7 ms·
Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, w
by tempsolution 7y ago
Interesting. I think its time to get rid of this junk. I always had a bad feeling about AVs, due to repeated "extra vulnerabilities" they seemed to introduce, while not providing measurable added value compared to Windows Defender.
That Kaspersky is apparently too stupid to fix this leak properly even after it was pointed out, suggests to me that their developers obviously are incompetent and the trust int hem doing AV right is approaching zero, if they can't even load a script into a website without leaking like the Iraqi marine.
- mirimir 7y agoIndeed. But then, I don't trust Microsoft, either. In Debian, I can be reasonably confident that no information leaves the system without my authorization. Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian?
- TonyTheSlayer 7y agoI think for the purposes of antivirus software, trust issues can be set aside here. Windows Defender ideally has the upper edge for choosing an antimalware solution for Windows in that it's baked in directly to the OS and therefore has more control and ability to prevent malicious activity than a third-party solution. You might not have to trust Microsoft due to privacy concerns, but for something like antivirus software that protects their operating system, intentionally making Windows Defender inferior software just isn't within their best interests.
- mirimir 7y agoHow can one "set aside" privacy issues?
- sverhagen 7y agoWasn't the argument you're responding to that Defender is the superior solution so that you don't have to trust other vendors than Microsoft, of which the trust point is moot if you've already chosen to run Windows?
- mirimir 7y agoMy point is that using Debian is the superior solution, from a privacy perspective. But yes, I do agree that Defender is the best option, if you must use Windows.
- ethbro 7y agoWindows Defender is a superior AV solution for the same reason first party map solutions are superior to third party. When part of your core functionality is dependent on coverage and total install count, you're never going to beat someone who leverages control of a lower part of the stack.
- earenndil 7y agoCertain companies pay microsoft ridiculous amounts of enterprise software; you can probably trust ms not to do anything that would piss off those companies, simply because they act in their own self-interest. Beyond that, not really. Debian and openbsd are probably as close as it gets to having an actually secure system, and if I had to pick an os for a very critical application, it would definitely be one of those. But really, honestly, any of debian, ubuntu, fedora, alpine, arch, gentoo, slackware; freebsd, openbsd, netbsd, dragonflybsd are probably more than sufficient for any practical need you might have for privacy and security.
- goatinaboat 7y agoThe reason the Windows Defender is so good these days is https://docs.microsoft.com/en-us/graph/security-concept-overview https://docs.microsoft.com/en-us/graph/security-concept-over... The idea is everyone pools their threat data and immunity to new threats can be rapidly disseminated via Azure. The time window any new malware has to exploit Windows 10 anywhere in the world is measured in 10s of minutes now. It’s impressive stuff. The ISG can spread immunity much faster than malware can spread itself. Of course wearing my cynics hat, they never bothered to backport it to Windows XP and that’s why the NHS was hit with WannaCry. But the other side is that they had plenty of time to upgrade...
- heavenlyblue 7y agoHow does it help against new threats exactly, if they are not auto-detected in the first place?
- goatinaboat 7y agoSuspicious files - if you fully buy into the solution - are uploaded to Azure and “controlled detonation” in a VM assesses if they’re malware. Then a signature is generated and distributed. It’s super slick. MS are serious about rehabilitating their security reputation.
- mey 7y agoIf you are using Windows, I recommend using defender over any other AV option[0]. Understand, if you are already using Windows, you are already trusting Microsoft. If you don't trust Microsoft you probably shouldn't be using Windows. [0] There are enterprise solutions that may be better for centralized control in a mixed environment (osx/Linux/windows). Please consult your CISO
- mirimir 7y agoI do agree with that. Except that I do use Windows without trusting Microsoft. I use install disks that I've purchased ~anonymously for cash. And I only run VMs, which hit the Internet via nested VPN chains, and sometimes Tor.
- bboygravity 7y agoSo all the telemetry that Windows collects from the VM's you're running are sent to Microsoft through nested VPNs over TOR? I don't think Microsoft minds or cares that your Windows VM telemetry gets send to them that way or any other way? How are your VPNs and TOR helping you with the Microsoft you don't trust?
- mirimir 7y agoMicrosoft can collect anything it wants from those VMs. Because they contain nothing that I don't want them to know. In particular, they don't contain anything about my meatspace identity. Sometimes I do need to put data on VMs that I want kept private. For that, I clone a Windows VM, add a virtual disk containing the data, and then start it with no network connectivity. When I'm done, I detach the data disk, and delete the VM.
