Live data from Hacker News

Avoid Non-Microsoft Antivirus Software

robert.ocallahan.org

21–30 of 388 posts

Re: Avoid Non-Microsoft Antivirus Software

#21
post #17

Most people forget the malware on hacked website. Browsers won't give you a warning. (OK. Chrome will show you a RED screen but not for all) They need not hack into your system. But they collected your login info, credit card. I even want to install one on my MacOS. MS AV still too slow at the moment. In Windows 10, you could turn on Defender to run both AV at the same time.

[deleted]

Re: Avoid Non-Microsoft Antivirus Software

#22
"Microsoft AV products" aren't exempt from breaking things with poorly implemented features. MSE on Windows 7 makes games (specifically, fresh installs of StarCraft II, CS:GO and Overwatch) unplayable for me due to CPU usage spikes, apparently due to it thinking that various game executables and settings files are suspicious. Exempting the directories from scanning and disabling suspected malware sample submission had no effect, what finally worked was switching to school-provided Sophos Endpoint. Antivirus can get messy and intrusive no matter who does it.

Re: Avoid Non-Microsoft Antivirus Software

#23
Defender has the nasty habit of aggressively scanning new games I download off Steam. There are two occasions where it'll do it:

- While it's downloading it seems to scan each chunk. I have a gigabit connection, with defender off I can download at nearly full speed. With it on I can download at about 1MB/s.

- While the game loads a level. For example, the intro level to the new Deus Ex took over 10 minutes to load the first time. At that point I disabled defender entirely and just promised myself I would be careful. Naive, I know, but at least I can play my video games.

Re: Avoid Non-Microsoft Antivirus Software

#26
post #4

> At best, there is negligible evidence that major non-MS AV products give a net improvement in security. I apologize for present anecdote when data is needed but I manage a Windows network with 100+ users and on a daily basis, Kaspersky catches 5-10 emails from Outlook that have nasty attachments. It prevents my users from opening these innocuous looking but nasty Invoice-Jan-2017.docx files. Without a good AV there…

> Invoice-Jan-2017.docx uh, docx files can hack my PC now? Is this a bug of MS Word or docx format really has ability to become a virus?

An extraordinary amount of Cryptolocker outbreaks were due to .docx files containing macros.

Yes, it has a default behaviour of "prompt to execute macros", but it happily shows the advice in the malicious document to "please click yes at this prompt to get a free iPhone", at which point the majority of users click "yes".

Re: Avoid Non-Microsoft Antivirus Software

#27
As always, it depends on the product that you are referring to. Purely by coincidence, I installed [product] again a few weeks ago, after having used Defender since Windows 10 launched.

> see bugs in AV products listed in Google's Project Zero

All software has vulnerabilities, including Defender. Searching for [product] in Project Zero shows that only 3 vulnerabilities have been discovered (which is arguably a bad thing, but not according to this author) and it took, at most, 4 days for them to be resolved.

> if they make your product incredibly slow and bloated

This is precisely the reason that I have returned to [product]: performance. I'm running off an HDD and Defender saturates my HDD for a good 2 minutes after boot. I don't experience this with [product]. In addition, it has a "gaming mode" which allows you to further cut back on its activity (I have never needed it). Looking at objective tests, Defender fares quite poorly in both performance[1] and protection[2].

Additionally, a homogeneous market is an easy market to exploit. Let's assume that everyone took this advice and installed Defender. It is guaranteed that Defender has vulnerabilities. If you wanted to pwn as many machines as possible, you would only have to worry about exploiting a single AV.

This is just bad advice, I'm sticking with the competition (which may not always be [product]). There are bad players (McAfee, Norton) but that does not mean everyone sans Microsoft is utterly incompetent.

[1]: http://www.av-comparatives.org/wp-content/uploads/2016/05/av... [2]: https://www.av-test.org/en/antivirus/home-windows/windows-10...

Re: Avoid Non-Microsoft Antivirus Software

#28
post #4

> At best, there is negligible evidence that major non-MS AV products give a net improvement in security. I apologize for present anecdote when data is needed but I manage a Windows network with 100+ users and on a daily basis, Kaspersky catches 5-10 emails from Outlook that have nasty attachments. It prevents my users from opening these innocuous looking but nasty Invoice-Jan-2017.docx files. Without a good AV there…

> Invoice-Jan-2017.docx uh, docx files can hack my PC now? Is this a bug of MS Word or docx format really has ability to become a virus?

There are exploits for pretty much every file format in existence. [1] There are also exploits that work by just having the e-mail arrive in your e-mail client without you having to even open the message. In fact the e-mail may not even reach your computer if you use some corporate proxy which has anti-virus installed. Project Zero revealed just recently a Norton/Symantec flaw where just sending the e-mail is enough for code execution. [2]

[1] Almost none of these are zero day though, so if you're up-to-date you'll be fine.

[2] https://googleprojectzero.blogspot.com.ee/2016/06/how-to-com...

Re: Avoid Non-Microsoft Antivirus Software

#29
post #4

> At best, there is negligible evidence that major non-MS AV products give a net improvement in security. I apologize for present anecdote when data is needed but I manage a Windows network with 100+ users and on a daily basis, Kaspersky catches 5-10 emails from Outlook that have nasty attachments. It prevents my users from opening these innocuous looking but nasty Invoice-Jan-2017.docx files. Without a good AV there…

> Invoice-Jan-2017.docx uh, docx files can hack my PC now? Is this a bug of MS Word or docx format really has ability to become a virus?

Probably .docx.exe or .docm (or whatever the macro enabled document extension is).
Post reply on HN