back
143 comments
I will go on the record here and one-up them, warning against the use of any antivirus product. SO many vulns and gaping, smoking holes in that kind of software over the years, it's not even funny. Faux-security is what most vendors are peddling.

https://twitter.com/GossiTheDog/status/1427935182200492039 is one of my favourite bugs from recent years. I acknowledge this bug is not specific to an antivirus product (but of course, Fortigate offers that as an optional component for traffic inspection - and I keep wondering what that sub-component's code quality is like 8-)), but anyone who tries WILL find examples for grave problems aplenty.

Yes, basically this. On the one hand, being able to parse every protocol and file format under the sun in search for malware means high complexity and a lot of attack surface. On the other hand, being able to read every file, intercept all network traffic, or peek into any processes memory means pretty much highest system privilege level. Big attack surface and high privilege level are a bad combination.

And regarding the point that the BSI is trying to make here: A high privilege process with an auto-update channel back home (as modern software tends to have), is basically an extremely powerful backdoor. That's definitely not something you want to have installed across loads of systems across your countries industry and critical infrastructure.

It's funny that they apparently only realize this now. The same reasoning in the article can be used pretty much regardless of the AVs country of origin.

It's definitely reasonable at this point to just skip using AV. It won't protect users from bad security habits and it tends to make your system performance worse even if it doesn't have vulnerabilities.

I have Windows Defender enabled on my machines since it comes with the OS (and work policy requires it), but I definitely had to exclude most of my work folders to be able to get work done.

It would be nice to have software that specifically blocks ransomware by trying to detect it heuristically, but that would probably not be very effective and the right solution is just to have backups.

Most insurances expect you to have an AV installed.
My favourite part of this tweet is the down-thread reply from the author:

"In fairness MSFT are really good in terms of web facing things, particularly security things." [1]

This, of course, aged like milk the very next month. [2]

[1] https://twitter.com/GossiTheDog/status/1427966653938143233

[2] https://www.paloaltonetworks.com/blog/2021/09/azurescape/

That's bad advice. It's a trade-off. Installing antivirus opens some security holes and closes others. It also adds heuristic analysis. It seems to me that the security world has come to the consensus that AV is better than no AV.
I warn about using any kind of snake oil.

Often sold under the marking terms "antivirus" or "personal firewall" or "cloud cyber security". Known side effects of this treatment are high CPU load, high RAM consumption, drain of battery power. Sometimes they also consume your money or looking at your data. So far I would consider other counter measures, like applying user rights, proper package management and re-consider your decision using this random stuff from the internet? If you're forced to use Windows the one with the least known side effects is Microsoft Security Essentials but even this has several drawbacks. If you're already using Linux or some kind of BSD you probably applied already these measures accordingly.

PS: This doesn't mean you shouldn't make sane use of software looking expectantly for malware. If your are a server admin and hosting a mail server which faces random stuff from the internet it makes sense to filter out bad stuff. And it won't spin up the fan of your laptop or drain its battery.

"If you're forced to use Windows the one with the least known side effects is Microsoft Security Essentials but even this has several drawbacks."

But permanently disabling it is very, very hard.

Anti virus can be very helpful in corporate environments if set up right and managed by knowledgeable people. Those people are expensive, but they're life savers when John from marketing clicks the "enable editing" button in a spreadsheet he just received from a spoofed email address.

The problem with corporate security is that security vendors often try to shovel as much crap onto your network as possible, rather than set you up with the security system you need. It's not hard to set up a company wide system that shows all green checkmarks and has tons of tray icons running to assure upper management that everyone's computer is now secure, especially with duplicate features and multiple daemons that a talkative sales rep might try to slip in for that sweet commission money. You also need someone competent to look through logs, keep checks on what's going on, and not get fired or demoted if they don't report anything new (because if you're lucky, there's nothing new to report).

For smaller businesses, the best you can do is hope for the best, really. Keep your consumer AV running and try to stick to common security advice, because there's no way you'll be able to get much use out of common business AV products if you don't have someone in your company who knows how to use those tools.

For consumers, Windows defender is often a decent balance. It's pretty good at detecting viruses, doesn't get in your face all the time, and although there's definitely a performance impact, it's low enough that office work shouldn't be affected by it too much. As a dev, I hate how much it gets in the way of many applications (especially those accessing many small files, like compilers), but I realise that this isn't exactly the most common workload for AV.

