Live data from Hacker News

McAfee quarantines svchost.exe on millions of WinXP machines worldwide

andreyf.tumblr.com

21–30 of 113 posts

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#21

Just another nail in the coffin of the usefulness of AV systems. And good riddance. My work computer actually has McAfee on it, which I've disabled through the registry. Don't like how slow it makes my computer. Education, people! It's better than buying useless feel-good software.

I did some benchmarks on a Dell Precision M65.

The hit from MacAfee was approximately 15-20% by my reckoning, in terms of time taken to run a compile and link cycle.

Worse still, as you pointed out, responsiveness is affected, which can be incredibly frustrating.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#22
post #9

Earlier quoted context omitted.

> Why do IT depts recommend installing this program? My suspicion is that they need something to spend a lot of money on. That old "more expensive perfume = better" thing, to appease the managers. I could be wrong.

You are. Despite all of its shortcomings, AV is still pretty effective at blocking crap for non-technical users. Perfect? Of course not. But even a 50% catch rate is better than nothing. At my current job, we see our fair share of 0-day and too-new-to-be-caught-by-AV stuff. However, we also see a great deal of infections from viruses that are at least 1-2 years old. Even stupid AV can catch viruses that old.

I mean McAfee in lieu of a less expensive perfume, like Avast. I'm assuming Avast is less expensive.... Avast is better, though.

(And is it just me or is HN freaking out right now?)

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#23

Just another nail in the coffin of the usefulness of AV systems. And good riddance. My work computer actually has McAfee on it, which I've disabled through the registry. Don't like how slow it makes my computer. Education, people! It's better than buying useless feel-good software.

With fake SSL certificates signed by "real" CAs, cross-site scripting and other advances in phishing attacks, just educating users may not be as effective as it used to be. Malware is quickly becoming advanced enough that even trained technical users may be fooled. Many attacks don't require user interaction. AV products may be slow to respond and signature matching won't catch everything, but if it catches half of what shows up on corporate networks it can still save a lot of time and money.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#24
post #17

Earlier quoted context omitted.

You'd be making a trade based on how the market responds to news. Just because you care about this news doesn't mean the market will. Unless the settlements are enormous, the market never will.

Unless the settlements are enormous, the market never will. Or if they lose big clients. My wife tells me all computers in PWC's NYC office are out.

Shame on PWC for not upgrading to Vista or Windows 7. A firm that large should have more foresight in IT planning.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#25

I don't understand why people install antivirus software on their machines. I read once that their catch rate is something like 20-30% which strikes me as no better than 0% for all the good it does most of their customers. It just seems to slow down computers a lot and yield little benefit other than protection for the IT staff when things go wrong. I could make antivirus software that does nothing and probably make…

You read Hacker News, which means you probably know more about computers than at least 99% of the population, and far more than 98%. Seriously, consider that.

Take something you don't know about. For me it's cars. If prevailing wisdom was that unless you bought some $40 item for your car, it could easily be stolen, you'd probably buy it right?

This is what people are told: Windows is insecure and anyone with a clue can just steal your credit card number. I know that if I just don't install crap from the internet, and have a reasonable firewall, I'm not going to get a virus. I haven't had antivirus in over a decade, though I've run some web-based ones on occasion to check, and have never had a problem. I know that, and you know that. My dad (who is much closer to the other 98% of the population) doesn't know that.

(As for corporate use, you answered your own question. IT staff installs it for no reason other than to be able to prove to their boss that it isn't their fault when stuff goes wrong. )

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#26
post #20

Earlier quoted context omitted.

I don't understand how even having a 20% detection rate isn't better than 0%. Am I missing something? Are there a lot of viruses popping over the net that even the 20% detection is already too late?

The 20% figure that was "once read" about is pure fiction. Any up to date test figures reveal something closer to 99.8% of a 3 million sample testbase for the better AVs. It's all a bit moot though as before this happened, McAfee was probably worse than anything a PC can get infected with. Now it's gone and proved it beyond any doubt.

But that's totally meaningless!

Think of it in another way, at any point in time you have x number of virus that you are likely to come across through whatever means. If all those viruses are in the 0.2%, then the catch rate isn't going to be 99.8% it's going to be 0%.

So being able to catch 99.8% of 3 millions viruses when new ones are released all the time is a pointless comparison for efficiency.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#27
post #6

[deleted]

A recent study linked here showed that frequent password changes were no good (can´t find the link right now).

The original post you're replying to was deleted, but, this comment interested me enough that I went and looked for the paper. It isn't up yet, but here's a writeup of it from the Boston Globe: http://www.boston.com/bostonglobe/ideas/articles/2010/04/11/....

The paper (Please Continue to Hold: An empirical study on user tolerance of security delays) is by Cormac Herley and a few others. All the other papers on Herley's page (http://research.microsoft.com/en-us/people/cormac/) are up, so, I'm assuming that this one will be too, at some point in the future.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#28

If I were a trader, I'd short McAfee right now. This probably means lots of settlements. EDIT: This could actually be a profitable venture. Somewith with at least basic HN-type knowledge and a daytrading account could make serious money. Finance professionals most probably have no idea how important specific IT news are during the day. One should be able to trade ahead of consensus pretty easily.

I thought about doing this a while ago, and started watching to see if I could find any way to predict stock prices based on tech news. I saw nothing I would put money behind. The stock price wont change based on news until after that quarters earnings are released, and for a big company one technical glitch won't effect those.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#29
post #23

Just another nail in the coffin of the usefulness of AV systems. And good riddance. My work computer actually has McAfee on it, which I've disabled through the registry. Don't like how slow it makes my computer. Education, people! It's better than buying useless feel-good software.

With fake SSL certificates signed by "real" CAs, cross-site scripting and other advances in phishing attacks, just educating users may not be as effective as it used to be. Malware is quickly becoming advanced enough that even trained technical users may be fooled. Many attacks don't require user interaction. AV products may be slow to respond and signature matching won't catch everything, but if it catches half of w…

I wonder if the value of the total things stopped by McAfee, in all its time, outweighs the purported damage of this incident.

I'm thinking no.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#30
post #20

Earlier quoted context omitted.

I don't understand how even having a 20% detection rate isn't better than 0%. Am I missing something? Are there a lot of viruses popping over the net that even the 20% detection is already too late?

The 20% figure that was "once read" about is pure fiction. Any up to date test figures reveal something closer to 99.8% of a 3 million sample testbase for the better AVs. It's all a bit moot though as before this happened, McAfee was probably worse than anything a PC can get infected with. Now it's gone and proved it beyond any doubt.

The 99.8% includes a known test set for historic viruses from the 80s and 90s. The stuff you really care about are the new things that sweep the web (Blaster, Slammer, Code Red, etc.). AV is inherently reactive, and that .2% you miss is likely the latest stuff.
Post reply on HN