[HN Gopher] Kaspersky is declared a US national security threat ...
___________________________________________________________________
Kaspersky is declared a US national security threat and is banned
by the FCC
Author : DocFeind
Score : 402 points
Date : 2022-03-29 13:51 UTC (9 hours ago)
(HTM) web link (hothardware.com)
(TXT) w3m dump (hothardware.com)
| wnevets wrote:
| Kaspersky was caught helping the Russian government back in 2017.
| Anyone still using their software in 2022 probably has much
| larger problems.
| zokula wrote:
| usednet wrote:
| Nobody within the hacking scene actually believed that story.
| It's remarkable that there's been 0 evidence that Kaspersky has
| ever had a backdoor yet so many people believe it.
|
| The NSA's own incompetence led them to run an antivirus on a
| computer with Equation Group spyware on it. Keep in mind that
| Kaspersky had been fighting Western intelligence services for
| years at that point. Israeli intelligence actually breached
| Kaspersky's network in 2015, no doubt because Kaspersky is the
| only AV company that actually exposes US-created malware.
| wnevets wrote:
| I'm getting deja vu to when I was told Russian's continued
| invasion of Ukraine was just propaganda by the West [1]
|
| https://twitter.com/Snowden/status/1494006204896620548
| usednet wrote:
| I'm getting deja vu to "WMDs", "moderate rebels,"
| "dictators," and "national security." Even a broken clock
| is right twice a day.
| wnevets wrote:
| is a record for how quick someone can turned to
| whataboutism?
| natch wrote:
| > Kaspersky also maintains that it "doesn't have any ties with
| any government, including Russia's
|
| This take is either naive in the extreme, or disingenuous.
|
| For a security company trying to maintain a trusted reputation,
| neither of those two options is good.
|
| While possibly technically accurate, it is a dodge or a flub that
| overlooks the fact that their autonomy can be usurped by the
| governments where they are based and where they operate.
|
| To be fair, this is true of almost any company I can think of,
| although I wonder if a DAO could get around it.
| genocidicbunny wrote:
| Exactly. They're one OMON or FSB visit away from 'having ties
| to the Russian government.' Refusing to acknowledge that is
| just downright disingenuous.
| vkou wrote:
| The same can be said about any vendor in the world, though.
|
| Any of them is one NSL away from becoming a spy, wrecker or
| saboteur.
|
| If your threat model includes foreign governments, don't use
| foreign closed source software. If your threat model includes
| your government, don't use domestic closed source software.
|
| Or do, but either be ready to mitigate the harm, or be
| willing to live with it.
| InitialLastName wrote:
| In terms of TFA, I suspect the ship has sailed with respect
| to intervention by the US government in network
| installations regulated by the FCC.
| T3RMINATED wrote:
| lizardactivist wrote:
| I'm happy with what I consider to be the most competent AV suite
| available, made by a team of researchers that is second to none.
|
| If the U.S. accusations are ever proven to be true, I will
| reconsider. But I'm not holding my breath, since the U.S. has
| time and again been proven to be guilty themselves of the very
| thing they accuse others of, and refuse to provide any proof of.
| [deleted]
| google234123 wrote:
| What would you consider "proof"? I feel like it's not far
| fetched to assume the Russian Government can compel Kaspersky
| to do things. This same government is so insecure that they
| order assassinations of minor political opposition leaders
| perfecthjrjth wrote:
| In the long term, this will prove to be a good decision, as other
| countries figure out that US companies (Microsoft, Google, FB,
| Twitter, Master, Visa etc) are in bed with spy agencies of the
| US. Other countries are given more reasons to NOT depend so much
| on these companies.
| ChrisArchitect wrote:
| More discussion 4 days ago:
| https://news.ycombinator.com/item?id=30806181
| dghughes wrote:
| Antivirus software manufacturers should jump at this and offer a
| free subscription to former Kaspersky users.
| asteroidp wrote:
| Good! Although 20 years too late
| [deleted]
| mc32 wrote:
| I think a lot of people have been saying this for years.
| However most people until recently thought it was unfounded
| hyperbola.
|
| We should at least be skeptical given the connections the
| founder has.
| buitreVirtual wrote:
| Just like, until recently, Europe (and especially Germany)
| thought it was paranoia to treat Russian oil and gas
| dependence as a risk.
| mc32 wrote:
| German policy was out in la-la land. Politicians sold the
| public on green policies before the infrastructure was
| ready and heavily relied on imported non green energy to
| get there. They didn't have to shut down their nuke plants,
| but 'make happy' led them down that path of dependence
| --just as most of the industrialized world is dependent on
| another questionable government for consumer goods and
| microelectronics. Offshoring is awesome for the ruling
| class until it isn't.
| dainiusse wrote:
| Exactly. These are very costly lessons, learnt on Ukrainian
| blood....
| gjsman-1000 wrote:
| Quick question - where does the FCC derive this authority?
| kube-system wrote:
| The FCC has the authority to regulate how federal funding for
| telecommunication is used.
|
| Those who do not use federal telecom subsidy funds are not
| affected.
| TheGuyWhoCodes wrote:
| All the enterprise businesses in the US I worked with, and had to
| go through security audits, already banned the use of Kaspersky.
| Even for suppliers.
|
| I guess this just makes it official.
| LeoPanthera wrote:
| I'd quite like to know whether AdGuard is safe, too. Founded in
| Moscow but incorporated in Cyprus.
| AzzieElbab wrote:
| All antiviruses should be declared security threat regardless of
| vendor. Just hope FTC stays clear of jetbrains
| kozak wrote:
| Telegram is next?
| stjohnswarts wrote:
| telegram is mostly outside of russia now isn't it? I think they
| still have a programming team there but the "owners" are
| outside the country.
| mohamez wrote:
| IIRC Telegram is banned in Russia, and its CEO is not in good
| terms with the Russian government.
| ComradePhil wrote:
| Definitely not banned in Russia:
| https://www.aljazeera.com/news/2022/3/19/last-apps-
| standing-...
| paganel wrote:
| Not sure why you're down-voted for stating out the facts as
| they are.
| FpUser wrote:
| Because some people do not like pesky facts when those
| interfere with the narrative?
| thematrixturtle wrote:
| They tried in 2018, but couldn't pull it off. It's unclear
| what Telegram agreed to in 2020 to get officially unblocked
| though.
|
| https://en.wikipedia.org/wiki/Blocking_Telegram_in_Russia
| ramesh31 wrote:
| >It's unclear what Telegram agreed to in 2020 to get
| officially unblocked though.
|
| Most likely implementing FSB backdoors.
| older wrote:
| It is not only not banned but "found a compromise" and agreed
| to co-operate with FSB according to Russian MP (google
| translated article from tjournal.ru): https://tjournal-
| ru.translate.goog/news/562296-durov-nashel-...
| MikusR wrote:
| According to Russian Minister of Foreign Affairs, Russia
| has no intention to invade Ukraine
| throwaway290 wrote:
| Telegram is very comfy in Russia (as in good luck finding
| a non-user). It also has no revenue stream. I put 2 and 2
| together.
| older wrote:
| In this case we have evidence. Telegram is not banned in
| Russia, and now we have an explanation about why.
| throwaway290 wrote:
| English-native source:
| https://www.independent.co.uk/news/world/europe/telegram-
| rus...
| kube-system wrote:
| Telegram is free isn't it? I don't think there are any federal
| funds being used to buy telegram today. So, there's not much
| for the FCC to ban.
| ibejoeb wrote:
| The White House campaign to explain its Russia policy on social
| media did so via Chinese properties Zoom and TikTok. I don't
| think we can rely only on domestic production right now.
| throwmeariver1 wrote:
| I found it always fishy that telegram applauds itself for being
| a secure messenger but decided against encryption by default.
| With the flick of a switch every doubt would go away but alas.
| pantulis wrote:
| I have also been amused by the number of technical people
| that prefer Telegram vs Whatsapp in terms of security.
| paganel wrote:
| > Telegram vs Whatsapp in terms of security.
|
| The 3-letter US agencies do not have direct access to
| Telegram's servers, they do have when it comes to Whatsapp
| (or to any other US-based company). The same goes if you're
| a Russian doing anti-government stuff in, well, Russia,
| it's better to put your fate in Whatsapp's (and Meta's)
| hands, presumably the US agencies won't come after you for
| being against the Russian government. It's a classical game
| of arbitration (for lack of a better word).
| older wrote:
| > The 3-letter US agencies do not have direct access to
| Telegram's servers
|
| What makes you think so?
| paganel wrote:
| Snowden, for a thing.
| stjohnswarts wrote:
| I don't recall snowden having any material on whatsapp
| backdoors though?
| older wrote:
| What about Snowden? How he would prevent US 3-letter
| agencies from having access to servers located in the US
| or in London?
| paganel wrote:
| Sorry, I had mis-read the question, thought you were
| talking about WhatsApp. That's news to me, the US server
| thing for Telegram.
| cout wrote:
| I agree with your logic, though a paranoid person might
| point out that they don't need access to telegram's
| servers; access to the app store or to automatic OS
| updates would be enough.
| paganel wrote:
| Yeah, me being a backend guy didn't think of the client
| side of things.
| older wrote:
| You agree to the logic based on a false premise that the
| 3-letter US agencies do not have direct access to
| Telegram's servers which are located in the US (among
| other places).
| ramesh31 wrote:
| >I have also been amused by the number of technical people
| that prefer Telegram vs Whatsapp in terms of security.
|
| Tribalism is a helluva drug.
| spacemanmatt wrote:
| I have also been amused by the number of technical people
| that prefer anything vs Signal in terms of security.
| codedokode wrote:
| Signal requires a phone number and doesn't allow
| anonymous usage as I understand.
| older wrote:
| Signal is designed for privacy, not for anonymity.
| saagarjha wrote:
| I've been amused by the number of technical people that
| prefer Signal vs just not shutting up about the messaging
| app they use and not pretending like they're some sort of
| authority on the topic instead of someone who deals with
| SOC2 compliance daily.
|
| (This is actually independent of you or Signal, I just
| find it amusing that people throw their security
| brand(tm) behind some app and it's just them picking the
| one they like most of the time.)
| cout wrote:
| End-to-end encrypted by default doesn't mean much if you
| don't trust the third party providing the software that does
| the encryption. One automatic app update can enable leaking
| of encrypted communication.
| throwmeariver1 wrote:
| The bigger problems for me would be the appstores because
| they could implement a mitm. Telegram and Signal have their
| client sources open so you at least can check and compile
| them yourself but if I would handle data that was so
| sensitive that I can't trust any other entity I would just
| self host matrix or xmpp and chat with myself...
| BitwiseFool wrote:
| I'm only tangentially aware of secure messaging apps. How do
| you feel about Signal? What is your preferred client?
| throwmeariver1 wrote:
| Telegram is fine if you just use it for 1on1 conversation
| with encryption enabled. The same goes for whatsapp
| (encryption is enabled by default). If you are looking for
| secure group chats signal would be my choice because it
| skips the server (WhatsApp sends all group messages to a
| server before distributing it). There are also more exotic
| providers like threema, matrix and many others but the
| onboarding for non technical users is harder, though they
| also have advantages like not needing a telephone number to
| sign up. For the general public I would use Signal mainly
| because it's directly in the middle of security and ease of
| use.
| sschueller wrote:
| Probably not but McAfee should be added just because it sucks
| so much.
| throw10920 wrote:
| Unironically, McAfee may be a greater threat to US national
| security than Kasperky. McAfee is actually used by the
| Department of Defense[1], and Kaspersky is not. Given how bad
| McAfee actually is, I think that that makes it worse.
|
| [1] https://en.wikipedia.org/wiki/Host_Based_Security_System
| _joel wrote:
| <> Norton entered the chat
| orangepurple wrote:
| McAfee uninstallation instructions by John McAfee himself
|
| https://www.youtube.com/watch?v=UQrAfQMpnZk
| orangepurple wrote:
| Telegram is run by a citizen of St Kitts and Nevis. He escaped
| Russia after they beat down his door.
| throwaway290 wrote:
| Who also promised to cooperate with russian government in
| exchange for lifting the ban on the app.
|
| And even if he didn't, if you run the most popular messenger
| app in Russia you can't simply hide behind "citizen of some
| other country". KGB is known for poisoning/shooting people
| abroad for much less, and especially if you have family or
| close relatives back in your country of birth you really have
| little leverage to speak of.
| ComradePhil wrote:
| Very likely, being founded and run by Russians... and a good
| way to stop people from communicating freely about the world
| affairs.