Though actually I installed kapersky free edition on an older comouter because it was fairly light and well behaved. Has a good reputation for catching things too. But yes I should really think about removing it now and I'm sure we all have sympathy for the trusting victims who paid to upgrade their bundled mccafee/Norton/sympatec and were worse off for paying extra....
I agree with the snake oil sentiment, and wanting a tool to monitor connections on a per application basis but being dissatisfied with everything I found, I wrote my own (https://elesiuta.github.io/picosnitch/).

Only then did I discover that creating any sort of tool that is running on the same machine it is supposed to protect, if malware is also on said machine, is basically a fool's errand.

I tried to overcome as many of the pitfalls as I reasonably could, but reached a point now where the best approach is to just document any remaining limitations and some of the other counter measures you can use.

There's a lot of anti-antivirus sentiment in these comments, and while I, too, hate AV and have grown up with it being nothing but snake oil, I wonder if that's still correct in the current era of "zero trust".

I think we've learned that corporate firewalls and VPNs don't really work all that well. In other words, if you can't rely on a safe boundary to the outside world, how do you ensure individual corporate machines are not compromised? What about newer software like Crowdstrike?

What do the big tech companies like Google, Microsoft, Meta, etc do on their employees computers? Do none of them use antivirus?

I feel traditional antivirus software is the very opposite of zero trust. It runs at a very high level of permissions and intercepts almost everything.
Kaspersky is indeed FSB controlled, lot of proofs of that in last 10 years, but of course they will not just upload all your data or brick PC in revenge for sanctions (well may be they will if told nuclear war has been started). They will behave according to the agreement, and just let FSB peek a bit for data they legitimately getting. Same as Microsoft / Google / Apple / Amazon etc. relationship with multiple US spying agencies.
Google translate: https://www-bsi-bund-de.translate.goog/DE/Service-Navi/Press...

(For the none German speakers)

The DeepL translation (deepl.com) seems to be a bit better:

# BSI warns against the use of Kaspersky antivirus products

The Federal Office for Information Security (BSI) warns against the use of antivirus software from the Russian manufacturer Kaspersky in accordance with §7 of the BSI Act. The BSI recommends replacing applications from Kaspersky's portfolio of antivirus software with alternative products.

Antivirus software, including the associated real-time cloud services, has extensive system permissions and must maintain a permanent, encrypted and unauditable connection to the manufacturer's servers for system-related reasons (at least for updates). Therefore, trust in a manufacturer's reliability and self-protection, as well as its authentic ability to act, is critical to the secure use of such systems. If there are doubts about the manufacturer's reliability, antivirus software poses a particular risk to an IT infrastructure that is to be protected.

The actions of military and/or intelligence forces in Russia, as well as the threats made by the Russian side against the EU, NATO and the Federal Republic of Germany in the course of the current armed conflict, are associated with a considerable risk of a successful IT attack. A Russian IT manufacturer may itself carry out offensive operations, be forced to attack target systems against its will, or itself be spied upon as a victim of a cyber operation without its knowledge, or be misused as a tool for attacks against its own customers.

All users of antivirus software can be affected by such operations. Companies and public authorities with special security interests and operators of critical infrastructures are particularly at risk. They have the option of seeking advice from the BSI or the relevant constitutional protection authorities.

Companies and other organizations should carefully plan and implement the replacement of essential components of their IT security infrastructure. If IT security products and, in particular, antivirus software were to be switched off without preparation, they might be left defenseless against attacks from the Internet. Switching to other products involves temporary losses in convenience, functionality and security. The BSI recommends that an individual evaluation and consideration of the current situation be carried out and, if necessary, that BSI-certified IT security service providers be consulted.

Press contact: Federal Office for Information Security Press Office Tel.: 0228-999582-5777 E-mail: presse@bsi.bund.de Website: www.bsi.bund.de

Twitter: @BSI_Federation #GermanyDigitallySecureBSI

> (For the none German speakers)

I'm sure there's a few for sure!

/s Thanks for the Translation

It's curious to look on at this situation from Linux. Perhaps I shouldn't be too comfortable but it's really a different world. I suppose that one should take care which distribution one uses as that is also an effective entry point for software from the outside but at least a bit more obvious and open than some AV company.
I'm anxious to see what the Steam Deck, one of the first popular, user accessible Linux computers, will do to the Linux landscape.

For ages now, Linux has been relatively virus free because let's be honest, Linux is either used by just a few nerds (who are often just a tad harder to trick than the tech illiterate) or by servers, for which entirely different classes of malware exists.

With effectively no antivirus protection, either because of a lack of options or because the outdated mantra that "you don't need it" because of some peculiarities that Apple used for years to deny the existence of macOS malware, Linux users are bound to run into viruses sooner rather than later. Hackers that are after Steam accounts will definitely try their hardest to infect Linux desktop users.

