[HN Gopher] The Impact of the Kaspersky Ban
___________________________________________________________________
The Impact of the Kaspersky Ban
Author : cyberlurker
Score : 16 points
Date : 2024-07-09 17:20 UTC (5 hours ago)
(HTM) web link (www.bitsight.com)
(TXT) w3m dump (www.bitsight.com)
| mmmlinux wrote:
| Is this retaliation for that time they detected unreleased NSA
| spyware? Has there ever been shown to be a security breach
| related, or is this just Russia bad? genuinely curious.
| golergka wrote:
| Kaspersky has been in FSB's pocket since forever. Banning
| hostile foreign intelligence from providing security services
| to your country is one of the very rare pieces of regulation
| even a staunch minarchist would support.
| ahofmann wrote:
| Following this argument, the whole world needs to stop using
| software from the USA (and china, and Russia and ...).
| tptacek wrote:
| OK. They can do that.
| bdcravens wrote:
| One could say it's similar to the reasons for banning TikTok
| (concerns about state control of software), but in general,
| it's an expanding of existing trade sanctions against Russia.
| fred_is_fred wrote:
| Tik-Tok and an Anti-virus program have pretty different
| privilege levels I would think. And generally one doesn't
| install Tik-Tok on servers in the data center, but I guess I
| could be surprised.
| alfalfasprout wrote:
| Antivirus software typically requires some level of privileged
| access. Given Kaspersky's deep collaboration with the Kremlin
| it's a serious attack vector.
| axpvms wrote:
| Russia is bad though, they just bombed a children's cancer
| hospital yesterday.
| greenavocado wrote:
| I can post a list a mile long of war crimes committed by each
| side.
| kspacewalk2 wrote:
| Each side of what? Are you attempting to draw equivalency
| between the actions of Ukraine and Russia?
| ipaddr wrote:
| The war is between the US (allies) and Russia. Ukraine is
| just a proxy country. Did the war start with the invasion
| of Ukraine or many years before when NATO decided it
| needed to expand?
| jiggawatts wrote:
| Sigh.
|
| Ukraine _begged_ to join NATO because they saw this
| coming a mile off.
|
| They're still begging.
|
| Asking to join the neighbourhood security watch is
| offensive only to burglars.
| rcxdude wrote:
| It most certainly started years ago when Russia invaded
| and annexed parts of Ukraine in 2014. Ukraine was
| lukewarm at best to the idea of NATO before that (and in
| fact, substantial parts of it were very pro-Russia, a
| sentiment which quickly changed when they saw what
| happened to the people in the areas of Ukraine under
| Russian control).
| jmprspret wrote:
| The US government, DoD, CIA, etc are all "bad" too. I'm not
| excusing Russia's actions, but if you're going the moral high
| ground, on civilian murder, you should be avoid US companies
| as well.
| gregw2 wrote:
| The clearest most specific summary explanation I have seen is:
|
| https://arstechnica.com/information-technology/2017/10/kaspe...
| Note the Israeli findings and the months of experiments by US
| intel agencies after the fact and the conclusions they drew.
|
| The initial counterargument from Kaspersky (which seems to
| address some but not other concerns raised in the above link)
| apparently was something like the following:
|
| https://arstechnica.com/information-technology/2017/11/kaspe...
|
| Both the above are from 2017 in the months after the issues
| about Kaspersky concerns first came to light. This triggered
| the ban of Kaspersky from US government computers back then.
| Not sure what info may or may not have come to light since then
| but most people are not even aware of the above.
|
| The official 2024 USG reasons which impact are outlined in four
| bullets in the press release here: https://www.bis.gov/press-
| release/commerce-department-prohib... which in turn points to
| an ODNI (Office of the Director of National Intelligence)
| public-facing PDF/slide of the reasons:
| https://www.dni.gov/files/CTIIC/documents/products/Kaspersky...
| and the US Commerce department's findings at
| https://oicts.bis.gov/pdfs/AppendixA.pdf (mostly blacked out
| but you get a sense of the back-n-forth reasoning justifying
| what steps short of a ban could be taken at least a little bit)
| and the Commerce Department Kaspersky FAQ at
| https://oicts.bis.gov/kaspersky/faq/
|
| I have no first/secondhand knowledge of any of this stuff but
| this is what my curiosity turned up when I went poking around.
|
| Having observed corporate US security practices, my perception
| is that a lot of protection involves scanning things using very
| low-level OS and/or network techniques. Remember that phrase
| "who guards the guardians? (
| https://en.wikipedia.org/wiki/Quis_custodiet_ipsos_custodes%...
| ) The Kaspersky ban by the US Commerce department appears to be
| essentially a concession that "who scans the scanners?" is not
| something the US can particularly do for products with the type
| of low-level access provided to AV/malware products,
| particularly products from entities with a concrete history of
| specific adverse (2014-2017) behavior from a particularly
| skilled hostile country (in this case Russia).
| tptacek wrote:
| Forget the ongoing military conflict, and Russia is a hostile
| US IC rival. We did much the same thing with Huawei, for
| reasons much more complex than "China bad".
| ReDeiPirati wrote:
| Leaving aside the valuable politics concern, I honestly love
| Kaspersky, it's the only AV that doesn't suck or become too
| spammy. Which alternative would you recommend? Please don't say
| Norton
| mathisdiego wrote:
| ESET is pretty good. Has a low false positive rate too which I
| loved about Kaspersky.
| PenguinCoder wrote:
| ESET has my recommendations for the same reason. Really good
| and way more light weight than many other solutions. Though
| I'd say anything more than Windows Defender for home users
| really isn't needed.
| jmprspret wrote:
| From an enterprise perspective (only because I don't use it on
| my personal machines), TrendMicro has really been improving. I
| highly recommend it.
| kelsolaar wrote:
| > Looking back into the recent weeks, we observed over 14 million
| unique IP addresses communicating with Kaspersky update servers,
| making a total of over 100 million connections.
|
| How is Bitsight "observing" here?
___________________________________________________________________
(page generated 2024-07-09 23:01 UTC)