Hacker News new | ask | show | jobs
by MisterWebz 3921 days ago
They've been gunning for Kaspersky ever since Kaspersky released information about state-sponsored malware.
7 comments

Who is "they?" Tavis Ormandy is a respected security researcher who often makes the news. Hell, not too long ago he found exploits in Sophos and Symantec products. He likes to target AV. Sophos, a UK product, was embarrassed internationally by the exploits he found. He is not playing any favors here. We need more people like him. AV has gotten a free pass for far too long.

If you're attacking Ormandy's character, I'd appreciate some proof over the usual conspirtard stuff that often gets upvoted uncritically on sites like reddit and HN. As far as I can tell, he is certainly one of the good guys and we are lucky to have him in such a high profile position at Google.

>Kaspersky released information about state-sponsored malware.

Kaspersky acutally is the dirtiest of the bunch with ties to Russian KGB/FSB. I suggest you rethink who your heroes are.

http://www.bloomberg.com/news/articles/2015-03-19/cybersecur...

http://www.wired.com/2012/07/ff_kaspersky/

Kaspersky is smart. He enjoys breathing and wants to avoid radioactive tea.
I'm guessing most people will miss the reference to https://en.wikipedia.org/wiki/Poisoning_of_Alexander_Litvine... so I'll just add a link.
This is my concern with any software from an obviously corrupt and autocratic state that attacks its citizens with impunity. How can I trust anyone there when they certainly, and rightfully, value their lives over my rights? No Russian is going to say no to the FSB torture machine. No one is going to become any sort of whistleblower. I would see any Russian software as being dangerous to run at this point and things only getting worse considering Putin's brazen anti-West attitude.

Maybe Kaspersky was safe to run once, but that's just not true anymore.

Plus, if I'm not confusing him, Tavis used to make some kick ass FVWM configurations. The kind of window manager stuff that you see in SF movie computers.

A really cool dude.

You're insinuating that Google is gunning for Kaspersky at the bidding of their NSA masters (or something)?

How deep does the rabbit hole go?

It's rabbits all the way down!
I'm suggesting a higher-up or someone else suggested Tavis target Kaspersky. I'm not suggesting Google execs all sat together and decided to destroy Kaspersky.

Is it that hard to believe that there are certain people that would like to dissuade Kaspersky from revealing further information about state-sponsored malware? I'm not even sure where this incredulity is coming from? Let's see you target an intelligence agency and see what happens.

Are you trying to imply Kaspersky are somehow a victim...? Installing their security product actively decreases your security in this case. That destroys their entire reason for even existing.

Kaspersky is no victim here. They've been so negligent in their own product's security that it is actively harmful to have it installed. That's literally the end of their product being useful for me and it applies to any other security company as well. I hope the rest of them get 'suggested' too, and soon! I'll be clear - this vulnerability is the one thing Kaspersky should have been spending their engineering resources on and they have failed utterly. Pack it up and close shop.

I would say Kaspersky should thank their lucky star Google has sponsored such research. This is priceless info.
Clearly you could not be less familiar with Tavis :)
Making their software safer, that'll learn 'em.
Bear in mind that they conclude the article with a complement to how quickly the issues were resolved and that the next one is due soon.
That doesn't make sense given that they have already broken two other antivirus in a similar fashion and they commented

  Thanks to Kaspersky for record breaking response times when handling this report, they’ve set a high bar to beat for other vendors! 
I wonder how fast they were given the comment about 'high bar'.
Suggesting that Google's allies want to keep the word on state-sponsored malware at a minimum?
How exactly are they able to introduce exploits into his code?
Into whose code? He found several bugs and is now writing about it. I'm not sure if I understand your question?