Live data from Hacker News

German Government Agency warns about using Kaspersky

bsi.bund.de

141–147 of 147 posts

Re: German Government Agency warns about using Kaspersky

#141
post #103
post #50

Earlier quoted context omitted.

Most insurances expect you to have an AV installed.

It’s also part of Windows hardening standards that are then pulled into compliance frameworks. My company installs at least 3 antimalware/security management products that cripple, I mean, protect endpoint systems. 2 vendors. None of them are integrated with each other. So files and executables are all scanned 3x. Git runs abysmally slow because of all the processes involved and tiny files. One of the reasons I run t…

You must work where I work. Symantec Endpoint Protection (of course set to scan at any access), CarbonBlack, Avecto, etc etc etc. And because the people complain about it they install stuff like Nexthink to diagnose performance issues.

Eventually you end with a system that has so much latency on every I/O operation and over 60 ETW traces running you can't even run or finish a WPR trace.

Re: German Government Agency warns about using Kaspersky

#142

This is interesting news, but submitted content must be in English on HN. Edit: Take it from dang, not me: https://news.ycombinator.com/item?id=27571809

Not sure why this comment is downvoted - my post was removed because of this, it is a real limitation (not so smart one).

I feel like browser translation widgets have gotten good enough that if half of HN is reading the article as a translation, they'll still be worlds ahead of the half of HN who doesn't read the article before commenting.

Re: German Government Agency warns about using Kaspersky

#143

I'm reading this as I am giving a class on Stuxnet this morning. We're doing worms and multi-stage malware. But inevitably the conversation turns to national boundaries, cyberwar, collateral damage (to individuals, hospitals, power plants, companies..). My students want to understand the relations between companies like Microsoft and the NSA, what happened to Siemens from the economic fallout, why the Iranians would…

> [...] "A miracle of interoperability" that allowed a movie made in Hollywood to be recorded on a DVD manufactured in China to run on a player assembled in India, according to standards designed in Nederlands and Japan, playing in a home in Australia. Well, it can be played in Australia only if its DVD region code is 4, and it cannot be played in any other countries you mentioned, which are all in different regions…

There are people who make things. And people who break things. Each have their time. We are living in an age where the latter have the upper-hand. But it will pass and we will build new monuments on their bones.

Re: German Government Agency warns about using Kaspersky

#145

Why are they even using Windows? The US is not an ally either.

Germany is one of the oldest NATO countries. Of course the US did supposedly intercept the Chancellor's phonecalls or emails or something, but it seems like not much ill-will was generated as a result.

> it seems like not much ill-will was generated as a result

That's because any ill-will at a government level would have been futile and disproportionate. There was public outrage at the wiretapping but largely the general assumption seems to have been that the US intelligence operates freely in Germany. That US intelligence services engage in surveillance against even close allies was an open secret and most likely widely known among German intelligence agencies and possibly the government too.

Historically, Germany post-WW2 existed at the whim of the US, France and UK. The governments of the occupation forces in the territory of West Germany had special legal rights based on contracts pre-dating and superceding the German constitution. Officially most of those special provisions expired but there's nothing in the original contracts requiring any successor contracts to be publicly acknowledged so depending on how much you like tinfoil hats, it's entirely possible that the US still holds a legal wildcard in German law.

And even if the US had no special legal exemptions, what would that ill-will translate to? Germans opposed the invasions of Afghanistan and Iraq but the German government continued to operate as usual, to the point of participating in "peacekeeping" during the military occupation following the regime changes.

Sanctioning the US would be economic suicide. Despite the outrage about human rights abuses, Germany still isn't sanctioning China. Russia got away with various abuses and even political assassinations without actual consequences because Russian gas was an important import. And the US not only dominates large parts of the German economy but also its culture.

Re: German Government Agency warns about using Kaspersky

#146
post #103

Earlier quoted context omitted.

It’s also part of Windows hardening standards that are then pulled into compliance frameworks. My company installs at least 3 antimalware/security management products that cripple, I mean, protect endpoint systems. 2 vendors. None of them are integrated with each other. So files and executables are all scanned 3x. Git runs abysmally slow because of all the processes involved and tiny files. One of the reasons I run t…

You must work where I work. Symantec Endpoint Protection (of course set to scan at any access), CarbonBlack, Avecto, etc etc etc. And because the people complain about it they install stuff like Nexthink to diagnose performance issues. Eventually you end with a system that has so much latency on every I/O operation and over 60 ETW traces running you can't even run or finish a WPR trace.

LOL. Different batch of software.

I think this experience is called “enterprise.”

MS really shot themselves in the foot adding the ability for stuff to insert itself into I/O that easily.

Re: German Government Agency warns about using Kaspersky

#147
post #68
post #50

Earlier quoted context omitted.

Most insurances expect you to have an AV installed.

Sometimes even on Linux servers, where the best an AV can do is take CPU and IO so that there's less for the malware.

A Linux virus that Just Works... I don't see it happening. Maybe if your distro officially supports it otherwise there will be missing libraries or incorrect drivers.
Post reply on HN