Live data from Hacker News

German Government Agency warns about using Kaspersky

bsi.bund.de

61–70 of 147 posts

Re: German Government Agency warns about using Kaspersky

#61
post #22

I warn about using any kind of snake oil. Often sold under the marking terms "antivirus" or "personal firewall" or "cloud cyber security". Known side effects of this treatment are high CPU load, high RAM consumption, drain of battery power. Sometimes they also consume your money or looking at your data. So far I would consider other counter measures, like applying user rights, proper package management and re-conside…

Anti virus can be very helpful in corporate environments if set up right and managed by knowledgeable people. Those people are expensive, but they're life savers when John from marketing clicks the "enable editing" button in a spreadsheet he just received from a spoofed email address. The problem with corporate security is that security vendors often try to shovel as much crap onto your network as possible, rather th…

No problem in a company, where spreadsheet not have root access to everything.

Re: German Government Agency warns about using Kaspersky

#62
post #20

It's curious to look on at this situation from Linux. Perhaps I shouldn't be too comfortable but it's really a different world. I suppose that one should take care which distribution one uses as that is also an effective entry point for software from the outside but at least a bit more obvious and open than some AV company.

I'm anxious to see what the Steam Deck, one of the first popular, user accessible Linux computers, will do to the Linux landscape. For ages now, Linux has been relatively virus free because let's be honest, Linux is either used by just a few nerds (who are often just a tad harder to trick than the tech illiterate) or by servers, for which entirely different classes of malware exists. With effectively no antivirus pro…

I've the users act right and use the package management and Steam, they will be fine. If the users decided to "save money" with warez, cracks and black market software they will suffer. And Antivirus software is available for Linux but only competent administrators use it, were needed.

Re: German Government Agency warns about using Kaspersky

#63
post #11

Earlier quoted context omitted.

The DeepL translation (deepl.com) seems to be a bit better: # BSI warns against the use of Kaspersky antivirus products The Federal Office for Information Security (BSI) warns against the use of antivirus software from the Russian manufacturer Kaspersky in accordance with §7 of the BSI Act. The BSI recommends replacing applications from Kaspersky's portfolio of antivirus software with alternative products. Antivirus…

Deepl is an amazing translation service. So much so, that i have seen sdveral peolle blindly writing into it...exposing all sorts of pii, both theirs and other persons. I often wonder what happens to it. And, tbh, being more circumspect, i haven't been bothered enough to try and find out.

same is true for google's. difference here is deepl is german and benefits from GDPR. so, from a comparative pov, I'd stick with deepl.

Re: German Government Agency warns about using Kaspersky

#64

This is interesting news, but submitted content must be in English on HN. Edit: Take it from dang, not me: https://news.ycombinator.com/item?id=27571809

Not sure why this comment is downvoted - my post was removed because of this, it is a real limitation (not so smart one).

Re: German Government Agency warns about using Kaspersky

#65

Earlier quoted context omitted.

It's definitely reasonable at this point to just skip using AV. It won't protect users from bad security habits and it tends to make your system performance worse even if it doesn't have vulnerabilities. I have Windows Defender enabled on my machines since it comes with the OS (and work policy requires it), but I definitely had to exclude most of my work folders to be able to get work done. It would be nice to have s…

> to have backups With the usual additional notes: unless you include an off-site, an off-line (or at least soft-offline) backup, and your backups get tested regularly enough, you don't have a backup system, you have aspirations & hopes! ---- For your valuable information anyway. For most individuals the core “it would really inconvenience my life if I lost it” data is surprisingly small¹, and the next layer (“losing…

"With the usual additional notes: unless you include an off-site, an off-line (or at least soft-offline) backup, and your backups get tested regularly enough, you don't have a backup system, you have aspirations & hopes!"

This should be posted in every place where people are involved with IT operations.

Re: German Government Agency warns about using Kaspersky

#66
post #17

I will go on the record here and one-up them, warning against the use of any antivirus product. SO many vulns and gaping, smoking holes in that kind of software over the years, it's not even funny. Faux-security is what most vendors are peddling. https://twitter.com/GossiTheDog/status/1427935182200492039 is one of my favourite bugs from recent years. I acknowledge this bug is not specific to an antivirus product (but…

Yes, basically this. On the one hand, being able to parse every protocol and file format under the sun in search for malware means high complexity and a lot of attack surface. On the other hand, being able to read every file, intercept all network traffic, or peek into any processes memory means pretty much highest system privilege level. Big attack surface and high privilege level are a bad combination.

