[HN Gopher] Kaspersky is declared a US national security threat ...
       ___________________________________________________________________
        
       Kaspersky is declared a US national security threat and is banned
       by the FCC
        
       Author : DocFeind
       Score  : 402 points
       Date   : 2022-03-29 13:51 UTC (9 hours ago)
        
 (HTM) web link (hothardware.com)
 (TXT) w3m dump (hothardware.com)
        
       | wnevets wrote:
       | Kaspersky was caught helping the Russian government back in 2017.
       | Anyone still using their software in 2022 probably has much
       | larger problems.
        
         | zokula wrote:
        
         | usednet wrote:
         | Nobody within the hacking scene actually believed that story.
         | It's remarkable that there's been 0 evidence that Kaspersky has
         | ever had a backdoor yet so many people believe it.
         | 
         | The NSA's own incompetence led them to run an antivirus on a
         | computer with Equation Group spyware on it. Keep in mind that
         | Kaspersky had been fighting Western intelligence services for
         | years at that point. Israeli intelligence actually breached
         | Kaspersky's network in 2015, no doubt because Kaspersky is the
         | only AV company that actually exposes US-created malware.
        
           | wnevets wrote:
           | I'm getting deja vu to when I was told Russian's continued
           | invasion of Ukraine was just propaganda by the West [1]
           | 
           | https://twitter.com/Snowden/status/1494006204896620548
        
             | usednet wrote:
             | I'm getting deja vu to "WMDs", "moderate rebels,"
             | "dictators," and "national security." Even a broken clock
             | is right twice a day.
        
               | wnevets wrote:
               | is a record for how quick someone can turned to
               | whataboutism?
        
       | natch wrote:
       | > Kaspersky also maintains that it "doesn't have any ties with
       | any government, including Russia's
       | 
       | This take is either naive in the extreme, or disingenuous.
       | 
       | For a security company trying to maintain a trusted reputation,
       | neither of those two options is good.
       | 
       | While possibly technically accurate, it is a dodge or a flub that
       | overlooks the fact that their autonomy can be usurped by the
       | governments where they are based and where they operate.
       | 
       | To be fair, this is true of almost any company I can think of,
       | although I wonder if a DAO could get around it.
        
         | genocidicbunny wrote:
         | Exactly. They're one OMON or FSB visit away from 'having ties
         | to the Russian government.' Refusing to acknowledge that is
         | just downright disingenuous.
        
           | vkou wrote:
           | The same can be said about any vendor in the world, though.
           | 
           | Any of them is one NSL away from becoming a spy, wrecker or
           | saboteur.
           | 
           | If your threat model includes foreign governments, don't use
           | foreign closed source software. If your threat model includes
           | your government, don't use domestic closed source software.
           | 
           | Or do, but either be ready to mitigate the harm, or be
           | willing to live with it.
        
             | InitialLastName wrote:
             | In terms of TFA, I suspect the ship has sailed with respect
             | to intervention by the US government in network
             | installations regulated by the FCC.
        
       | T3RMINATED wrote:
        
       | lizardactivist wrote:
       | I'm happy with what I consider to be the most competent AV suite
       | available, made by a team of researchers that is second to none.
       | 
       | If the U.S. accusations are ever proven to be true, I will
       | reconsider. But I'm not holding my breath, since the U.S. has
       | time and again been proven to be guilty themselves of the very
       | thing they accuse others of, and refuse to provide any proof of.
        
         | [deleted]
        
         | google234123 wrote:
         | What would you consider "proof"? I feel like it's not far
         | fetched to assume the Russian Government can compel Kaspersky
         | to do things. This same government is so insecure that they
         | order assassinations of minor political opposition leaders
        
       | perfecthjrjth wrote:
       | In the long term, this will prove to be a good decision, as other
       | countries figure out that US companies (Microsoft, Google, FB,
       | Twitter, Master, Visa etc) are in bed with spy agencies of the
       | US. Other countries are given more reasons to NOT depend so much
       | on these companies.
        
       | ChrisArchitect wrote:
       | More discussion 4 days ago:
       | https://news.ycombinator.com/item?id=30806181
        
       | dghughes wrote:
       | Antivirus software manufacturers should jump at this and offer a
       | free subscription to former Kaspersky users.
        
       | asteroidp wrote:
       | Good! Although 20 years too late
        
         | [deleted]
        
         | mc32 wrote:
         | I think a lot of people have been saying this for years.
         | However most people until recently thought it was unfounded
         | hyperbola.
         | 
         | We should at least be skeptical given the connections the
         | founder has.
        
           | buitreVirtual wrote:
           | Just like, until recently, Europe (and especially Germany)
           | thought it was paranoia to treat Russian oil and gas
           | dependence as a risk.
        
             | mc32 wrote:
             | German policy was out in la-la land. Politicians sold the
             | public on green policies before the infrastructure was
             | ready and heavily relied on imported non green energy to
             | get there. They didn't have to shut down their nuke plants,
             | but 'make happy' led them down that path of dependence
             | --just as most of the industrialized world is dependent on
             | another questionable government for consumer goods and
             | microelectronics. Offshoring is awesome for the ruling
             | class until it isn't.
        
             | dainiusse wrote:
             | Exactly. These are very costly lessons, learnt on Ukrainian
             | blood....
        
       | gjsman-1000 wrote:
       | Quick question - where does the FCC derive this authority?
        
         | kube-system wrote:
         | The FCC has the authority to regulate how federal funding for
         | telecommunication is used.
         | 
         | Those who do not use federal telecom subsidy funds are not
         | affected.
        
       | TheGuyWhoCodes wrote:
       | All the enterprise businesses in the US I worked with, and had to
       | go through security audits, already banned the use of Kaspersky.
       | Even for suppliers.
       | 
       | I guess this just makes it official.
        
       | LeoPanthera wrote:
       | I'd quite like to know whether AdGuard is safe, too. Founded in
       | Moscow but incorporated in Cyprus.
        
       | AzzieElbab wrote:
       | All antiviruses should be declared security threat regardless of
       | vendor. Just hope FTC stays clear of jetbrains
        
       | kozak wrote:
       | Telegram is next?
        
         | stjohnswarts wrote:
         | telegram is mostly outside of russia now isn't it? I think they
         | still have a programming team there but the "owners" are
         | outside the country.
        
         | mohamez wrote:
         | IIRC Telegram is banned in Russia, and its CEO is not in good
         | terms with the Russian government.
        
           | ComradePhil wrote:
           | Definitely not banned in Russia:
           | https://www.aljazeera.com/news/2022/3/19/last-apps-
           | standing-...
        
             | paganel wrote:
             | Not sure why you're down-voted for stating out the facts as
             | they are.
        
               | FpUser wrote:
               | Because some people do not like pesky facts when those
               | interfere with the narrative?
        
             | thematrixturtle wrote:
             | They tried in 2018, but couldn't pull it off. It's unclear
             | what Telegram agreed to in 2020 to get officially unblocked
             | though.
             | 
             | https://en.wikipedia.org/wiki/Blocking_Telegram_in_Russia
        
               | ramesh31 wrote:
               | >It's unclear what Telegram agreed to in 2020 to get
               | officially unblocked though.
               | 
               | Most likely implementing FSB backdoors.
        
           | older wrote:
           | It is not only not banned but "found a compromise" and agreed
           | to co-operate with FSB according to Russian MP (google
           | translated article from tjournal.ru): https://tjournal-
           | ru.translate.goog/news/562296-durov-nashel-...
        
             | MikusR wrote:
             | According to Russian Minister of Foreign Affairs, Russia
             | has no intention to invade Ukraine
        
               | throwaway290 wrote:
               | Telegram is very comfy in Russia (as in good luck finding
               | a non-user). It also has no revenue stream. I put 2 and 2
               | together.
        
               | older wrote:
               | In this case we have evidence. Telegram is not banned in
               | Russia, and now we have an explanation about why.
        
             | throwaway290 wrote:
             | English-native source:
             | https://www.independent.co.uk/news/world/europe/telegram-
             | rus...
        
         | kube-system wrote:
         | Telegram is free isn't it? I don't think there are any federal
         | funds being used to buy telegram today. So, there's not much
         | for the FCC to ban.
        
         | ibejoeb wrote:
         | The White House campaign to explain its Russia policy on social
         | media did so via Chinese properties Zoom and TikTok. I don't
         | think we can rely only on domestic production right now.
        
         | throwmeariver1 wrote:
         | I found it always fishy that telegram applauds itself for being
         | a secure messenger but decided against encryption by default.
         | With the flick of a switch every doubt would go away but alas.
        
           | pantulis wrote:
           | I have also been amused by the number of technical people
           | that prefer Telegram vs Whatsapp in terms of security.
        
             | paganel wrote:
             | > Telegram vs Whatsapp in terms of security.
             | 
             | The 3-letter US agencies do not have direct access to
             | Telegram's servers, they do have when it comes to Whatsapp
             | (or to any other US-based company). The same goes if you're
             | a Russian doing anti-government stuff in, well, Russia,
             | it's better to put your fate in Whatsapp's (and Meta's)
             | hands, presumably the US agencies won't come after you for
             | being against the Russian government. It's a classical game
             | of arbitration (for lack of a better word).
        
               | older wrote:
               | > The 3-letter US agencies do not have direct access to
               | Telegram's servers
               | 
               | What makes you think so?
        
               | paganel wrote:
               | Snowden, for a thing.
        
               | stjohnswarts wrote:
               | I don't recall snowden having any material on whatsapp
               | backdoors though?
        
               | older wrote:
               | What about Snowden? How he would prevent US 3-letter
               | agencies from having access to servers located in the US
               | or in London?
        
               | paganel wrote:
               | Sorry, I had mis-read the question, thought you were
               | talking about WhatsApp. That's news to me, the US server
               | thing for Telegram.
        
               | cout wrote:
               | I agree with your logic, though a paranoid person might
               | point out that they don't need access to telegram's
               | servers; access to the app store or to automatic OS
               | updates would be enough.
        
               | paganel wrote:
               | Yeah, me being a backend guy didn't think of the client
               | side of things.
        
               | older wrote:
               | You agree to the logic based on a false premise that the
               | 3-letter US agencies do not have direct access to
               | Telegram's servers which are located in the US (among
               | other places).
        
             | ramesh31 wrote:
             | >I have also been amused by the number of technical people
             | that prefer Telegram vs Whatsapp in terms of security.
             | 
             | Tribalism is a helluva drug.
        
             | spacemanmatt wrote:
             | I have also been amused by the number of technical people
             | that prefer anything vs Signal in terms of security.
        
               | codedokode wrote:
               | Signal requires a phone number and doesn't allow
               | anonymous usage as I understand.
        
               | older wrote:
               | Signal is designed for privacy, not for anonymity.
        
               | saagarjha wrote:
               | I've been amused by the number of technical people that
               | prefer Signal vs just not shutting up about the messaging
               | app they use and not pretending like they're some sort of
               | authority on the topic instead of someone who deals with
               | SOC2 compliance daily.
               | 
               | (This is actually independent of you or Signal, I just
               | find it amusing that people throw their security
               | brand(tm) behind some app and it's just them picking the
               | one they like most of the time.)
        
           | cout wrote:
           | End-to-end encrypted by default doesn't mean much if you
           | don't trust the third party providing the software that does
           | the encryption. One automatic app update can enable leaking
           | of encrypted communication.
        
             | throwmeariver1 wrote:
             | The bigger problems for me would be the appstores because
             | they could implement a mitm. Telegram and Signal have their
             | client sources open so you at least can check and compile
             | them yourself but if I would handle data that was so
             | sensitive that I can't trust any other entity I would just
             | self host matrix or xmpp and chat with myself...
        
           | BitwiseFool wrote:
           | I'm only tangentially aware of secure messaging apps. How do
           | you feel about Signal? What is your preferred client?
        
             | throwmeariver1 wrote:
             | Telegram is fine if you just use it for 1on1 conversation
             | with encryption enabled. The same goes for whatsapp
             | (encryption is enabled by default). If you are looking for
             | secure group chats signal would be my choice because it
             | skips the server (WhatsApp sends all group messages to a
             | server before distributing it). There are also more exotic
             | providers like threema, matrix and many others but the
             | onboarding for non technical users is harder, though they
             | also have advantages like not needing a telephone number to
             | sign up. For the general public I would use Signal mainly
             | because it's directly in the middle of security and ease of
             | use.
        
         | sschueller wrote:
         | Probably not but McAfee should be added just because it sucks
         | so much.
        
           | throw10920 wrote:
           | Unironically, McAfee may be a greater threat to US national
           | security than Kasperky. McAfee is actually used by the
           | Department of Defense[1], and Kaspersky is not. Given how bad
           | McAfee actually is, I think that that makes it worse.
           | 
           | [1] https://en.wikipedia.org/wiki/Host_Based_Security_System
        
           | _joel wrote:
           | <> Norton entered the chat
        
           | orangepurple wrote:
           | McAfee uninstallation instructions by John McAfee himself
           | 
           | https://www.youtube.com/watch?v=UQrAfQMpnZk
        
         | orangepurple wrote:
         | Telegram is run by a citizen of St Kitts and Nevis. He escaped
         | Russia after they beat down his door.
        
           | throwaway290 wrote:
           | Who also promised to cooperate with russian government in
           | exchange for lifting the ban on the app.
           | 
           | And even if he didn't, if you run the most popular messenger
           | app in Russia you can't simply hide behind "citizen of some
           | other country". KGB is known for poisoning/shooting people
           | abroad for much less, and especially if you have family or
           | close relatives back in your country of birth you really have
           | little leverage to speak of.
        
