10 ms·
German Government Agency warns about using Kaspersky
- nivenkos 5y agoWhy are they even using Windows? The US is not an ally either.
- phendrenad2 5y agoGermany is one of the oldest NATO countries. Of course the US did supposedly intercept the Chancellor's phonecalls or emails or something, but it seems like not much ill-will was generated as a result.
- lizardactivist 5y agoNot supposedly, definitely. And I think the fact that they actually did something like this is very concerning and shows two things: they are very deep inside EU computer and network systems, and that they do not truly consider the EU as an ally.
- hnbad 5y ago> it seems like not much ill-will was generated as a result That's because any ill-will at a government level would have been futile and disproportionate. There was public outrage at the wiretapping but largely the general assumption seems to have been that the US intelligence operates freely in Germany. That US intelligence services engage in surveillance against even close allies was an open secret and most likely widely known among German intelligence agencies and possibly the government too. Historically, Germany post-WW2 existed at the whim of the US, France and UK. The governments of the occupation forces in the territory of West Germany had special legal rights based on contracts pre-dating and superceding the German constitution. Officially most of those special provisions expired but there's nothing in the original contracts requiring any successor contracts to be publicly acknowledged so depending on how much you like tinfoil hats, it's entirely possible that the US still holds a legal wildcard in German law. And even if the US had no special legal exemptions, what would that ill-will translate to? Germans opposed the invasions of Afghanistan and Iraq but the German government continued to operate as usual, to the point of participating in "peacekeeping" during the military occupation following the regime changes. Sanctioning the US would be economic suicide. Despite the outrage about human rights abuses, Germany still isn't sanctioning China. Russia got away with various abuses and even political assassinations without actual consequences because Russian gas was an important import. And the US not only dominates large parts of the German economy but also its culture.
- MauranKilom 5y agoThis is interesting news, but submitted content must be in English on HN. Edit: Take it from dang, not me: https://news.ycombinator.com/item?id=27571809 https://news.ycombinator.com/item?id=27571809
- celticninja 5y agoIs there a rule that says that?
- Etheryte 5y agoLanguage isn't mentioned anywhere in the submission guidelines [0]. [0] https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- EugeneOZ 5y agoNot sure why this comment is downvoted - my post was removed because of this, it is a real limitation (not so smart one).
- saalweachter 5y agoI feel like browser translation widgets have gotten good enough that if half of HN is reading the article as a translation, they'll still be worlds ahead of the half of HN who doesn't read the article before commenting.
- montzark 5y agoLittle bit worried about Jetbrains products as well. I think they have development centers in Russia? Not worried about company, but rather some disgruntled employee, for example put this USB stick to your computer or otherwise we will prosecute you or your close one for participating in protests or some fabricated accusation.
- dannyw 5y agoInsider attacks should be part of every threat model.
- ognarb 5y agoLook at https://blog.jetbrains.com/blog/2022/03/11/jetbrains-statement-on-ukraine/ https://blog.jetbrains.com/blog/2022/03/11/jetbrains-stateme..., they are actively moving all their employees out of Russia.
- EugeneOZ 5y agoSorry, but there is no such information. Some employees have moved out of Russia - JB help to them is not mentioned. I hope I just misunderstood it and JB do help their employees to move out of Russia.
- pacificmint 5y agoJetbrains is Czech. They have suspended their sales and R&D activities in Russia and Belarus two weeks ago[1]. Hacker News discussion from when it was announced[2]. [1] https://blog.jetbrains.com/blog/2022/03/11/jetbrains-statement-on-ukraine/ https://blog.jetbrains.com/blog/2022/03/11/jetbrains-stateme... [2] https://news.ycombinator.com/item?id=30639572 https://news.ycombinator.com/item?id=30639572
- montzark 5y agoThanks! My bad.
- lmm 5y ago> Jetbrains is Czech. Their headquarters is Czech, but many of their developers are or at least were based in Russia. > They have suspended their sales and R&D activities in Russia and Belarus two weeks ago "R&D activities" is a funny phrase. Does that mean they've stopped all development in Russia (i.e. there are no longer Russian employees working in Russia with commit access) or not?
