• pandapoo
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    3 hours ago

    No problem, happy it helped.

    Your summary is mostly accurate, but I think a better way to understand it would be like this:

    Low level security software, by nature, is the ultimate attack vector, if compromised.

    Assume that all countries that have both a domestic tech sector, and a well-resourced national security apparatus, have some version of on demand government initiated supply chain attack capabilities.

    So it’s not like I believe that all Kaspersky installs include a RAT piped directly to some GRU/FSB unit, just the ability for a malicious payload to be inserted - just as the NSA can do with American tech companies.

    Not every risk can be mitigated, but some risks just shouldn’t be taken.

    • Zementid@feddit.nl
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 hours ago

      The difference for me is: As for now, the US is not run by a fascist (yet). Injecting Malicious Software to bust terrorism/mafia/corruption… ok,… Injecting Malicious Software to kill gays/opposition… Nope (and that is what I would expect the Russians to do)