         | ComradePhil wrote:
         | Very likely, being founded and run by Russians... and a good
         | way to stop people from communicating freely about the world
         | affairs.
        
           | morganvachon wrote:
           | Russian citizens != Russian government. The Telegram
           | development team is not on good terms with the Russian
           | government last I read. With that said, it still operates
           | within the borders so it's subject to government control
           | (just as any US-based messaging service is subject to US
           | government control). It's always a cat-and-mouse game between
           | those who want free, unfettered, unmonitored communications
           | and the governments that feel threatened by that kind of
           | freedom.
        
             | ComradePhil wrote:
             | You are thinking from a completely different perspective.
             | 
             | There's nothing for governments to allow people to
             | communicate freely. Telegram is one of the few platforms
             | that allows that... and this is a good opportunity for the
             | US government to do that.
        
             | older wrote:
             | Last I read Telegram is on very good terms with the Russian
             | government. I have already posted link to the source in
             | this thread.
        
       | luckydata wrote:
       | Inevitable and good. I'm relieved that we are at least stopping
       | the pretension that we don't have an ongoing conflict with the
       | "totalitarian east" of the world. China and Russia are absolutely
       | a threat to modern democracies and we have let the economic
       | interests of the few override those concerns for far too long,
       | with terrible consequences for both us AND their own population,
       | which we contribute to the oppression of by propping up those
       | totalitarian regimes with a constant stream of cash.
       | 
       | Globalization was a terrible idea the way it was done and I'm
       | glad it's coming to a close.
        
       | stjohnswarts wrote:
       | kaspersky should have completely left russia decades ago if they
       | wanted to free their reputation from FSB taint.
        
         | rcMgD2BwE72F wrote:
         | Like all the US companies leaving the US in 2003? I only
         | remember US companies trashing France around that time.
        
           | stjohnswarts wrote:
           | What? I guess enjoy your strawman? I never mentioned the US
           | and this isn't a comparable situation. I'm talking about a
           | business decision to not be associated with the KGB in
           | countries where you do the vast majority of your business (EU
           | and North America)
        
       | nanochad wrote:
       | We have placed full sanctions on Russia. It's common sense not to
       | rely on them too much.
        
         | ElectricalUnion wrote:
         | > full sanctions
         | 
         | [citation needed]
         | 
         | Isn't oil, gas and food trade still allowed? That is not "full
         | sanctions".
        
           | flavius29663 wrote:
           | oil and gas were banned by the US
        
       | the_snooze wrote:
       | Is there any point in using antivirus these days anyway? I'm open
       | to being wrong here, but I'm under the impression that antivirus
       | exists only to tick boxes in outdated security compliance
       | checklists. How big of a threat are viruses compared to, say,
       | rogue antivirus products themselves?
        
         | hans1729 wrote:
         | It's a thing in big orgs, where macros are enabled in excel and
         | employees can be tricked into opening mail attachments. Windows
         | defender should suffice, but like you said, from a
         | compliance/insurance perspective it may me valuable to say
         | "look, we scanned for signatures according to the latest
         | knowledge of [insert vendor]".
         | 
         | Personally I think that it's ridiculous that these huge orgs
         | fail to address the actual underlying issue, excel macros. But
         | hey, it's easier to fight the Symptome than to deal with the
         | root cause, especially if the latter would impact established
         | work flows god knows how far down the line.
        
           | beamatronic wrote:
           | The class of risky employees should perhaps be limited to
           | Chromebooks only.
        
             | 29083011397778 wrote:
             | This may work some of the time, but expect "I need
             | $windows_program" to foul your chances of this. It may not
             | always be legitimate, but telling heavy-duty transport
             | mechanics they can't have Cummins or Bendix software (for
             | engines and brakes) to help them diagnose, when that's the
             | only output for troubleshooting supported by the OEM, will
             | not end well.
        
               | jmrm wrote:
               | This makes me thing: When we are going to see those
               | Windows software directly on the web?
               | 
               | For me makes a lot of sense being able to sell a software
               | subscription instead of a one time product sell, and for
               | the other hand making available to use in any device in
               | the world with internet connection.
               | 
               | This also can be done like Chrome apps (like Docs) or
               | some Electron apps (like Spotify), where you can use
               | content without Internet for some time without any
               | problem.
               | 
               | For a mechanic who is looking for the amount of torque
               | needed on a bolt this could be perfectly viable, for
               | example.
        
               | 29083011397778 wrote:
               | > For a mechanic who is looking for the amount of torque
               | needed on a bolt this could be perfectly viable, for
               | example.
               | 
               | We're going to start talking past each other pretty
               | quickly if you think this is worthy of a (software)
               | service subscription. Torque specs belong in a manual
               | (ideally on corporate intra-net or paper); I'm talking
               | about when the engine is deeply unhappy, and you need
               | more to go on than a driver reporting a yellow check
               | light.
               | 
               | In the case of the latter, I'd say it absolutely deserves
               | to be a 20 year old program (which tend to be lighter)
               | that runs entirely offline. The last thing any garage
               | wants to do is chase hardware requirements or search for
               | a wifi signal either out in the yard, or in between
               | hoists, lifts, and miscelleaneous heavy equipment /
               | tooling - all of which tend to trash a wifi signal.
        
               | jacobr1 wrote:
               | This is already a thing. Plenty of companies use managed
               | virtual desktops via the web for this purpose.
               | 
               | AWS even offers "Workspaces" as service for this.
               | 
               | Though it doesn't solve the "without the internet"
               | problem.
        
             | stjohnswarts wrote:
             | This is why people don't like IT staff a lot of time. They
             | think their needs of making their own jobs easier outweigh
             | those of the organization and getting stuff done.
        
               | jacobr1 wrote:
               | The bigger problem is that the IT staff is often so
               | ludicrously underfunded, that they ARE a bottleneck.
               | There probably are ways to manage team/personal
               | productivity with organization needs, but without time to
               | dedicate to analysis, you get blanket solutions. Which is
               | another reason why self-provisioned SaaS rather than IT
               | managed systems are big.
        
             | hans1729 wrote:
             | Unfortunately I don't think belittling these employees
             | helps much here, especially considering how good a
             | dedicated phisher can become at their craft.
        
             | d3ad1ysp0rk wrote:
             | CEOs?
        
             | harikb wrote:
             | The software we develop should have better interfaces too.
             | A security expert should also review stuff created by UX.
             | 
             | Back when "I love you" virus started, we had pointed out
             | something simple as "open for read" vs "open as in
             | run/execute" should not have had the same interface.
             | 
             | All the new security enhancements we have today - don't run
             | as admin, alerts to request privileged access, sandboxing -
             | all of them existed for a decade, but the software vendors
             | never had the guts to weigh security higher than UX
        
           | carnitine wrote:
           | I think if Excel macros were banned in finance, trading
           | volume would drop by several hundred billion dollars per day.
        
             | saalweachter wrote:
             | Are you giving the pros or the cons?
        
               | sjmm1989 wrote:
               | Seriously though... Maybe this is something that should
               | be done.
        
           | annoyingnoob wrote:
           | I have personally watched Windows Defender fail to notice a
           | real virus infection from a USB flash drive. The USB flash
           | drive was plugged in and instantly Windows was infected -
           | Windows Defender did nothing. You could then manually run a
           | Windows Defender scan and it would find the infection but it
           | would not prevent the infection.
           | 
           | I think one's need for a security product should match one's
           | exposure to issues - it depends on your org. For a very long
           | time I was not a fan of anti-virus, in 2022 I'm back to
           | liking anti-virus (more like EDR these days).
        
             | driverdan wrote:
             | What mechanism would a flash drive use to infect a modern
             | version of Windows by only being plugged in?
        
             | RadixDLT wrote:
             | dont confuse BitDefender with Windows Defender, not the
             | same thing
        
               | annoyingnoob wrote:
               | I did not confuse them. Yes, I mentioned GravityZone in a
               | follow - which is a BitDefender product, and is the
               | product that found the issue when Windows Defender did
               | not.
        
             | 3np wrote:
             | Would one of the commercial antivirus products have caught
             | it, though? Did you check?
        
               | annoyingnoob wrote:
               | Yes. It was not a current virus, came from an old UEB
               | flash drive that had been lying around for years.
               | GravityZone noticed it and prevented it, which is why I
               | knew to go look at the Win10 box the flash drive was last
               | plugged into. Windows Defender's silence would have left
               | us with the virus installed because it was not
               | periodically scanning on its own.
        
             | gamblor956 wrote:
             | MS Defender used to automatically scan USB devices when
             | plugged in but that's not the default anymore (and AFAIK
             | hasn't been for a few years since one of the major
             | updates); you now have to enable it somewhere non-intuitive
             | (like the Policy Editor?).
        
               | ridgered4 wrote:
               | That's a really bizarre choice of default setting.
        
               | gamblor956 wrote:
               | Not really, when you consider that there are tens of
               | thousands of USB devices that work with Windows, many of
               | which can operate like a flash drive even though they
               | aren't (like cameras). I can imagine MS disabling this
               | feature by default due to the headaches involved.
               | 
               | Notably, autolaunching USB drives is also no longer the
               | default option for USB devices. The user has to
               | specifically _choose_ what action happens when the device
               | is first plugged in (and by default, that choice only
               | applies to the current instance; the user must manually
               | choose to have the choice apply the next time the device
               | is plugged in).
        
               | annoyingnoob wrote:
               | My point is that people thinking that Windows 10 comes
               | with Windows Defender, and that Windows Defender will
               | protect them by default, are in for a surprise. Defender
               | probably is not doing anything you might think it should,
               | by default.
        
           | bell-cot wrote:
           | I seem to recall an article about a big org, probably in
           | Finance, which took a serious look at the Excel Macro thing.
           | Only a puny fraction of their employees, pretty much all in a
           | couple specialized departments, actually used those. SO -
           | outside of those few and their dept's, all macros were
           | disabled/banned by fiat. Which allowed the relevant
           | malicious-macro-prevention resources & training to be focused
           | on those few.
        
           | dartharva wrote:
           | I would really hope my organization doesn't start blanket
           | banning excel macros for "security". It'll be a huge blow to
           | productivity for several.
        
             | excalibur wrote:
             | Draconian bans probably aren't the best way to achieve it,
             | but if it's productivity your org wants they should
             | concentrate on migrating those workflows out of Excel ASAP.
        
               | behringer wrote:
               | So which accountant is going to be programming your
               | node.js files?
               | 
               | There's a reason companies use excel.
        
             | slowmovintarget wrote:
             | They'd just learn Python. They'd be fine.
        
               | dartharva wrote:
               | I won't, even when I do know how to script in Python. We
               | don't really like having our workflows disrupted for
               | silly reasons
        
               | jmt_ wrote:
               | You can't just "#learntocode" Excel macros away from
               | industry.
        
         | orev wrote:
         | Corporate "anti-virus" is much more than just anti-virus these
         | days. Most of them don't even call themselves anti-virus, but
         | endpoint protection. Other than anti-virus, they let you set
         | policies on USB ports, block web browsing by categories or
         | specific domains, let you run software inventory reports, etc.
         | These things are very important, especially with work from
         | home, as you can't really block things at the office firewall
         | anymore.
        
           | lostlogin wrote:
           | They also slow your machine down, report back to the company
           | and throw annoying pop ups at you multiple times per day.
           | 
           | Never again.
        
         | irrational wrote:
         | My company forces all of us to use a product called Zscaler. I
         | have no idea if it is effective, but it is constantly running
         | and uses the vast majority of my CPU. The degree to which is
         | slows down my computer and slows down development is
         | astonishing. I have to wonder, across the entire company, if
         | the potential cost of stuff lost that zscaler supposedly
         | protects us from is worth more than the real cost of lost
         | productivity, not to mention whatever they are paying for
         | zscaler itself.
        
           | jacobr1 wrote:
           | You should see if you get them to debug the situation. Unlike
           | plenty of bloatware discussed on this posting, zscaler is
           | usually not that resource intensive. It is more of a better
           | corporate VPN, than it is a AV tool.
        
         | lotsofpulp wrote:
         | I assume it is a cover your ass thing for executives to point
         | to when malware happens on systems they are responsible for.
        
           | xtracto wrote:
           | More than that. It's still required by cert standard bodies
           | such as PCI and SOC2 .
           | 
           | Even if you as an exec know they are security theater you are
           | forced to comply due to these certifications.
        
         | brightball wrote:
         | While it's fairly easy to bypass them, half of the point seems
         | to be making sure that people still NEED to put in the effort
         | to bypass them.
        
         | fatnoah wrote:
         | Current AV software bloatware is a scourge on the world.
         | 
         | I spent about 30 minutes this weekend helping my sister-in-law
         | debug a slow internet. My observations were that attempting to
         | do anything resulted in about a 5-10 second pause, and general
         | sluggish response when trying to anything online. I disabled
         | anti-virus, etc. and it was still slow. I tried Edge and
         | everything was super-fast.
         | 
         | Digging further, the issue was McAfee Safe Search (powered by
         | Yahoo). It was singlehandedly adding 5-10 second lag on every
         | mouse click and character typed in the browser. Disabling and
         | blocking that resolved everything.
        
         | the8472 wrote:
         | > rogue antivirus products themselves?
         | 
         | It's not just rogue AV software. Buggy, insecure AVs are a big
         | problem too. They're attack surface! Especially when running
         | parsers and interpreters for untrusted inputs in kernel space.
        
           | iso1210 wrote:
           | > rogue AV software
           | 
           | You repeat yourself sir
        
           | commandlinefan wrote:
           | Even when they don't expose any security holes, they bog the
           | computer down so much that I'd almost rather have a virus -
           | at least a command-and-control virus might take steps to make
           | me unaware of its presence.
        