- samwillis 5y agoGoogle translate: https://www-bsi-bund-de.translate.goog/DE/Service-Navi/Presse/Pressemitteilungen/Presse2022/220315_Kaspersky-Warnung.html?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp https://www-bsi-bund-de.translate.goog/DE/Service-Navi/Press... (For the none German speakers)
- bilekas 5y ago> (For the none German speakers) I'm sure there's a few for sure! /s Thanks for the Translation
- ogogmad 5y agoThe DeepL translation (deepl.com) seems to be a bit better: # BSI warns against the use of Kaspersky antivirus products The Federal Office for Information Security (BSI) warns against the use of antivirus software from the Russian manufacturer Kaspersky in accordance with §7 of the BSI Act. The BSI recommends replacing applications from Kaspersky's portfolio of antivirus software with alternative products. Antivirus software, including the associated real-time cloud services, has extensive system permissions and must maintain a permanent, encrypted and unauditable connection to the manufacturer's servers for system-related reasons (at least for updates). Therefore, trust in a manufacturer's reliability and self-protection, as well as its authentic ability to act, is critical to the secure use of such systems. If there are doubts about the manufacturer's reliability, antivirus software poses a particular risk to an IT infrastructure that is to be protected. The actions of military and/or intelligence forces in Russia, as well as the threats made by the Russian side against the EU, NATO and the Federal Republic of Germany in the course of the current armed conflict, are associated with a considerable risk of a successful IT attack. A Russian IT manufacturer may itself carry out offensive operations, be forced to attack target systems against its will, or itself be spied upon as a victim of a cyber operation without its knowledge, or be misused as a tool for attacks against its own customers. All users of antivirus software can be affected by such operations. Companies and public authorities with special security interests and operators of critical infrastructures are particularly at risk. They have the option of seeking advice from the BSI or the relevant constitutional protection authorities. Companies and other organizations should carefully plan and implement the replacement of essential components of their IT security infrastructure. If IT security products and, in particular, antivirus software were to be switched off without preparation, they might be left defenseless against attacks from the Internet. Switching to other products involves temporary losses in convenience, functionality and security. The BSI recommends that an individual evaluation and consideration of the current situation be carried out and, if necessary, that BSI-certified IT security service providers be consulted. Press contact: Federal Office for Information Security Press Office Tel.: 0228-999582-5777 E-mail: presse@bsi.bund.de Website: www.bsi.bund.de Twitter: @BSI_Federation #GermanyDigitallySecureBSI
- samwillis 5y agoThis is interesting news but I think it's more about sanctions/politial pressure than an actual threat to general businesses and people. Once a zero day or backdoor has been used its burnt forever, nation state intelligent services need to be incredibly careful about when and where they use them. If one was to be placed in a Kaspersky product and used, that's Kaspersky burnt as a business forever, and with it the ability to use it as a vector for high value targets. They are not going to use a backdoor in a Kaspersky product for a general attack on people and business, at least not at this point. Realistically any high value target in the west isn't using Kaspersky anyway.
- tuukkah 5y ago> more about sanctions/politial pressure than an actual threat I think this would be one of their hybrid warfare steps (well) before actually going nuclear.
- lozenge 5y agoYou seem to be assuming a lot of things, like that Kaspersky couldn't deploy certain updates to targeted customers? That malware will leave behind trails of how it got on the computer? That plausible deniability is impossible? What happens when a definition update "reduces false positives" but actually lets in a Russian cyberweapon that is delivered independently?
- durnygbur 5y ago
- deleted 5y ago[deleted]
- c0l0 5y agoI will go on the record here and one-up them, warning against the use of any antivirus product. SO many vulns and gaping, smoking holes in that kind of software over the years, it's not even funny. Faux-security is what most vendors are peddling. https://twitter.com/GossiTheDog/status/1427935182200492039 https://twitter.com/GossiTheDog/status/1427935182200492039 is one of my favourite bugs from recent years. I acknowledge this bug is not specific to an antivirus product (but of course, Fortigate offers that as an optional component for traffic inspection - and I keep wondering what that sub-component's code quality is like 8-)), but anyone who tries WILL find examples for grave problems aplenty.