| morganvachon wrote:
| Russian citizens != Russian government. The Telegram
| development team is not on good terms with the Russian
| government last I read. With that said, it still operates
| within the borders so it's subject to government control
| (just as any US-based messaging service is subject to US
| government control). It's always a cat-and-mouse game between
| those who want free, unfettered, unmonitored communications
| and the governments that feel threatened by that kind of
| freedom.
| ComradePhil wrote:
| You are thinking from a completely different perspective.
|
| There's nothing for governments to allow people to
| communicate freely. Telegram is one of the few platforms
| that allows that... and this is a good opportunity for the
| US government to do that.
| older wrote:
| Last I read Telegram is on very good terms with the Russian
| government. I have already posted link to the source in
| this thread.
| luckydata wrote:
| Inevitable and good. I'm relieved that we are at least stopping
| the pretension that we don't have an ongoing conflict with the
| "totalitarian east" of the world. China and Russia are absolutely
| a threat to modern democracies and we have let the economic
| interests of the few override those concerns for far too long,
| with terrible consequences for both us AND their own population,
| which we contribute to the oppression of by propping up those
| totalitarian regimes with a constant stream of cash.
|
| Globalization was a terrible idea the way it was done and I'm
| glad it's coming to a close.
| stjohnswarts wrote:
| kaspersky should have completely left russia decades ago if they
| wanted to free their reputation from FSB taint.
| rcMgD2BwE72F wrote:
| Like all the US companies leaving the US in 2003? I only
| remember US companies trashing France around that time.
| stjohnswarts wrote:
| What? I guess enjoy your strawman? I never mentioned the US
| and this isn't a comparable situation. I'm talking about a
| business decision to not be associated with the KGB in
| countries where you do the vast majority of your business (EU
| and North America)
| nanochad wrote:
| We have placed full sanctions on Russia. It's common sense not to
| rely on them too much.
| ElectricalUnion wrote:
| > full sanctions
|
| [citation needed]
|
| Isn't oil, gas and food trade still allowed? That is not "full
| sanctions".
| flavius29663 wrote:
| oil and gas were banned by the US
| the_snooze wrote:
| Is there any point in using antivirus these days anyway? I'm open
| to being wrong here, but I'm under the impression that antivirus
| exists only to tick boxes in outdated security compliance
| checklists. How big of a threat are viruses compared to, say,
| rogue antivirus products themselves?
| hans1729 wrote:
| It's a thing in big orgs, where macros are enabled in excel and
| employees can be tricked into opening mail attachments. Windows
| defender should suffice, but like you said, from a
| compliance/insurance perspective it may me valuable to say
| "look, we scanned for signatures according to the latest
| knowledge of [insert vendor]".
|
| Personally I think that it's ridiculous that these huge orgs
| fail to address the actual underlying issue, excel macros. But
| hey, it's easier to fight the Symptome than to deal with the
| root cause, especially if the latter would impact established
| work flows god knows how far down the line.
| beamatronic wrote:
| The class of risky employees should perhaps be limited to
| Chromebooks only.
| 29083011397778 wrote:
| This may work some of the time, but expect "I need
| $windows_program" to foul your chances of this. It may not
| always be legitimate, but telling heavy-duty transport
| mechanics they can't have Cummins or Bendix software (for
| engines and brakes) to help them diagnose, when that's the
| only output for troubleshooting supported by the OEM, will
| not end well.
| jmrm wrote:
| This makes me thing: When we are going to see those
| Windows software directly on the web?
|
| For me makes a lot of sense being able to sell a software
| subscription instead of a one time product sell, and for
| the other hand making available to use in any device in
| the world with internet connection.
|
| This also can be done like Chrome apps (like Docs) or
| some Electron apps (like Spotify), where you can use
| content without Internet for some time without any
| problem.
|
| For a mechanic who is looking for the amount of torque
| needed on a bolt this could be perfectly viable, for
| example.
| 29083011397778 wrote:
| > For a mechanic who is looking for the amount of torque
| needed on a bolt this could be perfectly viable, for
| example.
|
| We're going to start talking past each other pretty
| quickly if you think this is worthy of a (software)
| service subscription. Torque specs belong in a manual
| (ideally on corporate intra-net or paper); I'm talking
| about when the engine is deeply unhappy, and you need
| more to go on than a driver reporting a yellow check
| light.
|
| In the case of the latter, I'd say it absolutely deserves
| to be a 20 year old program (which tend to be lighter)
| that runs entirely offline. The last thing any garage
| wants to do is chase hardware requirements or search for
| a wifi signal either out in the yard, or in between
| hoists, lifts, and miscelleaneous heavy equipment /
| tooling - all of which tend to trash a wifi signal.
| jacobr1 wrote:
| This is already a thing. Plenty of companies use managed
| virtual desktops via the web for this purpose.
|
| AWS even offers "Workspaces" as service for this.
|
| Though it doesn't solve the "without the internet"
| problem.
| stjohnswarts wrote:
| This is why people don't like IT staff a lot of time. They
| think their needs of making their own jobs easier outweigh
| those of the organization and getting stuff done.
| jacobr1 wrote:
| The bigger problem is that the IT staff is often so
| ludicrously underfunded, that they ARE a bottleneck.
| There probably are ways to manage team/personal
| productivity with organization needs, but without time to
| dedicate to analysis, you get blanket solutions. Which is
| another reason why self-provisioned SaaS rather than IT
| managed systems are big.
| hans1729 wrote:
| Unfortunately I don't think belittling these employees
| helps much here, especially considering how good a
| dedicated phisher can become at their craft.
| d3ad1ysp0rk wrote:
| CEOs?
| harikb wrote:
| The software we develop should have better interfaces too.
| A security expert should also review stuff created by UX.
|
| Back when "I love you" virus started, we had pointed out
| something simple as "open for read" vs "open as in
| run/execute" should not have had the same interface.
|
| All the new security enhancements we have today - don't run
| as admin, alerts to request privileged access, sandboxing -
| all of them existed for a decade, but the software vendors
| never had the guts to weigh security higher than UX
| carnitine wrote:
| I think if Excel macros were banned in finance, trading
| volume would drop by several hundred billion dollars per day.
| saalweachter wrote:
| Are you giving the pros or the cons?
| sjmm1989 wrote:
| Seriously though... Maybe this is something that should
| be done.
| annoyingnoob wrote:
| I have personally watched Windows Defender fail to notice a
| real virus infection from a USB flash drive. The USB flash
| drive was plugged in and instantly Windows was infected -
| Windows Defender did nothing. You could then manually run a
| Windows Defender scan and it would find the infection but it
| would not prevent the infection.
|
| I think one's need for a security product should match one's
| exposure to issues - it depends on your org. For a very long
| time I was not a fan of anti-virus, in 2022 I'm back to
| liking anti-virus (more like EDR these days).
| driverdan wrote:
| What mechanism would a flash drive use to infect a modern
| version of Windows by only being plugged in?
| RadixDLT wrote:
| dont confuse BitDefender with Windows Defender, not the
| same thing
| annoyingnoob wrote:
| I did not confuse them. Yes, I mentioned GravityZone in a
| follow - which is a BitDefender product, and is the
| product that found the issue when Windows Defender did
| not.
| 3np wrote:
| Would one of the commercial antivirus products have caught
| it, though? Did you check?
| annoyingnoob wrote:
| Yes. It was not a current virus, came from an old UEB
| flash drive that had been lying around for years.
| GravityZone noticed it and prevented it, which is why I
| knew to go look at the Win10 box the flash drive was last
| plugged into. Windows Defender's silence would have left
| us with the virus installed because it was not
| periodically scanning on its own.
| gamblor956 wrote:
| MS Defender used to automatically scan USB devices when
| plugged in but that's not the default anymore (and AFAIK
| hasn't been for a few years since one of the major
| updates); you now have to enable it somewhere non-intuitive
| (like the Policy Editor?).
| ridgered4 wrote:
| That's a really bizarre choice of default setting.
| gamblor956 wrote:
| Not really, when you consider that there are tens of
| thousands of USB devices that work with Windows, many of
| which can operate like a flash drive even though they
| aren't (like cameras). I can imagine MS disabling this
| feature by default due to the headaches involved.
|
| Notably, autolaunching USB drives is also no longer the
| default option for USB devices. The user has to
| specifically _choose_ what action happens when the device
| is first plugged in (and by default, that choice only
| applies to the current instance; the user must manually
| choose to have the choice apply the next time the device
| is plugged in).
| annoyingnoob wrote:
| My point is that people thinking that Windows 10 comes
| with Windows Defender, and that Windows Defender will
| protect them by default, are in for a surprise. Defender
| probably is not doing anything you might think it should,
| by default.
| bell-cot wrote:
| I seem to recall an article about a big org, probably in
| Finance, which took a serious look at the Excel Macro thing.
| Only a puny fraction of their employees, pretty much all in a
| couple specialized departments, actually used those. SO -
| outside of those few and their dept's, all macros were
| disabled/banned by fiat. Which allowed the relevant
| malicious-macro-prevention resources & training to be focused
| on those few.
| dartharva wrote:
| I would really hope my organization doesn't start blanket
| banning excel macros for "security". It'll be a huge blow to
| productivity for several.
| excalibur wrote:
| Draconian bans probably aren't the best way to achieve it,
| but if it's productivity your org wants they should
| concentrate on migrating those workflows out of Excel ASAP.
| behringer wrote:
| So which accountant is going to be programming your
| node.js files?
|
| There's a reason companies use excel.
| slowmovintarget wrote:
| They'd just learn Python. They'd be fine.
| dartharva wrote:
| I won't, even when I do know how to script in Python. We
| don't really like having our workflows disrupted for
| silly reasons
| jmt_ wrote:
| You can't just "#learntocode" Excel macros away from
| industry.
| orev wrote:
| Corporate "anti-virus" is much more than just anti-virus these
| days. Most of them don't even call themselves anti-virus, but
| endpoint protection. Other than anti-virus, they let you set
| policies on USB ports, block web browsing by categories or
| specific domains, let you run software inventory reports, etc.
| These things are very important, especially with work from
| home, as you can't really block things at the office firewall
| anymore.
| lostlogin wrote:
| They also slow your machine down, report back to the company
| and throw annoying pop ups at you multiple times per day.
|
| Never again.
| irrational wrote:
| My company forces all of us to use a product called Zscaler. I
| have no idea if it is effective, but it is constantly running
| and uses the vast majority of my CPU. The degree to which is
| slows down my computer and slows down development is
| astonishing. I have to wonder, across the entire company, if
| the potential cost of stuff lost that zscaler supposedly
| protects us from is worth more than the real cost of lost
| productivity, not to mention whatever they are paying for
| zscaler itself.
| jacobr1 wrote:
| You should see if you get them to debug the situation. Unlike
| plenty of bloatware discussed on this posting, zscaler is
| usually not that resource intensive. It is more of a better
| corporate VPN, than it is a AV tool.
| lotsofpulp wrote:
| I assume it is a cover your ass thing for executives to point
| to when malware happens on systems they are responsible for.
| xtracto wrote:
| More than that. It's still required by cert standard bodies
| such as PCI and SOC2 .
|
| Even if you as an exec know they are security theater you are
| forced to comply due to these certifications.
| brightball wrote:
| While it's fairly easy to bypass them, half of the point seems
| to be making sure that people still NEED to put in the effort
| to bypass them.
| fatnoah wrote:
| Current AV software bloatware is a scourge on the world.
|
| I spent about 30 minutes this weekend helping my sister-in-law
| debug a slow internet. My observations were that attempting to
| do anything resulted in about a 5-10 second pause, and general
| sluggish response when trying to anything online. I disabled
| anti-virus, etc. and it was still slow. I tried Edge and
| everything was super-fast.
|
| Digging further, the issue was McAfee Safe Search (powered by
| Yahoo). It was singlehandedly adding 5-10 second lag on every
| mouse click and character typed in the browser. Disabling and
| blocking that resolved everything.
| the8472 wrote:
| > rogue antivirus products themselves?
|
| It's not just rogue AV software. Buggy, insecure AVs are a big
| problem too. They're attack surface! Especially when running
| parsers and interpreters for untrusted inputs in kernel space.
| iso1210 wrote:
| > rogue AV software
|
| You repeat yourself sir
| commandlinefan wrote:
| Even when they don't expose any security holes, they bog the
| computer down so much that I'd almost rather have a virus -
| at least a command-and-control virus might take steps to make
| me unaware of its presence.
| vetinari wrote:
| In the '90s, there was a joke: What's the difference
| between Windows and viruses? Viruses do something.
| mumblemumble wrote:
| If I were a black hat, I think that the best gift I could
| hope for would be a 3rd-party program, likely developed on
| the cheap, whose entire purpose for existing is to sit in
| kernel space and promiscuously open Every. Single. File. in
| order to process its contents.
|
| (Granted, I'm a complete layperson in computer security, so
| there's likely something I'm missing.)
| b0afc375b5 wrote:
| I have not thought about 3rd party antivirus software in a long
| time. Granted my only use case for windows 10 is gaming, and
| any binary (or any file really) that I download goes straight
| to virustotal before I open it.
| KronisLV wrote:
| It surprises me how much many posters on Hacker News seem to be
| against using any sort of AV software - not even the built in
| Defender solution in Windows, if you have to use the OS for
| whatever reason, but i often see the sentiment expressed that
| supposedly the entire class of software is useless.
|
| What happened to defense in depth with all of the layers you
| can introduce?
|
| Surely if you run a Linux server, you might want a secure
| password for it, or better yet, key based authentication. Port
| knocking? Why not, throw it in there as another layer. Maybe
| deny authentication on an IP range basis? Why not. What about
| fail2ban or some other solution like that to disallow brute
| forcing? Sure. Or maybe require using a VPN to connect to it at
| all? Even better! Actually, even running your SSH server on a
| non-standard port will be enough to get rid of _some_ attempts
| to brute force the password.
|
| Sure, key based auth makes many of those moot points so i
| probably have the order of some of those steps wrong, but
| surely there's a lot of merit in combining whatever solutions
| you can to make the end result more secure, right? Hell, if
| you're running a web service of some sort or an application for
| yourself, adding basicauth in front of it at a web server level
| is enough to act as a safety net should the auth functionality
| of the actual application be broken, until you patch it.
|
| So why should Windows be any different? If i'm stuck using that
| OS, i'd surely want to use whatever software is available to me
| to make the uphill battle towards something vaguely secure more
| doable, no?
| x0x0 wrote:
| Part of this surely is that most apps are now delivered in
| the browser, so increasingly windows is a terminal to run
| chrome or edge.
| larrik wrote:
| > What happened to defense in depth with all of the layers
| you can introduce?
|
| What happened was antivirus itself became your biggest attack
| vector, so you were more secure without it. Plus Microsoft
| actually cares about security now, which wasn't the case 10+
| years ago.
| Melatonic wrote:
| For Windows one of the best things you can do, AV or not, is
| to NOT make your daily driver account an administrator.
| Create an admin account with a secure password and then
| another standard user account for yourself and use that
| standard user for everything. When installing something you
| will need to put in your admin password but it is really not
| a big deal to do so. Massively reduces your chance of
| ransomware and all kinds of crapware.
|
| Enabling protected folder access and process isolation in
| Windows 10 is also a good idea.
| JamesBarney wrote:
| tptacek could probably weigh in with a much better
| explanation.
|
| The tradeoff for having AV is having a giant application in
| admin land which increases the surface area available for an
| attack. Combine this with the that fact you don't get much
| protection because a virus can just be modified until the AV
| doesn't detect it and AV's just aren't worth it. This trade
| off made sense 20 years ago because OS's were less secure so
| you were increasing your surface area by relatively less than
| you are now.
| guelo wrote:
| what happened was the security industry proved over and over
| again that it cant be trusted. most windows recommendations i
| see say to use defender since Microsoft already owns you
| dblohm7 wrote:
| I used to work on the team at Mozilla that got stuck with
| dealing with all the terrible shit that AV programs do to web
| browsers. My recommendation for Windows users is to just use
| Defender.
|
| All that other crap does the exact same stuff to other programs
| that malware does, except they do so in the name of "security."
| Damogran6 wrote:
| Our bog-standard business ultrabooks have been requested to
| perform a full disk scan each Friday. Which means their CPUs
| and Fans are running solid, most all Fridays.
|
| I'm CERTAIN there are massive hidden costs in fan replacement
| and Laptop repairs and nothing useful discovered as a result.
| _joel wrote:
| I wonder how much unnecessary AV scans across the world
| contribute to carbon emissions? I bet it's not insignificant,
| full CPU and disk access!
| henryw wrote:
| I'm wondering this too since Windows has built-in antivirus
| now. https://www.microsoft.com/en-us/windows/comprehensive-
| securi...
| teh_klev wrote:
| Windows has had "Microsoft Security Essentials" built-in for
| longer than I can remember (10+ years?). It's not a terrible
| thing and keeps out of your way and doesn't seem to bog your
| machine down. Unlike the steaming pile of crap that my work
| computer runs (EndPoint) that consumes 60-80% CPU when doing
| its weekly full scan for over an hour right in the middle of
| the working day.
|
| MSE is really all I've used since binning AVG which turned
| into bloatware.
| stjohnswarts wrote:
| Took me a while to figure out why my browsers always seem
| to randomly pause for about 30 seconds. It's that piece of
| crap McCaffee. I can watch it's process go to 100% when the
| browser (firefox and vivaldi) freeze. It's garbage and I
| wish I could turn it off and just use MS AV but the IT
| staff swear by McAffee so I live with it.
| binarymax wrote:
| It's a good question for the Windows ecosystem, because it was
| absolutely necessary for Windows 7 and earlier, but I haven't
| used later versions.
|
| I've been using Linux/Mac exclusively for the past 10 years and
| never even considered it.
| gtirloni wrote:
| You actively disable Windows Defender?
| binarymax wrote:
| No. What in my message made you think that?
| pjmlp wrote:
| Then you are lucky not to work in companies where IT security
| policies apply to everyone regardless of the OS being used.
| nix23 wrote:
| >IT security policies apply
|
| Insecurity policies is correct, what you mean is protecting
| managers a* aka the antivirus failed on us ;)
| bastardoperator wrote:
| I don't think you're wrong at all. Considering symantec is
| mining with your computer on top of all the other terrible
| things anti-virus companies do to your computer, at this point
| a virus might be less intrusive.
| orangepurple wrote:
| The only software most Windows PCs need out of the box is
| TinyWall (https://tinywall.pados.hu/)
| layer8 wrote:
| The playful snow on the home page doesn't inspire confidence.
| orangepurple wrote:
| It is an excellent piece of software.
|
| Other projects by the same developer:
|
| https://www.patreon.com/posts/other-projects-36886285
| stjohnswarts wrote:
| Why is this better than the built in windows firewall?
| orangepurple wrote:
| Much, much easier to configure and manage and denies almost
| everything by default. Extremely easy to quickly unblock
| software as necessary too. 10-100x faster workflow compared
| to the built in firewall, so you will actually bother to use
| it instead of get complacent or ignore it.
| holoduke wrote:
| In a way I get it. I also agree with it. Europe should also try
| to reduce dependancy on American tech products for the scenario
| when the US becomes hostile towards Europe. A bit unlikely now,
| but you never know.
| hall0ween wrote:
| Agreed that Europe should reduce dependency on US tech product.
| Among the reasons is how the US govt has been caught spying on
| allies multiple times. Which is sad but a clear sense of ethics
| missing in the US govt (along with a long list of others).
|
| > A bit unlikely now, but you never know. On the timeline we
| exist, it's a possibility!
| qiskit wrote:
| Not just europe. Europe makes the most sense because europe is
| the wealthiest region on earth and has the ability to fund its
| own tech industry. Europe did it for aerospace ( Airbus ), but
| why they aren't doing it for something far more important than
| planes is beyond me. But China, India, Japan, etc should all be
| developing their own tech spheres. I can't believe that any
| major country allows Windows, Facebook, Google, Apple, etc in
| their nation. At the very least ban it until they develop their
| own local competitors first. Not only would this be good for
| China, India, Japan, EU, etc, it would also be good for tech
| and the rest of the world since they will have more options.
| It's amazing how useless so much of the world's leadership are.
| juanani wrote:
| cm2187 wrote:
| Doesn't any foreign company contributing a device driver to
| Microsoft present the same risk profile (could be based in
| Russia, or infiltrated by russian agents, or hacked by russia)?
| yololol wrote:
| I'm surprised that everyone here thinks that Kaspersky makes only
| antivirus products. They have a ton of security products,
| including their own microkernel-based OS:
| https://os.kaspersky.com/technologies/microkernel/
| ASalazarMX wrote:
| I guess NginX is hoping no one looks their way.
| tenebrisalietum wrote:
| F5 owns Nginx now.
| Maursault wrote:
| Ok, let's cut the crap. Is Kaspersky a dirtbag or not? I suspect
| not, but it is an unfortunate accident he was born in and runs
| his company from Russia, the government of which is a dirtbag,
| so, correct me if I am wrong, Kaspersky must be a dirtbag by
| association, but especially for discovering Stuxnet. Believable,
| but I think the real reasons Kaspersky is persona non grata is
| due to having discovered Stuxnet, and Kaspersky Lab suspected of
| uncovering secret US cyberweapons in the future.
|
| I am a patriot, but even I don't appreciate being lied to by my
| government. It would be good if the next best cyber security firm
| and software was half as good as Kaspersky's. But I suspect not.
| IngvarLynn wrote:
| Kaspersky consciously, under no pressure chose to be chekist.
| That is absolutely all You need to know about this person and
| his deeds, consequentially. The numerous ruminations on
| "coercion" are just deeply naive. He is a member of kremlin
| gang. Anything else falls into bottomless category of
| whitewashing.
| older wrote:
| Kaspersky graduated from The Technical Faculty of the KGB
| Higher School in 1987. That was a definition of a dirtbag in
| Soviet time.
| libraryatnight wrote:
| I can't find the actual profile on Wired anymore, but I found
| it on the internet archive: https://web.archive.org/web/20140
| 423055434/http://www.wired.... and also a sort of response to
| it https://web.archive.org/web/20140426095603/http://www.wire
| d....
|
| After I read that profile I decided I'd never use the
| software. I remember before news spread of the Russian troll
| farms being real, people talked about it like "who would do
| that?" Russia would.
|
| I don't think it's their quote - but I remember Penn of Penn
| & Teller saying about magic something to the effect that the
| magician does the things that people think "It could be...
| but who would do all of that work?" This is how I feel about
| Russia. They will or already are doing the things you think
| they won't and nothing is beyond being a tool for the state.
|
| I don't really like feeding the image of the Russian super
| villain, but I don't consider it overly paranoid to avoid
| installing software from hostile nations. Yes I used this
| same logic to convince my wife to uninstall tiktok.
| marvin wrote:
| Comparison notwithstanding, that's what I felt when I first
| heard about PRISM. Holy shit, I knew this was all possible,
| but I hadn't believed that someone actually went through
| all the effort of doing it.
| jwatt wrote:
| The original Wired links are:
|
| https://www.wired.com/2012/07/ff-kaspersky/
|
| https://www.wired.com/2012/07/kaspersky-indy/
| purplediamond wrote:
| Is hackernews cutting off links now. Neither of your links
| work. End of line contains "/http://wired/"
|
| Congratulations to both of you for uninstalling TikTok :)
| Facebook is next.
| mkbkn wrote:
| What he could have done then at that time? To not study? To
| remain illiterate?
| jonathanstrange wrote:
| I know brilliant people from the GDR who studied at Moscow
| Polytechnic University, they weren't in the KGB or Stasi.
| You had to be system-conform to study anything, that much
| is true, but that's still far away from joining the KGB.
| older wrote:
| You really think the choice was to go to KGB school or
| remain illiterate? There were a lot of other options to
| study. Much better options if your want to do science. For
| one thing, education in Soviet Union was decent and free
| for everyone. Going to KGB school was a choice, very
| specific one.
| aaomidi wrote:
| I know right? Like what the hell kind of criticism is that
| lol.
| mopsi wrote:
| The kind that understands historic nuance.
| naniwaduni wrote:
| That understands nuance, but not history.
| mmastrac wrote:
| His only statement so far on the far (keeping in mind this is
| rather than saying nothing) called it a "situation" in Ukraine.
| That's not much to read into, but he also could have chosen to
| say absolutely nothing.
|
| "We welcome the start of negotiations to resolve the current
| situation in Ukraine and hope that they will lead to a
| cessation of hostilities and a compromise. We believe that
| peaceful dialogue is the only possible instrument for resolving
| conflicts. War isn't good for anyone."
| RadixDLT wrote:
| funny you say that, because bitDefender always outshines
| Kaspersky in all the AV tests and was always ranked #1
|
| also dont forget that the Global Research & Analysis Team @
| Kaspersky is not Russian
| sharken wrote:
| Here is my humble opinion.