- jowsie 7y agoNot meaning to come across as mean, but could you explain your reasoning behind such precautions, and why they seem worth the extra effort to you? It would seem to me that if you just need to occasionally run an exe that you could most likely get it working with WINE.
- the_duke 7y agoYou are wrong about trusting Linux. Linux would badly need AV if it was a more popular desktop OS. Right now the user base is just too small to be a valuable target. A regular Linux distro (without SELinux or some kind of application sandboxing and a hardened setup including NOEXEC home, forbidding ptrace, ...) is very susceptible to compromise. All it takes is somehow getting the system to execute one unprivileged shell script and your user is permanently hosed. An attacker can spy on everything, including other applications memory, unless they prevent it. Browsers are also easily compromised by just injecting a extension that can spy on everything. Also he lack of dynamic firewalls makes it hard to monitor/prevent unwanted network traffic. (which could often be easily circumvented, though)
- mirimir 7y agoThanks. I do appreciate that there are vulnerabilities. So I work only in VMs. I do nothing on host machines except to run VMs, and keep the OS up to date. And I compartmentalize rigorously. Minimally in different VMs. When it matters more, in different host machines. And when it really matters, in different host machines on different LANs. Only text files cross important security boundaries. And machines that my ~anonymous personas use never see anything about my meatspace identity. This is, of course, just a hobby.
- codedokode 7y agoYes, Linux distributions don't have protection against malicious software. If you downloaded thrid-party program and run it, it can read everything from your home directory, including cookies and browser history, it can inject itself into browser process, it can see everything you type. And if you decided to add third-party apt repository, for example, to use Node.JS or VS Code, you give permanent root access to the owner of repository. Also, some third-party .deb packages (for example, Slack) automatically add their repository and public key to apt sources list upon installation. For example, there is a third-party repository, that allows installing multiple versions of PHP in Debian. This repository replaces cryptographic libraries provided by Debian with its own ones (you can see those packages here: https://packages.sury.org/php/pool/main/o/openssl/ https://packages.sury.org/php/pool/main/o/openssl/ ) Also, in Linux unprivileged program, run under "nobody" account, can read all unique hardware identifiers like MAC address, HDD serial number etc.
- FDSGSG 7y ago> or in trusting Debian? From a security POV Desktop Linux is an utter disaster. For attackers it's like going back a decade in time.
- mirimir 7y agoPlease explain. Security from what? By default, there are no services listening. And what malware runs on Linux?
- FDSGSG 7y ago>By default, there are no services listening. Desktop linux, not "the Linux kernel". The kernel isn't amazing, but on the desktop side you regularly see downright absurd stuff like this https://scarybeastsecurity.blogspot.com/2016/11/0day-exploit-compromising-linux-desktop.html https://scarybeastsecurity.blogspot.com/2016/11/0day-exploit... and less surprising bugs like this https://donncha.is/2016/12/compromising-ubuntu-desktop/ https://donncha.is/2016/12/compromising-ubuntu-desktop/ The quality of software outside of some widely deployed server software tends to be quite poor, exploit mitigations are not being implemented. >And what malware runs on Linux? Far too many to list. You can easily find hundreds of public examples. This terrible wikipedia page provides a decent starting point with a list of names to google https://en.wikipedia.org/wiki/Linux_malware https://en.wikipedia.org/wiki/Linux_malware
- zik 7y ago> you regularly see downright absurd stuff like this That's a bug which only occurs on five year old distributions and which was fixed years before any exploit was ever found. Honestly if that's being brought up as a bad example Linux is looking pretty good compared to other operating systems.
- RaleyField 7y agols -l ~/.bashrc and by design.
- 7y ago
- coribuci 7y ago> In Debian, I can be reasonably confident that no information leaves the system without my authorization. Only if you are not running a webbrowser > Edit: Just out of curiosity, am I wrong in mistrusting Microsoft, or in trusting Debian? Only fools trust Microsoft (or Google, or Facebook). I slightly hoped they were turning in the right direction in win 2000 and xp and even 7. But vista and the rest shown their true nature. About Debian i have mixed feelings. On one hand they are a very respectable distribution, on the other hand - systemd.
- mirimir 7y ago> Only if you are not running a webbrowser Touché. I am not hard-core enough to browse in terminal. I don't use Chrome/Chromium though. I actually rather like systemd. Most of the time, at least. But yes, I know the controversy. So do you like Devuan?