- kevingadd 5y agoIt's definitely reasonable at this point to just skip using AV. It won't protect users from bad security habits and it tends to make your system performance worse even if it doesn't have vulnerabilities. I have Windows Defender enabled on my machines since it comes with the OS (and work policy requires it), but I definitely had to exclude most of my work folders to be able to get work done. It would be nice to have software that specifically blocks ransomware by trying to detect it heuristically, but that would probably not be very effective and the right solution is just to have backups.
- Helmut10001 5y agoFirst I skipped using Antivirus altogether, but now I opted for intermediate solution using Microsoft's native Antivirus Defender. At least this is fairly guaranteed to be compatible with Windows itself. Regarding firewall: I don't trust Windows anymore - using an external HW firewall on my router (opnsense).
- dspillett 5y ago> to have backups With the usual additional notes: unless you include an off-site, an off-line (or at least soft-offline) backup, and your backups get tested regularly enough, you don't have a backup system, you have aspirations & hopes! ---- For your valuable information anyway. For most individuals the core “it would really inconvenience my life if I lost it” data is surprisingly small¹, and the next layer (“losing it would really annoy me”) is only a few tens of Gb². For personal use everything else in the grand scheme of things can be reacquired or won't be massively missed, things are a bit different for businesses of course. [1] password store, financial details & other officialdom, code & docs for personal projects that might come to something else [2] meaningful digital photos & such
- t43562 5y agoIt's curious to look on at this situation from Linux. Perhaps I shouldn't be too comfortable but it's really a different world. I suppose that one should take care which distribution one uses as that is also an effective entry point for software from the outside but at least a bit more obvious and open than some AV company.
- swiftcoder 5y agoAs a 25 year Mac user, I concur. I'm just glad that Microsoft eventually decided to bring antivirus in-house, and I don't ever again have to mess with 3rd-party security products for my Windows box
- Avamander 5y agoThough some say that Windows Defender is one of the easiest AV's to bypass. I wonder though if Microsoft Defender ATP and Virtualization-Based Security makes it more difficult.
- jeroenhd 5y agoI'm anxious to see what the Steam Deck, one of the first popular, user accessible Linux computers, will do to the Linux landscape. For ages now, Linux has been relatively virus free because let's be honest, Linux is either used by just a few nerds (who are often just a tad harder to trick than the tech illiterate) or by servers, for which entirely different classes of malware exists. With effectively no antivirus protection, either because of a lack of options or because the outdated mantra that "you don't need it" because of some peculiarities that Apple used for years to deny the existence of macOS malware, Linux users are bound to run into viruses sooner rather than later. Hackers that are after Steam accounts will definitely try their hardest to infect Linux desktop users. My best hope is that the way Linux distributions are woefully incompatible with each other will protect the hardcore Linux users somewhat from the viruses that will inevitably be spread across the "common" Linux environment. I'm sure we'll see Flatpak/Snap viruses down the line, but for a short while, we'll hopefully still have time to see where the Linux landscape is headed.
- ho_schi 5y agoI warn about using any kind of snake oil. Often sold under the marking terms "antivirus" or "personal firewall" or "cloud cyber security". Known side effects of this treatment are high CPU load, high RAM consumption, drain of battery power. Sometimes they also consume your money or looking at your data. So far I would consider other counter measures, like applying user rights, proper package management and re-consider your decision using this random stuff from the internet? If you're forced to use Windows the one with the least known side effects is Microsoft Security Essentials but even this has several drawbacks. If you're already using Linux or some kind of BSD you probably applied already these measures accordingly. PS: This doesn't mean you shouldn't make sane use of software looking expectantly for malware. If your are a server admin and hosting a mail server which faces random stuff from the internet it makes sense to filter out bad stuff. And it won't spin up the fan of your laptop or drain its battery.
