95
submitted 1 day ago by [email protected] to c/[email protected]
top 27 comments
sorted by: hot top controversial new old
[-] [email protected] 5 points 3 hours ago

Doesn't the play store have their "Play Protect" thing they're always shoving in my face? Why didn't that pick this up before 11 million people installed the app?

[-] [email protected] 6 points 9 hours ago

Whatever. Kaspersky is an FSB spy tool. You should not have any of their software installed on any devices.

[-] [email protected] 110 points 1 day ago

i fucking hate titles that start with "This".

[-] [email protected] 1 points 1 hour ago

I'm more of a "that" fan myself

[-] [email protected] 12 points 20 hours ago

how would you feel about an article titled,

"This" word in article titles infuriates internet readers

[-] [email protected] 3 points 6 hours ago* (last edited 6 hours ago)

Well, it's ""This"", not "This", so I'd say it's fine.

[-] [email protected] 22 points 22 hours ago

Yeah how to spot a clickbait title.

[-] [email protected] 24 points 1 day ago

Like it's a jeopardy question lol

[-] [email protected] 58 points 23 hours ago

Wuta Camera, Max Browser, WhatsApp Mods, Spotify Mods, and Minecraft Mods were found to be infected with a Necro Sideloader. All the apps are shown to contain CoralSDK. If you downloaded any of this remove the apps and wipe your phone.

[-] [email protected] 32 points 23 hours ago

This is an article summarizing a Bleeping computer article, which is summarizing the original source which is Kaspersky

https://securelist.com/necro-trojan-is-back-on-google-play/113881/

[-] [email protected] 22 points 1 day ago

I find it hilarious that the image is of Google Play and the title used the word "this". Pretty misleading

[-] [email protected] 7 points 23 hours ago

As someone de-googing, it's not too far off in my eyes. Apps depending on GSF is a major hindrance.

[-] [email protected] 4 points 23 hours ago

It is unintentionally correct: Google Play, and its contents, is corporate malware, people should use F-Droid to get safer and free (as in freedom) apps. Neostore is a nice app to access it.

[-] [email protected] 1 points 9 hours ago

I got so fed up with Neostore mishandling updates and sending me constant notifications about it that I've uninstalled and gone with Droidify instead.

[-] [email protected] 10 points 22 hours ago

Isn't Kaspersky literally Russian Spyware? How have they still any credibility?

[-] [email protected] 4 points 3 hours ago

Really every AV software is spyware for whatever country it operates in. Just depends on who you'd rather have your data.

[-] [email protected] 4 points 12 hours ago

No more than crowdstrike is for the American government. But yes.

[-] [email protected] 15 points 21 hours ago* (last edited 21 hours ago)

Yes... no... sorta....kinda... but no different than how most, if not all, large American security and tech vendors have either overt, or covert, links to the the American Security State.

Kaspersky is a long established credible actor and leader in the threat research space, hands down one of the best track records over the long run, and you should take their reporting and disclosures seriously.

I'm not saying that to dismiss the very valid concerns about installing Kaspersky on sensitive private sector and government systems, but to contextualize my answer.

On a sort of related note, earlier I said that the American security state has both overt, or covert, links all across the American tech sector.

What that means is that, even if a company holds their principles not compromising their customers or their product, the US government can either get a court order to force it, or they'll be targeted by something like the Pentagons Signature Reduction program and have sheep dipped employees worked into their organization.

Point is, Kaspersky is one of the few remaining Russian brands and entities still holds a lot of credibility in it's field, but again, that doesn't mean the concerns of Western government's aren't valid, just that they should be viewed in the proper context.

[-] [email protected] 1 points 10 hours ago

Great explanation! So, to summarize: They know their trade but their software should not be installed because it's like with US Software: Backdoors Likely Integrated.

On the other side, I still use some Google Products...

[-] [email protected] 1 points 3 hours ago* (last edited 3 hours ago)

No problem, happy it helped.

Your summary is mostly accurate, but I think a better way to understand it would be like this:

Low level security software, by nature, is the ultimate attack vector, if compromised.

Assume that all countries that have both a domestic tech sector, and a well-resourced national security apparatus, have some version of on demand government initiated supply chain attack capabilities.

So it's not like I believe that all Kaspersky installs include a RAT piped directly to some GRU/FSB unit, just the ability for a malicious payload to be inserted - just as the NSA can do with American tech companies.

Not every risk can be mitigated, but some risks just shouldn't be taken.

[-] [email protected] 1 points 3 hours ago

The difference for me is: As for now, the US is not run by a fascist (yet). Injecting Malicious Software to bust terrorism/mafia/corruption... ok,.... Injecting Malicious Software to kill gays/opposition... Nope (and that is what I would expect the Russians to do)

[-] [email protected] 3 points 19 hours ago

Mods are a classic vector.

this post was submitted on 24 Sep 2024
95 points (88.6% liked)

Technology

58246 readers
5072 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS