Live data from Hacker News

Avoid Non-Microsoft Antivirus Software

robert.ocallahan.org

41–50 of 388 posts

Re: Avoid Non-Microsoft Antivirus Software

#41
post #4

> At best, there is negligible evidence that major non-MS AV products give a net improvement in security. I apologize for present anecdote when data is needed but I manage a Windows network with 100+ users and on a daily basis, Kaspersky catches 5-10 emails from Outlook that have nasty attachments. It prevents my users from opening these innocuous looking but nasty Invoice-Jan-2017.docx files. Without a good AV there…

Have you actually tired Defender and tested it out against Kaspersky? Nobody is telling you to rely on just Office's security features; Defender is a full fledged AV product built into Windows. I believe it and System Center Endpoint Protection are essentially the same product, and in fact, in Windows 10 Defender just applies SCEP policies instead of installing a new program.

Re: Avoid Non-Microsoft Antivirus Software

#42
post #7

This is my advice to everyone I know that gets a new Windows PC. Windows 10's built-in protection is more than adequate, and catches the majority of bad software - anything more is unnecessary, and many of the AV vendors are predatory.

It sucks that you cannot reset your Windows to MS-Vendor settings.

For example if you get some Acer laptop and reset it using windows built-in functionality it'll still reset it with all the bloatware - including AV.

Re: Avoid Non-Microsoft Antivirus Software

#43

Defender has the nasty habit of aggressively scanning new games I download off Steam. There are two occasions where it'll do it: - While it's downloading it seems to scan each chunk. I have a gigabit connection, with defender off I can download at nearly full speed. With it on I can download at about 1MB/s. - While the game loads a level. For example, the intro level to the new Deus Ex took over 10 minutes to load th…

You can give it paths to exempt you know. https://www.tenforums.com/tutorials/5924-windows-defender-ex...

Yeah, but if you piss me off enough times I'm exempting all of my hard drives. It hasn't caught a single virus since 2009. I've not found it that hard to stay safe online.

Re: Avoid Non-Microsoft Antivirus Software

#44
post #4

> At best, there is negligible evidence that major non-MS AV products give a net improvement in security. I apologize for present anecdote when data is needed but I manage a Windows network with 100+ users and on a daily basis, Kaspersky catches 5-10 emails from Outlook that have nasty attachments. It prevents my users from opening these innocuous looking but nasty Invoice-Jan-2017.docx files. Without a good AV there…

You should setup and remove the virus at the source, from the mail server. End users should never receive these mail. Also this is a bad habit to receive invoice from mail (who do that in that way?? in a word docx?

Re: Avoid Non-Microsoft Antivirus Software

#45
post #4

> At best, there is negligible evidence that major non-MS AV products give a net improvement in security. I apologize for present anecdote when data is needed but I manage a Windows network with 100+ users and on a daily basis, Kaspersky catches 5-10 emails from Outlook that have nasty attachments. It prevents my users from opening these innocuous looking but nasty Invoice-Jan-2017.docx files. Without a good AV there…

For managed networks you should configure Application Whitelisting. Users simply shouldn't be able to click on something and execute it.

Re: Avoid Non-Microsoft Antivirus Software

#46
I also want to raise an alarm about a current AV practice, not mentioned in the article:

    AV products like Bitdefender will MITM
    your HTTPS connections by installing their
    own root certificates, by default and 
    without warnings
In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users.

And consider that I, a highly technical and security conscious software developer, only noticed it because I saw green icons appearing in my search results and then noticed that Google's SSL certificate is now a fake. And I only noticed it because I know how this shit works and those green icons seemed suspicious.

And yes, I'm using the word "fake", because I doubt that companies like Bitdefender have to pass the same certifications as a certificate authority or that they have any deals whatsoever with Google. And it's a serious vulnerability, because their certificate can get stolen and used by malicious software, not to mention you now have to trust a third-party with all of your secure connections, which includes your Google searches exposing your most secret desires, your Facebook and Slack chats, your bank account, everything. A third-party that does not have the scrutiny of your open-source web browser.

That's just preposterous and these products only survive because users are gullible and technically illiterate.

Re: Avoid Non-Microsoft Antivirus Software

#47
This - minus the Microsoft part - is what I have been preaching for many years, even back in the late nineties, before pulling myself together and decamping for Linuxland.

But users insist. I have probably never convinced anyone to go without the AV, at least not on a permanent basis.

The best I can do is usually to set up som ClamWin and a daily or weekly scan for everybody's peace of mind.

Re: Avoid Non-Microsoft Antivirus Software

#48
post #7

This is my advice to everyone I know that gets a new Windows PC. Windows 10's built-in protection is more than adequate, and catches the majority of bad software - anything more is unnecessary, and many of the AV vendors are predatory.

What stops majority of bad software for my family is disabling administrator account. They don't care installing patches and antivirus updates anyways.

Re: Avoid Non-Microsoft Antivirus Software

#49
post #27

As always, it depends on the product that you are referring to. Purely by coincidence, I installed [product] again a few weeks ago, after having used Defender since Windows 10 launched. > see bugs in AV products listed in Google's Project Zero All software has vulnerabilities, including Defender. Searching for [product] in Project Zero shows that only 3 vulnerabilities have been discovered (which is arguably a bad th…

>I'm running off an HDD and Defender saturates my HDD for a good 2 minutes after boot.

Yea, that's why I disable all AV - every install or clean build or untar or w/e brings the PC to a crawl. Haven't had problems yet.

Re: Avoid Non-Microsoft Antivirus Software

#50
While many AV companies are really bad, AV per say is still an extra layer of security. Telling people to remove a layer of security is bad advice. There's a problem though and if I knew how to solve it I'd be rich!
Post reply on HN