Live data from Hacker News

Avoid Non-Microsoft Antivirus Software

robert.ocallahan.org

61–70 of 388 posts

Re: Avoid Non-Microsoft Antivirus Software

#61

I also want to raise an alarm about a current AV practice, not mentioned in the article: AV products like Bitdefender will MITM your HTTPS connections by installing their own root certificates, by default and without warnings In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users. And consider that I, a highly technical and security conscious software dev…

Don't forget that if their software is changing the certificates for every HTTPS site you visit they're probably doing it on the fly. This means that the private key is on your computer. Assuming they generate a per install private key that won't be a big issue but if it's the same private key for all their installs it could get pretty bad once someone gets the key

Re: Avoid Non-Microsoft Antivirus Software

#62
post #30
post #24

I have the impression that the AV business is some kind of mixture of scam and mafia.

Users are to blame by pirating software. Of course, pirates don't do it for free.

There are lots of attack vectors, not just pirated software, and viable ones depending on desired outcome can range from email, browser, and direct software spread (pirate games). MacOS isn't safe, and neither is Linux though the attack vectors will vary.

If all you want is a DDoS, a fake advertising account can often deliver the desired effect without actually infecting anyone. It really depends on what the cost/benefit vs desired outcome is. Not everything requires root, and very few people actually check checksums for things they download.

Re: Avoid Non-Microsoft Antivirus Software

#63
post #27

As always, it depends on the product that you are referring to. Purely by coincidence, I installed [product] again a few weeks ago, after having used Defender since Windows 10 launched. > see bugs in AV products listed in Google's Project Zero All software has vulnerabilities, including Defender. Searching for [product] in Project Zero shows that only 3 vulnerabilities have been discovered (which is arguably a bad th…

All software has vulnerabilities but not all software has the egregious blunders that Travis Ormandy finds --- so many, in such a short period of time.

Furthermore, most software provides value that offsets security risks. Since the entire value of AV products is to improve security, when they fail to do that, they're worse than useless.

The homogeneous market argument is weak. If a determined attacker wants to compromise as many machines as possible with a single attack, they'll come up with an exploit that passes all AV products.

Re: Avoid Non-Microsoft Antivirus Software

#65

I also want to raise an alarm about a current AV practice, not mentioned in the article: AV products like Bitdefender will MITM your HTTPS connections by installing their own root certificates, by default and without warnings In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users. And consider that I, a highly technical and security conscious software dev…

Don't most browsers have hooks for AV (and other plugins) to get into web traffic without having to mess with TLS?

Re: Avoid Non-Microsoft Antivirus Software

#66

Defender has the nasty habit of aggressively scanning new games I download off Steam. There are two occasions where it'll do it: - While it's downloading it seems to scan each chunk. I have a gigabit connection, with defender off I can download at nearly full speed. With it on I can download at about 1MB/s. - While the game loads a level. For example, the intro level to the new Deus Ex took over 10 minutes to load th…

I wonder, have there been cases where viruses or trojans were spread via Steam?

Re: Avoid Non-Microsoft Antivirus Software

#67
post #37

I was running a crawler the other day on one of my PCs from a console app. Then suddenly the antivirus discovers that a page is infected, terminates the connection and wrecks havoc to the app which stays hung there for hours and I'm unable to terminate or even kill it from Task Manager. I had to restart the PC for the task to be forcefully killed. Thanks but no thanks. I uninstalled the damn thing the next day. How t…

What's the difference between your crawler and the botnet client as far as the AV concerned? You're the outlier among the AV customer segment.

Re: Avoid Non-Microsoft Antivirus Software

#68
post #36

It's irresponsible to make such a broad claim and back it up with really vague anecdotal evidence. Yes, there are a lot of lousy AV products that are at best a break-even for security, but there are some that don't suck and generally you have to pay for them - what a strange concept. I'm not going to advocate for any particular vendor as I used to work for an AV company (and currently use a product from a competitor)…

> really vague anecdotal evidence [...] > I can attest that I've used products that have caught threats that Windows Defender didn't Since you brought it up, the latter statements sounds suspiciously like the very definition of "really vague anecdotal evidence. SCNR

Perhaps it is counter-anecdotal evidence showing the futility of anecdotal evidence as a whole.

Re: Avoid Non-Microsoft Antivirus Software

#69
post #27

As always, it depends on the product that you are referring to. Purely by coincidence, I installed [product] again a few weeks ago, after having used Defender since Windows 10 launched. > see bugs in AV products listed in Google's Project Zero All software has vulnerabilities, including Defender. Searching for [product] in Project Zero shows that only 3 vulnerabilities have been discovered (which is arguably a bad th…

Avira won the speed test? It reliably made every PC I installed it on 2-3 times slower and adds a few minutes to the boot time compared to MSE or whatever it is now called.

Re: Avoid Non-Microsoft Antivirus Software

#70
post #7

This is my advice to everyone I know that gets a new Windows PC. Windows 10's built-in protection is more than adequate, and catches the majority of bad software - anything more is unnecessary, and many of the AV vendors are predatory.

It sucks that you cannot reset your Windows to MS-Vendor settings. For example if you get some Acer laptop and reset it using windows built-in functionality it'll still reset it with all the bloatware - including AV.

Microsoft released a tool[0] that does exactly that

[0]: https://www.microsoft.com/en-us/software-download/windows10s...

Post reply on HN