Live data from Hacker News

German Government Agency warns about using Kaspersky

bsi.bund.de

121–130 of 147 posts

Re: German Government Agency warns about using Kaspersky

#121
post #5
post #2

Little bit worried about Jetbrains products as well. I think they have development centers in Russia? Not worried about company, but rather some disgruntled employee, for example put this USB stick to your computer or otherwise we will prosecute you or your close one for participating in protests or some fabricated accusation.

Look at https://blog.jetbrains.com/blog/2022/03/11/jetbrains-stateme... , they are actively moving all their employees out of Russia.

Sorry, but there is no such information. Some employees have moved out of Russia - JB help to them is not mentioned. I hope I just misunderstood it and JB do help their employees to move out of Russia.

Re: German Government Agency warns about using Kaspersky

#122

Earlier quoted context omitted.

It's definitely reasonable at this point to just skip using AV. It won't protect users from bad security habits and it tends to make your system performance worse even if it doesn't have vulnerabilities. I have Windows Defender enabled on my machines since it comes with the OS (and work policy requires it), but I definitely had to exclude most of my work folders to be able to get work done. It would be nice to have s…

> to have backups With the usual additional notes: unless you include an off-site, an off-line (or at least soft-offline) backup, and your backups get tested regularly enough, you don't have a backup system, you have aspirations & hopes! ---- For your valuable information anyway. For most individuals the core “it would really inconvenience my life if I lost it” data is surprisingly small¹, and the next layer (“losing…

> your backups get tested regularly enough

And you test the tests and so forth.

Re: German Government Agency warns about using Kaspersky

#123
post #17

I will go on the record here and one-up them, warning against the use of any antivirus product. SO many vulns and gaping, smoking holes in that kind of software over the years, it's not even funny. Faux-security is what most vendors are peddling. https://twitter.com/GossiTheDog/status/1427935182200492039 is one of my favourite bugs from recent years. I acknowledge this bug is not specific to an antivirus product (but…

My favourite part of this tweet is the down-thread reply from the author: "In fairness MSFT are really good in terms of web facing things, particularly security things." [1] This, of course, aged like milk the very next month. [2] [1] https://twitter.com/GossiTheDog/status/1427966653938143233 [2] https://www.paloaltonetworks.com/blog/2021/09/azurescape/

> My favourite part of this tweet is the down-thread reply from the author:

> "In fairness MSFT are really good in terms of web facing things, particularly security things." [1]

> This, of course, aged like milk the very next month. [2]

Being "good at software security" (in modern terms) doesn't imply not having any vulnerabilities ever, or even serious vulnerabilities.

Re: German Government Agency warns about using Kaspersky

#124
I am not an IT professional but a bit confused by how many completely negative views there are here on AV use. I have a NOD32 license and at least twice per month a url is blocked while browsing in an unobtrusive way by the software, which makes sense as may have contained malicious JS or something. Maybe it would've been caught by ublock afterwards, or may have been caught by MS defender as well, but I like the assurance provided. You can argue that I'm browsing in an unsafe manner but I doubt many of you restrict your browsing to strictly "safe" chunks of the internet.

Re: German Government Agency warns about using Kaspersky

#126

Why are they even using Windows? The US is not an ally either.

Germany is one of the oldest NATO countries. Of course the US did supposedly intercept the Chancellor's phonecalls or emails or something, but it seems like not much ill-will was generated as a result.

Not supposedly, definitely. And I think the fact that they actually did something like this is very concerning and shows two things: they are very deep inside EU computer and network systems, and that they do not truly consider the EU as an ally.

Re: German Government Agency warns about using Kaspersky

#127
post #63

Earlier quoted context omitted.

Deepl is an amazing translation service. So much so, that i have seen sdveral peolle blindly writing into it...exposing all sorts of pii, both theirs and other persons. I often wonder what happens to it. And, tbh, being more circumspect, i haven't been bothered enough to try and find out.

same is true for google's. difference here is deepl is german and benefits from GDPR. so, from a comparative pov, I'd stick with deepl.

DeepL is better quality-wise when context matters. The synonym feature with auto rephrasing of the remaining sentence is amazing too.

Re: German Government Agency warns about using Kaspersky

#128
post #122

Earlier quoted context omitted.

> to have backups With the usual additional notes: unless you include an off-site, an off-line (or at least soft-offline) backup, and your backups get tested regularly enough, you don't have a backup system, you have aspirations & hopes! ---- For your valuable information anyway. For most individuals the core “it would really inconvenience my life if I lost it” data is surprisingly small¹, and the next layer (“losing…

> your backups get tested regularly enough And you test the tests and so forth.

It is tests and verifications all the way down!

No matter how careful you are adding automated tests and test to verify those tests have run OK, and making them fail safe (fail with a warning in this case) where possible, it will always soon get to a point that there needs to be a manual “have we seen the everything is OK message recently?” or similar is by far more efficient than adding another tests to send a warning when the last layer of tests has failed.

Re: German Government Agency warns about using Kaspersky

#129

Earlier quoted context omitted.

"With the usual additional notes: unless you include an off-site, an off-line (or at least soft-offline) backup, and your backups get tested regularly enough, you don't have a backup system, you have aspirations & hopes!" This should be posted in every place where people are involved with IT operations.

It gets posted on HN EVERY SINGLE TIME. Usually the words "have backups" triggers multiple lectures on offsite backups and testing and multiple factors and ...

I'll stop repeating myself when the world gets the damned hint!

(or stops complaining when something is lost because they didn't)

Re: German Government Agency warns about using Kaspersky

#130
post #98

Earlier quoted context omitted.

They never shipped a malware that would resist a fresh install. Nobody should ever use an OEM provided OS.

> They never shipped a malware that would resist a fresh install. Actually they did. It stored the malware in UEFI so after a format/clean reinstall of your OS you were still vulnerable. https://www.ghacks.net/2015/08/12/lenovo-once-again-in-hot-w...

Yes. That was bad. The thing is that Lenovos ThinkPads are still good.

Honestly, we just accept what Apple, Google and Xiaomi are doing every day. Maybe they note it somewhere in the terms or not. The difference is, that we've access to the BIOS and higher expectations to Lenovo. On the other side "What Aboutism" doesn't help :(

Post reply on HN