|
| Kaspersky is by definition a Russian company that provides
| antivirus software to many influential western companies and
| institutions.
|
| The risk of Kaspersky bowing to the pressure from Putin is just
| too great to ignore. For Kaspersky this can seem unfair, but
| that is one of the many consequences of Putins actions.
|
| Don't forget who started the invasion and who is still hurting
| innocent Ukrainians.
| ajross wrote:
| The sanctions in question are against Kaspersky Labs the
| company, not Eugene Kaspersky the man. Frankly none of the
| analysis involves a decision as to whether he is a "dirtbag",
| by association or not. It's just that there's no way anyone can
| reasonably trust "security" software produced by entities in a
| totalitarian state, especially so when it's at war.
| Maursault wrote:
| Thanks for the clarification.
|
| So it is not a situation were we have actual evidence of
| dirtbaggery against the company, but that we are _rationally_
| paranoid that Kaspersky Lab could somehow steal our Pokemons.
| dc-programmer wrote:
| The Stuxnet association seems completely basis, and you do not
| provide any evidence for the assertion. There were multiple
| firms and individuals responsible for the discovery, reverse
| engineering, and attribution of Stuxnet, so you are overplaying
| their involvement.
|
| This decision was certainly made by a bureaucrat who may not
| even know about Stuxnet. It's simple risk mitigation. Why even
| take the chance Kaspersky is a malicious entity? It's not
| important software.
|
| Some of the conspiracy theories people throw out around here...
| oh_sigh wrote:
| You think the US government waited 12 years to be able to turn
| the screws on Kaspersky because they uncovered Stuxnet?
| badrabbit wrote:
| Even american security companies have ties to the intelligence
| community. Kaspersky is no different. In most countries private
| sector pays more so state hackers work at places like
| Crowdstrike or Kaspersky after some time. Their relationship
| with the IC helps develop and share intelligence both ways.
| NelsonMinar wrote:
| There's an important difference: American security companies
| have ties to American intelligence. The concern here is
| Kaspersky has ties to Russian intelligence. If you're an
| American company or government agency and have to choose
| between the two the choice is pretty clear.
|
| I have a lot of respect for Kaspersky and hope they are still
| independent. But "ties to intelligence" can come in many
| forms: deliberate, coerced, or via infiltration. We've seen
| similar issues here in the US. Sometimes companies work
| voluntarily with the FBI and NSA, sometimes they are
| infiltrated or tricked by them.
| sovietmoonbase wrote:
| > If you're an American company or government agency and
| have to choose between the two the choice is pretty clear.
|
| I suppose that entirely depends on one's threat-model. As
| an American, I have greater concerns of USG oppression than
| I do Russian. As the Russians have their ham-fisted means
| of exterting influence on a company, the US has their very
| own nasty ways of infiltration.
|
| If you're interested in personal freedoms free of malicious
| government intrusion, they both suck.
| NelsonMinar wrote:
| BTCOG wrote:
| It's not just security companies. US ISPs are heavily tied to
| agencies and so are the large corps. The media is state ran
| just like Russia.
| older wrote:
| You can't be more wrong when you say "just like Russia". It
| is not even close. The killings of journalists,
| repressions... The last independent newspaper has to close
| its activity because it is not possible anymore to report
| truth while complying to the Russian laws:
| https://www.aljazeera.com/news/2022/3/28/russias-novaya-
| gaze...
|
| All this with Russian government/president approval rating
| of 70%.
| jacobr1 wrote:
| Without independent media, how can we trust the approval
| rating is accurate?
| older wrote:
| Levada-Center is the best bet we have:
| https://www.levada.ru/en/ratings/ But when even Russians
| who live in Germany are rallying in support of the
| Russia's war it is reasonable to assume that those
| ratings are accurate.
| csydas wrote:
| No, it really doesn't follow. The subset of russians
| living in germany who approve of the war has no bearing
| or relationship to all russians.
|
| The "living in germany" part doesn't contradict the same
| concerns that those living in russia have, as like those
| living in russia, the emigrated russians likely have:
|
| - family still in russia - ties to russia (financial,
| business, family, etc) - desire to visit russia without
| having to deal with legal harassment for actions done
| abroad - desire to be able to assist people
| (family/friends) living in russia without compromising
| them
|
| This does not mean that they are for or against a current
| government, but rather, that the proposed logic is
| specious as it tries to create a separation where it is
| not probable there is one while simultaneously
| extrapolating the results of a small sample size across a
| population that supposedly is without the influence of
| Russia.
| older wrote:
| Well, maybe you're right but I'm not so sure. After
| watching recent interviews with random people on the
| streets of Russian cities. Here's interesting thread on
| twitter by someone sharing his experience calling random
| Russians and trying to talk: https://twitter.com/GentileO
| slo/status/1506663082634145797
| SeanLuke wrote:
| > The media is state ran just like Russia.
|
| The whataboutism is out in full force here.
| davrosthedalek wrote:
| Indeed, and it's really absurd. Just compare Fox News and
| MSNBC. They might be both state run, but certainly not
| the same state.
| flavius29663 wrote:
| The media is heavily biased in the US, but nowhere near
| Russia style.
|
| You can still find the opposing views, quite easily.
| tjoff wrote:
| I thought the question was much older than stuxnet?
| JabavuAdams wrote:
| The problem is: how do you run a business that has offices and
| physical assets in Russia, without being at least partially
| beholden to the Russian government? They have demonstrated that
| they are not shy about using gangster tactics.
|
| One could say that the same is true in the US, but I believe
| the degree matters. Although the US government and intelligence
| agencies will and do try to overreach, there is a strong legal
| and cultural tradition of exposing, resisting, and fighting
| these overreaches in the US. I don't see that in Russia.
|
| So, I would not be surprised to see the US strong-arming US
| companies, but they would do this with sham/flimsy legal cover.
| The result of non-compliance would be at worst asset seizure
| and/or imprisonment. Both of these can be examined and
| contested. I imagine that the penalty for non-compliance in the
| Russian system would max out at having an unfortunate accident.
| Gangsters all, but the level of gangsterism and possibilities
| for investigation/redress matter.
|
| All that said, I'm not a US citizen (although in a Five-Eyes
| country), so I do worry about using US-hosted services.
| mjevans wrote:
| I live in the USA, therefore I need to consider it as part of
| my threat model mostly in the blunders / withholding exploits
| (thanks CIA ~.~) senses. For everything else I try to vote
| informed and support a combination of the EFF, ACLU, and
| other organizations that can be better informed experts on
| the law and it's applications.
| PoignardAzur wrote:
| _> One could say that the same is true in the US, but I
| believe the degree matters. Although the US government and
| intelligence agencies will and do try to overreach, there is
| a strong legal and cultural tradition of exposing, resisting,
| and fighting these overreaches in the US._
|
| That point would be a lot stronger if the US government
| hadn't demonstrated shocking callousness and disregard for
| international law in their efforts to catch notorious
| whistleblowers Snowden and Assange.
|
| I remember when Belarus downed a plane to catch a political
| dissident and all western countries acted shocked, even
| though these countries had tried to do _the exact same thing_
| to Snowden on the US 's behalf, with a presidential plane no
| less.
| ummwhat wrote:
| Hold up. Downed a plane is different from grounded a plane.
| I don't know the Belarusian case, but either you misused
| the word or they are _very_ different.
| jjeaff wrote:
| International law isn't really a thing if it has no teeth.
| I would be more worried about the US breaking its own laws.
| Which they of course do, on occasion. But there is a lot of
| pushback and not too much fear of reprisal if you call them
| out and fight them on it. For example, we are in the
| process of appointing a supreme court justice that, during
| her career, has fought against US Government overeach and
| represented alleged terrorists imprisoned (oh sorry,
| "detained"), in Guantanamo.
| [deleted]
| skeptikal wrote:
| layer8 wrote:
| Russia is free to ban Microsoft Defender et al.
| tablespoon wrote:
| > The problem is: how do you run a business that has
| offices and physical assets in <insert power country>,
| without being at least partially beholden to the <insert
| powerful country> government?
|
| The problem with this kind of Mad Libs argument is that it
| falsely implies the substitutions are equivalent when
| they're not. Also your quote shears away the context of the
| original statement that made it meaningful.
| alimov wrote:
| Please explain how they are not equivalent. Just because
| two governments are on good terms or are in some kind of
| partnership does not guarantee that one or the other will
| not take actions that benefit only them. What am I
| missing here?
| JumpCrisscross wrote:
| > _explain how they are not equivalent_
|
| Press. Political competition. Courts. Broadly, the rule
| of law.
|
| Nobody is perfect at any of these. But if the FSB wants a
| code change in Kaspersky, they're getting that code
| change. There is no independent press to report it. No
| opposition incentivized to call them out on it. No court
| in which they could lose.
| tablespoon wrote:
| >> explain how they are not equivalent
|
| > Press. Political competition. Courts. Broadly, the rule
| of law.
|
| Exactly. Mad-libs "arguments" typically boil down to an
| invitation to ignore salient differences (which the
| structure _cannot_ call attention to), make a superficial
| comparison, and finally arrive at a false equivalency.
| syshum wrote:
| hmm FISA, Gag orders, National Secrecy laws, etc all
| exist in US law, so tell me again how they are different?
|
| Also, as an American Citizen, who has more power to put
| me the individual in a cage, the FSB or NSA?
| sokoloff wrote:
| Who has more practical power to force code into a
| security product that runs in a privileged context,
| without anyone finding out? I think it's not the NSA.
| syshum wrote:
| Why do you believe that, the NSA had access to Cisco PIX
| systems for years and it was only disclosed once those
| systems started to be replaced with ASA and other newer
| hardware.
|
| I dont believe the NSA, CIA or even the FBI really have
| any actual legal limits.
| kelnos wrote:
| I think it's reasonable to acknowledge that, due to my
| citizenship and physical residence location, the NSA is
| probably more of a threat to my personal freedom than the
| FSB, but also acknowledge that, all things being equal,
| the FSB is a shadier organization than the NSA, with
| fewer legal restrictions on its behavior.
| sudosysgen wrote:
| There are no relevant legal restrictions on the NSA
| behaviour. We _know_ that the NSA breaks the law without
| any consequences. This idea that Western intelligence is
| any less corrupt and morally bankrupt, and indeed any
| less willing to interfere with people outside their
| borders as anyone else is frankly entirely ridiculous.
| alimov wrote:
| While the methods may differ, is this not true of any
| governments intelligence agencies? Whether or not there
| is press/courts/rule of law. For press to report on an
| event they have to be aware of it, for courts to
| intervene they also have to be aware of it, for rule of
| law to matter then no part of a government can operate
| outside of it in any manner, so no extrajudicial actions
| either.
| [deleted]
| JabavuAdams wrote:
| The point of press/courts/rule of law is that at least
| you have a chance. Without those, no chance. That
| matters.
|
| The US is not some monolithic entity. It's almost weirdly
| schizophrenic. Yes, the government will e.g. use some
| super-shaky legal arguments to justify torture _ahem_
| "enhanced interrogation", but on the other hand Freedom
| of Information Act requests still get processed. Yes, the
| NSA will spy on US citizens, but even they feel the need
| to come up with some legalistic / procedural cover.
|
| Even as the US's checks and balances are tested, and
| structural inequalities are examined, there is a broad
| and deep tradition of fighting the government and not
| going to jail like Navalny.
|
| The traditions and norms of a country's populace, and its
| institutions really really matter, especially when their
| institutions are being tested.
|
| Corruption is everywhere, but this is too simplistic a
| pattern-match.
|
| EDIT> Knight-Ridder did some fantastic and courageous
| investigative journalism debunking the US casus belli in
| the run-up to the Iraq Invasion. It didn't stop the
| invasion, but they were recognized later. Can we imagine
| that happening in Russia?
| kelnos wrote:
| > _Knight-Ridder did some fantastic and courageous
| investigative journalism debunking the US casus belli in
| the run-up to the Iraq Invasion. It didn 't stop the
| invasion, but they were recognized later. Can we imagine
| that happening in Russia?_
|
| This type of thing is something I wish people would
| recognize more. In Russia right now, the simple act of
| participating in a peaceful protest against the war in
| Ukraine could easily land you in jail. While the US
| government has at times had a sketchy anti-protest track
| record, can we really imagine the US federal government
| attempting to pass a law today that makes it a jail-able
| offense to speak out against a US military action? (Hint:
| the answer is, unequivocally, no.)
