. ultimately protecting windows systems w/ normal user processes not all up in my kernel, and on limited systems. It actually kinda makes sense.

Now, commercial IDS/IPS, I don’t even want to know how those are architected. I haven’t touched an OSS one (Snort) in years.

If I won the lottery, it would be kind of fun to just sit and find horrific exploits in these things.

Re: German Government Agency warns about using Kaspersky

#105
post #17

I will go on the record here and one-up them, warning against the use of any antivirus product. SO many vulns and gaping, smoking holes in that kind of software over the years, it's not even funny. Faux-security is what most vendors are peddling. https://twitter.com/GossiTheDog/status/1427935182200492039 is one of my favourite bugs from recent years. I acknowledge this bug is not specific to an antivirus product (but…

My favourite part of this tweet is the down-thread reply from the author:

"In fairness MSFT are really good in terms of web facing things, particularly security things." [1]

This, of course, aged like milk the very next month. [2]

[1] https://twitter.com/GossiTheDog/status/1427966653938143233

[2] https://www.paloaltonetworks.com/blog/2021/09/azurescape/

Re: German Government Agency warns about using Kaspersky

#106
The same warning obviously applies to all the American AV vendors, given what we have learned in the last years. And this is not idle speculation and baseless accusations, it's right from the inside part of the NSA and CIA leaks.

So what is one to do? Where is the free open-source AV the world needs, which has the same number of highly skilled full-time developers and researchers as Kaspersky does?

There really needs to be a global AV effort and software, funded by governments, but open and transparent, and based in a country which does not sit in the shadows of over-reaching spying agencies. But what will it take for this to happen?

Re: German Government Agency warns about using Kaspersky

#107
We supply servers running some proprietary control software and a school district put Kaspersky on it after receiving it. We mentioned to them we can't be involved with that product anywhere because of our companies involvement with DFARS, and frankly we are surprised they were able to get away with using it being a government organization. Still there though, guess they just don't care.

Re: German Government Agency warns about using Kaspersky

#108

There's a lot of anti-antivirus sentiment in these comments, and while I, too, hate AV and have grown up with it being nothing but snake oil, I wonder if that's still correct in the current era of "zero trust". I think we've learned that corporate firewalls and VPNs don't really work all that well. In other words, if you can't rely on a safe boundary to the outside world, how do you ensure individual corporate machin…

I feel traditional antivirus software is the very opposite of zero trust. It runs at a very high level of permissions and intercepts almost everything.

Re: German Government Agency warns about using Kaspersky

#109
post #17

I will go on the record here and one-up them, warning against the use of any antivirus product. SO many vulns and gaping, smoking holes in that kind of software over the years, it's not even funny. Faux-security is what most vendors are peddling. https://twitter.com/GossiTheDog/status/1427935182200492039 is one of my favourite bugs from recent years. I acknowledge this bug is not specific to an antivirus product (but…

That's bad advice. It's a trade-off. Installing antivirus opens some security holes and closes others. It also adds heuristic analysis. It seems to me that the security world has come to the consensus that AV is better than no AV.

> the security world has come to the consensus

Any links? If you really care about security of your OS, consider security through compartmentalization approach, which actually works. See also: https://qubes-os.org.

Re: German Government Agency warns about using Kaspersky

#110
post #2

Little bit worried about Jetbrains products as well. I think they have development centers in Russia? Not worried about company, but rather some disgruntled employee, for example put this USB stick to your computer or otherwise we will prosecute you or your close one for participating in protests or some fabricated accusation.

Jetbrains is Czech. They have suspended their sales and R&D activities in Russia and Belarus two weeks ago[1]. Hacker News discussion from when it was announced[2]. [1] https://blog.jetbrains.com/blog/2022/03/11/jetbrains-stateme... [2] https://news.ycombinator.com/item?id=30639572

> Jetbrains is Czech.

Their headquarters is Czech, but many of their developers are or at least were based in Russia.

> They have suspended their sales and R&D activities in Russia and Belarus two weeks ago

"R&D activities" is a funny phrase. Does that mean they've stopped all development in Russia (i.e. there are no longer Russian employees working in Russia with commit access) or not?

Post reply on HN