Eugene Kaspersky on shifting security, spying and geopolitics

omidomi

Level 71
Thread author
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Apr 5, 2014
6,001
The security CEO revealed his thoughts on the state of security, government backdoors and more in our exclusive interview
The security industry draws some interesting characters – well highlighted by every speaker at Kaspersky’s Security Analyst Summit happily downing the shot of whiskey handed to them after their presentation.

Founder Eugene Kaspersky is no different – he’s no John McAfee, but drama and controversy still surrounds the Russian CEO. He’s been accused of ties to the KGB (which he’s strenuously denied), his son was kidnapped for ransom after he was declared one of Russia’s richest men, and reports claim emails show he threatened to “rub out” rival firm AVG using fake samples.

In person, Kaspersky is perfectly affable, happily answering our questions whether individuals really need antivirus, if Bring Your Own Device (BYOD) was a bad move for corporate security, where the company stands on government snooping, and what the tension between Russia and the UK means for his business.

Has security moved away from individuals, and more towards institutions – such as from banking customers to the banks themselves?


It’s been moving that way for many years now. The criminals were attacking the individuals only ten years ago, and then they were shifting to small businesses and big businesses, and now to the enterprise and financial services. They’ve become much more professional… What does it mean for individuals? When your bank is attacked, who pays? [We suggested they do.] Who pays for your bank – it’s your country, your company.

Years ago I was asked: so if your computer is infected and they don’t steal the data, they just use your computer to send spam. Who pays for that? Do you not pay for it? You pay for it, because you pay for the internet connection. When they need to improve infrastructure [because it’s overloaded by spam], who pays for that? Every attack, we all pay for.

Is BYOD a bad idea for companies, given individuals and consumer level equipment might be less well protected?

It’s much more complicated. In the past, it was much more simple: you had your home computer, and you had your office computer, your home security and your business security. Now forget about home security – the devices are everywhere… and in many cases are connected to business.
Nothing’s going to stop it because it [BYOD] is an accelerator for business. If your company doesn’t use these technologies, there’s disadvantages to your employees… and you lose [out to your] competition. There’s no way to change it, no way to avoid it. We have to make these devices safer and more secure for the business environment… so we have more and more work to do.

Governments are keen to insert backdoors into tech services and software. Where does Kaspersky stand on this?

There are different layers to this question, and different things the police do. The secret service and the police, they want to know what’s going on, and they mean it for good: they want to see their terrorists and criminals. That’s good. But at the same time, they want a huge amount of data from a huge amount of people. That’s bad. They need data – but how much. That’s the question.

The second layer is when the cyber police or international police are spying on suspects. That’s good. That’s their job. The cyber tools they use, there’s nothing wrong there. But we will unfortunately protect even suspects from the tools [police and authorities] use, because we don’t know who is using the tool.

The criminals, the bad guys, the bad actors, they can use the cyber tools, the legal tools. We are like an X-ray. We detect the different malware no matter who is using it – the terrorists, the criminal, or the policeman. But we don’t know who is using it, so our policy is 100% clear: if we see a piece of malware, it will detect it.

The third layer is when the states spy on the states… you don’t need to send James Bond out anymore, you just click, click, click. We see a lot of it.
 

Myriad

Level 7
Verified
Well-known
May 22, 2016
349
"..... whether individuals really need antivirus .... "

A very valid question IMO
Something I was going to bring up in an earlier post ( but decided against )

Threat vectors are so much different these days .

For anybody using a bit of common sense when surfing and clicking , AV does almost nothing.
( BTW that should be UN-common sense .... good sense is rare , " common stupidity" is abundant )

Folks may feel a little more comfortable having AV .... a bit like Barley Sugar to prevent travel sickness ( it doesn't ).
 

DJ Panda

Level 30
Verified
Top Poster
Well-known
Aug 30, 2015
1,928
"..... whether individuals really need antivirus .... "

A very valid question IMO
Something I was going to bring up in an earlier post ( but decided against )

Threat vectors are so much different these days .

For anybody using a bit of common sense when surfing and clicking , AV does almost nothing.
( BTW that should be UN-common sense .... good sense is rare , " common stupidity" is abundant )

Folks may feel a little more comfortable having AV .... a bit like Barley Sugar to prevent travel sickness ( it doesn't ).


Not going to try smaking you down but now with the complex threats and cyber terrors of the world common sense isn't enough safe websites can become forms of exploit kits, malvertising. In order to stay safe you need your brain and some help and thats totally okay. If you can stay safe without an AV or any form of protection good luck. But I believe it is almost impossible to not become infected without some sort of protection. :)
 

DardiM

Level 26
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
May 14, 2016
1,597
I think that as soon as we install/run/download a new program on our PC (USB key ,internet directly, or e-mail) , or even if we are only surfing & clicking , a minimum of protection tools (not specifically an AV) is needed even if a good brain can help. But an AV will never be 100% secure 24/7, because new malware / virus can infect you before been in your "favorite AV data-base". This is where a good brain can help : never run/open an unknown file without be aware of a potential infection.

About Backdoors, there will always be pros and cons, and good or bad reasons :):(:rolleyes:

Thanks @omidomi for your post :)
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top