Live data from Hacker News

Avoid Non-Microsoft Antivirus Software

robert.ocallahan.org

51–60 of 388 posts

Re: Avoid Non-Microsoft Antivirus Software

#51
Some good points. The antivirus software itself is probably an interesting attack vector. However I don't like the assertion that Microsoft scanners are sufficient without some evidence (and In wouldn't be shocked if the MS-AV software itself was exploitable, too). At least run some tests and compare a couple of state of the art products.

The situation is generally bad, AV vendors are often shady. However I think "vet your AV vendor" is much better advice.

Re: Avoid Non-Microsoft Antivirus Software

#52
I will consider this. I "maintain" my relatives computers which is basically to install an anti-virus and adblock. They still get those sketchy messages from friends from time to time though, which is the main reason that I keep them with an AV. Is this correct? Does AV improve security for people who cannot differentiate between a .pdf and an .exe?

Personally I don't use an AV, I am a bit paranoid and technical competent so my case and my relatives is totally different.

Re: Avoid Non-Microsoft Antivirus Software

#53
post #27

As always, it depends on the product that you are referring to. Purely by coincidence, I installed [product] again a few weeks ago, after having used Defender since Windows 10 launched. > see bugs in AV products listed in Google's Project Zero All software has vulnerabilities, including Defender. Searching for [product] in Project Zero shows that only 3 vulnerabilities have been discovered (which is arguably a bad th…

> All software has vulnerabilities

Most software doesn't run in ring0. And most software doesn't actively break exploit mitigation techniques in other software either.

Re: Avoid Non-Microsoft Antivirus Software

#55

It's irresponsible to make such a broad claim and back it up with really vague anecdotal evidence. Yes, there are a lot of lousy AV products that are at best a break-even for security, but there are some that don't suck and generally you have to pay for them - what a strange concept. I'm not going to advocate for any particular vendor as I used to work for an AV company (and currently use a product from a competitor)…

I completely agree with you, I find this "disable antivirus" to be such a bad advice! Yes, it may work for tech savvy or security aware person. If you know what you're doing you're much less likely to get into problems. It won't work for general public though.

And the argument being made that "for example, see bugs in AV products listed in Google's Project Zero. These bugs indicate that not only do these products open many attack vectors" could be made for any piece of software your install.

Re: Avoid Non-Microsoft Antivirus Software

#56
post #30
post #24

I have the impression that the AV business is some kind of mixture of scam and mafia.

Users are to blame by pirating software. Of course, pirates don't do it for free.

Don't they? Pirates have been around since long before viruses really became a problem. What was their motivation then?

Re: Avoid Non-Microsoft Antivirus Software

#57
post #30

Earlier quoted context omitted.

Users are to blame by pirating software. Of course, pirates don't do it for free.

How does piracy come into this?

lots of binaries are not only patched to circument DRM, but also to contain malware

Re: Avoid Non-Microsoft Antivirus Software

#58

I also want to raise an alarm about a current AV practice, not mentioned in the article: AV products like Bitdefender will MITM your HTTPS connections by installing their own root certificates, by default and without warnings In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users. And consider that I, a highly technical and security conscious software dev…

i dont think you understand how this works. they install a root certicicate on your machine and do mitm "attack" so they can scan the urls, and block some attacks (i remember when some forum had embeded a pdf, that had some attack and antivirus blocked it )

also you have installed an application that has a root acces to the pc, if it was mallicius it could do allot more damage. it is ultimately a question of trust.

i created and installed my own root certificate because i dont want clicking on the exception if i open a new incognito window, its especialy anoying for websocket connections.

Re: Avoid Non-Microsoft Antivirus Software

#59
post #7

This is my advice to everyone I know that gets a new Windows PC. Windows 10's built-in protection is more than adequate, and catches the majority of bad software - anything more is unnecessary, and many of the AV vendors are predatory.

It sucks that you cannot reset your Windows to MS-Vendor settings. For example if you get some Acer laptop and reset it using windows built-in functionality it'll still reset it with all the bloatware - including AV.

This should do it:

https://www.microsoft.com/en-us/software-download/windows10s...

They've had similar tools since at least Windows 7 IIRC, if not XP - you've just always had to download them separately, and they've never been advertised with much enthusiasm. Probably trying to strike a balance between pleasing power-users and keeping the bundled-bloatware ecosystem happy, seeing as MS benefit financially from both.

Re: Avoid Non-Microsoft Antivirus Software

#60
post #51

Some good points. The antivirus software itself is probably an interesting attack vector. However I don't like the assertion that Microsoft scanners are sufficient without some evidence (and In wouldn't be shocked if the MS-AV software itself was exploitable, too). At least run some tests and compare a couple of state of the art products. The situation is generally bad, AV vendors are often shady. However I think "ve…

Most computer users are not competent enough to use their machine properly (and need stronger AV to protect them). What makes you think they have the technical capability to "vet their AV vendor"?
Post reply on HN