| tablespoon wrote:
| > This type of thing is something I wish people would
| recognize more. In Russia right now, the simple act of
| participating in a peaceful protest against the war in
| Ukraine could easily land you in jail.
|
| It's even worse than that: merely calling a war a war can
| land you in jail:
|
| https://www.ctvnews.ca/world/crisis-in-ukraine-to-russia-
| it-...:
|
| > Russia insists that it is not at "war" in Ukraine,
| instead referring to its violent campaign as a "special
| military operation." Under a harsh new law, Russians now
| face up to 15 years in prison if they spread "fake"
| reports and call the conflict what it is: a "war" and
| "invasion."
| dikaio wrote:
| "there is a broad and deep tradition of fighting the
| government and not going to jail like Navalny."
|
| Guess the 98% Federal conviction rate isn't accounted for
| when talking about the deep tradition of citizens
| fighting the government.
|
| Personal opinion, all governments are corrupt, including
| the US
| alimov wrote:
| > The point of press/courts/rule of law is that at least
| you have a chance. Without those, no chance. That
| matters.
|
| I agree with you.
|
| > Knight-Ridder did some fantastic and courageous
| investigative journalism debunking the US casus belli in
| the run-up to the Iraq Invasion. It didn't stop the
| invasion, but they were recognized later. Can we imagine
| that happening in Russia?
|
| Thanks I'll check it out
| makomk wrote:
| There definitely seems to be at least a little truth to
| that argument, though. Over the years Kaspersky has found
| and documented a whole bunch of seemingly US government
| linked malware whilst their Western competitors just
| haven't, and I think there's at least some evidence this
| is intentional on the part of those other companies.
| [deleted]
| saiya-jin wrote:
| It may be, or his company is really that good above
| others (I don't think he personally was involved in any
| of this, but hired good enough people to do so). I tend
| towards former but have no proof either way.
|
| I still have a serious and (since Russia-started a war in
| Ukraine) permanent problem with him - as pointed
| elsewhere [1] he went through KGB school - voluntarily,
| he was actually active KGB intelligence just like Putin.
| At those places, your objective morals go down the drain
| very fast and for good. And obviously both are still very
| close, he approves overall totalitarian direction of
| Russia and often spoke against 'too much freedom' in the
| west and on internet.
|
| [1] https://web.archive.org/web/20140423055434/http://www
| .wired....
| kelnos wrote:
| > _There definitely seems to be at least a little truth
| to that argument, though._
|
| Of course there is, but as this thread is trying to point
| out, that "little truth" is completely insufficient when
| assessing risk. The degree to which a particular
| government can interfere with companies headquartered
| there matters. The legal culture in those countries
| matter. The ability to contest and redress this
| interference matters. An estimate of the worst that can
| happen to an individual who resists this interference
| matters.
|
| I'm a US citizen living in the US, so I'm certainly
| biased, but I do believe my data (and my person, and if I
| ran a company, my company too) is much safer being in the
| US than in Russia.
|
| It's certain that all major world powers engage in
| various forms of cyber warfare. It's completely expected
| that countries (and companies within them) that are
| allied will (most of the time) not expose other allies
| for cyber attacks and malware distribution. It's also
| completely expected that antagonistic countries (and
| their companies) _will_ do so.
|
| Back to the point of this article: of _course_ Kaspersky
| is a US national security threat, _precisely_ because it
| (as a Russian entity) will try to expose the US
| government 's cyber warfare capabilities. Whether or not
| Kaspersky is a threat to the cybersecurity of individuals
| in the West isn't the issue here. (I would expect they
| probably are, to some extent, though!)
| sudosysgen wrote:
| We already do know, however, that the US has no shame
| "asking" US run companies for their customer's data
| without due process, and that this has been going on for
| every large US tech company. So I don't see the logic.
|
| You talk about assessing risk, but we know from the
| Snowden leaks that the risk in this matter in the US
| approaches 100% as the size of your company increase.
| What degree of risk is higher than 100%?
| edgyquant wrote:
| Which is the entire point of their argument? The Russian
| government is objectively worse by any honest metric.
| klibertp wrote:
| > The Russian government is objectively worse by any
| honest metric.
|
| Any metric you and I would like to use, yes. The govt of
| Saudi Arabia, which is an ally of ours, murders
| journalists with a chainsaw on a foreign soil and
| smuggles the body out of the host country in suitcases -
| yet no Saudi company is penalized. Supporting a proxy war
| in Yemen is not that different from Russian invasion, but
| somehow it suffers no consequences for doing so.
|
| It's actually easy to justify: for the vast majority of
| Saudis prince MBS is a good ruler. Who are we to judge
| how their government works, given completely different
| cultural backgrounds, religions, and different
| expectations resulting from that difference? We'd be
| happier if Saudi Arabia was a democracy with a rule of
| law instead of chainsaw, but if the majority of Saudis
| prefer the latter, we shouldn't try to force them to
| change, even if homosexuals can be legally stoned to
| death there.
|
| It's an easy argument, but it undermines the
| "objectively" part of your statement. If we accept MBS,
| we should accept Putin. If we don't accept the way SA
| works, as we don't accept Russia's, then we should not
| trade with the Saudis. We do trade with them, though - we
| (Poland) even increased (2x or more) the amount of oil
| imported from them this year, and they continue being our
| friends and valuable allies in the region.
|
| The situation is frankly schizophrenic. Either there are
| objective metrics, in which case they should be applied
| everywhere equally, or we allow Saudis do what they want,
| but then we have no grounds on which to condemn Putin.
|
| If we want to still stay close to Saudi Arabia _and_
| condemn Putin, we have to agree that we condemn Putin
| based on something else than objective standards of
| governing.
|
| I'd really like for our foreign policies to stay true to
| the ideals we hold dear, but that just doesn't seem to be
| the case. Putin is an actual, real threat, so we don't
| accept him and his buddies, while MBS only dismembers his
| own citizens (and he even allowed women to drive!), so we
| accept him. That's also a kind of "objective metric", but
| it's far from what you meant, and it makes me deeply
| uncomfortable TBH.
| naoqj wrote:
| Than what government? Definitely not the American.
| kelnos wrote:
| I'm honestly trying to figure out here if you are
| trolling, or if you genuinely believe that.
|
| If you do genuinely believe that the US government is
| worse (or at least just as bad) as the Russian government
| when it comes to citizens' personal liberties, I'd be
| very curious to understand why you believe that to be the
| case.
|
| Certainly I (as a US citizen living in the US) am biased,
| but I do believe I have a healthy level of criticism and
| skepticism of my own government, and yet I cannot see how
| we even come close to how bad the Russian government is.
| xur17 wrote:
| Did you read the GGP?
|
| > One could say that the same is true in the US, but I
| believe the degree matters. Although the US government
| and intelligence agencies will and do try to overreach,
| there is a strong legal and cultural tradition of
| exposing, resisting, and fighting these overreaches in
| the US. I don't see that in Russia.
|
| > So, I would not be surprised to see the US strong-
| arming US companies, but they would do this with
| sham/flimsy legal cover. The result of non-compliance
| would be at worst asset seizure and/or imprisonment. Both
| of these can be examined and contested. I imagine that
| the penalty for non-compliance in the Russian system
| would max out at having an unfortunate accident.
| Gangsters all, but the level of gangsterism and
| possibilities for investigation/redress matter.
| saiya-jin wrote:
| I, as non-US citizen, thus having sub-human rights in
| eyes of every US 3-letter agency, still prefer very much
| US approach to, well, practically any matter compared to
| Russian one.
|
| For Russians, they really don't like anybody else. All
| that slavic closeness is crap as we can see in Ukraine
| and elsewhere. Heck, they don't care about other Russians
| neither, just a cannon fodder and poor fuckers to exploit
| and then throw away like garbage. They may very well like
| to see the entire world burn in nuclear hell if they
| don't get what they want, that's why current situation is
| really one of those moments in history when future is
| decided.
|
| It would sure as hell help US image in entire world to
| actually backtrack a bit all those spying initiatives
| towards friendly, democratic and in all-important-US-
| aligned countries. Showing some respect with deeds and
| not just empty words and so on. I don't know how much
| that was/is visible from inside, but Trump made huge
| amount of damage to that, although to be fair he was just
| a continuation of overall trend.
| laurent92 wrote:
| It would help US to condemn Colin Powell for brandishing
| supposed proof of WMD at the UN Counsel in 2003, which
| they never found after invasion.
|
| It would help for the US to stop Predator attacks. Most
| of the world is convinced that they are illegal and
| illegitimate.
|
| And as a French person, I preferred Trump, because he
| didn't trigger any new war and he calmed down Little
| Rocket Man. He even shook his hand! And donated 100% of
| his salary to charities! Biden is back and the war is
| back: Bad negociation tactics, Hunter Biden shenanigans
| with billions transferred as a chairman of an oil company
| in Ukraine, female ministers of defense in all of Europe,
| focus on having transgender soldiers, so Putin believed
| we were weak and the field was open. The result is a war.
|
| We could have avoided this war.
|
| PS: I'm not saying female ministers of war are
| incompetent, I'm saying they make no-one afraid. It was
| way more frightening when Krouchtchev's general
| responsible for the nuclear button was a crazy alcoholic:
| When you're faced with an madlad, you take him seriously.
| kelnos wrote:
| Ah yes, casual misogyny masquerading as sound military
| strategy.
| TheGigaChad wrote:
| bboozzoo wrote:
| That's funny as the thread is about contrasting Russia
| with US, but I don't seen to recall US invading any
| neighboring countries under the false pretense of
| defending some minorities.
| laurent92 wrote:
| I remember a woman testifying that they were killing
| babies in Kuwait, and she was later discovered as being
| the daughter of an ambassador. Source:
| https://en.wikipedia.org/wiki/Nayirah_testimony
|
| I remember the late Colin Powell brandishing proof of WMD
| in Iraq at the UN Counsel. He will never land in the TPI,
| neither will the UN Counsel for basing a judgment upon
| unverified allegation causing dozens of thousands of
| illegal killings by the US army.
| robin_reala wrote:
| May I turn your attention to the Bay of Pigs invasion?
| kelnos wrote:
| Right, I mean, at least when the US invades a neighboring
| country, we don't try that hard to create false pretenses
| for it (https://en.wikipedia.org/wiki/Mexican%E2%80%93Ame
| rican_War).
|
| But, seriously, if you remove "neighboring" from your
| statement (which seems to be not particularly relevant to
| a discussion of morality and respecting the sovereignty
| of other nations), I'm sure we can find plenty of bad
| examples perpetrated by the US, many of them much more
| recent than the Mexican-American War.
| davrosthedalek wrote:
| Is there an equivalent of the EFF or ACLU in Russia?
| tablespoon wrote:
| > Is there an equivalent of the EFF or ACLU in Russia?
|
| If there was, it's been shut down (e.g. https://en.wikipe
| dia.org/wiki/Memorial_(society)#Intimidatio...).
| unethical_ban wrote:
| Regarding freedom of speech, _relative_ freedom of
| association and the ability to do business and to
| criticize governments, the US is miles ahead of Russia.
| jeffwask wrote:
| > The problem is: how do you run a business that has offices
| and physical assets > in Russia, without being at least
| partially beholden to the Russian government? > They have
| demonstrated that they are not shy about using gangster
| tactics.
|
| To be fair, the US government has used gangster tactics to
| get US companies to install backdoors and allow encryption
| breakers.
| andrewflnr wrote:
| The very next sentence in GP directly addresses your
| comment.
| iudqnolq wrote:
| > One could say that the same is true in the US, but I
| believe the degree matters.
|
| I think the key misconception behind this argument is the
| idea that harmful governments is a binary flag, such that if
| you're subjected to one adding more makes no difference. In
| fact, different governments have different concerns. This
| means if you're subject to the US and Russia you're
| significantly more constrained than if you were just subject
| to one. As such, it makes sense to reduce exposure even if
| you obviously can't eliminate it.
|
| (I also believe the US govt is much better than Russian, but
| I'm leaving that out because I my argument doesn't need it
| and I'm uninterested in that argument)
| seventytwo wrote:
| Your entire post is pure speculation.
| tomc1985 wrote:
| When was Kasepersky ever considered a dirtbag? That company has
| written a lot of technically in-depth security reports over
| various threats for a long time.