             | vetinari wrote:
             | In the '90s, there was a joke: What's the difference
             | between Windows and viruses? Viruses do something.
        
           | mumblemumble wrote:
           | If I were a black hat, I think that the best gift I could
           | hope for would be a 3rd-party program, likely developed on
           | the cheap, whose entire purpose for existing is to sit in
           | kernel space and promiscuously open Every. Single. File. in
           | order to process its contents.
           | 
           | (Granted, I'm a complete layperson in computer security, so
           | there's likely something I'm missing.)
        
         | b0afc375b5 wrote:
         | I have not thought about 3rd party antivirus software in a long
         | time. Granted my only use case for windows 10 is gaming, and
         | any binary (or any file really) that I download goes straight
         | to virustotal before I open it.
        
         | KronisLV wrote:
         | It surprises me how much many posters on Hacker News seem to be
         | against using any sort of AV software - not even the built in
         | Defender solution in Windows, if you have to use the OS for
         | whatever reason, but i often see the sentiment expressed that
         | supposedly the entire class of software is useless.
         | 
         | What happened to defense in depth with all of the layers you
         | can introduce?
         | 
         | Surely if you run a Linux server, you might want a secure
         | password for it, or better yet, key based authentication. Port
         | knocking? Why not, throw it in there as another layer. Maybe
         | deny authentication on an IP range basis? Why not. What about
         | fail2ban or some other solution like that to disallow brute
         | forcing? Sure. Or maybe require using a VPN to connect to it at
         | all? Even better! Actually, even running your SSH server on a
         | non-standard port will be enough to get rid of _some_ attempts
         | to brute force the password.
         | 
         | Sure, key based auth makes many of those moot points so i
         | probably have the order of some of those steps wrong, but
         | surely there's a lot of merit in combining whatever solutions
         | you can to make the end result more secure, right? Hell, if
         | you're running a web service of some sort or an application for
         | yourself, adding basicauth in front of it at a web server level
         | is enough to act as a safety net should the auth functionality
         | of the actual application be broken, until you patch it.
         | 
         | So why should Windows be any different? If i'm stuck using that
         | OS, i'd surely want to use whatever software is available to me
         | to make the uphill battle towards something vaguely secure more
         | doable, no?
        
           | x0x0 wrote:
           | Part of this surely is that most apps are now delivered in
           | the browser, so increasingly windows is a terminal to run
           | chrome or edge.
        
           | larrik wrote:
           | > What happened to defense in depth with all of the layers
           | you can introduce?
           | 
           | What happened was antivirus itself became your biggest attack
           | vector, so you were more secure without it. Plus Microsoft
           | actually cares about security now, which wasn't the case 10+
           | years ago.
        
           | Melatonic wrote:
           | For Windows one of the best things you can do, AV or not, is
           | to NOT make your daily driver account an administrator.
           | Create an admin account with a secure password and then
           | another standard user account for yourself and use that
           | standard user for everything. When installing something you
           | will need to put in your admin password but it is really not
           | a big deal to do so. Massively reduces your chance of
           | ransomware and all kinds of crapware.
           | 
           | Enabling protected folder access and process isolation in
           | Windows 10 is also a good idea.
        
           | JamesBarney wrote:
           | tptacek could probably weigh in with a much better
           | explanation.
           | 
           | The tradeoff for having AV is having a giant application in
           | admin land which increases the surface area available for an
           | attack. Combine this with the that fact you don't get much
           | protection because a virus can just be modified until the AV
           | doesn't detect it and AV's just aren't worth it. This trade
           | off made sense 20 years ago because OS's were less secure so
           | you were increasing your surface area by relatively less than
           | you are now.
        
           | guelo wrote:
           | what happened was the security industry proved over and over
           | again that it cant be trusted. most windows recommendations i
           | see say to use defender since Microsoft already owns you
        
         | dblohm7 wrote:
         | I used to work on the team at Mozilla that got stuck with
         | dealing with all the terrible shit that AV programs do to web
         | browsers. My recommendation for Windows users is to just use
         | Defender.
         | 
         | All that other crap does the exact same stuff to other programs
         | that malware does, except they do so in the name of "security."
        
         | Damogran6 wrote:
         | Our bog-standard business ultrabooks have been requested to
         | perform a full disk scan each Friday. Which means their CPUs
         | and Fans are running solid, most all Fridays.
         | 
         | I'm CERTAIN there are massive hidden costs in fan replacement
         | and Laptop repairs and nothing useful discovered as a result.
        
           | _joel wrote:
           | I wonder how much unnecessary AV scans across the world
           | contribute to carbon emissions? I bet it's not insignificant,
           | full CPU and disk access!
        
         | henryw wrote:
         | I'm wondering this too since Windows has built-in antivirus
         | now. https://www.microsoft.com/en-us/windows/comprehensive-
         | securi...
        
           | teh_klev wrote:
           | Windows has had "Microsoft Security Essentials" built-in for
           | longer than I can remember (10+ years?). It's not a terrible
           | thing and keeps out of your way and doesn't seem to bog your
           | machine down. Unlike the steaming pile of crap that my work
           | computer runs (EndPoint) that consumes 60-80% CPU when doing
           | its weekly full scan for over an hour right in the middle of
           | the working day.
           | 
           | MSE is really all I've used since binning AVG which turned
           | into bloatware.
        
             | stjohnswarts wrote:
             | Took me a while to figure out why my browsers always seem
             | to randomly pause for about 30 seconds. It's that piece of
             | crap McCaffee. I can watch it's process go to 100% when the
             | browser (firefox and vivaldi) freeze. It's garbage and I
             | wish I could turn it off and just use MS AV but the IT
             | staff swear by McAffee so I live with it.
        
         | binarymax wrote:
         | It's a good question for the Windows ecosystem, because it was
         | absolutely necessary for Windows 7 and earlier, but I haven't
         | used later versions.
         | 
         | I've been using Linux/Mac exclusively for the past 10 years and
         | never even considered it.
        
           | gtirloni wrote:
           | You actively disable Windows Defender?
        
             | binarymax wrote:
             | No. What in my message made you think that?
        
           | pjmlp wrote:
           | Then you are lucky not to work in companies where IT security
           | policies apply to everyone regardless of the OS being used.
        
             | nix23 wrote:
             | >IT security policies apply
             | 
             | Insecurity policies is correct, what you mean is protecting
             | managers a* aka the antivirus failed on us ;)
        
         | bastardoperator wrote:
         | I don't think you're wrong at all. Considering symantec is
         | mining with your computer on top of all the other terrible
         | things anti-virus companies do to your computer, at this point
         | a virus might be less intrusive.
        
       | orangepurple wrote:
       | The only software most Windows PCs need out of the box is
       | TinyWall (https://tinywall.pados.hu/)
        
         | layer8 wrote:
         | The playful snow on the home page doesn't inspire confidence.
        
           | orangepurple wrote:
           | It is an excellent piece of software.
           | 
           | Other projects by the same developer:
           | 
           | https://www.patreon.com/posts/other-projects-36886285
        
         | stjohnswarts wrote:
         | Why is this better than the built in windows firewall?
        
           | orangepurple wrote:
           | Much, much easier to configure and manage and denies almost
           | everything by default. Extremely easy to quickly unblock
           | software as necessary too. 10-100x faster workflow compared
           | to the built in firewall, so you will actually bother to use
           | it instead of get complacent or ignore it.
        
       | holoduke wrote:
       | In a way I get it. I also agree with it. Europe should also try
       | to reduce dependancy on American tech products for the scenario
       | when the US becomes hostile towards Europe. A bit unlikely now,
       | but you never know.
        
         | hall0ween wrote:
         | Agreed that Europe should reduce dependency on US tech product.
         | Among the reasons is how the US govt has been caught spying on
         | allies multiple times. Which is sad but a clear sense of ethics
         | missing in the US govt (along with a long list of others).
         | 
         | > A bit unlikely now, but you never know. On the timeline we
         | exist, it's a possibility!
        
         | qiskit wrote:
         | Not just europe. Europe makes the most sense because europe is
         | the wealthiest region on earth and has the ability to fund its
         | own tech industry. Europe did it for aerospace ( Airbus ), but
         | why they aren't doing it for something far more important than
         | planes is beyond me. But China, India, Japan, etc should all be
         | developing their own tech spheres. I can't believe that any
         | major country allows Windows, Facebook, Google, Apple, etc in
         | their nation. At the very least ban it until they develop their
         | own local competitors first. Not only would this be good for
         | China, India, Japan, EU, etc, it would also be good for tech
         | and the rest of the world since they will have more options.
         | It's amazing how useless so much of the world's leadership are.
        
         | juanani wrote:
        
       | cm2187 wrote:
       | Doesn't any foreign company contributing a device driver to
       | Microsoft present the same risk profile (could be based in
       | Russia, or infiltrated by russian agents, or hacked by russia)?
        
       | yololol wrote:
       | I'm surprised that everyone here thinks that Kaspersky makes only
       | antivirus products. They have a ton of security products,
       | including their own microkernel-based OS:
       | https://os.kaspersky.com/technologies/microkernel/
        
         | ASalazarMX wrote:
         | I guess NginX is hoping no one looks their way.
        
           | tenebrisalietum wrote:
           | F5 owns Nginx now.
        
       | Maursault wrote:
       | Ok, let's cut the crap. Is Kaspersky a dirtbag or not? I suspect
       | not, but it is an unfortunate accident he was born in and runs
       | his company from Russia, the government of which is a dirtbag,
       | so, correct me if I am wrong, Kaspersky must be a dirtbag by
       | association, but especially for discovering Stuxnet. Believable,
       | but I think the real reasons Kaspersky is persona non grata is
       | due to having discovered Stuxnet, and Kaspersky Lab suspected of
       | uncovering secret US cyberweapons in the future.
       | 
       | I am a patriot, but even I don't appreciate being lied to by my
       | government. It would be good if the next best cyber security firm
       | and software was half as good as Kaspersky's. But I suspect not.
        
         | IngvarLynn wrote:
         | Kaspersky consciously, under no pressure chose to be chekist.
         | That is absolutely all You need to know about this person and
         | his deeds, consequentially. The numerous ruminations on
         | "coercion" are just deeply naive. He is a member of kremlin
         | gang. Anything else falls into bottomless category of
         | whitewashing.
        
         | older wrote:
         | Kaspersky graduated from The Technical Faculty of the KGB
         | Higher School in 1987. That was a definition of a dirtbag in
         | Soviet time.
        
           | libraryatnight wrote:
           | I can't find the actual profile on Wired anymore, but I found
           | it on the internet archive: https://web.archive.org/web/20140
           | 423055434/http://www.wired.... and also a sort of response to
           | it https://web.archive.org/web/20140426095603/http://www.wire
           | d....
           | 
           | After I read that profile I decided I'd never use the
           | software. I remember before news spread of the Russian troll
           | farms being real, people talked about it like "who would do
           | that?" Russia would.
           | 
           | I don't think it's their quote - but I remember Penn of Penn
           | & Teller saying about magic something to the effect that the
           | magician does the things that people think "It could be...
           | but who would do all of that work?" This is how I feel about
           | Russia. They will or already are doing the things you think
           | they won't and nothing is beyond being a tool for the state.
           | 
           | I don't really like feeding the image of the Russian super
           | villain, but I don't consider it overly paranoid to avoid
           | installing software from hostile nations. Yes I used this
           | same logic to convince my wife to uninstall tiktok.
        
             | marvin wrote:
             | Comparison notwithstanding, that's what I felt when I first
             | heard about PRISM. Holy shit, I knew this was all possible,
             | but I hadn't believed that someone actually went through
             | all the effort of doing it.
        
             | jwatt wrote:
             | The original Wired links are:
             | 
             | https://www.wired.com/2012/07/ff-kaspersky/
             | 
             | https://www.wired.com/2012/07/kaspersky-indy/
        
             | purplediamond wrote:
             | Is hackernews cutting off links now. Neither of your links
             | work. End of line contains "/http://wired/"
             | 
             | Congratulations to both of you for uninstalling TikTok :)
             | Facebook is next.
        
           | mkbkn wrote:
           | What he could have done then at that time? To not study? To
           | remain illiterate?
        
             | jonathanstrange wrote:
             | I know brilliant people from the GDR who studied at Moscow
             | Polytechnic University, they weren't in the KGB or Stasi.
             | You had to be system-conform to study anything, that much
             | is true, but that's still far away from joining the KGB.
        
             | older wrote:
             | You really think the choice was to go to KGB school or
             | remain illiterate? There were a lot of other options to
             | study. Much better options if your want to do science. For
             | one thing, education in Soviet Union was decent and free
             | for everyone. Going to KGB school was a choice, very
             | specific one.
        
             | aaomidi wrote:
             | I know right? Like what the hell kind of criticism is that
             | lol.
        
               | mopsi wrote:
               | The kind that understands historic nuance.
        
               | naniwaduni wrote:
               | That understands nuance, but not history.
        
         | mmastrac wrote:
         | His only statement so far on the far (keeping in mind this is
         | rather than saying nothing) called it a "situation" in Ukraine.
         | That's not much to read into, but he also could have chosen to
         | say absolutely nothing.
         | 
         | "We welcome the start of negotiations to resolve the current
         | situation in Ukraine and hope that they will lead to a
         | cessation of hostilities and a compromise. We believe that
         | peaceful dialogue is the only possible instrument for resolving
         | conflicts. War isn't good for anyone."
        
