The Impact of the Kaspersky Ban
bitsight.com
bitsight.com
How is Bitsight "observing" here?
From their marketing: "Understand your adversaries and their online infrastructures to identify your potential cyberthreat exposures using a complete map of the internet."
E.g. see this test from a few years ago
https://www.av-comparatives.org/tests/performance-test-octob...
Though it seems they've improved recently and are average now in more recent tests
As a user I couldn’t really see any difference.
But remember, the US governments job is to protect the US, not Myanmar. And Facebook is within the legal jurisdiction of US officials.
This isn't a technology issue, it's a governance issue.
Any US or European company absolutely should not trust a Russian or Chinese company at the moment. Especially not for antivirus.
Just like any company based in Russia or China shouldn’t trust western companies.
But also you are comparing autocracies to democracies. Don’t pretend that the control the US is able to exert over their companies is in anyway comparable to what is common place in Russia/China. Remember the rash of murder/suicides of Russian oligarchs where they decided to kill their families and then off themselves. Or how about when Jack Ma was disappeared for a year.
Russia/China is in no way equivalent to western democracies on this issue. So please stop the whataboutism.
The amount of "control over companies" one state has over another is not going to be a strong debate point when your good guys here are, as we speak, sustaining an extreme act of at this point inarguable mass murder. All while, it should probably go without saying, sustaining a complete harmony in the respective state and private institutions at play. What a lovely coincidence I guess!
This is not even get into maybe the not so fine details of USA democracy these days.
I know you really felt like you had a point and some ground to stand at one time, but you gotta remain vigilant. History can move fast, and it does not reward loyalists.
Russia is at war with Ukraine. The EU is at war with nobody. Who's at war with the US?
You seem to be using the world "war" very lightly in a context where actual war is also happening.
And that's the aspect that's hitting me the most: people get into a "we're at war" mindset without needing their government to actually make official steps nor actually engage their responsibility. Banning TikTok is ok because of that "war but not really" atmosphere, where China is not an actual diplomatic enemy with open proof and potential discussions of them, but companies can still be punished purely on the grounds of involvement with China.
There is pretty good precedent for that usage.
That's not something I'd be longing to repeat from a citizen perspective.
The US/EU is definitely in a proxy fight with Russia in Ukraine. Russia is definitely running disinformation campaigns and funneling money across the US and EU to try and tilt elections to their far right allies. There have been several high profile breaches of US institutions recently traced back to Russia and Chinese hacker groups.
So that covers actual fighting, political attacks, and cyber attacks. This is literally the definition of hybrid warfare. Here is the Wikipedia page on this: https://en.wikipedia.org/wiki/Hybrid_warfare
The US also spies and runs disinformation campaigns in EU countries. Are we at hybrid war with the US ? Is the US at hybrid war with Japan since the actual war ended ? Or is the point to always be at hybrid war with somewhere ?
We are not in a direct conflict with Russia. But Russia has invaded a neighbor in order to steal the land, people and property. And is currently bombing children hospitals in the process of achieving its goals.
We are at war with the idea that in this day and age, this is normal and OK.
Since WW-II, the world has lived in "relative" safety. No national boundaries have been changed by force. Russia is not on-board with this plan and wants to go back to the old way of expanding borders.
We are at war with this ideology.
You have that relationship inverted. The US gov't is a mere shell at this point, having outsourced all its core functions to private companies. There is no "medicare" budget or "defense" budget, there is only the capital allocated to and embezzled by the medical & military industrial complex.
And rest assured they do their own set of overt disappearances, notably the Boeing whistleblower and Epstein. There is an obvious playbook they follow in such cases, first they bribe, blackmail, or discredit - before being indiscreet.
Jeffrey Dahmer killed people but Matthew Broderick did too, so you should never watch "Ferris Bueller's Day Off"
(1) Public discussion in the web about what is, has and will happen in global / security / foreign politics is completely broken.
(2) The reason is not and cannot be one-sided. However it may be better to think of groups with "mind control" powers and entities with not than any nation states or international organizations.
(3) I have never seen an attempt by anyone to do something about this; it seems that hope of rational (web) discussions and analysis is, has always been, and will for foreseeable future buried by whatever this is.
https://arstechnica.com/information-technology/2017/10/kaspe... Note the Israeli findings and the months of experiments by US intel agencies after the fact and the conclusions they drew.
The initial counterargument from Kaspersky (which seems to address some but not other concerns raised in the above link) apparently was something like the following:
https://arstechnica.com/information-technology/2017/11/kaspe...
Both the above are from 2017 in the months after the issues about Kaspersky concerns first came to light. This triggered the ban of Kaspersky from US government computers back then. Not sure what info may or may not have come to light since then but most people are not even aware of the above.
The official 2024 USG reasons which impact are outlined in four bullets in the press release here: https://www.bis.gov/press-release/commerce-department-prohib... which in turn points to an ODNI (Office of the Director of National Intelligence) public-facing PDF/slide of the reasons: https://www.dni.gov/files/CTIIC/documents/products/Kaspersky... and the US Commerce department's findings at https://oicts.bis.gov/pdfs/AppendixA.pdf (mostly blacked out but you get a sense of the back-n-forth reasoning justifying what steps short of a ban could be taken at least a little bit) and the Commerce Department Kaspersky FAQ at https://oicts.bis.gov/kaspersky/faq/
I have no first/secondhand knowledge of any of this stuff but this is what my curiosity turned up when I went poking around.
Having observed corporate US security practices, my perception is that a lot of protection involves scanning things using very low-level OS and/or network techniques. Remember that phrase "who guards the guardians? ( https://en.wikipedia.org/wiki/Quis_custodiet_ipsos_custodes%... ) The Kaspersky ban by the US Commerce department appears to be essentially a concession that "who scans the scanners?" is not something the US can particularly do for products with the type of low-level access provided to AV/malware products, particularly products from entities with a concrete history of specific adverse (2014-2017) behavior from a particularly skilled hostile country (in this case Russia).