- hutzlibu 5y ago"If you're forced to use Windows the one with the least known side effects is Microsoft Security Essentials but even this has several drawbacks." But permanently disabling it is very, very hard.
- midasuni 5y ago> But permanently disabling it is very, very hard. I installed linux in a new machine just last week
- hutzlibu 5y agoCongratulations, me too. But that didn't help me with the linux driver issues for my laptop. Nor does linux run adobe animate, or a bunch of other software.
- ho_schi 5y agoGood work! The only "correct" approach is telling Adobe that they need to provide native ports of their software or switching to other software. Regarding laptops, buy business laptops (Lenovo ThinkPad, Dell Developer Edition) or laptops made from vendors with a focus on Linux (Purism, System 76, Tuxedo) and stick with internals from AMD or Intel. So it boils down to knowing things before and giving the right companies your money. It worked somehow, Intel provided first good support, than AMD, Atheros and others followed. On the ugly side we have still ARM, Qualcomm (yep - now Atheros) and of course Nvidia. Actually the "stickers" with the Windows logo from Microsoft are the proof that the hardware runs good enough with the pre-installed version of Windows. And that the manufacturer has spend 80 $/€ or more for this. Some person also name this stickers "tax labels", nasty persons "protection money". Not that I want to encourage the Linux Foundation...
- protoman3000 5y agoWhat about Telegram?
- hutzlibu 5y agoThe client is open source, so should be quite safe and the company is not based in russia. But I think some servers are? In either case, it is not a medium for secure communication anyway. I use it more as a open forum software.
- tonyedgecombe 5y ago>In either case, it is not a medium for secure communication anyway. The problem is it is running on your machine.
- f1refly 5y agoWhy would that be a problem? The source is open, there are public builds by f-droid that are definetly not tempered with. I trust the fdroid maintainers.
- nonrandomstring 5y agoI'm reading this as I am giving a class on Stuxnet this morning. We're doing worms and multi-stage malware. But inevitably the conversation turns to national boundaries, cyberwar, collateral damage (to individuals, hospitals, power plants, companies..). My students want to understand the relations between companies like Microsoft and the NSA, what happened to Siemens from the economic fallout, why the Iranians would be running Windows? Who paid to clean up the tens of millions of infected machines out there? I keep getting questions that begin "Bit surely....?" We've been through an unprecedented period of human history in which the internet brought us together. That time is over. The fact that a Russian company could trade freely in the world such that American companies, only within a decade of the Cold War, would use Kaspersky (which I believe is an a good product) is absolutely remarkable. It's what Richard Buckland called "A miracle of interoperability" that allowed a movie made in Hollywood to be recorded on a DVD manufactured in China to run on a player assembled in India, according to standards designed in Nederlands and Japan, playing in a home in Australia. That level of trust and cooperation has to run both ways. It's at least as remarkable as Russians, Chinese and Iranians running Microsoft Windows. The internet delivered on much of its promise to unite the world. But what I've seen in the past 5-10 years is so much effort by everyone to _undo_ that trust. Greed and surveillance capitalism has played as much a part as gobernment intelligence over-reach and economic warmongering. All parties have abused trust and now we are withdrawing into silos again. From a business perspective, maybe we'll need to reckon with a future more centred around domestic sales and use. Perhaps the "splinternet" is just the beginning of a global divergence at the protocol level. How can we (proponents of a true INTER-net) avoid this?
- ganzuul 5y agoDecentralization from meshnets up. The user agent needs to handle the entire electronic presence, establish the identity of it's user, and keep watch on its friends like a herd.