|
| AFAIK it's a (relatively) honest business, though sadly the
| target of American russophobia
| eunos wrote:
| I think there was an incident in which some NSA contractor
| had Kaspersky installed in their workstation and the
| heuristic caught up NSA tools https://www.theguardian.com/tec
| hnology/2017/oct/26/kaspersky...
| toyg wrote:
| They did the right thing - finding suspiciously malicious
| code is their job. Not their fault the user was an idiot,
| spooks PEBKAC is still PEBKAC.
| flutas wrote:
| > They did the right thing - finding suspiciously
| malicious code is their job. Not their fault the user was
| an idiot, spooks PEBKAC is still PEBKAC.
|
| Except for this part, which leaves a huge question of "do
| they share knowledge with the russian govt."
|
| > But the bigger unknown is whether and how Kaspersky's
| acknowledged discovery and acquisition of NSA hacking
| tools resulted in Russian intelligence agencies
| discovering the NSA contractor, and targeting him for
| further, apparently successful, attacks.
| dralley wrote:
| Sure, but the allegation was that soon after Kasperky
| detected the NSA tools on his system he was hit with a
| very targeted cyberattack. IIRC that's where the
| allegations of Kasperky's involvement with the Russian
| government came in.
|
| And anecdotally there were a lot of MSPs in /r/sysadmin
| claiming that every single one of their Kasperky
| customers would be hit by ransomware while few if any of
| their other customers were.
| guelo wrote:
| Was it America-phobia that made russia direct endless waves
| of cyber-attacks at us?
| kmeisthax wrote:
| The concern isn't Kaspersky being a dirtbag, it's Putin
| legally mandating they _become_ a dirtbag. That 's how nation
| states and wars work.
|
| In fact, there's a similar concern that the EU has with the
| US. The US's CLOUD Act forces American tech companies to
| comply with US legal subpoenas in foreign jurisdictions,
| which means that said tech companies cannot also comply with
| GDPR data export rules. Hence, it's illegal to include US
| services on EU websites[0] until and unless the US either
| agrees to pass GDPR into US law (so that exported EU data is
| still protected) or repeals the CLOUD Act (so that localized
| EU data is legally untouchable by the FBI or CIA).
|
| The idea that we can treat a company as wholly separate from
| it's host nation is more of a legal fiction than anything
| else. It's not, in and of itself, russophobia. If the person
| running Kaspersky was trying to, say, flee Russia; and people
| said he couldnt't be trusted, then that would be russophobia.
|
| [0] Note: It is still legal for EU citizens to use those US
| services directly. This _only_ covers data export by EU
| companies to third-parties.
| tomc1985 wrote:
| Sorry, my reference to Russophobia was more at past light
| that has been shown on Kaspersky, before this year's
| invasion of Ukraine. I agree that it is entirely possible
| that Kaspersky could be weaponized now
| flavius29663 wrote:
| > American russophobia
|
| When you are entering a cold war with Russia, it's not
| Russophobia, it's common sense to not allow a potential state
| actor to have root access to millions of devices in your
| country.
|
| Also, Kaspersky was literally a former KGB
|
| > At the age of 16, Kaspersky entered a five-year program
| with The Technical Faculty of the KGB Higher School,[15]
| which prepared intelligence officers for the Russian military
| and KGB.[7][8] He graduated in 1987[15] with a degree in
| mathematical engineering and computer technology.[4][8] After
| graduating college, Kaspersky served the Soviet military
| intelligence service [6] as a software engineer.[2][10] He
| met his first wife Natalya Kaspersky at Severskoye, a KGB
| vacation resort, in 1987.[2]
|
| https://en.wikipedia.org/wiki/Eugene_Kaspersky#Early_life
| Maursault wrote:
| Unsure of reason for downvotes, but this was my observation
| as well, and my experience is that Kaspersky Labs scanning
| software successfully sanitizes its targets and does so
| without giving the uncanny feeling of wasting one's time.
|
| Putin and friends are moronic for bullying and harassing and
| mugging Ukraine. But if I were him, I would definitely
| declare apple pie a security threat in response.
| tomc1985 wrote:
| Yeah, it was my preferred AV for a while, til I switched to
| a local company
| DyslexicAtheist wrote:
| I don't think there is a conspiracy here about tit-for-tat
| stuxnet or even if he is a "dirtbag". All AV shift trust from
| the system to the AV. That is the root of the issue and it is
| an unsolved problem no matter where you try to secure something
| in the end there is always a compromise somewhere that boils
| down to _" but eventually you need to trust something"_.
|
| If that something is owned by your enemy in a hot war it's game
| over.
|
| The minute a vendor can be leaned on by a hostile government
| (even they are not in the country like the founder of Telegram)
| and the interest is strong enough to lean on them (hot war) the
| trust assumption becomes problematic. How problematic? I think
| it doesn't get more urgent then in a hot war.
|
| Kaspersky needs to pack up in all NATO countries. Not just
| because they pay taxes in RU (also this is a good enough reason
| for me). But also because if you share data with a non-NATO
| country it immediately becomes problematic too if your business
| partner is using their products.
|
| The options under which they should be allowed to continue to
| operate is purely academic because it involves not only
| shifting all operations out of RU but also getting rid of any
| executive who moves to the new location that can be leaned on
| back home (e.g. family and friends etc).
|
| There is no middle ground because the minute these steps are
| initiated Kaspersky has good reason to feel mistreated by the
| West. So even they kept their hands clean until now they might
| start doing what they've been accused of anyway.
|
| Also if Positive Tech and others have been sanctions already
| some months ago there is no reason to give this much bigger
| potential threat a pass.
| cptskippy wrote:
| > Ok, let's cut the crap.
|
| Clearly you were joking?
|
| The crap is your assertion that this has anything to something
| other than what's happening in Ukraine.
|
| Kaspersky is collateral damage and fallout from Russia s
| actions and nothing more.
|
| Please let's cut the crap.
| starwind wrote:
| Kaspersky himself had deep connections with the KGB
| viktorcode wrote:
| It doesn't matter. The fact is Kaspersky (the company) can be
| coerced by the Russian government to exploit their highly
| privileged systems access to millions of computers around the
| globe.
|
| I don't expect Kaspersky (the person) to play hero under these
| circumstances.
| ajsnigrutin wrote:
| So can microsoft, adobe, google, etc. Even without them, NSA
| can intercept the hardware and put their software on those
| boxes... wikileaks showed a bunch of stuff NSA did.
|
| If you're a valuable target, it's basically choosing if you
| want to be spied on by the russians or the americans. (or
| installing linux, and hoping for the best).
| at-fates-hands wrote:
| > Even without them, NSA can intercept the hardware and put
| their software on those boxes.
|
| Its interesting to note that not many people remember
| (maybe a generational thing?) Kevin Poulsen found multiple
| government listening devices installed on Pac Bell networks
| that were listening to foreign embassy phone traffic which
| was highly illegal at the time.
|
| It doesn't surprise me the extent the NSA and other three
| letter agencies have gone to get at information they deem
| valuable or important.
| kbenson wrote:
| > So can microsoft, adobe, google, etc. Even without them,
| NSA can intercept the hardware and put their software on
| those boxes...
|
| Those companies often actually have people scan the
| hardware they receive to check for alterations. There was a
| whole thing about this a decade ago where a reporter
| (wrongly, IIRC) accused Facebook and Google of having
| compromised motherboards, and people from those companies
| were commenting here about how they are actually very
| careful with their supply lines and have people vet what
| they receive with scanning electron microscopes in some
| instances. (I'll try to find some of the submissions here
| and edit them as links on the bottom shortly).
|
| I also have it on good authority (a good friend that worked
| at Google at the time) that Google found out that someone
| (the NSA) was tapping their inter-datacenter links and
| that's one of the reasons they made sure all data between
| datacenters was encrypted, and that was _prior_ to the
| Snowden leaks.
|
| So yes, agencies are constantly _attempting_ to infiltrate
| large tech companies for their own purposes. That doesn 't
| mean they always succeed, or that those companies just give
| up and accept that it happens. They all fight it quite
| actively.
| rnk wrote:
| That google thing is not really a secret. It was widely
| discussed inside google too. Maybe it came out of Edward
| Snowden.
| ajsnigrutin wrote:
| I was talking about google/apple being able to inject
| arbitrary code into (almost) any phone via (eg.) google
| play service update or whatever apple has. Also microsoft
| with windows update, and many other companies too.
| kelnos wrote:
| Do you have evidence that this happens due to outside or
| government interference in the company's release process?
| If not, this is just a conspiracy theory.
| airtonix wrote:
| They didn't claim that this happens because of government
| interference... -_-
|
| It's also not a theory.
| kbenson wrote:
| I was really referring to the part of your comment about
| the NSA's ability to intercept the hardware.
|
| It's true that any any software that allows auto-updating
| can be used to load arbitrary code onto a system, limited
| only by whatever additional safeguards are in place. In
| the case of the OS vendor, that can't really be guarded
| against, but it exists farther up the stack as well.
| Chrome and Firefox can just as easily load nefarious code
| onto your computer, limited only by what the OS prevents
| (which is generally more on a mobile platform,
| thankfully) and what their own reputation can sustain if
| they were found doing so.
| TaylorAlexander wrote:
| This is true, tho installing linux is probably not going to
| make a difference if you are a target. But the USA can
| issue national security letters through the FISA court with
| gag orders that keep the NSL secret. Not only that, but the
| major US companies have lucrative government contracts such
| that it can be in their interest to provide the US
| government with certain kinds of access without being
| compelled through national security letters.
| trasz wrote:
| Except that the statement being discussed isn't targeted at
| people who are a target for NSA, but rather those that
| might be a target for Russia.
| UnFleshedOne wrote:
| Don't expect him to be _able_ to play hero even if he wanted.
| chess_buster wrote:
| In my opinion, that's the right way to look at it.
| mrtnmcc wrote:
| Plenty of legit potential concerns.. Russian govt could
| "nationalize" Kaspersky at any moment and push rogue updates.
| cf141q5325 wrote:
| Shouldnt i have the same concerns with software from the US?
| You dont really have to nationalize to force devs to push
| malicious code (looking at you Australia)
| devwastaken wrote:
| Russia can do it without any backlash from their citizens.
| U.S. can't do it to their own citizens without backlash.
| Differences in representation of population means different
| incentives.
| rat9988 wrote:
| The only backlash I saw is the backlash to snowden from
| its own country.
| monetus wrote:
| That is just silly, and has to be said in bad faith. Are
| you serious?
| rat9988 wrote:
| I do.
| PoignardAzur wrote:
| Where's the bad faith? The US and its allies pulled down
| the plane of _the fucking president of Bolivia_ to catch
| Snowden.
|
| Those are not the actions of the state worried about
| public perception, except in a "silence the dissidents"
| sense.
| ajsnigrutin wrote:
| Backlash after the wikileaks? What backlash? FISA courts?
| Gag orders?
|
| Just call the "other guys" terrorists, nazis, whatever,
| and americans can occupy and bomb whatever country they
| want (and they did that to many countries) withot any
| backlash. Gone are the days of the hippies and anti-war-
| anything... sadly.
|
| I was kinda hoping for a "revolution" in one of the
| european countries (eg france) during covid, where people
| would "remove" the current government, and make the other
| governments atleast worry a bit when their people get
| mad... but sadly, not even that.
| dralley wrote:
| Sure.
|
| But we're talking about a government that just stole
| hundreds of millions of dollars in foreign planes (and
| other equipment) and took down satellite radio networks
| with cyberattacks (causing a lot of collateral damage),
| recently backdoor'd thousands of companies via Solarwinds,
| and looked the other way w/r/t ransomware groups until one
| of them caused a major international incident (Colonial
| pipeline). The threat from other nations is a lot more
| theoretical than it is for Russia.
| [deleted]
| ed25519FUUU wrote:
| As a US citizen you still have some semblance of rights
| under the constitution that dictate what the government can
| do.
| DiogenesKynikos wrote:
| Snowden's leaks showed that the NSA was simply ignoring
| the 4th Amendment, and that the secret FISA court was
| letting the NSA do so.
|
| Theoretically, the Constitution protects you. In reality,
| the intelligence community acts largely in secret, and
| there's very little preventing them from violating the
| Bill of Rights. Citizens don't even know what rights
| they've given up until someone like Snowden spills the
| beans.
| temp8964 wrote:
| No. You need to understand what you are comparing to. The
| question is comparing US and Russia. No. It's not the
| same.
|
| But you turned this question into comparing US to
| perfection. Yes, you are right. US is not perfection.
|
| But there is a big difference between 70 to 10, even both
| are not 100.
