Do you still trust Kaspersky AV?

w1z4rd

Karmic Sangoma
Joined
Jan 17, 2005
Messages
52,146
Reaction score
8,340
Location
127.0.0.1
So I like to install different AVs on various PCs in my office. Mostly to test them out and secondly to add a tiny layer of obfuscation to my setup. A company with only on AV (no matter which one you use) is always easier to crypt and get around than multiple different AVs on a network. So today I decided to reinstall the AV on my laptop and I was going through the top performing AVs and both Bitdefender and Kaspersky feature really high. I have a Bitdefender install already on one of the PCs so I was thinking about installing Kaspersky.

As I sat waiting for the file to download I was reading up on the company behind it. Kaspersky Labs. They are very much a Moscow based company.. which has me concerned.

1) The owner is ex KGB/FSB (thats one super tight club that people who leave are sometimes killed)
2) There is no major business in Russia that is not directly in control of Putin and the Kremlin. You are either part of the group and pay them their tithe or you are found guilty of tax evasion and your company is confiscated from you (this is well documented)
3) Putin is very familiar with using asymmetrical warfare and based on his dirty methods of messing with democracy and invading countries like Georgia and Ukraine. I simply dont trust him. At all. This is exactly something he would do. Its too big an oppertunity not to.
4) Under Federal Law in Russia they are allowed to ask Kaspersky to install backdoors or subtle monitoring systems.
5) In 2015 Bloomberg accused Kaspersky of having very close ties to Russian intelligence and military officials. A claim he called "sensationalist" and "exploiting paranoia", but a claim he never denies...
6) The close ties between Kaspersky and the FSB to me is highlighted in how they broke the Stuxnet and Flame stories.
7) A good indicator that Kaspersky has some political influence is how they gun for American intelligence viruses and trojans but never say a word about what the FSB are producing...

For me to trust this AV is too big a leap of faith for me. I read too much news on the Russian and Putin to trust anything they say. I know too much about Russian tactics to trust this software.

I do understand I could be very wrong. That Putin has decided to keep the integrity of the software rather than use it as a powerful digital weapon. I could also believe that somehow Kaspersky is not BFF`s with intelligence and that somehow he managed to leave them without owning them anything. I could also believe that he managed to retain control of his company because he really is just that awesome.... but I cant. There are just too many red flags for me when all the information is combined.

So personally, I will not be installing it. Do geopolitical events and politics impact how much you trust a product? Do you even care if the FSB have access to your machine?

I know many countries practice surveillance and to a degree I am not too concerned about them as most are functioning democracies with governments that can be held accountable. As we saw with the Snowden leaks and the NSA getting its surveillance powers curtailed due to overreach.

I want to install Kaspersky, but I am too skeptical to. Russians can often make wonderful software (Such as Telegram), but I cant trust a company with my security that is in bed with the Kremlin.

Further reading:

http://www.bloomberg.com/news/artic...ity-kaspersky-has-close-ties-to-russian-spies
http://www.wired.com/2012/07/ff_kaspersky/
http://www.wired.com/2012/07/kaspersky-indy/


Do you trust the product like you used to? Does Russia having access to your information upset
 
I personally use Eset because it's lighter, but I have no doubts about Kaspersky and it's quality.
I always recommend Kaspersky.
 
I personally use Eset because it's lighter, but I have no doubts about Kaspersky and it's quality.
I always recommend Kaspersky.

Ive got ESET already on one of my machines. Despite its poorer performance this year :/

Kaspersky ranks really high. Top performer like Bitdefender. I really want to install it, but I cant bring myself to take that leap of trust.
 
Last edited:
When I still used Windows a couple of years ago I always used Kaspersky.

A lot has changed in a couple of years. Two years ago this would not be a concern of mine either. The ability of the software in question is excellent, which is why this is frustrating for me :P
 
You'll probably find more NSA backdoor software on your machines already than from the Kremlin.
 
You'll probably find more NSA backdoor software on your machines already than from the Kremlin.

Could very well be. Im not as worried about the Americans having my data (which they already do... I have a Gmail account) than I am with Putin having access to my data. I have data and communications I would prefer the Kremlin do not have access to.
 
Could very well be. Im not as worried about the Americans having my data (which they already do... I have a Gmail account) than I am with Putin having access to my data.
I'd boycott the Russkies for Putin's shady nuke deal with Butternut 1, so do what you feel is right for you.
 
Every software is always under scrutiny and especially av are tested by security analysts to determine if there are vulnerabilities. This includes analyzing web traffic from said applications on multiple levels. Kaspersky is a cash cow for the Russians so any credible accusation is a threat to their business.

You won't find american government using it, for the same reasons as they don't allow Chinese mobile towers in America: market protection thinly veiled as security concerns. The Russians are rightly concerned over clandestine back doors that was exploited by stuxnet because it was used against American agitators and likely planted by American and Israeli software engineers. Stuxnet was first uncovered by Kaspersky so this should speak to their expertise.

So the question I suppose is who do you fear the most, the yanks or the ruskies? Av is not such a critical function to the average user but big companies who have data to protect will balance the risk of having high volatility protection with the risk of economic espionage. If you just want your less clued-up staff to avoid the pitfalls of free smileys and annoying toolbars, I don't expect big brother will be very interested in what you have stored on your systems.
 
