Live data from Hacker News

Kaspersky is declared a US national security threat and is banned by the FCC

hothardware.com

141–150 of 435 posts

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#141
post #101
post #66

Earlier quoted context omitted.

Kaspersky graduated from The Technical Faculty of the KGB Higher School in 1987. That was a definition of a dirtbag in Soviet time.

What he could have done then at that time? To not study? To remain illiterate?

I know brilliant people from the GDR who studied at Moscow Polytechnic University, they weren't in the KGB or Stasi. You had to be system-conform to study anything, that much is true, but that's still far away from joining the KGB.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#142

Earlier quoted context omitted.

It’s a thing in big orgs, where macros are enabled in excel and employees can be tricked into opening mail attachments. Windows defender should suffice, but like you said, from a compliance/insurance perspective it may me valuable to say “look, we scanned for signatures according to the latest knowledge of [insert vendor]”. Personally I think that it’s ridiculous that these huge orgs fail to address the actual underl…

I think if Excel macros were banned in finance, trading volume would drop by several hundred billion dollars per day.

Are you giving the pros or the cons?

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#143
post #48

Is there any point in using antivirus these days anyway? I'm open to being wrong here, but I'm under the impression that antivirus exists only to tick boxes in outdated security compliance checklists. How big of a threat are viruses compared to, say, rogue antivirus products themselves?

> rogue antivirus products themselves? It's not just rogue AV software. Buggy, insecure AVs are a big problem too. They're attack surface! Especially when running parsers and interpreters for untrusted inputs in kernel space.

> rogue AV software

You repeat yourself sir

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#144

Earlier quoted context omitted.

The problem is: how do you run a business that has offices and physical assets in Russia, without being at least partially beholden to the Russian government? They have demonstrated that they are not shy about using gangster tactics. One could say that the same is true in the US, but I believe the degree matters. Although the US government and intelligence agencies will and do try to overreach, there is a strong lega…

> The problem is: how do you run a business that has offices and physical assets > in Russia, without being at least partially beholden to the Russian government? > They have demonstrated that they are not shy about using gangster tactics. To be fair, the US government has used gangster tactics to get US companies to install backdoors and allow encryption breakers.

The very next sentence in GP directly addresses your comment.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#145
post #48

Earlier quoted context omitted.

> rogue antivirus products themselves? It's not just rogue AV software. Buggy, insecure AVs are a big problem too. They're attack surface! Especially when running parsers and interpreters for untrusted inputs in kernel space.

Even when they don't expose any security holes, they bog the computer down so much that I'd almost rather have a virus - at least a command-and-control virus might take steps to make me unaware of its presence.

In the '90s, there was a joke: What's the difference between Windows and viruses? Viruses do something.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#146

Earlier quoted context omitted.

I think if Excel macros were banned in finance, trading volume would drop by several hundred billion dollars per day.

Are you giving the pros or the cons?

Seriously though... Maybe this is something that should be done.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#148

Earlier quoted context omitted.

The problem is: how do you run a business that has offices and physical assets in Russia, without being at least partially beholden to the Russian government? They have demonstrated that they are not shy about using gangster tactics. One could say that the same is true in the US, but I believe the degree matters. Although the US government and intelligence agencies will and do try to overreach, there is a strong lega…

Quoted post unavailable.

Russia is free to ban Microsoft Defender et al.

Re: Kaspersky is declared a US national security threat and is banned by the FCC

#149

Is there any point in using antivirus these days anyway? I'm open to being wrong here, but I'm under the impression that antivirus exists only to tick boxes in outdated security compliance checklists. How big of a threat are viruses compared to, say, rogue antivirus products themselves?

It’s a thing in big orgs, where macros are enabled in excel and employees can be tricked into opening mail attachments. Windows defender should suffice, but like you said, from a compliance/insurance perspective it may me valuable to say “look, we scanned for signatures according to the latest knowledge of [insert vendor]”. Personally I think that it’s ridiculous that these huge orgs fail to address the actual underl…

I seem to recall an article about a big org, probably in Finance, which took a serious look at the Excel Macro thing. Only a puny fraction of their employees, pretty much all in a couple specialized departments, actually used those. SO - outside of those few and their dept's, all macros were disabled/banned by fiat. Which allowed the relevant malicious-macro-prevention resources & training to be focused on those few.
Post reply on HN