Live data from Hacker News

Avoid Non-Microsoft Antivirus Software

robert.ocallahan.org

71–80 of 388 posts

Re: Avoid Non-Microsoft Antivirus Software

#71

I also want to raise an alarm about a current AV practice, not mentioned in the article: AV products like Bitdefender will MITM your HTTPS connections by installing their own root certificates, by default and without warnings In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users. And consider that I, a highly technical and security conscious software dev…

i dont think you understand how this works. they install a root certicicate on your machine and do mitm "attack" so they can scan the urls, and block some attacks (i remember when some forum had embeded a pdf, that had some attack and antivirus blocked it ) also you have installed an application that has a root acces to the pc, if it was mallicius it could do allot more damage. it is ultimately a question of trust. i…

I don't think you understand how HTTPS works.

> so they can scan the urls, and block some attacks

The purpose of HTTPS is to provide a guarantee that your connection to Google is direct, with no intermediaries, such that (1) only Google knows your search query and (2) you get a guarantee that the received content is from Google.

And you get this guarantee from certificate authorities that have a good reputation and that are in business because they've proven they can keep their shit secure. And when one of them violates that trust, the OS / browser vendors can start to invalidate their certificates. AV companies are bypassing it all.

The blocking of attacks reasoning is kind of bullshit, because Google's Safe Browsing service and browser extensions maintained by a community like uBlock Origin are doing a better job of warning against potentially malicious websites. There are always vulnerabilities to exploit of course, though it's getting harder for those to pop up due to the modern sandboxing of browsers.

However I have yet to see evidence that AV software is doing a better job of catching those, because it's a whack-a-mole game and it's more likely that browser vendors find and fix those vulnerabilities faster than AV companies, because bugs get reported to browser vendors first. And sure, if you have Adobe Reader or Oracle Java installed as plugins in your browser, that's a huge risk, but it's actually easier to uninstall those and browsers have started disallowing plugins. Safari for example is disabling everything by default.

The problem with installing their own root certificate is precisely one of trust. Yes, you allow a piece of software to run with root permissions, for as long as you don't see it do stupid shit, like installing a root certificate, at which point all of that trust should be gone.

And that is because a custom root certificate that doesn't belong to a competent certificate authority cannot be trusted and will increase the attack surface. This is security 101.

Re: Avoid Non-Microsoft Antivirus Software

#73
post #30
post #24

I have the impression that the AV business is some kind of mixture of scam and mafia.

Users are to blame by pirating software. Of course, pirates don't do it for free.

Yes they do, the cracking scene ethos is all about technical one-upmanship and the thrill and glory of beating copy protection. Or at least it used to be. The really smart ones do it for their own enjoyment or ideological reasons.

Re: Avoid Non-Microsoft Antivirus Software

#74
post #7

This is my advice to everyone I know that gets a new Windows PC. Windows 10's built-in protection is more than adequate, and catches the majority of bad software - anything more is unnecessary, and many of the AV vendors are predatory.

It sucks that you cannot reset your Windows to MS-Vendor settings. For example if you get some Acer laptop and reset it using windows built-in functionality it'll still reset it with all the bloatware - including AV.

Yes, that was the point of the "Signature Windows" series laptops, which looked promising but didn't seem to actually go anywhere...

Re: Avoid Non-Microsoft Antivirus Software

#75

What's more, as third party antivirus software becomes increasingly irrelevant, many of these companies resort to harmful and even actively malicious tactics to stay in business. On the more benign end, you see an increase in 'safe web browsing' and such tools that parse javascript while browsing and somehow attempt to make it.. safer, I guess. My main experience with these things is when they randomly decide to bloc…

A friend of mine worked as an on-site contractor for the AVG. He claimed that the "toolbar department" in the company, working on the browser toolbar displaying ads is as big as the "antivirus department", working on the engine (or bigger). It shouldn't be a surprise, since the toolbar is the main revenue source for the company.

