Live data from Hacker News

German Government Agency warns about using Kaspersky

bsi.bund.de

51–60 of 147 posts

Re: German Government Agency warns about using Kaspersky

#51
post #20

It's curious to look on at this situation from Linux. Perhaps I shouldn't be too comfortable but it's really a different world. I suppose that one should take care which distribution one uses as that is also an effective entry point for software from the outside but at least a bit more obvious and open than some AV company.

I'm anxious to see what the Steam Deck, one of the first popular, user accessible Linux computers, will do to the Linux landscape.

For ages now, Linux has been relatively virus free because let's be honest, Linux is either used by just a few nerds (who are often just a tad harder to trick than the tech illiterate) or by servers, for which entirely different classes of malware exists.

With effectively no antivirus protection, either because of a lack of options or because the outdated mantra that "you don't need it" because of some peculiarities that Apple used for years to deny the existence of macOS malware, Linux users are bound to run into viruses sooner rather than later. Hackers that are after Steam accounts will definitely try their hardest to infect Linux desktop users.

My best hope is that the way Linux distributions are woefully incompatible with each other will protect the hardcore Linux users somewhat from the viruses that will inevitably be spread across the "common" Linux environment. I'm sure we'll see Flatpak/Snap viruses down the line, but for a short while, we'll hopefully still have time to see where the Linux landscape is headed.

Re: German Government Agency warns about using Kaspersky

#52
post #22

I warn about using any kind of snake oil. Often sold under the marking terms "antivirus" or "personal firewall" or "cloud cyber security". Known side effects of this treatment are high CPU load, high RAM consumption, drain of battery power. Sometimes they also consume your money or looking at your data. So far I would consider other counter measures, like applying user rights, proper package management and re-conside…

"If you're forced to use Windows the one with the least known side effects is Microsoft Security Essentials but even this has several drawbacks." But permanently disabling it is very, very hard.

Actually it's not. Just add an exclusiun for C:/ - it still hogs some memory but the i/o drawbacks are gone. There is probably also a way to let it scan Downloads only but I didn't found it yet. In this configuration it still scans USB drives.

Re: German Government Agency warns about using Kaspersky

#53
post #11

Google translate: https://www-bsi-bund-de.translate.goog/DE/Service-Navi/Press... (For the none German speakers)

The DeepL translation (deepl.com) seems to be a bit better: # BSI warns against the use of Kaspersky antivirus products The Federal Office for Information Security (BSI) warns against the use of antivirus software from the Russian manufacturer Kaspersky in accordance with §7 of the BSI Act. The BSI recommends replacing applications from Kaspersky's portfolio of antivirus software with alternative products. Antivirus…

Deepl is an amazing translation service. So much so, that i have seen sdveral peolle blindly writing into it...exposing all sorts of pii, both theirs and other persons. I often wonder what happens to it.

And, tbh, being more circumspect, i haven't been bothered enough to try and find out.

Re: German Government Agency warns about using Kaspersky

#54
post #50
post #17

I will go on the record here and one-up them, warning against the use of any antivirus product. SO many vulns and gaping, smoking holes in that kind of software over the years, it's not even funny. Faux-security is what most vendors are peddling. https://twitter.com/GossiTheDog/status/1427935182200492039 is one of my favourite bugs from recent years. I acknowledge this bug is not specific to an antivirus product (but…

Most insurances expect you to have an AV installed.

Does Windows Defeneder not count?

Re: German Government Agency warns about using Kaspersky

#55
There's a lot of anti-antivirus sentiment in these comments, and while I, too, hate AV and have grown up with it being nothing but snake oil, I wonder if that's still correct in the current era of "zero trust".

I think we've learned that corporate firewalls and VPNs don't really work all that well. In other words, if you can't rely on a safe boundary to the outside world, how do you ensure individual corporate machines are not compromised? What about newer software like Crowdstrike?

What do the big tech companies like Google, Microsoft, Meta, etc do on their employees computers? Do none of them use antivirus?

Re: German Government Agency warns about using Kaspersky

#56

Earlier quoted context omitted.

