Live data from Hacker News

Netflix Is Dumping Anti-Virus, Presages Death of an Industry

forbes.com

21–30 of 75 posts

Re: Netflix Is Dumping Anti-Virus, Presages Death of an Industry

#22

I guess we're going to debate the merits of statements in a thinly-veiled bit of PR now? There's almost no news about this company until about a month ago ( http://www.networkworld.com/article/2955017/security/endpoin... ). They recently hired a new PR company ( http://www.mgpr.info/ ) who's been spamming articles to Reuters on SentinelOne's behalf ( https://www.google.com/?gws_rd=ssl#q=site:reuters.com+sentin... ),…

[deleted]

Re: Netflix Is Dumping Anti-Virus, Presages Death of an Industry

#23
post #19

Earlier quoted context omitted.

> Many, many security patches are way late. My main point was: a virus that uses a 0-day (or unpatched/unfixed 0-day) is likely going to cause problems for an AV: > AVs, typically, would struggle to catch an e.g. malicious BIOS flash resulting from an escalation vulnerability. Over-exaggerating to clarify: AVs are like bringing a knife to a gunfight. You might just be actually able to eliminate the weaker opponents (…

It takes about 5min to refactor the code of existing malware to avoid detection, heck playing around with compiler settings is enough in many cases. I've recompiled Netcat probably 200 times by now, small refactoring playing with compiler flags (compile with x64 profile, debug on, add some symbols etc..) and every time it avoids every AV out there. I usually use Virustotal which means that it will be short lived but…

There's actually tools to automatically do what you're talking about for malware: http://www.rapid7.com/db/modules/encoder/x86/shikata_ga_nai

(Japanese for "it can't be helped")

Re: Netflix Is Dumping Anti-Virus, Presages Death of an Industry

#25

So who cares what Netflix does for anti-virus? Their business is about running servers with almost read only data that can't normally propagate a virus infection.

This is about what they're using on staff desktops, not their video-delivery systems.

Re: Netflix Is Dumping Anti-Virus, Presages Death of an Industry

#26
post #19

Earlier quoted context omitted.

> Many, many security patches are way late. My main point was: a virus that uses a 0-day (or unpatched/unfixed 0-day) is likely going to cause problems for an AV: > AVs, typically, would struggle to catch an e.g. malicious BIOS flash resulting from an escalation vulnerability. Over-exaggerating to clarify: AVs are like bringing a knife to a gunfight. You might just be actually able to eliminate the weaker opponents (…

It takes about 5min to refactor the code of existing malware to avoid detection, heck playing around with compiler settings is enough in many cases. I've recompiled Netcat probably 200 times by now, small refactoring playing with compiler flags (compile with x64 profile, debug on, add some symbols etc..) and every time it avoids every AV out there. I usually use Virustotal which means that it will be short lived but…

How does that work against AVs with heuristics?

Re: Netflix Is Dumping Anti-Virus, Presages Death of an Industry

#27

Wait until an employee gets some malware and some data gets leaked or lost. Then they'll be running back.

if you read the linked article the you will notice that they don't dump AV - they just switched to a "AV" product that does away with the signature database completely and replacing it with heuristics - it also sounds like there is some white listing of processes involved as well. This is something AV products have been doing for quite some time now.

Re: Netflix Is Dumping Anti-Virus, Presages Death of an Industry

#28

So who cares what Netflix does for anti-virus? Their business is about running servers with almost read only data that can't normally propagate a virus infection.

> servers with almost read only data that can't normally propagate a virus infection.

Those are FreeBSD servers so you are correct but something needs to prevent that data from being put on their by other OSes.

Re: Netflix Is Dumping Anti-Virus, Presages Death of an Industry

#29

I guess we're going to debate the merits of statements in a thinly-veiled bit of PR now? There's almost no news about this company until about a month ago ( http://www.networkworld.com/article/2955017/security/endpoin... ). They recently hired a new PR company ( http://www.mgpr.info/ ) who's been spamming articles to Reuters on SentinelOne's behalf ( https://www.google.com/?gws_rd=ssl#q=site:reuters.com+sentin... ),…

Yes, I thought there was a PR smell about that article.
Post reply on HN