Live data from Hacker News

German Government Agency warns about using Kaspersky

bsi.bund.de

81–90 of 147 posts

Re: German Government Agency warns about using Kaspersky

#81
post #74

Earlier quoted context omitted.

The biggest benefit to being "virus free" (even though it's not), is the package management. On windows, most software installs, updates, etc., rely on you executing a random .exe file, downloaded from some random page online, while on linux, you trust the team of maintainers (who usually know what they're doing) to keep repositories relatively safe. The same idea came for apple and google, and their software stores,…

Did apple really fuck up or are they actually succeeding with iOS being the most "safe" mainstream end-user operating system by far. Arguably they fucked up by bungling the Mac App Store so running executables downloaded from the web and software updating itself is still common.

I mean... sometimes you want to install 3rd party, non-appstore software, and not having that possibility is a fuck-up for me (and a reason not to buy apple).

Re: German Government Agency warns about using Kaspersky

#82
post #22

I warn about using any kind of snake oil. Often sold under the marking terms "antivirus" or "personal firewall" or "cloud cyber security". Known side effects of this treatment are high CPU load, high RAM consumption, drain of battery power. Sometimes they also consume your money or looking at your data. So far I would consider other counter measures, like applying user rights, proper package management and re-conside…

Anti virus can be very helpful in corporate environments if set up right and managed by knowledgeable people. Those people are expensive, but they're life savers when John from marketing clicks the "enable editing" button in a spreadsheet he just received from a spoofed email address. The problem with corporate security is that security vendors often try to shovel as much crap onto your network as possible, rather th…

Working on a large corporation, I liken our AV deployments and endpoint security as the invisible hand of productivity destruction. I’m not saying these products don’t block malware, I’m not disagreeing with you at all.

It should be stated that, with a high degree of confidence, deploying these measures against your internal employees personal systems and cloud deployments WILL invariably lead to the destruction of employee output and system performance, when things inevitably do go wrong and whole operating systems are hosed if not obliterated.

Back up your data folks +Your environments +Your passwords.

It can take weeks to get back up to full speed when your system dies to AV or anything else.

Re: German Government Agency warns about using Kaspersky

#83
post #39
post #27

Earlier quoted context omitted.

Can you expand on this, perhaps with a link to documentation about this?

I used The Google and found these links: 0. https://www.nytimes.com/2021/01/06/us/politics/russia-cyber-... 1. https://www.securityweek.com/investigation-launched-role-jet... 2. https://www.zdnet.com/article/jetbrains-denies-being-involve...

Thanks!

Re: German Government Agency warns about using Kaspersky

#84
post #62

Earlier quoted context omitted.

I'm anxious to see what the Steam Deck, one of the first popular, user accessible Linux computers, will do to the Linux landscape. For ages now, Linux has been relatively virus free because let's be honest, Linux is either used by just a few nerds (who are often just a tad harder to trick than the tech illiterate) or by servers, for which entirely different classes of malware exists. With effectively no antivirus pro…

I've the users act right and use the package management and Steam, they will be fine. If the users decided to "save money" with warez, cracks and black market software they will suffer. And Antivirus software is available for Linux but only competent administrators use it, were needed.

You don't need warez at all. For example, people might want to run Microsoft Office on the deck if they hook it up to a dock (which Valve will sell later).

You can't run Office on Linux, of course, but there are plenty of scripts you can download to set up a VM and do some remote desktop trickery (I've just recently gotten cassowary running on my laptop for exactly this use case).

It's the small touches like these that are the problem. Linux on the desktop, and especially Arch based Linux as is running on the Deck, eventually needs some kind of shell script to work around some kind of issue or lacking feature that people have come to expect from Windows.

Hell, even the "official" software stores will eventually become polluted because let's be honest, nobody guards Flatpak against malware and promising to make games run faster combined with a YouTube/Tiktok campaign will probably get enough installs to get plenty of hacked Steam accounts.

I've never seen an offering for Linux AV that doesn't require some kind of endpoint server setup. Most Linux viruses attack servers, and those seem to be the target of the Linux AV industry. ClamAV exists, but that's probably all you can say about that, it's not exactly difficult to evade.

Re: German Government Agency warns about using Kaspersky

#85
Kaspersky is indeed FSB controlled, lot of proofs of that in last 10 years, but of course they will not just upload all your data or brick PC in revenge for sanctions (well may be they will if told nuclear war has been started). They will behave according to the agreement, and just let FSB peek a bit for data they legitimately getting. Same as Microsoft / Google / Apple / Amazon etc. relationship with multiple US spying agencies.

Re: German Government Agency warns about using Kaspersky

#86
post #17

I will go on the record here and one-up them, warning against the use of any antivirus product. SO many vulns and gaping, smoking holes in that kind of software over the years, it's not even funny. Faux-security is what most vendors are peddling. https://twitter.com/GossiTheDog/status/1427935182200492039 is one of my favourite bugs from recent years. I acknowledge this bug is not specific to an antivirus product (but…

It's definitely reasonable at this point to just skip using AV. It won't protect users from bad security habits and it tends to make your system performance worse even if it doesn't have vulnerabilities. I have Windows Defender enabled on my machines since it comes with the OS (and work policy requires it), but I definitely had to exclude most of my work folders to be able to get work done. It would be nice to have s…

> specifically blocks ransomware

If microsoft made the "shadow copy"/"previous versions"/"system restore" functionality a core part of the kernel that even someone with admin rights can't mess with (which it almost is already), then that could be used to roll the system back to 5 mins before ransomware infection easily.

Re: German Government Agency warns about using Kaspersky

#87
The illusion of cybersecurity is finally being questioned.

AV scanning emails has been a phishing scam for decades which benefits the criminals.

Because so many people have worked on so many parts of a computer beit the hardware or software, who do you trust when you dont trust random strangers in the street and people like to gossip and spread rumours? Is this a classic case of cognitive dissonance or just shows giving money for something makes someone/something instantly trustworthy when their own survival comes before yours?

Re: German Government Agency warns about using Kaspersky

#88

Earlier quoted context omitted.

When I see the evidence. Party in sauna with the hookers was a quite “specific” sort of connection between E. Kaspersky and FSB officers.

Quoted post unavailable.

No, thanks.

I mean: you didn't mention who else was involved. And I’m not going to deny the evidence - I understand there are not so many “clean” players in this league.

Re: German Government Agency warns about using Kaspersky

#89
post #17

I will go on the record here and one-up them, warning against the use of any antivirus product. SO many vulns and gaping, smoking holes in that kind of software over the years, it's not even funny. Faux-security is what most vendors are peddling. https://twitter.com/GossiTheDog/status/1427935182200492039 is one of my favourite bugs from recent years. I acknowledge this bug is not specific to an antivirus product (but…

That's bad advice. It's a trade-off. Installing antivirus opens some security holes and closes others. It also adds heuristic analysis. It seems to me that the security world has come to the consensus that AV is better than no AV.

Re: German Government Agency warns about using Kaspersky

#90
post #38

It’s been interesting to note how Kaspersky has been responding to the scrutiny. It’s almost always the same - ”we have been audited a huge amount of times and no-one has ever found anything!” It’s suspicious because as someone who is a vendor of risk management, they’re leaving out the gaping hole fact which is that software is updateable and oftentimes AV will do so automatically. Potent risk is pretty huge. Same a…

Assume, just for the sake of argument, that Kaspersky has no back doors and no connections to state organs.

What would you, as Kaspersky CEO, would say?

Post reply on HN