         | RadixDLT wrote:
         | funny you say that, because bitDefender always outshines
         | Kaspersky in all the AV tests and was always ranked #1
         | 
         | also dont forget that the Global Research & Analysis Team @
         | Kaspersky is not Russian
        
         | sharken wrote:
         | Here is my humble opinion.
         | 
         | Kaspersky is by definition a Russian company that provides
         | antivirus software to many influential western companies and
         | institutions.
         | 
         | The risk of Kaspersky bowing to the pressure from Putin is just
         | too great to ignore. For Kaspersky this can seem unfair, but
         | that is one of the many consequences of Putins actions.
         | 
         | Don't forget who started the invasion and who is still hurting
         | innocent Ukrainians.
        
         | ajross wrote:
         | The sanctions in question are against Kaspersky Labs the
         | company, not Eugene Kaspersky the man. Frankly none of the
         | analysis involves a decision as to whether he is a "dirtbag",
         | by association or not. It's just that there's no way anyone can
         | reasonably trust "security" software produced by entities in a
         | totalitarian state, especially so when it's at war.
        
           | Maursault wrote:
           | Thanks for the clarification.
           | 
           | So it is not a situation were we have actual evidence of
           | dirtbaggery against the company, but that we are _rationally_
           | paranoid that Kaspersky Lab could somehow steal our Pokemons.
        
         | dc-programmer wrote:
         | The Stuxnet association seems completely basis, and you do not
         | provide any evidence for the assertion. There were multiple
         | firms and individuals responsible for the discovery, reverse
         | engineering, and attribution of Stuxnet, so you are overplaying
         | their involvement.
         | 
         | This decision was certainly made by a bureaucrat who may not
         | even know about Stuxnet. It's simple risk mitigation. Why even
         | take the chance Kaspersky is a malicious entity? It's not
         | important software.
         | 
         | Some of the conspiracy theories people throw out around here...
        
         | oh_sigh wrote:
         | You think the US government waited 12 years to be able to turn
         | the screws on Kaspersky because they uncovered Stuxnet?
        
         | badrabbit wrote:
         | Even american security companies have ties to the intelligence
         | community. Kaspersky is no different. In most countries private
         | sector pays more so state hackers work at places like
         | Crowdstrike or Kaspersky after some time. Their relationship
         | with the IC helps develop and share intelligence both ways.
        
           | NelsonMinar wrote:
           | There's an important difference: American security companies
           | have ties to American intelligence. The concern here is
           | Kaspersky has ties to Russian intelligence. If you're an
           | American company or government agency and have to choose
           | between the two the choice is pretty clear.
           | 
           | I have a lot of respect for Kaspersky and hope they are still
           | independent. But "ties to intelligence" can come in many
           | forms: deliberate, coerced, or via infiltration. We've seen
           | similar issues here in the US. Sometimes companies work
           | voluntarily with the FBI and NSA, sometimes they are
           | infiltrated or tricked by them.
        
             | sovietmoonbase wrote:
             | > If you're an American company or government agency and
             | have to choose between the two the choice is pretty clear.
             | 
             | I suppose that entirely depends on one's threat-model. As
             | an American, I have greater concerns of USG oppression than
             | I do Russian. As the Russians have their ham-fisted means
             | of exterting influence on a company, the US has their very
             | own nasty ways of infiltration.
             | 
             | If you're interested in personal freedoms free of malicious
             | government intrusion, they both suck.
        
               | NelsonMinar wrote:
        
           | BTCOG wrote:
           | It's not just security companies. US ISPs are heavily tied to
           | agencies and so are the large corps. The media is state ran
           | just like Russia.
        
             | older wrote:
             | You can't be more wrong when you say "just like Russia". It
             | is not even close. The killings of journalists,
             | repressions... The last independent newspaper has to close
             | its activity because it is not possible anymore to report
             | truth while complying to the Russian laws:
             | https://www.aljazeera.com/news/2022/3/28/russias-novaya-
             | gaze...
             | 
             | All this with Russian government/president approval rating
             | of 70%.
        
               | jacobr1 wrote:
               | Without independent media, how can we trust the approval
               | rating is accurate?
        
               | older wrote:
               | Levada-Center is the best bet we have:
               | https://www.levada.ru/en/ratings/ But when even Russians
               | who live in Germany are rallying in support of the
               | Russia's war it is reasonable to assume that those
               | ratings are accurate.
        
               | csydas wrote:
               | No, it really doesn't follow. The subset of russians
               | living in germany who approve of the war has no bearing
               | or relationship to all russians.
               | 
               | The "living in germany" part doesn't contradict the same
               | concerns that those living in russia have, as like those
               | living in russia, the emigrated russians likely have:
               | 
               | - family still in russia - ties to russia (financial,
               | business, family, etc) - desire to visit russia without
               | having to deal with legal harassment for actions done
               | abroad - desire to be able to assist people
               | (family/friends) living in russia without compromising
               | them
               | 
               | This does not mean that they are for or against a current
               | government, but rather, that the proposed logic is
               | specious as it tries to create a separation where it is
               | not probable there is one while simultaneously
               | extrapolating the results of a small sample size across a
               | population that supposedly is without the influence of
               | Russia.
        
               | older wrote:
               | Well, maybe you're right but I'm not so sure. After
               | watching recent interviews with random people on the
               | streets of Russian cities. Here's interesting thread on
               | twitter by someone sharing his experience calling random
               | Russians and trying to talk: https://twitter.com/GentileO
               | slo/status/1506663082634145797
        
             | SeanLuke wrote:
             | > The media is state ran just like Russia.
             | 
             | The whataboutism is out in full force here.
        
               | davrosthedalek wrote:
               | Indeed, and it's really absurd. Just compare Fox News and
               | MSNBC. They might be both state run, but certainly not
               | the same state.
        
             | flavius29663 wrote:
             | The media is heavily biased in the US, but nowhere near
             | Russia style.
             | 
             | You can still find the opposing views, quite easily.
        
         | tjoff wrote:
         | I thought the question was much older than stuxnet?
        
         | JabavuAdams wrote:
         | The problem is: how do you run a business that has offices and
         | physical assets in Russia, without being at least partially
         | beholden to the Russian government? They have demonstrated that
         | they are not shy about using gangster tactics.
         | 
         | One could say that the same is true in the US, but I believe
         | the degree matters. Although the US government and intelligence
         | agencies will and do try to overreach, there is a strong legal
         | and cultural tradition of exposing, resisting, and fighting
         | these overreaches in the US. I don't see that in Russia.
         | 
         | So, I would not be surprised to see the US strong-arming US
         | companies, but they would do this with sham/flimsy legal cover.
         | The result of non-compliance would be at worst asset seizure
         | and/or imprisonment. Both of these can be examined and
         | contested. I imagine that the penalty for non-compliance in the
         | Russian system would max out at having an unfortunate accident.
         | Gangsters all, but the level of gangsterism and possibilities
         | for investigation/redress matter.
         | 
         | All that said, I'm not a US citizen (although in a Five-Eyes
         | country), so I do worry about using US-hosted services.
        
           | mjevans wrote:
           | I live in the USA, therefore I need to consider it as part of
           | my threat model mostly in the blunders / withholding exploits
           | (thanks CIA ~.~) senses. For everything else I try to vote
           | informed and support a combination of the EFF, ACLU, and
           | other organizations that can be better informed experts on
           | the law and it's applications.
        
           | PoignardAzur wrote:
           | _> One could say that the same is true in the US, but I
           | believe the degree matters. Although the US government and
           | intelligence agencies will and do try to overreach, there is
           | a strong legal and cultural tradition of exposing, resisting,
           | and fighting these overreaches in the US._
           | 
           | That point would be a lot stronger if the US government
           | hadn't demonstrated shocking callousness and disregard for
           | international law in their efforts to catch notorious
           | whistleblowers Snowden and Assange.
           | 
           | I remember when Belarus downed a plane to catch a political
           | dissident and all western countries acted shocked, even
           | though these countries had tried to do _the exact same thing_
           | to Snowden on the US 's behalf, with a presidential plane no
           | less.
        
             | ummwhat wrote:
             | Hold up. Downed a plane is different from grounded a plane.
             | I don't know the Belarusian case, but either you misused
             | the word or they are _very_ different.
        
             | jjeaff wrote:
             | International law isn't really a thing if it has no teeth.
             | I would be more worried about the US breaking its own laws.
             | Which they of course do, on occasion. But there is a lot of
             | pushback and not too much fear of reprisal if you call them
             | out and fight them on it. For example, we are in the
             | process of appointing a supreme court justice that, during
             | her career, has fought against US Government overeach and
             | represented alleged terrorists imprisoned (oh sorry,
             | "detained"), in Guantanamo.
        
             | [deleted]
        
           | skeptikal wrote:
        
             | layer8 wrote:
             | Russia is free to ban Microsoft Defender et al.
        
             | tablespoon wrote:
             | > The problem is: how do you run a business that has
             | offices and physical assets in <insert power country>,
             | without being at least partially beholden to the <insert
             | powerful country> government?
             | 
             | The problem with this kind of Mad Libs argument is that it
             | falsely implies the substitutions are equivalent when
             | they're not. Also your quote shears away the context of the
             | original statement that made it meaningful.
        
               | alimov wrote:
               | Please explain how they are not equivalent. Just because
               | two governments are on good terms or are in some kind of
               | partnership does not guarantee that one or the other will
               | not take actions that benefit only them. What am I
               | missing here?
        
               | JumpCrisscross wrote:
               | > _explain how they are not equivalent_
               | 
               | Press. Political competition. Courts. Broadly, the rule
               | of law.
               | 
               | Nobody is perfect at any of these. But if the FSB wants a
               | code change in Kaspersky, they're getting that code
               | change. There is no independent press to report it. No
               | opposition incentivized to call them out on it. No court
               | in which they could lose.
        
               | tablespoon wrote:
               | >> explain how they are not equivalent
               | 
               | > Press. Political competition. Courts. Broadly, the rule
               | of law.
               | 
               | Exactly. Mad-libs "arguments" typically boil down to an
               | invitation to ignore salient differences (which the
               | structure _cannot_ call attention to), make a superficial
               | comparison, and finally arrive at a false equivalency.
        
               | syshum wrote:
               | hmm FISA, Gag orders, National Secrecy laws, etc all
               | exist in US law, so tell me again how they are different?
               | 
               | Also, as an American Citizen, who has more power to put
               | me the individual in a cage, the FSB or NSA?
        
               | sokoloff wrote:
               | Who has more practical power to force code into a
               | security product that runs in a privileged context,
               | without anyone finding out? I think it's not the NSA.
        
               | syshum wrote:
               | Why do you believe that, the NSA had access to Cisco PIX
               | systems for years and it was only disclosed once those
               | systems started to be replaced with ASA and other newer
               | hardware.
               | 
               | I dont believe the NSA, CIA or even the FBI really have
               | any actual legal limits.
        
               | kelnos wrote:
               | I think it's reasonable to acknowledge that, due to my
               | citizenship and physical residence location, the NSA is
               | probably more of a threat to my personal freedom than the
               | FSB, but also acknowledge that, all things being equal,
               | the FSB is a shadier organization than the NSA, with
               | fewer legal restrictions on its behavior.
        
               | sudosysgen wrote:
               | There are no relevant legal restrictions on the NSA
               | behaviour. We _know_ that the NSA breaks the law without
               | any consequences. This idea that Western intelligence is
               | any less corrupt and morally bankrupt, and indeed any
               | less willing to interfere with people outside their
               | borders as anyone else is frankly entirely ridiculous.
        
               | alimov wrote:
               | While the methods may differ, is this not true of any
               | governments intelligence agencies? Whether or not there
               | is press/courts/rule of law. For press to report on an
               | event they have to be aware of it, for courts to
               | intervene they also have to be aware of it, for rule of
               | law to matter then no part of a government can operate
               | outside of it in any manner, so no extrajudicial actions
               | either.
        
               | [deleted]
        
               | JabavuAdams wrote:
               | The point of press/courts/rule of law is that at least
               | you have a chance. Without those, no chance. That
               | matters.
               | 
               | The US is not some monolithic entity. It's almost weirdly
               | schizophrenic. Yes, the government will e.g. use some
               | super-shaky legal arguments to justify torture _ahem_
               | "enhanced interrogation", but on the other hand Freedom
               | of Information Act requests still get processed. Yes, the
               | NSA will spy on US citizens, but even they feel the need
               | to come up with some legalistic / procedural cover.
               | 
               | Even as the US's checks and balances are tested, and
               | structural inequalities are examined, there is a broad
               | and deep tradition of fighting the government and not
               | going to jail like Navalny.
               | 
               | The traditions and norms of a country's populace, and its
               | institutions really really matter, especially when their
               | institutions are being tested.
               | 
               | Corruption is everywhere, but this is too simplistic a
               | pattern-match.
               | 
               | EDIT> Knight-Ridder did some fantastic and courageous
               | investigative journalism debunking the US casus belli in
               | the run-up to the Iraq Invasion. It didn't stop the
               | invasion, but they were recognized later. Can we imagine
               | that happening in Russia?
        
               | kelnos wrote:
               | > _Knight-Ridder did some fantastic and courageous
               | investigative journalism debunking the US casus belli in
               | the run-up to the Iraq Invasion. It didn 't stop the
               | invasion, but they were recognized later. Can we imagine
               | that happening in Russia?_
               | 
               | This type of thing is something I wish people would
               | recognize more. In Russia right now, the simple act of
               | participating in a peaceful protest against the war in
               | Ukraine could easily land you in jail. While the US
               | government has at times had a sketchy anti-protest track
               | record, can we really imagine the US federal government
               | attempting to pass a law today that makes it a jail-able
               | offense to speak out against a US military action? (Hint:
               | the answer is, unequivocally, no.)
        
