Live data from Hacker News

Antivirus software could make your company more vulnerable

csoonline.com

41–48 of 48 posts

Re: Antivirus software could make your company more vulnerable

#41
Personally, I won't trust those AV software which are free but claims themselves have FULL function. There is no free lunch in the world. Sometimes, we make jokes on Qihoo 360, we say itself is already a virus. A lot of pop-ups, consuming computing resources. It is very annoying!

Re: Antivirus software could make your company more vulnerable

#43
post #4

I avoided AV software for most of my life. Though, when I worked as a student admin, I would always install AV for the majority of my users. Most users (especially older) simply could never learn not to download that cool new 'freeware' app or game or not double click a downloaded exe (the fact that hidden extensions are still the default on Windows OS is absurd). As a more savvy user, I did not desire the typical AV…

At the moment the number of hypervisor escape exploits are fairly limited, so running a browser in a virtual machine where the system image is always destroyed has a certain cachet to it. I know a couple of people who have Chromebooks for browsing (at least one got the CB for free at Google I/O and they felt that was all it was good for :-) When I get some time I'd like to clean up my air-gap browser, which was a web…

Nice, but for maximum tin-hatted-ness, can I suggest mechanical arms typing on the laptop keyboard and moving/clicking the mouse? Who knows what lurks in that Bluetooth stack and firmware? :-)

Re: Antivirus software could make your company more vulnerable

#44

Earlier quoted context omitted.

>> I'm not sure the AVs have helped much, but they give some sort of psychological benefit, at least. I find this a very dangerous way of thinking. You use the placebo (well, not even a placebo, just useless) and then you stop worrying that much about opening downloaded files, checking their hash if you trust the source, visiting dodgy websites... An analogy taken to the extreme, would be to smoke and binge drinking…

Not necessarily! It depends! It could be that the constant popups about updating the AV, about allowing access to trusted programs etc. constantly reminds him of the aspect of security and has this aspect in the back of his mind while browsing, so it may actually enhance security awareness. As in "I'm the sort of person who cares a lot about viruses, so much that I have an AV and adblocker etc., so I'm also the kind…

>> Installing an AV doesn't automatically reduce your defenses. Only if you over-trust it.

Recent news might point otherwise and there's a debate about it. Does an antivirus really protect you from a real threat? On the other hand, as you're running extra software you're increasing your attack surface, which makes you more vulnerable.

I've seen very clever people pointing to the latter and marketing efforts to make me believe the former. Still, haven't made up my own opinion. In any case, I stick to just Windows Defender and EMET (https://support.microsoft.com/en-us/kb/2458544) to mitigate.

Re: Antivirus software could make your company more vulnerable

#45
post #14
post #4

I avoided AV software for most of my life. Though, when I worked as a student admin, I would always install AV for the majority of my users. Most users (especially older) simply could never learn not to download that cool new 'freeware' app or game or not double click a downloaded exe (the fact that hidden extensions are still the default on Windows OS is absurd). As a more savvy user, I did not desire the typical AV…

NoScript with the occasional whitelist has been a perfect solution for me. I don't feel like I'm missing any part of the web, in fact, most of it is better without JS. At this point, sometimes I go weeks without having to add anything to the list. I don't think it would be a good solution for my mom but she only uses an iPad now so it doesn't matter.

Try uMatrix. It's Noscript and then some.

Re: Antivirus software could make your company more vulnerable

#46

Earlier quoted context omitted.

This[1] is on the very top of the fronpage right now. TrendMicro has a daemon listening on localhost that can execute arbitary commands. [1] https://news.ycombinator.com/item?id=10882563

Right. (But that's one AV vendor. Others have the same possibility, of course.) But is it still better (more secure) to run without any AV at all? Something like this leaves you vulnerable to that flaw, but no AV leaves you vulnerable to everything (unless a firewall saves you).

It is better to run with no AV at all.

Re: Antivirus software could make your company more vulnerable

#47
post #8

Earlier quoted context omitted.

>> the fact that hidden extensions are still the default on Windows OS is absurd Is this the case for Apple's OS well (Yosemite or whatever its called nowadays)?

OS X is a UNIX, so file extensions don't matter a whole lot. You can double click a plain Mach-O executable file and it'll run it in a Terminal window. For application bundles (folder with name ending in .app), OS X will warn you if the file was downloaded/not signed by a key trusted by Apple.

Thanks, as someone who hasn't used a UNIX os since Highschool I am not very familiar with them.

As an aside I am thinking about installing a light UNIX distro on my netbook. Win 7 is so painful with only 1GB of RAM. (I love being poor student).

Now I got some money so I can either buy a new laptop for $350 or attempt to save some money by installing a light UNIX distro. Problem is, I dont want to learn another OS.

Re: Antivirus software could make your company more vulnerable

#48
post #31
post #4

I avoided AV software for most of my life. Though, when I worked as a student admin, I would always install AV for the majority of my users. Most users (especially older) simply could never learn not to download that cool new 'freeware' app or game or not double click a downloaded exe (the fact that hidden extensions are still the default on Windows OS is absurd). As a more savvy user, I did not desire the typical AV…

Regarding "future for tech-aware users will be browsers in [...] container/VM", see also Qubes OS: https://www.qubes-os.org/screenshots/ https://www.qubes-os.org/ https://www.qubes-os.org/intro/ and the (microkernel-based) Genode OS with somewhat similar approach: http://genode.org/documentation/release-notes/15.11#Rigid_se... http://genode.org/documentation/release-notes/15.11#Genode_a... http://genode.org/about/ an…

Thanks for the info! I'll take a look.
Post reply on HN