> But permanently disabling it is very, very hard. I installed linux in a new machine just last week

Congratulations, me too. But that didn't help me with the linux driver issues for my laptop. Nor does linux run adobe animate, or a bunch of other software.

Good work!

The only "correct" approach is telling Adobe that they need to provide native ports of their software or switching to other software. Regarding laptops, buy business laptops (Lenovo ThinkPad, Dell Developer Edition) or laptops made from vendors with a focus on Linux (Purism, System 76, Tuxedo) and stick with internals from AMD or Intel. So it boils down to knowing things before and giving the right companies your money. It worked somehow, Intel provided first good support, than AMD, Atheros and others followed. On the ugly side we have still ARM, Qualcomm (yep - now Atheros) and of course Nvidia.

Actually the "stickers" with the Windows logo from Microsoft are the proof that the hardware runs good enough with the pre-installed version of Windows. And that the manufacturer has spend 80 $/€ or more for this. Some person also name this stickers "tax labels", nasty persons "protection money". Not that I want to encourage the Linux Foundation...

Re: German Government Agency warns about using Kaspersky

#57
post #20

It's curious to look on at this situation from Linux. Perhaps I shouldn't be too comfortable but it's really a different world. I suppose that one should take care which distribution one uses as that is also an effective entry point for software from the outside but at least a bit more obvious and open than some AV company.

I'm anxious to see what the Steam Deck, one of the first popular, user accessible Linux computers, will do to the Linux landscape. For ages now, Linux has been relatively virus free because let's be honest, Linux is either used by just a few nerds (who are often just a tad harder to trick than the tech illiterate) or by servers, for which entirely different classes of malware exists. With effectively no antivirus pro…

The biggest benefit to being "virus free" (even though it's not), is the package management. On windows, most software installs, updates, etc., rely on you executing a random .exe file, downloaded from some random page online, while on linux, you trust the team of maintainers (who usually know what they're doing) to keep repositories relatively safe.

The same idea came for apple and google, and their software stores, but google mostly fucked it up by allowing a "flashlight app" to access your contacts and gps location, and apple fucked up by not allowing you to sideload a program at all, even when you know what you're doing and trust the software.

Re: German Government Agency warns about using Kaspersky

#58
post #38

It’s been interesting to note how Kaspersky has been responding to the scrutiny. It’s almost always the same - ”we have been audited a huge amount of times and no-one has ever found anything!” It’s suspicious because as someone who is a vendor of risk management, they’re leaving out the gaping hole fact which is that software is updateable and oftentimes AV will do so automatically. Potent risk is pretty huge. Same a…

But this applies to any software that has auto-updates. Can we be sure that Microsoft/Google/Apple don't sign backdoor updates for the NSA for specific targets? As far as I know these national security orders are non-public and we don't even know if it's happening.

But Russia used Ukraine in the past as "playground" for cyber attacks: Some mandated tax software auto-update was hackend and delivered a ransomware trojan without any chance to pay i.e. pure data destruction.

Re: German Government Agency warns about using Kaspersky

#59

Seeing that the west just killed off payments in the Moscow metro, stopped security patches for Cisco networking equipment etc. etc. There is a bit of projection going on: We fear that Russia might do to us, what we just did to them. But what is the end result of this? Any "potential enemy of the west" will have to do their own tech, and we will only use our own stuff. Sounds like a bad trade for us; instead of selli…

It would be a legit thought if Kaspersky (company and the owner) wouldn't have direct connections to FSB.

Re: German Government Agency warns about using Kaspersky

#60

Earlier quoted context omitted.

"If you're forced to use Windows the one with the least known side effects is Microsoft Security Essentials but even this has several drawbacks." But permanently disabling it is very, very hard.

Intellij Idea recommends to exclude directories related to project and IDE from MSE. I think that's a reasonable compromise between performance and security.

They once setup here the scanners to prevent modification of executable files. The linker called by GNU's GCC was...well...surprised. Not a problem if you build the Windows stuff also on Linux.
Post reply on HN