And regarding the point that the BSI is trying to make here: A high privilege process with an auto-update channel back home (as modern software tends to have), is basically an extremely powerful backdoor. That's definitely not something you want to have installed across loads of systems across your countries industry and critical infrastructure.

It's funny that they apparently only realize this now. The same reasoning in the article can be used pretty much regardless of the AVs country of origin.

Re: German Government Agency warns about using Kaspersky

#67

I'm reading this as I am giving a class on Stuxnet this morning. We're doing worms and multi-stage malware. But inevitably the conversation turns to national boundaries, cyberwar, collateral damage (to individuals, hospitals, power plants, companies..). My students want to understand the relations between companies like Microsoft and the NSA, what happened to Siemens from the economic fallout, why the Iranians would…

> [...] "A miracle of interoperability" that allowed a movie made in Hollywood to be recorded on a DVD manufactured in China to run on a player assembled in India, according to standards designed in Nederlands and Japan, playing in a home in Australia.

Well, it can be played in Australia only if its DVD region code is 4, and it cannot be played in any other countries you mentioned, which are all in different regions (USA: 1; China: 6; India: 5; the Netherlands and Japan: 2). So there's that. "A miracle of interoperability."

https://en.wikipedia.org/wiki/DVD_region_code

Re: German Government Agency warns about using Kaspersky

#68
post #50
post #17

I will go on the record here and one-up them, warning against the use of any antivirus product. SO many vulns and gaping, smoking holes in that kind of software over the years, it's not even funny. Faux-security is what most vendors are peddling. https://twitter.com/GossiTheDog/status/1427935182200492039 is one of my favourite bugs from recent years. I acknowledge this bug is not specific to an antivirus product (but…

Most insurances expect you to have an AV installed.

Sometimes even on Linux servers, where the best an AV can do is take CPU and IO so that there's less for the malware.

Re: German Government Agency warns about using Kaspersky

#69
post #22

I warn about using any kind of snake oil. Often sold under the marking terms "antivirus" or "personal firewall" or "cloud cyber security". Known side effects of this treatment are high CPU load, high RAM consumption, drain of battery power. Sometimes they also consume your money or looking at your data. So far I would consider other counter measures, like applying user rights, proper package management and re-conside…

Anti virus can be very helpful in corporate environments if set up right and managed by knowledgeable people. Those people are expensive, but they're life savers when John from marketing clicks the "enable editing" button in a spreadsheet he just received from a spoofed email address. The problem with corporate security is that security vendors often try to shovel as much crap onto your network as possible, rather th…

Will be difficult. Most people are trained in a way that . "Antivirus" means "Ass covering successfully applied. I'm no longer responsible!".

The "antivirus" was sold as solution to the MBA people for thirty years and computer magazines told the consumers the same wrong story. I've seen arguments like "ISO27001 requires us to install an antivirus on that application servers". Suddenly you see "undefined behavior" on the same application server. Guess how get's blamed? Not the responsible people.

When we see weird issues on customers systems "Please turn off antivirus" is in a high number of times the solution, suddenly defined behavior. The problem with antivirus software is that it is the actual implementation of undefined behavior.

I'm not a network admin! John from marketing should be in an isolated VLAN or something like that? Only access to an departed internal file server? Because it will fail. Maybe there is JavaScript in the next spreadsheet and Microsoft Security Essentials is happy "JavaScript? Let me see. I want put my nose inside!": https://docs.microsoft.com/en-us/security-updates/SecurityAd...

Failure will happen in general computing and the systems need to be resilient about that. The other approach is what we see in mission critical systems? Multiple parallel instances if possible, no unchecked updates, no random software, only input through defined interfaces.

Re: German Government Agency warns about using Kaspersky

#70
post #38

It’s been interesting to note how Kaspersky has been responding to the scrutiny. It’s almost always the same - ”we have been audited a huge amount of times and no-one has ever found anything!” It’s suspicious because as someone who is a vendor of risk management, they’re leaving out the gaping hole fact which is that software is updateable and oftentimes AV will do so automatically. Potent risk is pretty huge. Same a…

> Same applies also to the Huawei discourse.

How? Huawei routers and switches don't auto-update.

Post reply on HN