               | tablespoon wrote:
               | > This type of thing is something I wish people would
               | recognize more. In Russia right now, the simple act of
               | participating in a peaceful protest against the war in
               | Ukraine could easily land you in jail.
               | 
               | It's even worse than that: merely calling a war a war can
               | land you in jail:
               | 
               | https://www.ctvnews.ca/world/crisis-in-ukraine-to-russia-
               | it-...:
               | 
               | > Russia insists that it is not at "war" in Ukraine,
               | instead referring to its violent campaign as a "special
               | military operation." Under a harsh new law, Russians now
               | face up to 15 years in prison if they spread "fake"
               | reports and call the conflict what it is: a "war" and
               | "invasion."
        
               | dikaio wrote:
               | "there is a broad and deep tradition of fighting the
               | government and not going to jail like Navalny."
               | 
               | Guess the 98% Federal conviction rate isn't accounted for
               | when talking about the deep tradition of citizens
               | fighting the government.
               | 
               | Personal opinion, all governments are corrupt, including
               | the US
        
               | alimov wrote:
               | > The point of press/courts/rule of law is that at least
               | you have a chance. Without those, no chance. That
               | matters.
               | 
               | I agree with you.
               | 
               | > Knight-Ridder did some fantastic and courageous
               | investigative journalism debunking the US casus belli in
               | the run-up to the Iraq Invasion. It didn't stop the
               | invasion, but they were recognized later. Can we imagine
               | that happening in Russia?
               | 
               | Thanks I'll check it out
        
               | makomk wrote:
               | There definitely seems to be at least a little truth to
               | that argument, though. Over the years Kaspersky has found
               | and documented a whole bunch of seemingly US government
               | linked malware whilst their Western competitors just
               | haven't, and I think there's at least some evidence this
               | is intentional on the part of those other companies.
        
               | [deleted]
        
               | saiya-jin wrote:
               | It may be, or his company is really that good above
               | others (I don't think he personally was involved in any
               | of this, but hired good enough people to do so). I tend
               | towards former but have no proof either way.
               | 
               | I still have a serious and (since Russia-started a war in
               | Ukraine) permanent problem with him - as pointed
               | elsewhere [1] he went through KGB school - voluntarily,
               | he was actually active KGB intelligence just like Putin.
               | At those places, your objective morals go down the drain
               | very fast and for good. And obviously both are still very
               | close, he approves overall totalitarian direction of
               | Russia and often spoke against 'too much freedom' in the
               | west and on internet.
               | 
               | [1] https://web.archive.org/web/20140423055434/http://www
               | .wired....
        
               | kelnos wrote:
               | > _There definitely seems to be at least a little truth
               | to that argument, though._
               | 
               | Of course there is, but as this thread is trying to point
               | out, that "little truth" is completely insufficient when
               | assessing risk. The degree to which a particular
               | government can interfere with companies headquartered
               | there matters. The legal culture in those countries
               | matter. The ability to contest and redress this
               | interference matters. An estimate of the worst that can
               | happen to an individual who resists this interference
               | matters.
               | 
               | I'm a US citizen living in the US, so I'm certainly
               | biased, but I do believe my data (and my person, and if I
               | ran a company, my company too) is much safer being in the
               | US than in Russia.
               | 
               | It's certain that all major world powers engage in
               | various forms of cyber warfare. It's completely expected
               | that countries (and companies within them) that are
               | allied will (most of the time) not expose other allies
               | for cyber attacks and malware distribution. It's also
               | completely expected that antagonistic countries (and
               | their companies) _will_ do so.
               | 
               | Back to the point of this article: of _course_ Kaspersky
               | is a US national security threat, _precisely_ because it
               | (as a Russian entity) will try to expose the US
               | government 's cyber warfare capabilities. Whether or not
               | Kaspersky is a threat to the cybersecurity of individuals
               | in the West isn't the issue here. (I would expect they
               | probably are, to some extent, though!)
        
               | sudosysgen wrote:
               | We already do know, however, that the US has no shame
               | "asking" US run companies for their customer's data
               | without due process, and that this has been going on for
               | every large US tech company. So I don't see the logic.
               | 
               | You talk about assessing risk, but we know from the
               | Snowden leaks that the risk in this matter in the US
               | approaches 100% as the size of your company increase.
               | What degree of risk is higher than 100%?
        
             | edgyquant wrote:
             | Which is the entire point of their argument? The Russian
             | government is objectively worse by any honest metric.
        
               | klibertp wrote:
               | > The Russian government is objectively worse by any
               | honest metric.
               | 
               | Any metric you and I would like to use, yes. The govt of
               | Saudi Arabia, which is an ally of ours, murders
               | journalists with a chainsaw on a foreign soil and
               | smuggles the body out of the host country in suitcases -
               | yet no Saudi company is penalized. Supporting a proxy war
               | in Yemen is not that different from Russian invasion, but
               | somehow it suffers no consequences for doing so.
               | 
               | It's actually easy to justify: for the vast majority of
               | Saudis prince MBS is a good ruler. Who are we to judge
               | how their government works, given completely different
               | cultural backgrounds, religions, and different
               | expectations resulting from that difference? We'd be
               | happier if Saudi Arabia was a democracy with a rule of
               | law instead of chainsaw, but if the majority of Saudis
               | prefer the latter, we shouldn't try to force them to
               | change, even if homosexuals can be legally stoned to
               | death there.
               | 
               | It's an easy argument, but it undermines the
               | "objectively" part of your statement. If we accept MBS,
               | we should accept Putin. If we don't accept the way SA
               | works, as we don't accept Russia's, then we should not
               | trade with the Saudis. We do trade with them, though - we
               | (Poland) even increased (2x or more) the amount of oil
               | imported from them this year, and they continue being our
               | friends and valuable allies in the region.
               | 
               | The situation is frankly schizophrenic. Either there are
               | objective metrics, in which case they should be applied
               | everywhere equally, or we allow Saudis do what they want,
               | but then we have no grounds on which to condemn Putin.
               | 
               | If we want to still stay close to Saudi Arabia _and_
               | condemn Putin, we have to agree that we condemn Putin
               | based on something else than objective standards of
               | governing.
               | 
               | I'd really like for our foreign policies to stay true to
               | the ideals we hold dear, but that just doesn't seem to be
               | the case. Putin is an actual, real threat, so we don't
               | accept him and his buddies, while MBS only dismembers his
               | own citizens (and he even allowed women to drive!), so we
               | accept him. That's also a kind of "objective metric", but
               | it's far from what you meant, and it makes me deeply
               | uncomfortable TBH.
        
               | naoqj wrote:
               | Than what government? Definitely not the American.
        
               | kelnos wrote:
               | I'm honestly trying to figure out here if you are
               | trolling, or if you genuinely believe that.
               | 
               | If you do genuinely believe that the US government is
               | worse (or at least just as bad) as the Russian government
               | when it comes to citizens' personal liberties, I'd be
               | very curious to understand why you believe that to be the
               | case.
               | 
               | Certainly I (as a US citizen living in the US) am biased,
               | but I do believe I have a healthy level of criticism and
               | skepticism of my own government, and yet I cannot see how
               | we even come close to how bad the Russian government is.
        
               | xur17 wrote:
               | Did you read the GGP?
               | 
               | > One could say that the same is true in the US, but I
               | believe the degree matters. Although the US government
               | and intelligence agencies will and do try to overreach,
               | there is a strong legal and cultural tradition of
               | exposing, resisting, and fighting these overreaches in
               | the US. I don't see that in Russia.
               | 
               | > So, I would not be surprised to see the US strong-
               | arming US companies, but they would do this with
               | sham/flimsy legal cover. The result of non-compliance
               | would be at worst asset seizure and/or imprisonment. Both
               | of these can be examined and contested. I imagine that
               | the penalty for non-compliance in the Russian system
               | would max out at having an unfortunate accident.
               | Gangsters all, but the level of gangsterism and
               | possibilities for investigation/redress matter.
        
               | saiya-jin wrote:
               | I, as non-US citizen, thus having sub-human rights in
               | eyes of every US 3-letter agency, still prefer very much
               | US approach to, well, practically any matter compared to
               | Russian one.
               | 
               | For Russians, they really don't like anybody else. All
               | that slavic closeness is crap as we can see in Ukraine
               | and elsewhere. Heck, they don't care about other Russians
               | neither, just a cannon fodder and poor fuckers to exploit
               | and then throw away like garbage. They may very well like
               | to see the entire world burn in nuclear hell if they
               | don't get what they want, that's why current situation is
               | really one of those moments in history when future is
               | decided.
               | 
               | It would sure as hell help US image in entire world to
               | actually backtrack a bit all those spying initiatives
               | towards friendly, democratic and in all-important-US-
               | aligned countries. Showing some respect with deeds and
               | not just empty words and so on. I don't know how much
               | that was/is visible from inside, but Trump made huge
               | amount of damage to that, although to be fair he was just
               | a continuation of overall trend.
        
               | laurent92 wrote:
               | It would help US to condemn Colin Powell for brandishing
               | supposed proof of WMD at the UN Counsel in 2003, which
               | they never found after invasion.
               | 
               | It would help for the US to stop Predator attacks. Most
               | of the world is convinced that they are illegal and
               | illegitimate.
               | 
               | And as a French person, I preferred Trump, because he
               | didn't trigger any new war and he calmed down Little
               | Rocket Man. He even shook his hand! And donated 100% of
               | his salary to charities! Biden is back and the war is
               | back: Bad negociation tactics, Hunter Biden shenanigans
               | with billions transferred as a chairman of an oil company
               | in Ukraine, female ministers of defense in all of Europe,
               | focus on having transgender soldiers, so Putin believed
               | we were weak and the field was open. The result is a war.
               | 
               | We could have avoided this war.
               | 
               | PS: I'm not saying female ministers of war are
               | incompetent, I'm saying they make no-one afraid. It was
               | way more frightening when Krouchtchev's general
               | responsible for the nuclear button was a crazy alcoholic:
               | When you're faced with an madlad, you take him seriously.
        
               | kelnos wrote:
               | Ah yes, casual misogyny masquerading as sound military
               | strategy.
        
               | TheGigaChad wrote:
        
               | bboozzoo wrote:
               | That's funny as the thread is about contrasting Russia
               | with US, but I don't seen to recall US invading any
               | neighboring countries under the false pretense of
               | defending some minorities.
        
               | laurent92 wrote:
               | I remember a woman testifying that they were killing
               | babies in Kuwait, and she was later discovered as being
               | the daughter of an ambassador. Source:
               | https://en.wikipedia.org/wiki/Nayirah_testimony
               | 
               | I remember the late Colin Powell brandishing proof of WMD
               | in Iraq at the UN Counsel. He will never land in the TPI,
               | neither will the UN Counsel for basing a judgment upon
               | unverified allegation causing dozens of thousands of
               | illegal killings by the US army.
        
               | robin_reala wrote:
               | May I turn your attention to the Bay of Pigs invasion?
        
               | kelnos wrote:
               | Right, I mean, at least when the US invades a neighboring
               | country, we don't try that hard to create false pretenses
               | for it (https://en.wikipedia.org/wiki/Mexican%E2%80%93Ame
               | rican_War).
               | 
               | But, seriously, if you remove "neighboring" from your
               | statement (which seems to be not particularly relevant to
               | a discussion of morality and respecting the sovereignty
               | of other nations), I'm sure we can find plenty of bad
               | examples perpetrated by the US, many of them much more
               | recent than the Mexican-American War.
        
               | davrosthedalek wrote:
               | Is there an equivalent of the EFF or ACLU in Russia?
        
               | tablespoon wrote:
               | > Is there an equivalent of the EFF or ACLU in Russia?
               | 
               | If there was, it's been shut down (e.g. https://en.wikipe
               | dia.org/wiki/Memorial_(society)#Intimidatio...).
        
               | unethical_ban wrote:
               | Regarding freedom of speech, _relative_ freedom of
               | association and the ability to do business and to
               | criticize governments, the US is miles ahead of Russia.
        
           | jeffwask wrote:
           | > The problem is: how do you run a business that has offices
           | and physical assets > in Russia, without being at least
           | partially beholden to the Russian government? > They have
           | demonstrated that they are not shy about using gangster
           | tactics.
           | 
           | To be fair, the US government has used gangster tactics to
           | get US companies to install backdoors and allow encryption
           | breakers.
        
             | andrewflnr wrote:
             | The very next sentence in GP directly addresses your
             | comment.
        
           | iudqnolq wrote:
           | > One could say that the same is true in the US, but I
           | believe the degree matters.
           | 
           | I think the key misconception behind this argument is the
           | idea that harmful governments is a binary flag, such that if
           | you're subjected to one adding more makes no difference. In
           | fact, different governments have different concerns. This
           | means if you're subject to the US and Russia you're
           | significantly more constrained than if you were just subject
           | to one. As such, it makes sense to reduce exposure even if
           | you obviously can't eliminate it.
           | 
           | (I also believe the US govt is much better than Russian, but
           | I'm leaving that out because I my argument doesn't need it
           | and I'm uninterested in that argument)
        
         | seventytwo wrote:
         | Your entire post is pure speculation.
        
         | tomc1985 wrote:
         | When was Kasepersky ever considered a dirtbag? That company has
         | written a lot of technically in-depth security reports over
         | various threats for a long time.
         | 
         | AFAIK it's a (relatively) honest business, though sadly the
         | target of American russophobia
        
           | eunos wrote:
           | I think there was an incident in which some NSA contractor
           | had Kaspersky installed in their workstation and the
           | heuristic caught up NSA tools https://www.theguardian.com/tec
           | hnology/2017/oct/26/kaspersky...
        
