• @pandapoo@sh.itjust.works
    link
    fedilink
    English
    15
    edit-2
    22 hours ago

    Yes… no… sorta…kinda… but no different than how most, if not all, large American security and tech vendors have either overt, or covert, links to the the American Security State.

    Kaspersky is a long established credible actor and leader in the threat research space, hands down one of the best track records over the long run, and you should take their reporting and disclosures seriously.

    I’m not saying that to dismiss the very valid concerns about installing Kaspersky on sensitive private sector and government systems, but to contextualize my answer.

    On a sort of related note, earlier I said that the American security state has both overt, or covert, links all across the American tech sector.

    What that means is that, even if a company holds their principles not compromising their customers or their product, the US government can either get a court order to force it, or they’ll be targeted by something like the Pentagons Signature Reduction program and have sheep dipped employees worked into their organization.

    Point is, Kaspersky is one of the few remaining Russian brands and entities still holds a lot of credibility in it’s field, but again, that doesn’t mean the concerns of Western government’s aren’t valid, just that they should be viewed in the proper context.

    • @Zementid@feddit.nl
      link
      fedilink
      English
      110 hours ago

      Great explanation! So, to summarize: They know their trade but their software should not be installed because it’s like with US Software: Backdoors Likely Integrated.

      On the other side, I still use some Google Products…

      • @pandapoo@sh.itjust.works
        link
        fedilink
        English
        1
        edit-2
        3 hours ago

        No problem, happy it helped.

        Your summary is mostly accurate, but I think a better way to understand it would be like this:

        Low level security software, by nature, is the ultimate attack vector, if compromised.

        Assume that all countries that have both a domestic tech sector, and a well-resourced national security apparatus, have some version of on demand government initiated supply chain attack capabilities.

        So it’s not like I believe that all Kaspersky installs include a RAT piped directly to some GRU/FSB unit, just the ability for a malicious payload to be inserted - just as the NSA can do with American tech companies.

        Not every risk can be mitigated, but some risks just shouldn’t be taken.

        • @Zementid@feddit.nl
          link
          fedilink
          English
          13 hours ago

          The difference for me is: As for now, the US is not run by a fascist (yet). Injecting Malicious Software to bust terrorism/mafia/corruption… ok,… Injecting Malicious Software to kill gays/opposition… Nope (and that is what I would expect the Russians to do)