My best hope is that the way Linux distributions are woefully incompatible with each other will protect the hardcore Linux users somewhat from the viruses that will inevitably be spread across the "common" Linux environment. I'm sure we'll see Flatpak/Snap viruses down the line, but for a short while, we'll hopefully still have time to see where the Linux landscape is headed.

As a 25 year Mac user, I concur.

I'm just glad that Microsoft eventually decided to bring antivirus in-house, and I don't ever again have to mess with 3rd-party security products for my Windows box

The potential issue I see on Linux is the spread of third party distribution channels, like npm / pip / etc, which also tend to undergo much less scrutiny than official packages.

Sure, if someone gets root on my Linux PC, they could do a lot of damage. But my most important things are parked in my home folder, which any old script running as my user can access without any problem. No need for privilege escalation or other fancy things.

AppArmor and SELinux can probably mitigate this, but I don't think they see particular widespread use in "default deny" mode.

Linux is very secure by default, if you stick to open-source software and install it from the distro package managers. What I worry about is when Linux becomes more popular, and commercial software is ported over, and people start pirating it. The door is wide open when people start typing their root passwords into keygens. I expect the Linux world will have a revelation where they discover the power of AV.
With the fast moving legal landscape in Russia this seems like a smart move. Given the new laws getting added in Russia now, a law coercing Kaspersky to help the Russian government attacking its customers that Kremlin sees as enemies. Do not seem that far fetched.
This is interesting news but I think it's more about sanctions/politial pressure than an actual threat to general businesses and people.

Once a zero day or backdoor has been used its burnt forever, nation state intelligent services need to be incredibly careful about when and where they use them. If one was to be placed in a Kaspersky product and used, that's Kaspersky burnt as a business forever, and with it the ability to use it as a vector for high value targets. They are not going to use a backdoor in a Kaspersky product for a general attack on people and business, at least not at this point. Realistically any high value target in the west isn't using Kaspersky anyway.

> more about sanctions/politial pressure than an actual threat

I think this would be one of their hybrid warfare steps (well) before actually going nuclear.

You seem to be assuming a lot of things, like that Kaspersky couldn't deploy certain updates to targeted customers? That malware will leave behind trails of how it got on the computer? That plausible deniability is impossible?

What happens when a definition update "reduces false positives" but actually lets in a Russian cyberweapon that is delivered independently?

I'm reading this as I am giving a class on Stuxnet this morning.

We're doing worms and multi-stage malware. But inevitably the conversation turns to national boundaries, cyberwar, collateral damage (to individuals, hospitals, power plants, companies..). My students want to understand the relations between companies like Microsoft and the NSA, what happened to Siemens from the economic fallout, why the Iranians would be running Windows? Who paid to clean up the tens of millions of infected machines out there? I keep getting questions that begin "Bit surely....?"

We've been through an unprecedented period of human history in which the internet brought us together. That time is over.

The fact that a Russian company could trade freely in the world such that American companies, only within a decade of the Cold War, would use Kaspersky (which I believe is an a good product) is absolutely remarkable.

It's what Richard Buckland called "A miracle of interoperability" that allowed a movie made in Hollywood to be recorded on a DVD manufactured in China to run on a player assembled in India, according to standards designed in Nederlands and Japan, playing in a home in Australia.

That level of trust and cooperation has to run both ways. It's at least as remarkable as Russians, Chinese and Iranians running Microsoft Windows. The internet delivered on much of its promise to unite the world. But what I've seen in the past 5-10 years is so much effort by everyone to _undo_ that trust. Greed and surveillance capitalism has played as much a part as gobernment intelligence over-reach and economic warmongering. All parties have abused trust and now we are withdrawing into silos again.

From a business perspective, maybe we'll need to reckon with a future more centred around domestic sales and use. Perhaps the "splinternet" is just the beginning of a global divergence at the protocol level.

How can we (proponents of a true INTER-net) avoid this?

> [...] "A miracle of interoperability" that allowed a movie made in Hollywood to be recorded on a DVD manufactured in China to run on a player assembled in India, according to standards designed in Nederlands and Japan, playing in a home in Australia.