             | toyg wrote:
             | They did the right thing - finding suspiciously malicious
             | code is their job. Not their fault the user was an idiot,
             | spooks PEBKAC is still PEBKAC.
        
               | flutas wrote:
               | > They did the right thing - finding suspiciously
               | malicious code is their job. Not their fault the user was
               | an idiot, spooks PEBKAC is still PEBKAC.
               | 
               | Except for this part, which leaves a huge question of "do
               | they share knowledge with the russian govt."
               | 
               | > But the bigger unknown is whether and how Kaspersky's
               | acknowledged discovery and acquisition of NSA hacking
               | tools resulted in Russian intelligence agencies
               | discovering the NSA contractor, and targeting him for
               | further, apparently successful, attacks.
        
               | dralley wrote:
               | Sure, but the allegation was that soon after Kasperky
               | detected the NSA tools on his system he was hit with a
               | very targeted cyberattack. IIRC that's where the
               | allegations of Kasperky's involvement with the Russian
               | government came in.
               | 
               | And anecdotally there were a lot of MSPs in /r/sysadmin
               | claiming that every single one of their Kasperky
               | customers would be hit by ransomware while few if any of
               | their other customers were.
        
           | guelo wrote:
           | Was it America-phobia that made russia direct endless waves
           | of cyber-attacks at us?
        
           | kmeisthax wrote:
           | The concern isn't Kaspersky being a dirtbag, it's Putin
           | legally mandating they _become_ a dirtbag. That 's how nation
           | states and wars work.
           | 
           | In fact, there's a similar concern that the EU has with the
           | US. The US's CLOUD Act forces American tech companies to
           | comply with US legal subpoenas in foreign jurisdictions,
           | which means that said tech companies cannot also comply with
           | GDPR data export rules. Hence, it's illegal to include US
           | services on EU websites[0] until and unless the US either
           | agrees to pass GDPR into US law (so that exported EU data is
           | still protected) or repeals the CLOUD Act (so that localized
           | EU data is legally untouchable by the FBI or CIA).
           | 
           | The idea that we can treat a company as wholly separate from
           | it's host nation is more of a legal fiction than anything
           | else. It's not, in and of itself, russophobia. If the person
           | running Kaspersky was trying to, say, flee Russia; and people
           | said he couldnt't be trusted, then that would be russophobia.
           | 
           | [0] Note: It is still legal for EU citizens to use those US
           | services directly. This _only_ covers data export by EU
           | companies to third-parties.
        
             | tomc1985 wrote:
             | Sorry, my reference to Russophobia was more at past light
             | that has been shown on Kaspersky, before this year's
             | invasion of Ukraine. I agree that it is entirely possible
             | that Kaspersky could be weaponized now
        
           | flavius29663 wrote:
           | > American russophobia
           | 
           | When you are entering a cold war with Russia, it's not
           | Russophobia, it's common sense to not allow a potential state
           | actor to have root access to millions of devices in your
           | country.
           | 
           | Also, Kaspersky was literally a former KGB
           | 
           | > At the age of 16, Kaspersky entered a five-year program
           | with The Technical Faculty of the KGB Higher School,[15]
           | which prepared intelligence officers for the Russian military
           | and KGB.[7][8] He graduated in 1987[15] with a degree in
           | mathematical engineering and computer technology.[4][8] After
           | graduating college, Kaspersky served the Soviet military
           | intelligence service [6] as a software engineer.[2][10] He
           | met his first wife Natalya Kaspersky at Severskoye, a KGB
           | vacation resort, in 1987.[2]
           | 
           | https://en.wikipedia.org/wiki/Eugene_Kaspersky#Early_life
        
           | Maursault wrote:
           | Unsure of reason for downvotes, but this was my observation
           | as well, and my experience is that Kaspersky Labs scanning
           | software successfully sanitizes its targets and does so
           | without giving the uncanny feeling of wasting one's time.
           | 
           | Putin and friends are moronic for bullying and harassing and
           | mugging Ukraine. But if I were him, I would definitely
           | declare apple pie a security threat in response.
        
             | tomc1985 wrote:
             | Yeah, it was my preferred AV for a while, til I switched to
             | a local company
        
         | DyslexicAtheist wrote:
         | I don't think there is a conspiracy here about tit-for-tat
         | stuxnet or even if he is a "dirtbag". All AV shift trust from
         | the system to the AV. That is the root of the issue and it is
         | an unsolved problem no matter where you try to secure something
         | in the end there is always a compromise somewhere that boils
         | down to _" but eventually you need to trust something"_.
         | 
         | If that something is owned by your enemy in a hot war it's game
         | over.
         | 
         | The minute a vendor can be leaned on by a hostile government
         | (even they are not in the country like the founder of Telegram)
         | and the interest is strong enough to lean on them (hot war) the
         | trust assumption becomes problematic. How problematic? I think
         | it doesn't get more urgent then in a hot war.
         | 
         | Kaspersky needs to pack up in all NATO countries. Not just
         | because they pay taxes in RU (also this is a good enough reason
         | for me). But also because if you share data with a non-NATO
         | country it immediately becomes problematic too if your business
         | partner is using their products.
         | 
         | The options under which they should be allowed to continue to
         | operate is purely academic because it involves not only
         | shifting all operations out of RU but also getting rid of any
         | executive who moves to the new location that can be leaned on
         | back home (e.g. family and friends etc).
         | 
         | There is no middle ground because the minute these steps are
         | initiated Kaspersky has good reason to feel mistreated by the
         | West. So even they kept their hands clean until now they might
         | start doing what they've been accused of anyway.
         | 
         | Also if Positive Tech and others have been sanctions already
         | some months ago there is no reason to give this much bigger
         | potential threat a pass.
        
         | cptskippy wrote:
         | > Ok, let's cut the crap.
         | 
         | Clearly you were joking?
         | 
         | The crap is your assertion that this has anything to something
         | other than what's happening in Ukraine.
         | 
         | Kaspersky is collateral damage and fallout from Russia s
         | actions and nothing more.
         | 
         | Please let's cut the crap.
        
         | starwind wrote:
         | Kaspersky himself had deep connections with the KGB
        
         | viktorcode wrote:
         | It doesn't matter. The fact is Kaspersky (the company) can be
         | coerced by the Russian government to exploit their highly
         | privileged systems access to millions of computers around the
         | globe.
         | 
         | I don't expect Kaspersky (the person) to play hero under these
         | circumstances.
        
           | ajsnigrutin wrote:
           | So can microsoft, adobe, google, etc. Even without them, NSA
           | can intercept the hardware and put their software on those
           | boxes... wikileaks showed a bunch of stuff NSA did.
           | 
           | If you're a valuable target, it's basically choosing if you
           | want to be spied on by the russians or the americans. (or
           | installing linux, and hoping for the best).
        
             | at-fates-hands wrote:
             | > Even without them, NSA can intercept the hardware and put
             | their software on those boxes.
             | 
             | Its interesting to note that not many people remember
             | (maybe a generational thing?) Kevin Poulsen found multiple
             | government listening devices installed on Pac Bell networks
             | that were listening to foreign embassy phone traffic which
             | was highly illegal at the time.
             | 
             | It doesn't surprise me the extent the NSA and other three
             | letter agencies have gone to get at information they deem
             | valuable or important.
        
             | kbenson wrote:
             | > So can microsoft, adobe, google, etc. Even without them,
             | NSA can intercept the hardware and put their software on
             | those boxes...
             | 
             | Those companies often actually have people scan the
             | hardware they receive to check for alterations. There was a
             | whole thing about this a decade ago where a reporter
             | (wrongly, IIRC) accused Facebook and Google of having
             | compromised motherboards, and people from those companies
             | were commenting here about how they are actually very
             | careful with their supply lines and have people vet what
             | they receive with scanning electron microscopes in some
             | instances. (I'll try to find some of the submissions here
             | and edit them as links on the bottom shortly).
             | 
             | I also have it on good authority (a good friend that worked
             | at Google at the time) that Google found out that someone
             | (the NSA) was tapping their inter-datacenter links and
             | that's one of the reasons they made sure all data between
             | datacenters was encrypted, and that was _prior_ to the
             | Snowden leaks.
             | 
             | So yes, agencies are constantly _attempting_ to infiltrate
             | large tech companies for their own purposes. That doesn 't
             | mean they always succeed, or that those companies just give
             | up and accept that it happens. They all fight it quite
             | actively.
        
               | rnk wrote:
               | That google thing is not really a secret. It was widely
               | discussed inside google too. Maybe it came out of Edward
               | Snowden.
        
               | ajsnigrutin wrote:
               | I was talking about google/apple being able to inject
               | arbitrary code into (almost) any phone via (eg.) google
               | play service update or whatever apple has. Also microsoft
               | with windows update, and many other companies too.
        
               | kelnos wrote:
               | Do you have evidence that this happens due to outside or
               | government interference in the company's release process?
               | If not, this is just a conspiracy theory.
        
               | airtonix wrote:
               | They didn't claim that this happens because of government
               | interference... -_-
               | 
               | It's also not a theory.
        
               | kbenson wrote:
               | I was really referring to the part of your comment about
               | the NSA's ability to intercept the hardware.
               | 
               | It's true that any any software that allows auto-updating
               | can be used to load arbitrary code onto a system, limited
               | only by whatever additional safeguards are in place. In
               | the case of the OS vendor, that can't really be guarded
               | against, but it exists farther up the stack as well.
               | Chrome and Firefox can just as easily load nefarious code
               | onto your computer, limited only by what the OS prevents
               | (which is generally more on a mobile platform,
               | thankfully) and what their own reputation can sustain if
               | they were found doing so.
        
             | TaylorAlexander wrote:
             | This is true, tho installing linux is probably not going to
             | make a difference if you are a target. But the USA can
             | issue national security letters through the FISA court with
             | gag orders that keep the NSL secret. Not only that, but the
             | major US companies have lucrative government contracts such
             | that it can be in their interest to provide the US
             | government with certain kinds of access without being
             | compelled through national security letters.
        
             | trasz wrote:
             | Except that the statement being discussed isn't targeted at
             | people who are a target for NSA, but rather those that
             | might be a target for Russia.
        
           | UnFleshedOne wrote:
           | Don't expect him to be _able_ to play hero even if he wanted.
        
             | chess_buster wrote:
             | In my opinion, that's the right way to look at it.
        
         | mrtnmcc wrote:
         | Plenty of legit potential concerns.. Russian govt could
         | "nationalize" Kaspersky at any moment and push rogue updates.
        
           | cf141q5325 wrote:
           | Shouldnt i have the same concerns with software from the US?
           | You dont really have to nationalize to force devs to push
           | malicious code (looking at you Australia)
        
             | devwastaken wrote:
             | Russia can do it without any backlash from their citizens.
             | U.S. can't do it to their own citizens without backlash.
             | Differences in representation of population means different
             | incentives.
        
               | rat9988 wrote:
               | The only backlash I saw is the backlash to snowden from
               | its own country.
        
               | monetus wrote:
               | That is just silly, and has to be said in bad faith. Are
               | you serious?
        
               | rat9988 wrote:
               | I do.
        
               | PoignardAzur wrote:
               | Where's the bad faith? The US and its allies pulled down
               | the plane of _the fucking president of Bolivia_ to catch
               | Snowden.
               | 
               | Those are not the actions of the state worried about
               | public perception, except in a "silence the dissidents"
               | sense.
        
               | ajsnigrutin wrote:
               | Backlash after the wikileaks? What backlash? FISA courts?
               | Gag orders?
               | 
               | Just call the "other guys" terrorists, nazis, whatever,
               | and americans can occupy and bomb whatever country they
               | want (and they did that to many countries) withot any
               | backlash. Gone are the days of the hippies and anti-war-
               | anything... sadly.
               | 
               | I was kinda hoping for a "revolution" in one of the
               | european countries (eg france) during covid, where people
               | would "remove" the current government, and make the other
               | governments atleast worry a bit when their people get
               | mad... but sadly, not even that.
        
             | dralley wrote:
             | Sure.
             | 
             | But we're talking about a government that just stole
             | hundreds of millions of dollars in foreign planes (and
             | other equipment) and took down satellite radio networks
             | with cyberattacks (causing a lot of collateral damage),
             | recently backdoor'd thousands of companies via Solarwinds,
             | and looked the other way w/r/t ransomware groups until one
             | of them caused a major international incident (Colonial
             | pipeline). The threat from other nations is a lot more
             | theoretical than it is for Russia.
        
             | [deleted]
        
             | ed25519FUUU wrote:
             | As a US citizen you still have some semblance of rights
             | under the constitution that dictate what the government can
             | do.
        
               | DiogenesKynikos wrote:
               | Snowden's leaks showed that the NSA was simply ignoring
               | the 4th Amendment, and that the secret FISA court was
               | letting the NSA do so.
               | 
               | Theoretically, the Constitution protects you. In reality,
               | the intelligence community acts largely in secret, and
               | there's very little preventing them from violating the
               | Bill of Rights. Citizens don't even know what rights
               | they've given up until someone like Snowden spills the
               | beans.
        
               | temp8964 wrote:
               | No. You need to understand what you are comparing to. The
               | question is comparing US and Russia. No. It's not the
               | same.
               | 
               | But you turned this question into comparing US to
               | perfection. Yes, you are right. US is not perfection.
               | 
               | But there is a big difference between 70 to 10, even both
               | are not 100.
               | 
               | What Snowden revealed does not make 70 to 10. If you
               | think that way, you don't understand how bad an
               | authoritarian regime is.
        
