Live data from Hacker News

Kaspersky AV injected unique ID allowing sites to track users in incognito mode

heise.de

131–140 of 164 posts

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#131
post #86
post #77

Earlier quoted context omitted.

They don’t sell it or rent it, they give it away! That’s some pro-level weasel wording.

They're saying they sell your information, but not your personal information. And then they say that any information they get isn't personal.

Given that most private info such as SSNs have been leaked to the public domain, that covers quite a lot haha.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#132
post #2

Their fix is apparently to not leak machine-unique UUIDs but UUIDs unique to the version of the AV. Thanks Kaspersky for leaking if the users AV is vulnerable to exploits!

That's not really a big deal. The attackers can just be indiscriminate and hit a good number of vulnerable instances. And it's already pretty standard for clients to send used agent versions.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#133
post #67

Anti-virus here means anti-privacy. What shocks me most is that this is in the paid versions as well. I run Linux and have ClamAV installed for some compliance thingy, yet I have never run it (the compliance thingy tells me to have AV installed, not to actually run it). I can totally recommend some up-to-date Linux distro in case you want to steer clear of "virusses (etc)".

Why does it shock you? Do you think Kaspersky was selling user info, and not just doing their security scanning work with an unintentionally leaking side effect?

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#134
post #2

Their fix is apparently to not leak machine-unique UUIDs but UUIDs unique to the version of the AV. Thanks Kaspersky for leaking if the users AV is vulnerable to exploits!

That's not really a big deal. The attackers can just be indiscriminate and hit a good number of vulnerable instances. And it's already pretty standard for clients to send used agent versions.

Well, it is, because you can now deploy much more targetted payloads, which means you can hit even more instances with a little bit of extra work, comparatively.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#135
post #8

Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender. That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing…

Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

Is that so? Chromium browser, distributed in Debian repositories, sends a signal to Google (with cookies) every time you open new tab if you use Google as default search engine (you can easily verify this by opening a new tab, running developer tools and refreshing the tab. The URL is https://www.google.ru/_/chrome/newtab?ie=UTF-8 and it has headers preventing caching).

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#136
post #8

Earlier quoted context omitted.

Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

You are wrong about trusting Linux. Linux would badly need AV if it was a more popular desktop OS. Right now the user base is just too small to be a valuable target. A regular Linux distro (without SELinux or some kind of application sandboxing and a hardened setup including NOEXEC home, forbidding ptrace, ...) is very susceptible to compromise. All it takes is somehow getting the system to execute one unprivileged s…

Yes, Linux distributions don't have protection against malicious software. If you downloaded thrid-party program and run it, it can read everything from your home directory, including cookies and browser history, it can inject itself into browser process, it can see everything you type.

And if you decided to add third-party apt repository, for example, to use Node.JS or VS Code, you give permanent root access to the owner of repository. Also, some third-party .deb packages (for example, Slack) automatically add their repository and public key to apt sources list upon installation.

For example, there is a third-party repository, that allows installing multiple versions of PHP in Debian. This repository replaces cryptographic libraries provided by Debian with its own ones (you can see those packages here: https://packages.sury.org/php/pool/main/o/openssl/ )

Also, in Linux unprivileged program, run under "nobody" account, can read all unique hardware identifiers like MAC address, HDD serial number etc.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#137
Why would they use a unique id unless they intending to track or deliver unique JS payloads to each user?

Edit: Especially frightening given allegations of FSB ties that other users pointed out https://en.wikipedia.org/wiki/Kaspersky_bans_and_allegations...

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#138

Earlier quoted context omitted.

I haven’t ran Windows outside a VM (and only then for FPGA/ASIC programming tools) in the better part of a decade myself and loathe every second of the time I do run it in a VM, yet I still think you are out of line here. Maybe consider cooling off before posting more?

Specifically, what is bad in pointing out windows is a security liability, and a low quality os generally speaking? Along with blunt user spying though ads inside a product you paid for? Something tells me i stepped into a vicious fandom of that os.

Perhaps your arguments would be more persuasive if you didn't immediately label anyone who disagrees with you a "fanboi".

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#140

Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender. That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing…

Android AVs are data hoarding goldminers. The Android ecosystem is replete with AVs with questionable privacy policy. To me, it seems like most utilities on Android (like AVs) solely exist to compromise user's privacy. Some even bundle in free VPNs (and you can straight away guess why it's free). One of India's largest telecom networks, known for self enforced censorship via deep packet inspection, has an AV on PlayS…

Reminds of me the WoT Extension "Data breach": https://www.makeuseof.com/tag/web-trust-data-breach-accident...
Post reply on HN