Re: Avoid Non-Microsoft Antivirus Software

#76
Ok, disclaimer first: I've previously worked at Kaspersky Lab (incident response division). Now, I want to say that many of the incidents that we have investigated, would have been prevented by anti-virus software (in many cases AV software was deliberately disabled by user). And I'm talking about incidents that resulted in million-dollar thefts - not just cases of some user getting cryptolocker on their home computer. I agree that AV software is bloated and has very large, messy and barely maintainable codebase, but I disagree with people who say that "I have never used any AV products and in 10 years have never been infected with malware" - this attitude is careless, to say the least, and in corporate environment could lead to huge financial losses. There are many criminal groups that put serious effort in the development and distribution of malware - not just script kiddies, but professional programmers and hackers.

BTW, there are also region-specific malware - so for example I would rely more on Kaspersky for detection of malware targeted at Russian businesses, than Symantec or Microsoft AVs.

Re: Avoid Non-Microsoft Antivirus Software

#77
post #65

I also want to raise an alarm about a current AV practice, not mentioned in the article: AV products like Bitdefender will MITM your HTTPS connections by installing their own root certificates, by default and without warnings In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users. And consider that I, a highly technical and security conscious software dev…

Don't most browsers have hooks for AV (and other plugins) to get into web traffic without having to mess with TLS?

No, I don't think so and if it does, please tell me which browser does it so I can keep away from it, because that defeats the purpose of TLS.

Either way, Bitdefender installs their own root certificate and generates their own for google.com. I've got proof if you want.

Re: Avoid Non-Microsoft Antivirus Software

#78

I also want to raise an alarm about a current AV practice, not mentioned in the article: AV products like Bitdefender will MITM your HTTPS connections by installing their own root certificates, by default and without warnings In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users. And consider that I, a highly technical and security conscious software dev…

Microsoft doesn't exactly have a great record with root certificates either.

>Emergency Windows update revokes dozens of bogus Google, Yahoo SSL certificates

https://arstechnica.com/security/2014/07/emergency-windows-u...

They revoked certs like this silently in the past which makes it even worse.

Re: Avoid Non-Microsoft Antivirus Software

#79
Who writes all these viruses ?

I mean, I've experimented with assembler when I was a teenager and I may have developed some kind of program which could replicate itself.. but I highly doubt today's viruses are written by teenagers...

Who and why do people write viruses ? Is this a thing at all or are all the viruses written by the Antivirus makers themselves ?

More 'threats' is good news for the A/V makers so why not have a separate department which develops them ?

I wouldn't be surprised at all, given that much crazier things are happening in this world..

Can anyone confirm or disprove this ?

Re: Avoid Non-Microsoft Antivirus Software

#80

What's more, as third party antivirus software becomes increasingly irrelevant, many of these companies resort to harmful and even actively malicious tactics to stay in business. On the more benign end, you see an increase in 'safe web browsing' and such tools that parse javascript while browsing and somehow attempt to make it.. safer, I guess. My main experience with these things is when they randomly decide to bloc…

> I should say here that I fully expect someone reading this has managed to uninstall an AVG toolbar with no issues. They have multiple different auxiliary tools to their antivirus, and I'm not sure specifically which one(s) caused me trouble personally.

I can say this: I never had a problem with uninstalling a browser toolbar, or restoring the default search engine in the browser. What I always have problems with, is getting rid of AV software itself. Oh God, how hard it is sometimes.

Norton AV taking half an hour to uninstall is a known thing; I'm convinced they actually have some Sleep() calls in their code just to piss people off. But just last week I tried to get rid of Comodo AV (+ 2 bullshit pieces of software it installed) on my neighbour's computer. Took a while. The uninstaller didn't work (it reported "an error" and gave up), so ultimately I had to resort to manually deleting stuff until the uninstaller finally unlocked itself and cleaned up the rest.

I've been having similar experiences with all AV software in past few years. They're a menace.

Post reply on HN