               | DiogenesKynikos wrote:
               | Putting a numeric value on this is silly. The fact is
               | that the United States government can compel companies to
               | aid in its surveillance (just recall when they forced
               | Snowden's email provider to install a backdoor).
               | 
               | Even if a company does not want to participate or is not
               | compelled to do so, the US government has very
               | significant capacity to break into and co-opt systems
               | (all the way from targeted surveillance of individuals by
               | intercepting and bugging hardware to tapping undersea
               | cables to indiscriminately hoover up communications).
               | 
               | So when people say that Kaspersky might be forced to go
               | along with Russian intelligence, the same goes for
               | American tech companies and US intelligence. There is
               | indeed a 4th Amendment that is supposed to protect
               | Americans, but the last two decades have shown that the
               | government is perfectly willing to ignore that legal
               | restriction.
               | 
               | The US has the most extensive global surveillance system
               | in the world. US intelligence services receive about as
               | much funding as the entire Russian military. I have no
               | doubt that Russia tries very hard to engage in extensive
               | foreign surveillance, but its not in the same league as
               | the US.
        
               | rat9988 wrote:
               | I put both russia and us at 10. Why would I rate it any
               | better, given its past?
        
               | jiscariot wrote:
               | In the US the press can be openly antagonistic toward the
               | government without reprisal beyond maybe having a WH
               | press-core pass tossed. This provides a path for
               | whistleblowers.
               | 
               | Could the Russian press behave toward Putin as the US
               | press toward Trump? If so, then you can have your 10s.
        
               | juanani wrote:
        
               | rat9988 wrote:
               | Snowden and assange have been used as example. Although,
               | there are probably more people shut by the Russian
               | government than by the us, by far. The thing is, the US
               | secret services are secretive enough that non one can
               | complain about, independently of the ability of the
               | people to complain.
        
               | lern_too_spel wrote:
               | No, Snowden's leaks show DoD lawyers working hard to
               | justify programs under the 4th Amendment. In the fallout
               | of the leaks, all but phone metadata collection passed
               | muster.
        
               | DiogenesKynikos wrote:
               | The dragnet surveillance programs that Snowden revealed
               | are obviously outlawed by the 4th Amendment.
               | 
               | Of course lawyers working for these agencies will try to
               | justify them. That's what they're paid to do. During the
               | Bush Jr. years, lawyers for the administration also
               | argued that torture was legal, despite the fact that it's
               | blatantly illegal.
               | 
               | Nevertheless, these programs are incredibly difficult to
               | challenge in court, because the secrecy surrounding them
               | makes even proving standing nearly impossible.
        
               | [deleted]
        
               | berdario wrote:
               | That's nice for some people, but is cf141q5325 even a US
               | citizen?
               | 
               | I'm not, so from that point of view US companies cannot
               | offer many guarantees to me
        
               | [deleted]
        
             | AniseAbyss wrote:
             | It's about probability. I mean I have my issues with US
             | foreign policy but at the end of the day they are more
             | friendly and reliable than Russia.
             | 
             | Yeah if the US ever goes rogue we're all doomed but then
             | your antivirus software will be the least of your worries.
        
             | nopcode wrote:
             | I've worked in multiple European environments (gov &
             | private sector) that mandated usage of European anti-virus
             | & firewalls.
             | 
             | In finance I had a client that didn't trust any vendor and
             | asked me to reverse engineer VPN appliances (they negotiate
             | a special clause with the vendor), which makes more sense
             | then trusting based on country of origin.
        
             | MattGaiser wrote:
             | Depends on the country. Unlike Russia, the government in
             | the USA is not all powerful.
        
               | confiq wrote:
               | except when it comes to force companies out of the USA
               | because of "security reasons".
               | 
               | I think Russia is using similar tactics, does it?
        
               | dragontamer wrote:
               | Try saying the words "Ukraine War" in Russia. That alone
               | is grounds for getting arrested, possibly disappeared
               | and/or tortured.
               | 
               | You have to say "Ukrainian Special Security Operation".
        
               | mardifoufs wrote:
               | This is from the first article I came across on the RT
               | front page right now:
               | 
               | >Moscow attacked neighboring Ukraine last month,
               | following a seven-year standoff over Kiev's failure to
               | implement the terms of the Minsk agreements, and Russia's
               | eventual recognition of the Donbass republics of Donetsk
               | and Lugansk. The German- and French-brokered protocols
               | had been designed to regularize the status of those
               | regions within the Ukrainian state.
               | 
               | >Russia has now demanded that Ukraine officially declare
               | itself a neutral country that will never join the US-led
               | NATO military alliance. Kiev insists the Russian
               | offensive was completely unprovoked and has denied claims
               | it was planning to retake the two republics by force.
               | 
               | It doesn't seem like they are afraid of getting
               | disappeared for saying russia attacked ukraine.
        
               | [deleted]
        
               | dragontamer wrote:
               | RT is the propaganda arm of the Russian government
               | operating in other countries.
               | 
               | Internal newspapers, such as Novaya Gazeta, have been
               | shut down for saying "war" in print. Just the latest in
               | many papers, radio channels and more that have been
               | silenced in Russia.
               | 
               | > It doesn't seem like they are afraid of getting
               | disappeared for saying russia attacked ukraine.
               | 
               | They didn't use the word "war".
        
               | kergonath wrote:
               | "That guy who killed someone is not that bad, because the
               | other guy punched someone and everybody seems happy with
               | that".
               | 
               | Bullshit. The US is an imperialist, sometimes oppressive
               | pseudo-democracy, but nothing like that mafia-run
               | kleptocracy.
        
               | ajsnigrutin wrote:
               | This is a very americo-centric view....
               | 
               | Most of the world consideres americans the "bad guys",
               | and a lot worse than the russians. You can start with
               | southern america and middle east. Then the balkans (where
               | putin is doing the same as you guys did with kosovo).
               | Even parts of africa would have a say.
               | 
               | Here in the balkans, people were actively rooting for
               | trump in the last two elections, because they were afraid
               | Hillary would start a new war here...
        
               | kergonath wrote:
               | You are way off base. First, I am not American and well
               | aware of the imperialist and oppressive aspects. I would
               | be quite happy to see the American hegemony disappear,
               | but not for it to be replaced by Russian aggression or
               | Chinese imperialism.
               | 
               | > Most of the world consideres americans the "bad guys",
               | and a lot worse than the russians. You can start with
               | southern america and middle east.
               | 
               | Their absurd support for tin pot dictators in South
               | America was and is reprehensible, and the whole Iraq war
               | was morally bankrupt and threw fuel on a fire that we'll
               | be trying to put out for decades. And yet, nothing the
               | American did in the Middle East came anywhere near Aleppo
               | or Mariupol. Or the Holodomor. Or the Prague spring.
               | 
               | > Then the balkans (where putin is doing the same as you
               | guys did with kosovo).
               | 
               | Come on, now. You cannot possibly compare Sarajevo (with
               | an actual genocide being carried out, surprisingly, by
               | the side with Russian support) with the charade Putin
               | used as a fig leaf to invade Ukraine. This is pure
               | propaganda. The region would not be any better today had
               | the ethnically cleansing gone all the way to the end,
               | quite the contrary. Europe should have had grown a spine
               | and actually done something.
               | 
               | > Here in the balkans, people were actively rooting for
               | trump in the last two elections, because they were afraid
               | Hillary would start a new war here...
               | 
               | Well, maybe you did, but that's not what I heard from my
               | greek friends. The Americans are not complicated to
               | understand, they are going where their interests are.
               | What the hell would they do in the Balkans? That is just
               | stupid.
        
               | ajsnigrutin wrote:
               | > Their absurd support for tin pot dictators in South
               | America was and is reprehensible, and the whole Iraq war
               | was morally bankrupt and threw fuel on a fire that we'll
               | be trying to put out for decades. And yet, nothing the
               | American did in the Middle East came anywhere near Aleppo
               | or Mariupol. Or the Holodomor. Or the Prague spring.
               | 
               | Yeah sure... and iraq had weapons of mass destruction,
               | and iraqi soldiers killed babies, and afghanistan had to
               | be occupied for 20 years, because a few saudis flew a few
               | planes into a few buildings. Plus syria, libya, lebanon
               | etc... and considering how far back you go in history,
               | there's also blood from vietnam on americans hand. And
               | it's funny how it's a "beloved ruler" when it's a friend
               | of america and "nasty dictator" when it's not... so
               | america has to replace the ones they don't like (eg
               | iran.)
               | 
               | Sarajevo is not in kosovo, quite a few years were between
               | sarajevo and the bombing of yugoslavia/serbia. Kosovo
               | albanians wanted to separate from the main country, and
               | the main country (yugoslavia then) wouldn't let them...
               | then they formed armed groups that attacked the serbs,
               | and serbs attacked the albanians... basically the same
               | thing that was happening with the russian minority in eg.
               | donbas and lugansk in ukraine. Then someone (USA) had
               | some geopolicital interests in the balkans, bombed the
               | country for 78 days, bombed hospitals, passenger trains,
               | busses, schools, tv stations, cluster bombed a few
               | cities, bridges, roads, highways etc, and built a nato
               | base in kosovo.
               | 
               | So, why have a base in the balkans, if they don't need
               | it?
        
             | jcranberry wrote:
             | Maybe, if the US government thought they could get some
             | useful information from you.
        
             | dahdum wrote:
             | > Shouldnt i have the same concerns with software from the
             | US? You dont really have to nationalize to force devs to
             | push malicious code (looking at you Australia)
             | 
             | You should have the same concerns about software from
             | anywhere, including the US. I believe it's a couple orders
             | of magnitude more likely I'd be harmed by Russian
             | government malicious code than any other nation.
             | 
             | Russia is in crisis, striking indiscriminately, and has no
             | reputation left to lose. So that's where my concern lies.
        
               | ajsnigrutin wrote:
               | > Russia is in crisis, striking indiscriminately, and has
               | no reputation left to lose. So that's where my concern
               | lies.
               | 
               | With wikileaks, we've seen, that americans did all of the
               | same things, you now try to accuse russia of potentialy
               | doing.
               | 
               | I'm not saying russians won't do it, but americans
               | already did it.
        
               | trasz wrote:
               | They have - in the past. The threat from Russia is now.
        
               | ajsnigrutin wrote:
               | So you're saying that they suddenly stopped for no reason
               | at all?
        
           | rangerelf wrote:
           | They don't need to nationalize anything, they can just
           | threaten his family with imminent and painful retribution and
           | he'll open it up to anything they want. Period.
           | 
           | All these people whining about "they're both the same", they
           | are not. "Bay of Pigs" argument does not apply, last time I
           | checked Cuba was still standing where on the other hand
           | Ukraine is burning and getting demolished.
           | 
           | It seems that those complaining really really do not
           | understand the horror of living under an "official" or
           | "unofficial" (i.e. government sanctioned vs. government
           | tolerated) mafia rule: either you do what they tell you, or
           | you cease to be, along with your spouse, children, parents,
           | siblings, etc. There is absolutely no negotiation.
        
       | mrkramer wrote:
       | Kaspersky has a very good research team which uncovered a lot of
       | APT hacking groups including Russian ones so I don't see a reason
       | why would they be a threat. But on the other hand Russian state
       | can force them to snoop files and traffic from their clients but
       | I doubt that will happen because everyone would stop using them
       | and they would go bankrupt. Imo US government should use domestic
       | antivirus solutions.
        
         | layer8 wrote:
         | > I doubt that will happen because everyone would stop using
         | them and they would go bankrupt.
         | 
         | The Russian state might not care a lot about that possible
         | consequence and still coerce them to include malware in the
         | next update.
        
           | mrkramer wrote:
           | EU, US and their allies can kick Kaspersky off the market. It
           | would be a game over for Kaspersky meaning zero
           | installs(licenses) and zero revenue. It is not worth to do it
           | not even in the short term. Trust would be forever lost.
        
             | tablespoon wrote:
             | >> The Russian state might not care a lot about that
             | possible consequence and still coerce them to include
             | malware in the next update.
             | 
             | > EU, US and their allies can kick Kaspersky off the
             | market. It would be a game over for Kaspersky meaning zero
             | installs(licenses) and zero revenue. It is not worth to do
             | it not even in the short term. Trust would be forever lost.
             | 
             | Do you think Putin would shed even a single tear over
             | Kaspersky, if what you describe was the consequence of him
             | getting something he wanted?
        
             | stjohnswarts wrote:
             | Trust doesn't matter when you and your team know the
             | alternative is 20 years in a Siberian gulag.
        
         | RadixDLT wrote:
         | the team is called Costin Raiu
        
       | encryptluks2 wrote:
       | Wonder if Google, Facebook, Twitter, Microsoft, etc will be added
       | to this list. While US may consider them national security
       | assets, it is usually the opposite that is true. Like building
       | backdoors into encryption, these services build backdoors into
       | peoples lives. Also note, it usually often only takes one rogue
       | employee with superuser access to compromise a system.
        
         | DeWilde wrote:
         | Why would the US declare companies that benefit them as
         | security threats?
        
         | elzbardico wrote:
         | This is by design. All those companies are in bed with the
         | feds, and no matter what administration. The State is not there
         | to protect and serve you. Unless proven otherwise the State
         | sees you as a potential enemy.
        
         | lmkg wrote:
         | They're US companies, which means the US has a variety of
         | options to influence its operations. While there are a variety
         | of risks that such companies present, Kaspersky is in the
         | qualitatively different situation that a _different_ nation-
         | state has greater influence on its operations.
        
