4 ms·
Quote: "The BOD calls on departments and agencies to identify any use or presence of Kaspersky products on their information systems in the next 30 days, to de
by AngeloAnolin 9y ago
Quote:
"The BOD calls on departments and agencies to identify any use or presence of Kaspersky products on their information systems in the next 30 days, to develop detailed plans to remove and discontinue present and future use of the products in the next 60 days, and at 90 days from the date of this directive"
That number of days could be critical. If they have intel telling them that Kaspersky can be used as a vector to exploit their systems by Russia, then this could be used outright to further exploit their systems and possibly (?) plant more ways to attack, even after Kaspersky has been removed.
I am assuming that DHS will already have in place another security company to handle other potential scenarios and ensure the security of their system while the transition process is happening.
- csydas 9y agoIt could just be an excuse to award a contract to a variety of local security firms to perform a "Post-Kaspersky Security Audit" at great expense in the interest of National Security, but that's just baseless cynical speculation. It's a weird move, and I would like to imagine that there is some solid reasoning behind the endeavor besides posturing and playing up to hot-button issues. But it really does just seem like the sort of issue that either ends up in bureaucratic limbo (e.g., Kaspersky remains installed for months while agencies look to find a replacement that meets their criteria) or that leaves the computers unprotected while the search continues.