- anon_123g987 5y ago> [...] "A miracle of interoperability" that allowed a movie made in Hollywood to be recorded on a DVD manufactured in China to run on a player assembled in India, according to standards designed in Nederlands and Japan, playing in a home in Australia. Well, it can be played in Australia only if its DVD region code is 4, and it cannot be played in any other countries you mentioned, which are all in different regions (USA: 1; China: 6; India: 5; the Netherlands and Japan: 2). So there's that. "A miracle of interoperability." https://en.wikipedia.org/wiki/DVD_region_code https://en.wikipedia.org/wiki/DVD_region_code
- severino 5y agoSo they basically say Russia can spy on you if using Kaspersky (but the German government, or its "allies", can't). Then, I guess that using Kaspersky is a wise decision unless you happen to live in Russia or Ukraine. Dowloading ;-)
- waihtis 5y agoIt’s been interesting to note how Kaspersky has been responding to the scrutiny. It’s almost always the same - ”we have been audited a huge amount of times and no-one has ever found anything!” It’s suspicious because as someone who is a vendor of risk management, they’re leaving out the gaping hole fact which is that software is updateable and oftentimes AV will do so automatically. Potent risk is pretty huge. Same applies also to the Huawei discourse.
- nisa 5y agoBut this applies to any software that has auto-updates. Can we be sure that Microsoft/Google/Apple don't sign backdoor updates for the NSA for specific targets? As far as I know these national security orders are non-public and we don't even know if it's happening. But Russia used Ukraine in the past as "playground" for cyber attacks: Some mandated tax software auto-update was hackend and delivered a ransomware trojan without any chance to pay i.e. pure data destruction.
- waihtis 5y agoNo, it doesn't. Because not all software companies can be a) under influence of a foreign government potentially hostile towards yours and b) software has varying degrees of replacement difficulty. Example - building an entire smart city network on top of Huawei network gear. It would be very difficult to rip it out and replace on a whim if China suddenly decided to side with Russia in a war against the West, which is literally a possibility floating in the air right now. End state - you have a hostile actor who has access & control of your critical infrastructure. ¯\_(ツ)_/¯
- sofixa 5y ago> Same applies also to the Huawei discourse. How? Huawei routers and switches don't auto-update.
- alexklark 5y agoTheir whole range of management software do.
- aszantu 5y agoclamwin is actually light weight and nicely unintrusive
- schleck8 5y agoAnd has notoriously bad signatures afaik.
- throwaway4good 5y agoSeeing that the west just killed off payments in the Moscow metro, stopped security patches for Cisco networking equipment etc. etc. There is a bit of projection going on: We fear that Russia might do to us, what we just did to them. But what is the end result of this? Any "potential enemy of the west" will have to do their own tech, and we will only use our own stuff. Sounds like a bad trade for us; instead of selling all this stuff we have already made for a nice buck, we now insists that everyone makes their own.
- EugeneOZ 5y agoIt would be a legit thought if Kaspersky (company and the owner) wouldn't have direct connections to FSB.
- throwaway4good 5y agoIn the same manner, you can easily connect any of the big US tech companies to the US intelligence services or military.
- EugeneOZ 5y agoWhen I see the evidence. Party in sauna with the hookers was a quite “specific” sort of connection between E. Kaspersky and FSB officers.
- losvedir 5y agoThere's a lot of anti-antivirus sentiment in these comments, and while I, too, hate AV and have grown up with it being nothing but snake oil, I wonder if that's still correct in the current era of "zero trust". I think we've learned that corporate firewalls and VPNs don't really work all that well. In other words, if you can't rely on a safe boundary to the outside world, how do you ensure individual corporate machines are not compromised? What about newer software like Crowdstrike? What do the big tech companies like Google, Microsoft, Meta, etc do on their employees computers? Do none of them use antivirus?
- jeltz 5y agoI feel traditional antivirus software is the very opposite of zero trust. It runs at a very high level of permissions and intercepts almost everything.
- viraptor 5y agohttps://www.microsoft.com/security/blog/2018/10/26/windows-defender-antivirus-can-now-run-in-a-sandbox/ https://www.microsoft.com/security/blog/2018/10/26/windows-d... There are of course still some occasional issues, but the scanning is pretty restricted these days.
- einarfd 5y agoWith the fast moving legal landscape in Russia this seems like a smart move. Given the new laws getting added in Russia now, a law coercing Kaspersky to help the Russian government attacking its customers that Kremlin sees as enemies. Do not seem that far fetched.