MSE and malwarebytes + some smarts is all you need.

No, you don't need to download the 300kb game "keygen".

No, not really. You can easily crypt past MSE. Not a ****. I suppose for an average user with absolutely no confidential data on their systems that might be okay. Assuming you never become important enough to be spearphished. MSE is pretty much at the low end when it comes to detection rates.
 
Could very well be. Im not as worried about the Americans having my data (which they already do... I have a Gmail account) than I am with Putin having access to my data. I have data and communications I would prefer the Kremlin do not have access to.

I'm sure if Kaspersky was doing anything nefarious people wold have picked up on it by now.

ghoti said:
I suppose for an average user with absolutely no confidential data on their systems that might be okay.

If that's the case why is the computer connected to the internet? Treat everything connected to the internet as if it's been compromised friend, don't panic but also don't store any extremely sensitive info on the system either.
 
I'm sure if Kaspersky was doing anything nefarious people wold have picked up on it by now.
No, thats not a thing. This new stage of Russian government evolution is only 2 years


If that's the case why is the computer connected to the internet?
Thats how I communicate and I have incredible levels of security.


Treat everything connected to the internet as if it's been compromised friend,
I am very very careful thanks.


don't panic but also don't store any extremely sensitive info on the system either.
Considering the amount of encrypted communications I get through it... that would be implausible.
 
FYi your gmail is not available for perusing without reasonable suspicion of terrorism, and any other type of subpoena is very public.

I don't think measuring the Russians and the Americans by the same yardstick is a fair approach. The ruskies are simply not in the same league when it comes to mass surveillance. Their it industry is negligible compared to us and even their space program is run using American microchips (which congress wants to sanction because of Ukraine).

They are furthermore chronically distrustful of U.S. surveillance so storing vast quantities of personal information is unlike them. What are they going to do with your credit card etc anyway? I think your mistrust is misplaced and you give them way too much credit.
 
Maybe you should worry more about that phone/tablet/laptop of yours with the "Made in China" label . In the same note, this is what Huawei said when accused, and i am certain Kaspersky will say the same thing. They would be taking an INCREDIBLE risk . If they are caught the company is dead overnight. I mean think about it, in a world riddled with hackers deciphering code, it's just plain stupid.

So from a business perspective, it doesn't make sense to build in holes/backdoors/FSB-espionage tools , even the russians themselves are suspicious of their own government (much like we are of the ANC) and even their own hackers would expose Kaspersky if they were colluding with the FSB to breach our data.

http://www.theregister.co.uk/2014/04/25/huawei_responds_to_spying_allegations/
Chinese hardware manufacturer Huawei says allegations it provides backdoors for espionage in its kit remain unproven and would be “commercial suicide”.

“The hypothetical - that our equipment could be used for espionage by the Chinese government - has never been proven,” spokesman Scott Sykes told press at the company’s annual global analyst event in Shenzen this week.

“If it were ever proven, we would lose 65 per cent of our business overnight. That would be corporate suicide.”

As the world’s second largest networking equipment supplier, Huawei has raised concerns amongst Anglophone spooks. It was banned from bidding for contracts for the Australian national data backbone.
 
Last edited:
First of all, what are you doing that makes you so worried about the Russkies? ;)

In reality the minions do not matter to these global powers, unless you work in some high profile job or have access to certain systems. But even this argument does not hold water. I've seen bespoke malware and new malware that runs through anything.

That said, I am a Kaspersky fan, even if not a Russkie fan.

But then I'm no Yank fan either. As for the allegations ...
We need to look where much of this is coming from. Cisco and the US government had a lot to say about the Chinese, especially Huawei. In reality it was all negative marketing and smear campaigns to ensure a better market for US products. However do not open those US products (oops, made in China). iPhone? The argument is that the US monitors quality etc. Sure. As for Cisco? We all know what Snowden revealed. Talk about the pot calling the kettle black. Still, nobody can doubt the quality of Cisco products. Nor iPhone.

I apply the same logic impartially to Russia and Kaspersky.

Why am I a Kaspersky fan? Yet also have Wireshark, an invisible Linux bridge etc? :D

In some of my work with clients, even a college (talk about stress testing - students), I've seen nasties that numerous other packages mentioned here can't completely remove. Some aren't even detected. However some are good at destroying legitimate apps (especially security apps). At some stage manual intervention is required. However, a quick answer is to download a Kaspersky trial, update and run it. So far this approach has worked well.

Further I think we need to appreciate a lot of nasties are made in Eastern Europe and a certain area a bit south east. The Americans are mostly the target. As such Kaspersky is very close to the source. Add to that their involvement in the community. The Americans will tell you how their products fits into your need for defense, but not listen to you, at least not really, they are more interested in your wallet. The European's are a bit more open. However Kaspersky's staff are approachable where you encounter them. I submitted a few bespoke attacks to them. Two days later the malware was being removed. Their whole approach to security is vastly different.

I have seen things that Kaspersky slipped up on, but another package caught. But all in all, Kaspersky has been best.

Yet you have to decide for yourself. Also remember - no AV is total 100% defense. Apply common sense.
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X