|
| What Snowden revealed does not make 70 to 10. If you
| think that way, you don't understand how bad an
| authoritarian regime is.
| DiogenesKynikos wrote:
| Putting a numeric value on this is silly. The fact is
| that the United States government can compel companies to
| aid in its surveillance (just recall when they forced
| Snowden's email provider to install a backdoor).
|
| Even if a company does not want to participate or is not
| compelled to do so, the US government has very
| significant capacity to break into and co-opt systems
| (all the way from targeted surveillance of individuals by
| intercepting and bugging hardware to tapping undersea
| cables to indiscriminately hoover up communications).
|
| So when people say that Kaspersky might be forced to go
| along with Russian intelligence, the same goes for
| American tech companies and US intelligence. There is
| indeed a 4th Amendment that is supposed to protect
| Americans, but the last two decades have shown that the
| government is perfectly willing to ignore that legal
| restriction.
|
| The US has the most extensive global surveillance system
| in the world. US intelligence services receive about as
| much funding as the entire Russian military. I have no
| doubt that Russia tries very hard to engage in extensive
| foreign surveillance, but its not in the same league as
| the US.
| rat9988 wrote:
| I put both russia and us at 10. Why would I rate it any
| better, given its past?
| jiscariot wrote:
| In the US the press can be openly antagonistic toward the
| government without reprisal beyond maybe having a WH
| press-core pass tossed. This provides a path for
| whistleblowers.
|
| Could the Russian press behave toward Putin as the US
| press toward Trump? If so, then you can have your 10s.
| juanani wrote:
| rat9988 wrote:
| Snowden and assange have been used as example. Although,
| there are probably more people shut by the Russian
| government than by the us, by far. The thing is, the US
| secret services are secretive enough that non one can
| complain about, independently of the ability of the
| people to complain.
| lern_too_spel wrote:
| No, Snowden's leaks show DoD lawyers working hard to
| justify programs under the 4th Amendment. In the fallout
| of the leaks, all but phone metadata collection passed
| muster.
| DiogenesKynikos wrote:
| The dragnet surveillance programs that Snowden revealed
| are obviously outlawed by the 4th Amendment.
|
| Of course lawyers working for these agencies will try to
| justify them. That's what they're paid to do. During the
| Bush Jr. years, lawyers for the administration also
| argued that torture was legal, despite the fact that it's
| blatantly illegal.
|
| Nevertheless, these programs are incredibly difficult to
| challenge in court, because the secrecy surrounding them
| makes even proving standing nearly impossible.
| [deleted]
| berdario wrote:
| That's nice for some people, but is cf141q5325 even a US
| citizen?
|
| I'm not, so from that point of view US companies cannot
| offer many guarantees to me
| [deleted]
| AniseAbyss wrote:
| It's about probability. I mean I have my issues with US
| foreign policy but at the end of the day they are more
| friendly and reliable than Russia.
|
| Yeah if the US ever goes rogue we're all doomed but then
| your antivirus software will be the least of your worries.
| nopcode wrote:
| I've worked in multiple European environments (gov &
| private sector) that mandated usage of European anti-virus
| & firewalls.
|
| In finance I had a client that didn't trust any vendor and
| asked me to reverse engineer VPN appliances (they negotiate
| a special clause with the vendor), which makes more sense
| then trusting based on country of origin.
| MattGaiser wrote:
| Depends on the country. Unlike Russia, the government in
| the USA is not all powerful.
| confiq wrote:
| except when it comes to force companies out of the USA
| because of "security reasons".
|
| I think Russia is using similar tactics, does it?
| dragontamer wrote:
| Try saying the words "Ukraine War" in Russia. That alone
| is grounds for getting arrested, possibly disappeared
| and/or tortured.
|
| You have to say "Ukrainian Special Security Operation".
| mardifoufs wrote:
| This is from the first article I came across on the RT
| front page right now:
|
| >Moscow attacked neighboring Ukraine last month,
| following a seven-year standoff over Kiev's failure to
| implement the terms of the Minsk agreements, and Russia's
| eventual recognition of the Donbass republics of Donetsk
| and Lugansk. The German- and French-brokered protocols
| had been designed to regularize the status of those
| regions within the Ukrainian state.
|
| >Russia has now demanded that Ukraine officially declare
| itself a neutral country that will never join the US-led
| NATO military alliance. Kiev insists the Russian
| offensive was completely unprovoked and has denied claims
| it was planning to retake the two republics by force.
|
| It doesn't seem like they are afraid of getting
| disappeared for saying russia attacked ukraine.
| [deleted]
| dragontamer wrote:
| RT is the propaganda arm of the Russian government
| operating in other countries.
|
| Internal newspapers, such as Novaya Gazeta, have been
| shut down for saying "war" in print. Just the latest in
| many papers, radio channels and more that have been
| silenced in Russia.
|
| > It doesn't seem like they are afraid of getting
| disappeared for saying russia attacked ukraine.
|
| They didn't use the word "war".
| kergonath wrote:
| "That guy who killed someone is not that bad, because the
| other guy punched someone and everybody seems happy with
| that".
|
| Bullshit. The US is an imperialist, sometimes oppressive
| pseudo-democracy, but nothing like that mafia-run
| kleptocracy.
| ajsnigrutin wrote:
| This is a very americo-centric view....
|
| Most of the world consideres americans the "bad guys",
| and a lot worse than the russians. You can start with
| southern america and middle east. Then the balkans (where
| putin is doing the same as you guys did with kosovo).
| Even parts of africa would have a say.
|
| Here in the balkans, people were actively rooting for
| trump in the last two elections, because they were afraid
| Hillary would start a new war here...
| kergonath wrote:
| You are way off base. First, I am not American and well
| aware of the imperialist and oppressive aspects. I would
| be quite happy to see the American hegemony disappear,
| but not for it to be replaced by Russian aggression or
| Chinese imperialism.
|
| > Most of the world consideres americans the "bad guys",
| and a lot worse than the russians. You can start with
| southern america and middle east.
|
| Their absurd support for tin pot dictators in South
| America was and is reprehensible, and the whole Iraq war
| was morally bankrupt and threw fuel on a fire that we'll
| be trying to put out for decades. And yet, nothing the
| American did in the Middle East came anywhere near Aleppo
| or Mariupol. Or the Holodomor. Or the Prague spring.
|
| > Then the balkans (where putin is doing the same as you
| guys did with kosovo).
|
| Come on, now. You cannot possibly compare Sarajevo (with
| an actual genocide being carried out, surprisingly, by
| the side with Russian support) with the charade Putin
| used as a fig leaf to invade Ukraine. This is pure
| propaganda. The region would not be any better today had
| the ethnically cleansing gone all the way to the end,
| quite the contrary. Europe should have had grown a spine
| and actually done something.
|
| > Here in the balkans, people were actively rooting for
| trump in the last two elections, because they were afraid
| Hillary would start a new war here...
|
| Well, maybe you did, but that's not what I heard from my
| greek friends. The Americans are not complicated to
| understand, they are going where their interests are.
| What the hell would they do in the Balkans? That is just
| stupid.
| ajsnigrutin wrote:
| > Their absurd support for tin pot dictators in South
| America was and is reprehensible, and the whole Iraq war
| was morally bankrupt and threw fuel on a fire that we'll
| be trying to put out for decades. And yet, nothing the
| American did in the Middle East came anywhere near Aleppo
| or Mariupol. Or the Holodomor. Or the Prague spring.
|
| Yeah sure... and iraq had weapons of mass destruction,
| and iraqi soldiers killed babies, and afghanistan had to
| be occupied for 20 years, because a few saudis flew a few
| planes into a few buildings. Plus syria, libya, lebanon
| etc... and considering how far back you go in history,
| there's also blood from vietnam on americans hand. And
| it's funny how it's a "beloved ruler" when it's a friend
| of america and "nasty dictator" when it's not... so
| america has to replace the ones they don't like (eg
| iran.)
|
| Sarajevo is not in kosovo, quite a few years were between
| sarajevo and the bombing of yugoslavia/serbia. Kosovo
| albanians wanted to separate from the main country, and
| the main country (yugoslavia then) wouldn't let them...
| then they formed armed groups that attacked the serbs,
| and serbs attacked the albanians... basically the same
| thing that was happening with the russian minority in eg.
| donbas and lugansk in ukraine. Then someone (USA) had
| some geopolicital interests in the balkans, bombed the
| country for 78 days, bombed hospitals, passenger trains,
| busses, schools, tv stations, cluster bombed a few
| cities, bridges, roads, highways etc, and built a nato
| base in kosovo.
|
| So, why have a base in the balkans, if they don't need
| it?
| jcranberry wrote:
| Maybe, if the US government thought they could get some
| useful information from you.
| dahdum wrote:
| > Shouldnt i have the same concerns with software from the
| US? You dont really have to nationalize to force devs to
| push malicious code (looking at you Australia)
|
| You should have the same concerns about software from
| anywhere, including the US. I believe it's a couple orders
| of magnitude more likely I'd be harmed by Russian
| government malicious code than any other nation.
|
| Russia is in crisis, striking indiscriminately, and has no
| reputation left to lose. So that's where my concern lies.
| ajsnigrutin wrote:
| > Russia is in crisis, striking indiscriminately, and has
| no reputation left to lose. So that's where my concern
| lies.
|
| With wikileaks, we've seen, that americans did all of the
| same things, you now try to accuse russia of potentialy
| doing.
|
| I'm not saying russians won't do it, but americans
| already did it.
| trasz wrote:
| They have - in the past. The threat from Russia is now.
| ajsnigrutin wrote:
| So you're saying that they suddenly stopped for no reason
| at all?
| rangerelf wrote:
| They don't need to nationalize anything, they can just
| threaten his family with imminent and painful retribution and
| he'll open it up to anything they want. Period.
|
| All these people whining about "they're both the same", they
| are not. "Bay of Pigs" argument does not apply, last time I
| checked Cuba was still standing where on the other hand
| Ukraine is burning and getting demolished.
|
| It seems that those complaining really really do not
| understand the horror of living under an "official" or
| "unofficial" (i.e. government sanctioned vs. government
| tolerated) mafia rule: either you do what they tell you, or
| you cease to be, along with your spouse, children, parents,
| siblings, etc. There is absolutely no negotiation.
| mrkramer wrote:
| Kaspersky has a very good research team which uncovered a lot of
| APT hacking groups including Russian ones so I don't see a reason
| why would they be a threat. But on the other hand Russian state
| can force them to snoop files and traffic from their clients but
| I doubt that will happen because everyone would stop using them
| and they would go bankrupt. Imo US government should use domestic
| antivirus solutions.
| layer8 wrote:
| > I doubt that will happen because everyone would stop using
| them and they would go bankrupt.
|
| The Russian state might not care a lot about that possible
| consequence and still coerce them to include malware in the
| next update.
| mrkramer wrote:
| EU, US and their allies can kick Kaspersky off the market. It
| would be a game over for Kaspersky meaning zero
| installs(licenses) and zero revenue. It is not worth to do it
| not even in the short term. Trust would be forever lost.
| tablespoon wrote:
| >> The Russian state might not care a lot about that
| possible consequence and still coerce them to include
| malware in the next update.
|
| > EU, US and their allies can kick Kaspersky off the
| market. It would be a game over for Kaspersky meaning zero
| installs(licenses) and zero revenue. It is not worth to do
| it not even in the short term. Trust would be forever lost.
|
| Do you think Putin would shed even a single tear over
| Kaspersky, if what you describe was the consequence of him
| getting something he wanted?
| stjohnswarts wrote:
| Trust doesn't matter when you and your team know the
| alternative is 20 years in a Siberian gulag.
| RadixDLT wrote:
| the team is called Costin Raiu
| encryptluks2 wrote:
| Wonder if Google, Facebook, Twitter, Microsoft, etc will be added
| to this list. While US may consider them national security
| assets, it is usually the opposite that is true. Like building
| backdoors into encryption, these services build backdoors into
| peoples lives. Also note, it usually often only takes one rogue
| employee with superuser access to compromise a system.
| DeWilde wrote:
| Why would the US declare companies that benefit them as
| security threats?
| elzbardico wrote:
| This is by design. All those companies are in bed with the
| feds, and no matter what administration. The State is not there
| to protect and serve you. Unless proven otherwise the State
| sees you as a potential enemy.
| lmkg wrote:
| They're US companies, which means the US has a variety of
| options to influence its operations. While there are a variety
| of risks that such companies present, Kaspersky is in the
| qualitatively different situation that a _different_ nation-
| state has greater influence on its operations.
