Live data from Hacker News

McAfee quarantines svchost.exe on millions of WinXP machines worldwide

andreyf.tumblr.com

51–60 of 113 posts

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#51

Earlier quoted context omitted.

You read Hacker News, which means you probably know more about computers than at least 99% of the population, and far more than 98%. Seriously, consider that. Take something you don't know about. For me it's cars. If prevailing wisdom was that unless you bought some $40 item for your car, it could easily be stolen, you'd probably buy it right? This is what people are told: Windows is insecure and anyone with a clue c…

For the IT staff, the fact that your computer slows down is an externality; it is not their problem. If the anti-virus can catch a few viruses and doesn't result in many help-desk tickets, then it makes their lives easier. Cleaning up a virus is a tedious task, as even a simple re-imaging can take a while, and that's if you can use a standard image. They also don't know how smart their users are. Some of them are gre…

> Their current goal is usually just to make sure it runs at all.

Indeed. I'm the lead of the "IT Staff" at a small non-profit (~70 users) running mostly on second-hand desktops. Two-thirds of our staff is unpaid, usually interns who are here a few days a week for 3 months, and then they're gone and someone new takes their place. Training proper computer behavior is hard.

So... we run A/V (not McAffee), because we have to. We also lock down the systems hard, not because I think that's a nice thing to do to your users, but because we have to. Imaging all these different desktop models is difficult, and we have very limited resources for doing re-imaging/re-installs/virus cleaning/whatever.

My goal is to enable you to sit down at your computer and be able to perform your job. A 20% performance hit on all computers is worth it if it means that 20% of the computers aren't down for maintenance. :)

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#52

I don't have time to counter all the misinformation here. Just a couple quick points: - McAfee has been crap for a long time now; they're not much better than Norton's products from the last few years. - Corporate networks are running McAfee because McAfee (and TrendMicro, and other garbage a/v vendors) provide incentives to VARs, consultants, resellers, etc. - However, this is a far cry from "all antivirus is bad".…

First off, I don't claim to be an IT person or know what normal users need to be safe. I can only speak to my personal experience as a programmer. I haven't had a virus in 14 years. I haven't ever run anti-virus software. I have a good feel for all the systems that I use. A little paranoia goes a long way. Not to say that I couldn't be targeted. I'm sure a skilled cracker could break my boxen. But I doubt any antivirus would stop them.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#53
post #20

Earlier quoted context omitted.

The 20% figure that was "once read" about is pure fiction. Any up to date test figures reveal something closer to 99.8% of a 3 million sample testbase for the better AVs. It's all a bit moot though as before this happened, McAfee was probably worse than anything a PC can get infected with. Now it's gone and proved it beyond any doubt.

But that's totally meaningless! Think of it in another way, at any point in time you have x number of virus that you are likely to come across through whatever means. If all those viruses are in the 0.2%, then the catch rate isn't going to be 99.8% it's going to be 0%. So being able to catch 99.8% of 3 millions viruses when new ones are released all the time is a pointless comparison for efficiency.

20% is totally meaningless as well, but you posted it.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#54

I don't have time to counter all the misinformation here. Just a couple quick points: - McAfee has been crap for a long time now; they're not much better than Norton's products from the last few years. - Corporate networks are running McAfee because McAfee (and TrendMicro, and other garbage a/v vendors) provide incentives to VARs, consultants, resellers, etc. - However, this is a far cry from "all antivirus is bad".…

First off, I don't claim to be an IT person or know what normal users need to be safe. I can only speak to my personal experience as a programmer. I haven't had a virus in 14 years. I haven't ever run anti-virus software. I have a good feel for all the systems that I use. A little paranoia goes a long way. Not to say that I couldn't be targeted. I'm sure a skilled cracker could break my boxen. But I doubt any antivir…

"I haven't had a virus in 14 years. I haven't ever run anti-virus software."

Then I'd say you probably have a virus ;-)

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#55
post #40

Crazy to think about the consequences of a mistake like this. This was sent by a friend to an email list I'm on: "Well, consider this community hospital fubared. IT dudes running around pulling out their hair. If it wasn't affecting patient care it would be a humorous scene-but I can't check xray's, or labs or anything. Took out a horrendously bloody gallbladder this morning, and I can't tell (labwise) if she's still…

Wow. Kinda makes me wonder if we should be using general-purpose computers for so many things. The anti-virus is kind of a major single point of failure for machines that need to do just a few specific things.

Best Practices, n.: Making the same mistakes everyone else does.

However, what are the odds of someone being able to make special-purpose machines to do everything COTS boxes are used for, and making those machines as fast, cheap, and reliable as COTS systems are now? Some things seem obvious (x-ray machines, lab machines) but accounting and record-keeping? Going back to adding machines and purely manual filing is not an option in a large hospital, especially if it has to maintain modern standards of patient care over a large patient population.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#56

I don't have time to counter all the misinformation here. Just a couple quick points: - McAfee has been crap for a long time now; they're not much better than Norton's products from the last few years. - Corporate networks are running McAfee because McAfee (and TrendMicro, and other garbage a/v vendors) provide incentives to VARs, consultants, resellers, etc. - However, this is a far cry from "all antivirus is bad".…

Speaking as someone who knows something about these things, it is clear that you are not as informed as you are making yourself out to be. There are two reasons why I say that. (1) Your knowledge of the AV industry is outdated. McAfee has actually been trending upwards in recent years. (2) A 97% detection rate is obviously bullshit. If any product achieved a detection rate anywhere close to that number, the false positive count would be through the roof. As this incident makes clear, the cost of a false positive can be astronomically high. Again, any AV product advertising or claiming 97% detection is bullshit. Any AV engine can achieve that number if accepts an unrealistic number of false positives. The fact that you even quoted that number makes me question your qualifications for giving advice about AV.

For non technical people reading this thread, the general sentiment of other commentators is correct. Most AV is garbage. It will protect you from about a 1/3 of what is out there at the cost of computer performance. Make an educated decision about whether to run it at home or not. On your corporate network, do whatever your security guy tells you to do.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#58

Why does AV software not have a secure checksum-based whitelist? It is not as if Microsoft keeps the important system files secret.

For that matter, why didn't they test this on at least one machine before releasing it? Is it not standard to have a release process that includes testing?

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#59
post #40

Crazy to think about the consequences of a mistake like this. This was sent by a friend to an email list I'm on: "Well, consider this community hospital fubared. IT dudes running around pulling out their hair. If it wasn't affecting patient care it would be a humorous scene-but I can't check xray's, or labs or anything. Took out a horrendously bloody gallbladder this morning, and I can't tell (labwise) if she's still…

[deleted]

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#60

Earlier quoted context omitted.

Well, first off, I have bad news for you: the more recent rootkits we've been seeing are doing exactly this. They are very quiet, very sneaky, very hard to remove, and they just love it when you purchase items online. As far as whether viruses or antivirus software are worse to deal with -- well, I have three systems in the shop so far today for virus infections that were so bad that it rendered the computer unusable…

The last computer virus I got was the stoned virus on a DOS 6.2 machines sometime around 1989-90. And I never run anti-virus software. At home I have Windows, OS X and Linux boxen and not in 20 years have I had a computer virus. It's really all about usage patterns more than anything else.

That's like saying that having sex without a condom is safe as long as you have certain 'usage patterns'.

Chances are you have contracted something, but just don't know about it.

The OS X and linux boxes are pretty safe, but if you use your windows machines online you're bound to have been bitten by drive by malware at least once.

Unless those machines have never been used to surf the web.

Even very reputable sites have had bad cases of advertising injected malware, in some of the most unlikely delivery vehicles.

Post reply on HN