- alexklark 5y agoKaspersky is indeed FSB controlled, lot of proofs of that in last 10 years, but of course they will not just upload all your data or brick PC in revenge for sanctions (well may be they will if told nuclear war has been started). They will behave according to the agreement, and just let FSB peek a bit for data they legitimately getting. Same as Microsoft / Google / Apple / Amazon etc. relationship with multiple US spying agencies.
- Terry_Roll 5y agoThe illusion of cybersecurity is finally being questioned. AV scanning emails has been a phishing scam for decades which benefits the criminals. Because so many people have worked on so many parts of a computer beit the hardware or software, who do you trust when you dont trust random strangers in the street and people like to gossip and spread rumours? Is this a classic case of cognitive dissonance or just shows giving money for something makes someone/something instantly trustworthy when their own survival comes before yours?
- _the_inflator 5y agoThis ban on Kaspersky in software is similar to the US ban on Chinese Huawei for 5G. What I am really waiting for is a ban on cloud services like Github. Since Russia is now basically even more rogue than Iran, I bet something like this here is in the making: https://techcrunch.com/2019/07/29/github-ban-sanctioned-countries/ https://techcrunch.com/2019/07/29/github-ban-sanctioned-coun... And it's reversal till this day: https://github.blog/2021-01-05-advancing-developer-freedom-github-is-fully-available-in-iran/ https://github.blog/2021-01-05-advancing-developer-freedom-g... Cybercrime is still a thing in Russia.
- lizardactivist 5y agoThe same warning obviously applies to all the American AV vendors, given what we have learned in the last years. And this is not idle speculation and baseless accusations, it's right from the inside part of the NSA and CIA leaks. So what is one to do? Where is the free open-source AV the world needs, which has the same number of highly skilled full-time developers and researchers as Kaspersky does? There really needs to be a global AV effort and software, funded by governments, but open and transparent, and based in a country which does not sit in the shadows of over-reaching spying agencies. But what will it take for this to happen?
- Maxburn 5y agoWe supply servers running some proprietary control software and a school district put Kaspersky on it after receiving it. We mentioned to them we can't be involved with that product anywhere because of our companies involvement with DFARS, and frankly we are surprised they were able to get away with using it being a government organization. Still there though, guess they just don't care.
- GrumpyNl 5y agoWhat do you guys recommend? Windows defender or?
- lizardactivist 5y agoI always recommend Kaspersky, as it's one of the best AV suites out there, and because there is still no proof whatsoever that the Russian government is "inside" KAV.
- slenk 5y agoWhat makes it the best over other options? Windows Defender turned on plus a firewall protects like...everything.
- schleck8 5y agoBitdefender is the most recommended other option. Sophos and F Secure are good too, so is Emsisoft and G Data. Depends on who you want to share your data with and how much you are willing to spend. Emsisoft is the least bloated option, they don't include all the password and vpn nonsense.
- loufe 5y agoI am not an IT professional but a bit confused by how many completely negative views there are here on AV use. I have a NOD32 license and at least twice per month a url is blocked while browsing in an unobtrusive way by the software, which makes sense as may have contained malicious JS or something. Maybe it would've been caught by ublock afterwards, or may have been caught by MS defender as well, but I like the assurance provided. You can argue that I'm browsing in an unsafe manner but I doubt many of you restrict your browsing to strictly "safe" chunks of the internet.
- lpcvoid 5y agoThe point is that the AV does not do much here. The security model should be proper sandboxing within the browser, along with block lists that get used by ublock origin if you wish. A third party program running alongside your browser, inspecting the URLs you visit (possibly then via TLS certificate MITM?), is just a weird way to think about security in my opinion. Not even talking about the potential new attack surface that may be introduced in some way.
- DavideNL 5y agoWhat anti-virus (if any) does one recommend their 60 year old parents on a Macbook...?
- fomine3 5y agoAside from avoiding Kaspersky on important division in western world is practical, I wish Kaspersky survive. They are great about detection and analysis and not based on western world.