- Fnoord 7y ago[1] (Debian had a weak PRNG for ~2 years in ~2006-2008) teaches us every distribution or OS vendor can make huge mistakes, with very simple actions (ie. the systems are complicated). (I'm not saying you should not trust Debian though.) I do wonder if a stateful OS such as nixOS can help mitigate the threat of malware easier (sans extradition of data, for that we'd need capability-based security, or something like pledge). If it'd be user-friendly, like TimeMachine, that is. [1] https://www.schneier.com/blog/archives/2008/05/random_number_b.html https://www.schneier.com/blog/archives/2008/05/random_number...
- scarface74 7y agoHave you personally audited every line of every piece of code in your Debian install? The usual retort is “many eyes”. How “many eyes” were on the OpenSSL vulnerability that was in many open source distributions for a year and a half.
- codedokode 7y agoIs that so? Chromium browser, distributed in Debian repositories, sends a signal to Google (with cookies) every time you open new tab if you use Google as default search engine (you can easily verify this by opening a new tab, running developer tools and refreshing the tab. The URL is https://www.google.ru/_/chrome/newtab?ie=UTF-8 https://www.google.ru/_/chrome/newtab?ie=UTF-8 and it has headers preventing caching).
- mirimir 7y agoNo sane person would use Chrome/Chromium and Google, and expect privacy.
- dmix 7y agoGetting rid of AVs is old news. If almost no one in infosec trusts using them then why bother? https://twitter.com/justinschuh/status/802491391121260544 https://twitter.com/justinschuh/status/802491391121260544 https://robert.ocallahan.org/2017/01/disable-your-antivirus-software-except.html https://robert.ocallahan.org/2017/01/disable-your-antivirus-...
- trilila 7y agoSometimes i get the feeling some are contrarian only for the sake of it. Advocating using windoze without av is like advocating not using condoms because it doesn't feel good.
- chmod775 7y agoWindows with its built-in Windows Defender and your Common Sense 2019 Computer Professional Edition is going to be enough nowadays.
- trilila 7y agoAs a rare windows user (two or free times a year) i never trust a machine without an av. maybe things changed, but i see windows as so unsafe that i would not even login with to regular email, let alone make online payments. I simply see that os as a vulnerability by default.
- chmod775 7y agoI don't run Windows myself, but honestly: Remote exploitable Windows vulnerabilities on a default install are somewhat rare nowadays. MS has come a long way here.
- trilila 7y agoI remember the smashing the stack for fun and profit windows days. It was so easy to inject shell code it was laughable. Btw can you still name a file smss.exe, run it, and not end the process with the task manager?
- mkl 7y agoThe last paragraph of the article was particularly astounding on this point, in that it explains how to disable the script injection rather than purge all Kaspersky software from the computer. That seems to contradict everything that preceded it.
- chmod775 7y agoI know how to uninstall software. I probably wouldn't know where to disable a particular feature or that I could disable it at all.
- mkl 7y agoI guess I don't understand why anyone would want to leave it installed after that magnitude of trust violation (silent privacy-destroying MITM of HTTPS traffic by default). Why do you? Edit: Or maybe I'm misinterpreting?
- noisem4ker 7y agoNot everyone is able to choose what software is installed on the machine they use. Especially for AV, that may be enforced by the company one works for.
- wolco 7y agoWhat company is using Kaspersky? Aren't they on US security blacklists?
- chmod775 7y agoThis may be surprising, but there's people outside the US. In fact more than 95% of people are not presently in the US.
- wolco 7y agoIt would be surprising if 95% of businesses outside of the US use Kaspersky. It would be surprising for any large company using them. Most installs are from individual people in and outside of the US.
- ignoramous 7y agoAndroid AVs are data hoarding goldminers. The Android ecosystem is replete with AVs with questionable privacy policy. To me, it seems like most utilities on Android (like AVs) solely exist to compromise user's privacy. Some even bundle in free VPNs (and you can straight away guess why it's free). One of India's largest telecom networks, known for self enforced censorship via deep packet inspection, has an AV on PlayStore with 10m installs. Some excerpts from their privacy policy [0]: > Reliance Jio does not sell or rent any Personal Information. Followed by: > Reliance Jio may provide your information or data to its partners, associates, service providers and third parties as necessary or appropriate > Any personally identifiable information provided by you will not be considered as sensitive if it is freely available and / or accessible in the public domain. [0] https://www.jio.com/en-in/jio-security-privacy-policy https://www.jio.com/en-in/jio-security-privacy-policy