Live data from Hacker News

Kaspersky AV injected unique ID allowing sites to track users in incognito mode

heise.de

31–40 of 164 posts

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#31
post #27
post #23

Earlier quoted context omitted.

If you are using Windows, I recommend using defender over any other AV option[0]. Understand, if you are already using Windows, you are already trusting Microsoft. If you don't trust Microsoft you probably shouldn't be using Windows. [0] There are enterprise solutions that may be better for centralized control in a mixed environment (osx/Linux/windows). Please consult your CISO

I do agree with that. Except that I do use Windows without trusting Microsoft. I use install disks that I've purchased ~anonymously for cash. And I only run VMs, which hit the Internet via nested VPN chains, and sometimes Tor.

So all the telemetry that Windows collects from the VM's you're running are sent to Microsoft through nested VPNs over TOR?

I don't think Microsoft minds or cares that your Windows VM telemetry gets send to them that way or any other way?

How are your VPNs and TOR helping you with the Microsoft you don't trust?

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#32
post #8

Earlier quoted context omitted.

Indeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?

I think for the purposes of antivirus software, trust issues can be set aside here. Windows Defender ideally has the upper edge for choosing an antimalware solution for Windows in that it's baked in directly to the OS and therefore has more control and ability to prevent malicious activity than a third-party solution. You might not have to trust Microsoft due to privacy concerns, but for something like antivirus soft…

Windows Defender is a superior AV solution for the same reason first party map solutions are superior to third party.

When part of your core functionality is dependent on coverage and total install count, you're never going to beat someone who leverages control of a lower part of the stack.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#33

Earlier quoted context omitted.

If nothing else, herd immunity. That said, I don't know if there's any compelling reason to use something beyond what the OS vendor already provides.

Agree with you, on Windows. But when you go into Linux and Mac territory, there really isn't any OS Vendor specific security solution that does what many people need. AV is still super important to have for people who don't understand that downloading a fake flash player to watch the newest game of thrones episode isn't the best idea. And there's a lot of those people out there.

Ironically those are the same people who will install 2 or 3 different virus scanners simultaneously ("just in case") thereby making their PC as unusable as it would be with even the worse virus.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#35
Some years ago I found Mcafee Enterprise doing something similar, where it added a unique ID to the user agent string on Firefox. It didn't inject it tlat runtime though, it actually modified your Firefox profile files to set it.

I presume this wouldn't allow tracking in private browsing mode (I guess Firefox doesn't use the standard user agent), but still not good.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#36
post #7
post #5

Earlier quoted context omitted.

Jumpshot is Avast. Just a subsidiary.

Does that somehow make it OK?

That's what some people seem to think about Pocket belonging to Mozilla or Mozilla owning part of Cliqz... it's OK if they have a business relationship that loosely looks like control

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#37
post #17

Earlier quoted context omitted.

I think for the purposes of antivirus software, trust issues can be set aside here. Windows Defender ideally has the upper edge for choosing an antimalware solution for Windows in that it's baked in directly to the OS and therefore has more control and ability to prevent malicious activity than a third-party solution. You might not have to trust Microsoft due to privacy concerns, but for something like antivirus soft…

How can one "set aside" privacy issues?

Wasn't the argument you're responding to that Defender is the superior solution so that you don't have to trust other vendors than Microsoft, of which the trust point is moot if you've already chosen to run Windows?

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#38
post #27

Earlier quoted context omitted.

I do agree with that. Except that I do use Windows without trusting Microsoft. I use install disks that I've purchased ~anonymously for cash. And I only run VMs, which hit the Internet via nested VPN chains, and sometimes Tor.

So all the telemetry that Windows collects from the VM's you're running are sent to Microsoft through nested VPNs over TOR? I don't think Microsoft minds or cares that your Windows VM telemetry gets send to them that way or any other way? How are your VPNs and TOR helping you with the Microsoft you don't trust?

Microsoft can collect anything it wants from those VMs. Because they contain nothing that I don't want them to know. In particular, they don't contain anything about my meatspace identity.

Sometimes I do need to put data on VMs that I want kept private. For that, I clone a Windows VM, add a virtual disk containing the data, and then start it with no network connectivity. When I'm done, I detach the data disk, and delete the VM.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#39
post #17

Earlier quoted context omitted.

How can one "set aside" privacy issues?

Wasn't the argument you're responding to that Defender is the superior solution so that you don't have to trust other vendors than Microsoft, of which the trust point is moot if you've already chosen to run Windows?

My point is that using Debian is the superior solution, from a privacy perspective. But yes, I do agree that Defender is the best option, if you must use Windows.

Re: Kaspersky AV injected unique ID allowing sites to track users in incognito mode

#40

Honest question: what is AV even for these days? I have had some form of AV on all of my Windows machines since the 90's. I don't think I have seen a detection in at least ten years.

Every single company I worked for installed AV on our work computers, which was a huge resource hog and made the highest-specced MacBook Pros feel like cheap netbook. I suspect it is mandated by some sort of compliance requirement, and the IT departments are just ticking a box. Maybe that's how this industry is still alive.

If you have an IT department, they will insist on AV software just to cover their ass. Noone there wants to be the one explaining to a clueless boss that they didn't use av software og something bad happened.
Post reply on HN