         | smoldesu wrote:
         | So, we ban all MAANG products for federal use. Who supplies us
         | software/hardware next? How do we trust them _more_ than what
         | we had before?
        
           | encryptluks2 wrote:
           | By requiring that government services use regularly audited
           | open source products.
        
             | ComradePhil wrote:
             | But then how can governments sneak in their targeted
             | exploits?
        
               | avbanks wrote:
               | Via a PR?
        
       | CWuestefeld wrote:
       | I spent Sunday researching alternatives, then uninstalling KIS
       | and trying to install BitDefender.
       | 
       | From this I conclude that the current state of AV/Security apps
       | is dismal. Researching alternatives is difficult, it falls
       | directly into the cesspool that is web product recommendation in
       | 2022. Trying to weed out the garbage articles, I find a handful
       | of apps that are consistently rated that the top.
       | 
       | I discarded the recommendation of McAfee. I'm forced to use that
       | awful thing at work, and I won't deal with the performance
       | penalty it exacts. I wound up deciding that BitDefender was the
       | best choice.
       | 
       | But setting up the new software has been an awful out-of-box
       | experience. Configuring the tool was a serious chore. The tools
       | (like for the firewall) were clunky and difficult to use, and
       | once I finished on one machine there's no way to export the
       | settings to apply to other devices. Going to their website to
       | make suggestions, I found another post indicating that their tool
       | is unable to restore from quarantine, files that belong in
       | protected parts of the filesystem. The support analyst had
       | replied "thanks for the interesting suggestion" - for something
       | that seems like a Severity 1 bug!
       | 
       | I'm not trying to advocate for Kaspersky - I can see that with
       | security being its raison d'etre, they're a bridge too far. But
       | come on, the rest of the industry really needs to get their act
       | together. The KIS product is really head and shoulders above
       | other products I've seen, and we should be competing on the
       | merits, not just "the Russians are a*holes".
        
         | legalcorrection wrote:
         | I'm curious, can you tell me why Windows Defender is
         | inadequate? I also gather that Microsoft sells an enhanced
         | version for businesses with needs beyond local machine
         | antivirus.
        
           | Maursault wrote:
           | I can't speak to its inadequacy, but I can point out that it
           | is obviously unethical for Microsoft to sell a broken
           | operating system and then separately profit from a product
           | that mitigates part of what is broken in Windows. Microsoft
           | now has no incentive to fix Windows, and, in fact, benefits
           | from not fixing it. Seems to me that is a job for Linux,
           | anyway, and this one time Linux fell down on the job and
           | failed utterly, iow, not even Linux can make Windows secure.
           | Does anyone else see the irony of the FCC banning Kaspersky?
           | It is as silly and ineffective as banning viruses and
           | malware. If they had any concern for security as opposed to
           | security theater, they'd ban Windows.
        
             | legalcorrection wrote:
             | That's not really a fair critique. Maybe if this was the
             | year 2000. But modern 'antivirus' isn't about fixing a
             | poorly designed OS. It looks for known malware signatures,
             | detects suspicious activity in other software, and so
             | forth. You need that kind of thing on any platform,
             | especially ones that run a web browser and/or let users
             | install the software of their choice.
             | 
             | All of that functionality is available in the free version.
             | The paid version is for managing the security of entire
             | large networks of devices from things like ransomware and
             | advanced persistent threats.
        
               | Maursault wrote:
               | > That's not really a fair critique.... You need that
               | kind of thing on any platform
               | 
               | This is the boilerplate response to the valid complaint
               | that Windows security is a nightmare. While in theory,
               | other platforms (Linux, BSDs, and idk, OS/400, OS/2,
               | etc.) technically can get infected by viruses, in
               | practice, infection on these platforms would be a
               | vanishingly rare oddity, even compared to the also
               | incredibly rare cases of intrusion.
               | 
               | That said, every major non-Windows platform in its
               | default install configuration is inherently more secure
               | than a Windows system that has had all of its known
               | default security issues addressed, even those beyond what
               | Windows Defender provides. Windows is not simply a more
               | attractive target for malware authors because it is a
               | more popular platform with a larger install base, it is a
               | more popular target because it is inherently insecure,
               | and we know it is inherently insecure because it would be
               | foolish for anyone to run Windows and access the WWW
               | without first addressing its security issues.
               | 
               | It is possible, and likely even probable, that someone
               | could use an unhardened, non-Windows system in its
               | default install configuration for ordinary personal
               | computing _for years_ without ever experiencing the
               | security threats that online Windows users face on a
               | minute by minute basis.
               | 
               | But to be fair to Windows, it honestly often is a turnkey
               | solution to whatever office computing needs there be, and
               | without it, information security, as an area of study, as
               | a profession, and as an industry, would not even exist as
               | we know it today. The fact of the matter is that Windows'
               | security issues (and other issues Windows exhibits
               | unrelated to security) creates jobs, and this can not be
               | ignored. Arguably, the jobs Windows creates are more
               | important than the security issues it introduces. Also,
               | to be fair, without C, C++, .NET, Python, Perl, and
               | JavaScript, Windows would probably be 90% more secure, so
               | it is not all Microsoft's fault and, in a sense, some of
               | the problem is beyond their control.
        
               | legalcorrection wrote:
               | > _That said, every major non-Windows platform in its
               | default install configuration is inherently more secure
               | than a Windows system that has had all of its known
               | default security issues addressed, even those beyond what
               | Windows Defender provides._
               | 
               | Highly disputed.
               | 
               | > _Windows is not simply a more attractive target for
               | malware authors because it is a more popular platform
               | with a larger install base, it is a more popular target
               | because it is inherently insecure and we know it is
               | inherently insecure because it would be foolish for
               | anyone to run Windows and access the WWW without first
               | addressing its security issues._
               | 
               | Do you have any specifics about any of this? It really
               | just sounds like Slashdot talking points from the Windows
               | XP era.
        
           | CWuestefeld wrote:
           | I guess that's a fair question, as it does seem to suffice
           | for most people. I have a few reasons:
           | 
           | * Extensive use of Chinese sites, which are quite a mess. I
           | think the risks of visiting that part of the Internet are
           | much greater than someone engaged in more typical usage.
           | 
           | * Features like firewall are useful for things other than
           | protecting against direct hacks, and I use it to ensure
           | privacy and occasionally even to simulate failures when
           | testing my code. I think that Defender has such a thing, but
           | less sophisticated?
           | 
           | * Probably just being more paranoid than most, having lived
           | through an era when less protection was available, and having
           | to un-hack family members.
           | 
           | ETA: also, it's good to have a different sort of protection
           | when the majority is all homogeneous. Windows Defender is the
           | obvious high-value target for hackers. Same kind of weakness
           | and monoculture.
        
             | jaywalk wrote:
             | The Windows Defender firewall is pretty sophisticated. I
             | can't imagine what functionality you'd need from a local
             | firewall that it doesn't offer.
        
               | jabroni_salad wrote:
               | I'm in the space and it's actually pretty rare to see a
               | real 3rd party host-based firewall. Most AV products that
               | have firewall really just offer a different control
               | surface for the built-in windows firewall or iptables.
        
         | dangus wrote:
         | I think your last sentence is what Putin counts on, that the
         | West won't risk "hurting the business environment" to respond
         | to his military campaign.
         | 
         | I think one of the flaws of Western culture is how much
         | business efficiency is put on a pedestal above all other
         | priorities.
         | 
         | Because of that type of mindset, the West can't even
         | manufacture simple cloth or paper masks during a healthcare
         | crisis (as an example).
        
           | CWuestefeld wrote:
           | Devils advocate: that efficiency is one important reason why
           | we're rich enough to be able to afford so much else. Like,
           | CO2 emissions are best controlled by societies who are able
           | to shoulder the greater expense of avoiding coal and such. If
           | we can't count on these efficiencies, we're going to lose a
           | huge amount of positives.
           | 
           | This sounds to me kind of like the fallacy of "if it saves
           | even one life, it's worth it". That's of course ridiculous,
           | because saving that life costs so much that we'll be unable
           | to save countless other lives. In reality, the balancing of
           | costs and benefits is much more subtle and complex.
        
             | dangus wrote:
             | To be clear I'm not saying to move to the extreme end of
             | the spectrum.
             | 
             | My point is that the West often seems to consider low costs
             | and efficiency above long-term implications.
             | 
             | I'm not saying the West should pull an Argentina [1], but
             | the West also shouldn't always be metaphorically choosing
             | the lowest bidder.
             | 
             | [1] https://www.npr.org/sections/money/2017/02/17/515850029
             | /epis...
        
         | p1peridine wrote:
         | It's possible to use Kaspersky Free but block the apps internet
         | connection*
         | 
         | Network Settings > uncheck Traffic processing
         | 
         | Network Settings > Do not scan encrypted connections
         | 
         | Once in a while, allow internet connection, do a quick database
         | update then immediately block the internet connection again.
         | 
         | * Firewall (router or software).
        
           | mmastrac wrote:
           | With something that has hooks that deep in your OS, blocking
           | internet access via the application itself is not going to be
           | effective in any way if it's hostile software (or turns into
           | hostile software via government decree).
        
         | Arubis wrote:
         | I fully agree that the antivirus market is a cesspool, and long
         | has been so. The upside is that Microsoft's first-party
         | solution is decent and ships with the OS, so you can sidestep
         | the entire project of figuring out which third-party AVs
         | somehow manage to do more good than harm.
         | 
         | I haven't looked into AV for macOS in ages; when last I did
         | (~5y?), Sophos (if corporate/paid) and ClamAV (fine for home
         | use) seemed reasonably non-interfering.
        
         | Jamie9912 wrote:
         | Did you take a look at ESET?
        
           | omgmajk wrote:
           | I run ESET for the only reason that it was offered to me
           | cheaply and has worked fine over the years without feeling
           | intrusive.
        
           | CWuestefeld wrote:
           | That was actually going to be my first choice. From what I
           | read it seems better polished than others. But then I read
           | some recent lab tests in which ESET missed blocking a
           | ransomware attack. And that's the threat model that worries
           | me the most.
        
             | timbit42 wrote:
             | Any anti-virus can miss a malware at any time because they
             | rely on updates which take at least a day if not more to be
             | prepared and tested before being distributed in the
             | updates. Don't worry about ESET missing one ransomware
             | attack in a lab test. Do backups daily.
        
         | [deleted]
        
       | MisterTea wrote:
       | At work we are required to have EDR software by our accounting
       | firm (accounts inserting themselves into IT is annoying). We were
       | running Kaspersky as well until this happened though we were
       | already unhappy with it so no loss.
       | 
       | Anyway it made me think: is there a way to roll your own EDR for
       | Windows/Linux/BSD? Basically, can we do EDR without the EDR
       | software?
        
       | ddaalluu2 wrote:
        
       | sjmm1989 wrote:
       | So... let's say a person still wanted to use an Antivirus product
       | anyways, despite not really trusting them due to reasons like
       | this article here; or anything you can say about Norton, etc,
       | etc.
       | 
       | What would you all suggest? Aside from McAfee, Norton and of
       | course Kaspersky. I'm all ears. Some helpful hints though might
       | be:
       | 
       | 1. I don't want it giving me pop-ups constantly to remind me of a
       | sale they are having.
       | 
       | 2. It can't interfere with legitimate programs more than once in
       | a blue moon.
       | 
       | 3. It has be capable of being run with other security software at
       | the same time without incurring an infraction against #2.
       | 
       | 4. It has to cost less than 100$ per year, if there has to be
       | payment at all.
       | 
       | I'm asking this because I need a reliable choice to use when
       | suggesting to my potential customers out there. I have some go
       | to's that I used to use, but with everything the way it is right
       | now; I want some input.
        
         | rntksi wrote:
         | We've been running ESET Nod32 for over a decade.
         | 
         | Its strength is that it uses very low memory and CPU cycles due
         | to the way it is built.
         | 
         | It ticks all the boxes you've given above.
        
         | LeoPanthera wrote:
         | For home use, Sophos Home: https://home.sophos.com/en-us
         | 
         | (Disclosure: I used to work for Sophos, I no longer do.)
         | 
         | It's a good mix of traditional antivirus, antimalware, and
         | privacy tools. It's also available for Macs.
        
         | AniseAbyss wrote:
         | Malwarebytes?
        
         | stjohnswarts wrote:
         | Just use what comes with microsoft. If you want another layer
         | of scanning then install Malwarebytes. Those two should be
         | plenty for anybody. Also set their DNS to use something that
         | blocks known malware sites (quad 9 is what I use).
        
         | Hamuko wrote:
         | At least the business version of F-Secure is not annoying the
         | living daylights out of me, although I have the more onerous
         | securities turned off (like the browser protection).
        
         | srhngpr wrote:
         | Windows Defender.
         | 
         | See: https://0ut3r.space/2022/03/06/windows-defender/ and
         | recent discussion on HN:
         | https://news.ycombinator.com/item?id=30580444
        
       | coliveira wrote:
       | So, basically we are allowed to protect against any external
       | security threat, except the ones created by US spy agencies.
        
         | timbit42 wrote:
         | Why aren't you allowed to protect against threats created by
         | the US spy agencies?
        
           | usednet wrote:
           | Because then you get a gag order and a wiretap.
        
       | randomsilence wrote:
       | Why do we accept the risk of intrusion from antivirus software at
       | all?
       | 
       | All antivirus software developers should open-source their
       | traversal software and thus guarantee that no harm can be done.
       | The scanning doesn't need write access and doesn't need network
       | access.
        
       ___________________________________________________________________
       (page generated 2022-03-29 23:01 UTC)