Live data from Hacker News

Kaspersky OS

eugene.kaspersky.com

141–150 of 290 posts

Re: Kaspersky OS

#141

Only use it if you want to send all of your information to FSB (modern KGB). Evgeniy Kasperskiy has friends in government, police and FSB. He also is apologet of state surveillance.

I prefer the FSB to have access to my files than NSA. What FSB can do to me? Send to Guantanamo?

Guantanamo may seem like a 5-star resort compared to where the FSB could send you...

Re: Kaspersky OS

#142
post #137
post #124

Earlier quoted context omitted.

You could just as easily say Symantec/Norton/Microsoft Defender/Windows/Google is CIA/NSA. Isn't it, though? Apple seems to be the only company that has stood up to the three letter agencies. (I'm a US citizen.)

Actually MS was the one to first challenge National Security Letters. Moreover if it was found out that they had left a back door in it would result in the loss of billions of dollars in business, from Europe alone. Whereas Kaspersky very clearly will always have a Russian government/corporate client.

Are you sure Microsoft was? I thought Yahoo did. I can't find the reference now (Google is full of references to Yahoo being the first to disclose an NSL), but I seem to remember something from 2008-2009 era and Microsoft's challenge was in 2012-2013 era if memory serves. Not that this matters much in the grand scheme, but I'd still love to know which company really has that distinction. Links appreciated if you find one!

Re: Kaspersky OS

#143
post #123

Earlier quoted context omitted.

You could say the same for Cisco, Juniper, and Microsoft. Even your anti-virus companies has worked with the govt to allow some govt sponsored malware through. Would be great if Kaspersky OS will be free and open source.

Come on... it's not like Oracle started as a project Larry Ellison worked on for the CIA...

Yes, but the quality of oracle means that a backdoor is your least concern ;)

Re: Kaspersky OS

#144

Earlier quoted context omitted.

Yeah you only FTrace your entire networking stack at watch if it ever sends/receives packets without your knowledge. Or use libpcap and accomplish the same task. Or use a user space packet stack stack and disable your default network interface. I get not everything on the system is pure FOSS. But every binary ball isn't NSA spyware. If you assume that is true, you literally cannot use ANY computer. FOSS OS's make it…

If you can't trust your processor you can't trust any of your verification chain that runs on said processor.

Ahem http://rationalviews.com/t/presentation-on-fully-open-source...

You could go into that rabbit hole. I'd recommend against it... I lost days reading all the docs and playing with this

Re: Kaspersky OS

#145

Only use it if you want to send all of your information to FSB (modern KGB). Evgeniy Kasperskiy has friends in government, police and FSB. He also is apologet of state surveillance.

So should we also only use McAfee products if we want to send all the our information to CIA?

Re: Kaspersky OS

#146
post #137

Earlier quoted context omitted.

Actually MS was the one to first challenge National Security Letters. Moreover if it was found out that they had left a back door in it would result in the loss of billions of dollars in business, from Europe alone. Whereas Kaspersky very clearly will always have a Russian government/corporate client.

Are you sure Microsoft was? I thought Yahoo did. I can't find the reference now (Google is full of references to Yahoo being the first to disclose an NSL), but I seem to remember something from 2008-2009 era and Microsoft's challenge was in 2012-2013 era if memory serves. Not that this matters much in the grand scheme, but I'd still love to know which company really has that distinction. Links appreciated if you find…

I suspect you're right, that said Yahoo has lost all respect from me after they've basically turned over everything without question after Mayer became CEO. In all honesty it's very hard to tell because the challenges are secret and sealed for the most part.

Re: Kaspersky OS

#147

Earlier quoted context omitted.

It's another FUD. Keep in mind that Kaspersky lab have found EQUATION Group, no one else could.

How many Russian state sponsored hacking teams have they uncovered?

How many Russian state sponsored hacking teams have Symantec uncovered? They didn't even assign any specific state to the hacking teams, it can only be assumed from the targets. The fact that anyone spends time and publishes such findings is commendable, and is more than I have seen from other companies.

PS. Perhaps I just missed some publications, so I would welcome any links.

Re: Kaspersky OS

#148

Earlier quoted context omitted.

FreeBSD, OpenBSD, and Linux don't.

Well except that they have vulnerabilities that the aforementioned agencies can exploit. So pragmatically, it's the same thing. Even disregarding vulnerabilities, these OSes are not secured by design. Keeping your OS secured is a strong trade-off with convenience. Although I guess that if you use OpenBSD, that's a strong signal that you want to go the extra mile in the direction of security.

I really do need to put more effort into using OpenBSD for my daily stuff.

I use it for my router, but my desktop is Linux (Steam. It's because of Steam. I'll be totally honest :D )

Re: Kaspersky OS

#149
post #87

Earlier quoted context omitted.

So we have 2-3 very niche deployments. Does it really make L4 popular in embedded systems? Also, OKL4, specially the version claimed to run on qualcomm is very different from the original L4 (I say claimed since multiple attempts to reverse engineer qualcomm baseband firmware showed no traces of OKL4) edit: if you think this is incorrect please provide a valid counterpoint. downvoting a post this way to hide its pres…

It runs on billions of baseband processors. It's popular by any sane definition of the word.

Following that logic, iOS is also popular in the embedded space.

Re: Kaspersky OS

#150
Just a few days ago I became aware of CertiKOS, which is apparently a formally verified kernel [0] [1]. I think these two aspects--formal verifiability and being open source--are key for a truly secure OS of the future.

[0] http://news.yale.edu/2016/11/14/certikos-breakthrough-toward...

[1] https://www.usenix.org/conference/osdi16/technical-sessions/...

Post reply on HN