| smoldesu wrote:
| So, we ban all MAANG products for federal use. Who supplies us
| software/hardware next? How do we trust them _more_ than what
| we had before?
| encryptluks2 wrote:
| By requiring that government services use regularly audited
| open source products.
| ComradePhil wrote:
| But then how can governments sneak in their targeted
| exploits?
| avbanks wrote:
| Via a PR?
| CWuestefeld wrote:
| I spent Sunday researching alternatives, then uninstalling KIS
| and trying to install BitDefender.
|
| From this I conclude that the current state of AV/Security apps
| is dismal. Researching alternatives is difficult, it falls
| directly into the cesspool that is web product recommendation in
| 2022. Trying to weed out the garbage articles, I find a handful
| of apps that are consistently rated that the top.
|
| I discarded the recommendation of McAfee. I'm forced to use that
| awful thing at work, and I won't deal with the performance
| penalty it exacts. I wound up deciding that BitDefender was the
| best choice.
|
| But setting up the new software has been an awful out-of-box
| experience. Configuring the tool was a serious chore. The tools
| (like for the firewall) were clunky and difficult to use, and
| once I finished on one machine there's no way to export the
| settings to apply to other devices. Going to their website to
| make suggestions, I found another post indicating that their tool
| is unable to restore from quarantine, files that belong in
| protected parts of the filesystem. The support analyst had
| replied "thanks for the interesting suggestion" - for something
| that seems like a Severity 1 bug!
|
| I'm not trying to advocate for Kaspersky - I can see that with
| security being its raison d'etre, they're a bridge too far. But
| come on, the rest of the industry really needs to get their act
| together. The KIS product is really head and shoulders above
| other products I've seen, and we should be competing on the
| merits, not just "the Russians are a*holes".
| legalcorrection wrote:
| I'm curious, can you tell me why Windows Defender is
| inadequate? I also gather that Microsoft sells an enhanced
| version for businesses with needs beyond local machine
| antivirus.
| Maursault wrote:
| I can't speak to its inadequacy, but I can point out that it
| is obviously unethical for Microsoft to sell a broken
| operating system and then separately profit from a product
| that mitigates part of what is broken in Windows. Microsoft
| now has no incentive to fix Windows, and, in fact, benefits
| from not fixing it. Seems to me that is a job for Linux,
| anyway, and this one time Linux fell down on the job and
| failed utterly, iow, not even Linux can make Windows secure.
| Does anyone else see the irony of the FCC banning Kaspersky?
| It is as silly and ineffective as banning viruses and
| malware. If they had any concern for security as opposed to
| security theater, they'd ban Windows.
| legalcorrection wrote:
| That's not really a fair critique. Maybe if this was the
| year 2000. But modern 'antivirus' isn't about fixing a
| poorly designed OS. It looks for known malware signatures,
| detects suspicious activity in other software, and so
| forth. You need that kind of thing on any platform,
| especially ones that run a web browser and/or let users
| install the software of their choice.
|
| All of that functionality is available in the free version.
| The paid version is for managing the security of entire
| large networks of devices from things like ransomware and
| advanced persistent threats.
| Maursault wrote:
| > That's not really a fair critique.... You need that
| kind of thing on any platform
|
| This is the boilerplate response to the valid complaint
| that Windows security is a nightmare. While in theory,
| other platforms (Linux, BSDs, and idk, OS/400, OS/2,
| etc.) technically can get infected by viruses, in
| practice, infection on these platforms would be a
| vanishingly rare oddity, even compared to the also
| incredibly rare cases of intrusion.
|
| That said, every major non-Windows platform in its
| default install configuration is inherently more secure
| than a Windows system that has had all of its known
| default security issues addressed, even those beyond what
| Windows Defender provides. Windows is not simply a more
| attractive target for malware authors because it is a
| more popular platform with a larger install base, it is a
| more popular target because it is inherently insecure,
| and we know it is inherently insecure because it would be
| foolish for anyone to run Windows and access the WWW
| without first addressing its security issues.
|
| It is possible, and likely even probable, that someone
| could use an unhardened, non-Windows system in its
| default install configuration for ordinary personal
| computing _for years_ without ever experiencing the
| security threats that online Windows users face on a
| minute by minute basis.
|
| But to be fair to Windows, it honestly often is a turnkey
| solution to whatever office computing needs there be, and
| without it, information security, as an area of study, as
| a profession, and as an industry, would not even exist as
| we know it today. The fact of the matter is that Windows'
| security issues (and other issues Windows exhibits
| unrelated to security) creates jobs, and this can not be
| ignored. Arguably, the jobs Windows creates are more
| important than the security issues it introduces. Also,
| to be fair, without C, C++, .NET, Python, Perl, and
| JavaScript, Windows would probably be 90% more secure, so
| it is not all Microsoft's fault and, in a sense, some of
| the problem is beyond their control.
| legalcorrection wrote:
| > _That said, every major non-Windows platform in its
| default install configuration is inherently more secure
| than a Windows system that has had all of its known
| default security issues addressed, even those beyond what
| Windows Defender provides._
|
| Highly disputed.
|
| > _Windows is not simply a more attractive target for
| malware authors because it is a more popular platform
| with a larger install base, it is a more popular target
| because it is inherently insecure and we know it is
| inherently insecure because it would be foolish for
| anyone to run Windows and access the WWW without first
| addressing its security issues._
|
| Do you have any specifics about any of this? It really
| just sounds like Slashdot talking points from the Windows
| XP era.
| CWuestefeld wrote:
| I guess that's a fair question, as it does seem to suffice
| for most people. I have a few reasons:
|
| * Extensive use of Chinese sites, which are quite a mess. I
| think the risks of visiting that part of the Internet are
| much greater than someone engaged in more typical usage.
|
| * Features like firewall are useful for things other than
| protecting against direct hacks, and I use it to ensure
| privacy and occasionally even to simulate failures when
| testing my code. I think that Defender has such a thing, but
| less sophisticated?
|
| * Probably just being more paranoid than most, having lived
| through an era when less protection was available, and having
| to un-hack family members.
|
| ETA: also, it's good to have a different sort of protection
| when the majority is all homogeneous. Windows Defender is the
| obvious high-value target for hackers. Same kind of weakness
| and monoculture.
| jaywalk wrote:
| The Windows Defender firewall is pretty sophisticated. I
| can't imagine what functionality you'd need from a local
| firewall that it doesn't offer.
| jabroni_salad wrote:
| I'm in the space and it's actually pretty rare to see a
| real 3rd party host-based firewall. Most AV products that
| have firewall really just offer a different control
| surface for the built-in windows firewall or iptables.
| dangus wrote:
| I think your last sentence is what Putin counts on, that the
| West won't risk "hurting the business environment" to respond
| to his military campaign.
|
| I think one of the flaws of Western culture is how much
| business efficiency is put on a pedestal above all other
| priorities.
|
| Because of that type of mindset, the West can't even
| manufacture simple cloth or paper masks during a healthcare
| crisis (as an example).
| CWuestefeld wrote:
| Devils advocate: that efficiency is one important reason why
| we're rich enough to be able to afford so much else. Like,
| CO2 emissions are best controlled by societies who are able
| to shoulder the greater expense of avoiding coal and such. If
| we can't count on these efficiencies, we're going to lose a
| huge amount of positives.
|
| This sounds to me kind of like the fallacy of "if it saves
| even one life, it's worth it". That's of course ridiculous,
| because saving that life costs so much that we'll be unable
| to save countless other lives. In reality, the balancing of
| costs and benefits is much more subtle and complex.
| dangus wrote:
| To be clear I'm not saying to move to the extreme end of
| the spectrum.
|
| My point is that the West often seems to consider low costs
| and efficiency above long-term implications.
|
| I'm not saying the West should pull an Argentina [1], but
| the West also shouldn't always be metaphorically choosing
| the lowest bidder.
|
| [1] https://www.npr.org/sections/money/2017/02/17/515850029
| /epis...
| p1peridine wrote:
| It's possible to use Kaspersky Free but block the apps internet
| connection*
|
| Network Settings > uncheck Traffic processing
|
| Network Settings > Do not scan encrypted connections
|
| Once in a while, allow internet connection, do a quick database
| update then immediately block the internet connection again.
|
| * Firewall (router or software).
| mmastrac wrote:
| With something that has hooks that deep in your OS, blocking
| internet access via the application itself is not going to be
| effective in any way if it's hostile software (or turns into
| hostile software via government decree).
| Arubis wrote:
| I fully agree that the antivirus market is a cesspool, and long
| has been so. The upside is that Microsoft's first-party
| solution is decent and ships with the OS, so you can sidestep
| the entire project of figuring out which third-party AVs
| somehow manage to do more good than harm.
|
| I haven't looked into AV for macOS in ages; when last I did
| (~5y?), Sophos (if corporate/paid) and ClamAV (fine for home
| use) seemed reasonably non-interfering.
| Jamie9912 wrote:
| Did you take a look at ESET?
| omgmajk wrote:
| I run ESET for the only reason that it was offered to me
| cheaply and has worked fine over the years without feeling
| intrusive.
| CWuestefeld wrote:
| That was actually going to be my first choice. From what I
| read it seems better polished than others. But then I read
| some recent lab tests in which ESET missed blocking a
| ransomware attack. And that's the threat model that worries
| me the most.
| timbit42 wrote:
| Any anti-virus can miss a malware at any time because they
| rely on updates which take at least a day if not more to be
| prepared and tested before being distributed in the
| updates. Don't worry about ESET missing one ransomware
| attack in a lab test. Do backups daily.
| [deleted]
| MisterTea wrote:
| At work we are required to have EDR software by our accounting
| firm (accounts inserting themselves into IT is annoying). We were
| running Kaspersky as well until this happened though we were
| already unhappy with it so no loss.
|
| Anyway it made me think: is there a way to roll your own EDR for
| Windows/Linux/BSD? Basically, can we do EDR without the EDR
| software?
| ddaalluu2 wrote:
| sjmm1989 wrote:
| So... let's say a person still wanted to use an Antivirus product
| anyways, despite not really trusting them due to reasons like
| this article here; or anything you can say about Norton, etc,
| etc.
|
| What would you all suggest? Aside from McAfee, Norton and of
| course Kaspersky. I'm all ears. Some helpful hints though might
| be:
|
| 1. I don't want it giving me pop-ups constantly to remind me of a
| sale they are having.
|
| 2. It can't interfere with legitimate programs more than once in
| a blue moon.
|
| 3. It has be capable of being run with other security software at
| the same time without incurring an infraction against #2.
|
| 4. It has to cost less than 100$ per year, if there has to be
| payment at all.
|
| I'm asking this because I need a reliable choice to use when
| suggesting to my potential customers out there. I have some go
| to's that I used to use, but with everything the way it is right
| now; I want some input.
| rntksi wrote:
| We've been running ESET Nod32 for over a decade.
|
| Its strength is that it uses very low memory and CPU cycles due
| to the way it is built.
|
| It ticks all the boxes you've given above.
| LeoPanthera wrote:
| For home use, Sophos Home: https://home.sophos.com/en-us
|
| (Disclosure: I used to work for Sophos, I no longer do.)
|
| It's a good mix of traditional antivirus, antimalware, and
| privacy tools. It's also available for Macs.
| AniseAbyss wrote:
| Malwarebytes?
| stjohnswarts wrote:
| Just use what comes with microsoft. If you want another layer
| of scanning then install Malwarebytes. Those two should be
| plenty for anybody. Also set their DNS to use something that
| blocks known malware sites (quad 9 is what I use).
| Hamuko wrote:
| At least the business version of F-Secure is not annoying the
| living daylights out of me, although I have the more onerous
| securities turned off (like the browser protection).
| srhngpr wrote:
| Windows Defender.
|
| See: https://0ut3r.space/2022/03/06/windows-defender/ and
| recent discussion on HN:
| https://news.ycombinator.com/item?id=30580444
| coliveira wrote:
| So, basically we are allowed to protect against any external
| security threat, except the ones created by US spy agencies.
| timbit42 wrote:
| Why aren't you allowed to protect against threats created by
| the US spy agencies?
| usednet wrote:
| Because then you get a gag order and a wiretap.
| randomsilence wrote:
| Why do we accept the risk of intrusion from antivirus software at
| all?
|
| All antivirus software developers should open-source their
| traversal software and thus guarantee that no harm can be done.
| The scanning doesn't need write access and doesn't need network
| access.
___________________________________________________________________
(page generated 2022-03-29 23:01 UTC)