Well, it can be played in Australia only if its DVD region code is 4, and it cannot be played in any other countries you mentioned, which are all in different regions (USA: 1; China: 6; India: 5; the Netherlands and Japan: 2). So there's that. "A miracle of interoperability."

https://en.wikipedia.org/wiki/DVD_region_code

Decentralization from meshnets up. The user agent needs to handle the entire electronic presence, establish the identity of it's user, and keep watch on its friends like a herd.
I am not an IT professional but a bit confused by how many completely negative views there are here on AV use. I have a NOD32 license and at least twice per month a url is blocked while browsing in an unobtrusive way by the software, which makes sense as may have contained malicious JS or something. Maybe it would've been caught by ublock afterwards, or may have been caught by MS defender as well, but I like the assurance provided. You can argue that I'm browsing in an unsafe manner but I doubt many of you restrict your browsing to strictly "safe" chunks of the internet.
The point is that the AV does not do much here. The security model should be proper sandboxing within the browser, along with block lists that get used by ublock origin if you wish. A third party program running alongside your browser, inspecting the URLs you visit (possibly then via TLS certificate MITM?), is just a weird way to think about security in my opinion. Not even talking about the potential new attack surface that may be introduced in some way.
The illusion of cybersecurity is finally being questioned.

AV scanning emails has been a phishing scam for decades which benefits the criminals.

Because so many people have worked on so many parts of a computer beit the hardware or software, who do you trust when you dont trust random strangers in the street and people like to gossip and spread rumours? Is this a classic case of cognitive dissonance or just shows giving money for something makes someone/something instantly trustworthy when their own survival comes before yours?

This ban on Kaspersky in software is similar to the US ban on Chinese Huawei for 5G.

What I am really waiting for is a ban on cloud services like Github. Since Russia is now basically even more rogue than Iran, I bet something like this here is in the making: https://techcrunch.com/2019/07/29/github-ban-sanctioned-coun... And it's reversal till this day: https://github.blog/2021-01-05-advancing-developer-freedom-g...

Cybercrime is still a thing in Russia.

The same warning obviously applies to all the American AV vendors, given what we have learned in the last years. And this is not idle speculation and baseless accusations, it's right from the inside part of the NSA and CIA leaks.

So what is one to do? Where is the free open-source AV the world needs, which has the same number of highly skilled full-time developers and researchers as Kaspersky does?

There really needs to be a global AV effort and software, funded by governments, but open and transparent, and based in a country which does not sit in the shadows of over-reaching spying agencies. But what will it take for this to happen?

What about Telegram?
The client is open source, so should be quite safe and the company is not based in russia. But I think some servers are?

In either case, it is not a medium for secure communication anyway.

I use it more as a open forum software.

It’s been interesting to note how Kaspersky has been responding to the scrutiny. It’s almost always the same - ”we have been audited a huge amount of times and no-one has ever found anything!”

It’s suspicious because as someone who is a vendor of risk management, they’re leaving out the gaping hole fact which is that software is updateable and oftentimes AV will do so automatically. Potent risk is pretty huge.

Same applies also to the Huawei discourse.

But this applies to any software that has auto-updates. Can we be sure that Microsoft/Google/Apple don't sign backdoor updates for the NSA for specific targets? As far as I know these national security orders are non-public and we don't even know if it's happening.

But Russia used Ukraine in the past as "playground" for cyber attacks: Some mandated tax software auto-update was hackend and delivered a ransomware trojan without any chance to pay i.e. pure data destruction.

We supply servers running some proprietary control software and a school district put Kaspersky on it after receiving it. We mentioned to them we can't be involved with that product anywhere because of our companies involvement with DFARS, and frankly we are surprised they were able to get away with using it being a government organization. Still there though, guess they just don't care.
This is interesting news, but submitted content must be in English on HN.

Edit: Take it from dang, not me: https://news.ycombinator.com/item?id=27571809

Aside from avoiding Kaspersky on important division in western world is practical, I wish Kaspersky survive. They are great about detection and analysis and not based on western world.
What anti-virus (if any) does one recommend their 60 year old parents on a Macbook...?
What do you guys recommend? Windows defender or?
clamwin is actually light weight and nicely unintrusive
Why are they even using Windows?

The US is not an ally either.

So they basically say Russia can spy on you if using Kaspersky (but the German government, or its "allies", can't). Then, I guess that using Kaspersky is a wise decision unless you happen to live in Russia or Ukraine. Dowloading ;-)
Seeing that the west just killed off payments in the Moscow metro, stopped security patches for Cisco networking equipment etc. etc. There is a bit of projection going on: We fear that Russia might do to us, what we just did to them.

But what is the end result of this? Any "potential enemy of the west" will have to do their own tech, and we will only use our own stuff. Sounds like a bad trade for us; instead of selling all this stuff we have already made for a nice buck, we now insists that everyone makes their own.

Little bit worried about Jetbrains products as well. I think they have development centers in Russia? Not worried about company, but rather some disgruntled employee, for example put this USB stick to your computer or otherwise we will prosecute you or your close one for participating in protests or some fabricated accusation.