Security Wares Like Kaspersky AV Can Make You More Vulnerable to Attacks
Products often open computers to hacks they otherwise wouldn't be vulnerable to.
Dan Goodin | September 23, 2015
Antivirus applications and other security software are supposed to make users more secure, but a growing body of research shows that in some cases, they can open people to hacks they otherwise wouldn't be vulnerable to.
What these tools do is a widespread method. They install a root certificate into the user's browser and then they perform a so-called Man in the Middle attack. They present the user a certificate generated on the fly and manage the connection to HTTPS servers themselves. Superfish and Privdog did this in an obviously wrong way, Superfish by using the same root certificate on all installations and Privdog by just accepting every invalid certificate from web pages. What about other software that also does MitM interception of HTTPS traffic? Source: https://blog.hboeck.de/archives/869-How-Kaspersky-makes-you-vulnerable-to-the-FREAK-attack-and-other-ways-Antivirus-software-lowers-your-HTTPS-security.html |
<more at http://arstechnica.com/security/2015/09/security-wares-like-kaspersky-av-can-make-you-more-vulnerable-to-attacks/; related links: http://www.thegeekbyte.com/6028/kaspersky-av-makes-you-more-vulnerable-to-attacks/ (Kaspersky AV makes you more vulnerable to attacks. September 24, 2015. "Any Antivirus is created to make users more secure, but Kaspersky antivirus is doing the opposite. According to Tavis Ormandy, a member of Google Project Zero team, Kaspersky antivirus makes you more vulnerable to attacks.") and [A Rebuttal:] http://usa.kaspersky.com/about-us/press-center/in-the-news/5-myths-virtualization-security-you-may-be-more-vulnerable-you-thi (5 Myths of Virtualization Security: You May Be More Vulnerable Than You Think. "Businesses increasingly are relying on virtual machines to handle more critical data and tasks than ever before. The reality is that virtualization is growing as a platform for managing customer data, financial transactions and the applications that businesses use. Simply put, virtualization is a core component of today's mission-critical IT infrastructure. However, while the increased reliance on virtualization is very real, many businesses are misguided about their security needs in this environment. There are several myths that have serious consequences that can impact performance and leave organizations vulnerable to an attack. Understanding these issues can help you make smarter decisions about your business' virtual environment. Read more.">
No comments:
Post a Comment