Live data from Hacker News

Kaspersky OS

eugene.kaspersky.com

191–200 of 290 posts

Re: Kaspersky OS

#191

Earlier quoted context omitted.

Right. I'm saying give up on expecting the project to change. The project isn't for what you want it to be for and never will be. You should be shouting at companies who use it for applications where security is a must. That's where the madness lies. I use OpenBSD and so should you :)

I also use OpenBSD (and donate to it, since I have more money than time right now)... but damn, they do need a VM that I can use, so that it can be my regular desktop.

QEMU too slow?

Re: Kaspersky OS

#192

Earlier quoted context omitted.

These two statements contradict each other: > The underlying problem, IMO, is people. They just don't care about security, they want to deliver working device. > This unassuming black box is [...] designed for networks with extreme requirements for data security. You can claim that nobody will buy Kaspersky's device, or that they did poor market research. But you can't claim that they don't care about security.

Kaspersky certainly care about security, it's their business. I'm talking about people who build routers or web cameras. I doubt that Kaspersky built OS for internal use, they want to license it to other manufacturers. But I'm not sure that other manufacturers will want to pay for this extra security (if they would want, they already have better options).

"Kaspersky certainly care about security, it's their business."

Their business is selling antivirus & other software, not security. They have no history whatsoever of building a piece of software immune to code injection by determined attackers. There are companies and academics that build stuff like that. Some were evaluated by pentesters of third parties. Kaspersky has neither that background nor evaluations by expert breakers. We should by default think they don't know what they're doing and the product is insecure until proven otherwise. Like always.

People often mistake "company in security industry selling security products" with "knows how to secure software or systems." They're two very different things.

Re: Kaspersky OS

#193

Earlier quoted context omitted.

Of course it's fair. He built it to just have a person UNIX that he enjoys working on. Lots of other people did the same. Security was never a priority for them. Whereas, by that time, there were already multiple OS's with strong levels of built-in security. He could've copied stuff from them. There's even more now. They're still keeping broken model for (a) their priorities that put security low and (b) avoiding rew…

Right. I'm saying give up on expecting the project to change. The project isn't for what you want it to be for and never will be. You should be shouting at companies who use it for applications where security is a must. That's where the madness lies. I use OpenBSD and so should you :)

Well that's mostly true. I guess we have to shout at the cloud companies then. ;)

Re: Kaspersky OS

#194

Earlier quoted context omitted.

Right. I'm saying give up on expecting the project to change. The project isn't for what you want it to be for and never will be. You should be shouting at companies who use it for applications where security is a must. That's where the madness lies. I use OpenBSD and so should you :)

I also use OpenBSD (and donate to it, since I have more money than time right now)... but damn, they do need a VM that I can use, so that it can be my regular desktop.

Are you saying a VMM to virtualize other software or a pre-configured VM containing OpenBSD you can run on top of other OS's with better hardware support? Or something else entirely?

Re: Kaspersky OS

#195

Earlier quoted context omitted.

Exactly. Priorities = what you get out of your work. Far as Linux vs OpenBSD box, remember also that contributors (including corporate) are partly to blame here since they chose to put their investments into a project that doesn't care about security instead of one that bakes it in. Even if Theo et al weren't pleasant, they could've forked OpenBSD keeping any of their improvements while making what changes they absol…

A very valid point. IBM contributes a TON of code to Linux. They could easily have worked to improve security if they cared. Or, improved BSD, and avoided all that GPL stuff if they wanted.

I was actually shocked they didn't contribute to FreeBSD instead then rebrand their management or security customizations as their own enterprise OS. The Chinese ended up doing that with Kylan. Cambridge's CHERI team made it capability-secure with minimal modifications. IBM was in ideal position to do that, too, given they had legendary Paul Karger who already built high-assurance OS's and CPU's for them.

Let's just call it Another Missed Opportunity for the Big Blue. :)

Re: Kaspersky OS

#196

Earlier quoted context omitted.

I also use OpenBSD (and donate to it, since I have more money than time right now)... but damn, they do need a VM that I can use, so that it can be my regular desktop.

QEMU too slow?

Sadly yes. For several specific clients I have to run their Win7 VM in an emulator, and it can't quite manage on my (rather old) hardware right now.

Due for a hardware refresh soon, and I will obviously be trying it again :)

Re: Kaspersky OS

#197

Earlier quoted context omitted.

Right. I'm saying give up on expecting the project to change. The project isn't for what you want it to be for and never will be. You should be shouting at companies who use it for applications where security is a must. That's where the madness lies. I use OpenBSD and so should you :)

Well that's mostly true. I guess we have to shout at the cloud companies then. ;)

Digital Ocean supports FreeBSD, but not OpenBSD. Which is close, but not quite the same. Perhaps with a little persuasion, they could be talked into it

Re: Kaspersky OS

#198

Earlier quoted context omitted.

A very valid point. IBM contributes a TON of code to Linux. They could easily have worked to improve security if they cared. Or, improved BSD, and avoided all that GPL stuff if they wanted.

I was actually shocked they didn't contribute to FreeBSD instead then rebrand their management or security customizations as their own enterprise OS. The Chinese ended up doing that with Kylan. Cambridge's CHERI team made it capability-secure with minimal modifications. IBM was in ideal position to do that, too, given they had legendary Paul Karger who already built high-assurance OS's and CPU's for them. Let's just…

That's a big book right there!

I was really disappointed in how Apple treated BSD, but I am stupid and naive. I would have expected that from IBM though.

Re: Kaspersky OS

#200

Earlier quoted context omitted.

I also use OpenBSD (and donate to it, since I have more money than time right now)... but damn, they do need a VM that I can use, so that it can be my regular desktop.

Are you saying a VMM to virtualize other software or a pre-configured VM containing OpenBSD you can run on top of other OS's with better hardware support? Or something else entirely?

A VM to virtualize other software. In this case, my desktop has to support some clients who have very specific VM images of Win7 to access them. VirtualBox and VMware are fine, but for QEMU it's just way too slow (for me, at the moment)
Post reply on HN