Live data from Hacker News

Avoid Non-Microsoft Antivirus Software

robert.ocallahan.org

101–110 of 388 posts

Re: Avoid Non-Microsoft Antivirus Software

#102
Just yesterday I had the computer of a friend in front of me, it had three anti-virus applications installed. No idea which was running. I wonder though, do those uninstall mechanism actually work and remove everything?

I kinda have my doubts.

Re: Avoid Non-Microsoft Antivirus Software

#103
post #65

Earlier quoted context omitted.

Don't most browsers have hooks for AV (and other plugins) to get into web traffic without having to mess with TLS?

No, I don't think so and if it does, please tell me which browser does it so I can keep away from it, because that defeats the purpose of TLS. Either way, Bitdefender installs their own root certificate and generates their own for google.com. I've got proof if you want.

I don't think it defeats the purpose of TLS.

From Wikipedia: "TLS and SSL are cryptographic protocols that provide communications security over a computer network". Your host is not "the network" and it's expected to be your trusted asset.

If the AV software can't be trusted, that's another issue not addressed by TLS.

Re: Avoid Non-Microsoft Antivirus Software

#104

Earlier quoted context omitted.

I don't think you understand how HTTPS works. > so they can scan the urls, and block some attacks The purpose of HTTPS is to provide a guarantee that your connection to Google is direct, with no intermediaries, such that (1) only Google knows your search query and (2) you get a guarantee that the received content is from Google. And you get this guarantee from certificate authorities that have a good reputation and t…

There are no intermediaries, AV mitm the traffic because otherwise it cannot scan the content, nor the urls, if it was remote on the AV vendor server then i would understand it but its doing it on you local machine, and you can disable it if you dont want it. If i have a antivirus installed on my pc and get infected with one of those fly byes i would be furious because i was thinking that im protected. I dont know wh…

I still don't see why AV should scan websites. Get AD blocker + javascript blocker (with whitelist for trusted sites) and AV to scan local files. MITM'ing TLS makes more troubles and potential dangers than it solves.

Re: Avoid Non-Microsoft Antivirus Software

#105
post #9

Granny won't believe me :( she feels safer because of some popup that tells her she's safe.

Not only your granny. I also want to remember the android icon which gained thousand of 5 star reviews for 'protecting' the smartphone. https://www.theguardian.com/technology/2014/apr/10/fake-andr...

I don't have an AV on my windows machine since ~8years and no problems so far.

Re: Avoid Non-Microsoft Antivirus Software

#106

Ok, disclaimer first: I've previously worked at Kaspersky Lab (incident response division). Now, I want to say that many of the incidents that we have investigated, would have been prevented by anti-virus software (in many cases AV software was deliberately disabled by user). And I'm talking about incidents that resulted in million-dollar thefts - not just cases of some user getting cryptolocker on their home compute…

I'm pretty sure no AV would help against targeted attacks on high profile target. If you have multi-million business to secure, you play at totally different risk model.

Re: Avoid Non-Microsoft Antivirus Software

#108
post #85

Earlier quoted context omitted.

i dont think you understand how this works. they install a root certicicate on your machine and do mitm "attack" so they can scan the urls, and block some attacks (i remember when some forum had embeded a pdf, that had some attack and antivirus blocked it ) also you have installed an application that has a root acces to the pc, if it was mallicius it could do allot more damage. it is ultimately a question of trust. i…

That is a bad idea. If you MITM the connection locally it triples the computational cost for both encryption and handshake operations. Then more websites don't use TLS because it's three times as slow for the user. It also prevents you from using a good cipher suite when the MITM doesn't support it even though the browser and the server both do, again reducing security or performance or both. And it's very easy to sc…

ok some of those are valid concerns but i would argue that being infected trumps all of those. they have to get it only once.

Re: Avoid Non-Microsoft Antivirus Software

#109
post #40
post #4

> At best, there is negligible evidence that major non-MS AV products give a net improvement in security. I apologize for present anecdote when data is needed but I manage a Windows network with 100+ users and on a daily basis, Kaspersky catches 5-10 emails from Outlook that have nasty attachments. It prevents my users from opening these innocuous looking but nasty Invoice-Jan-2017.docx files. Without a good AV there…

Email attachments should be scanned by the mail server.

https://en.wikipedia.org/wiki/Defense_in_depth_(computing)

Re: Avoid Non-Microsoft Antivirus Software

#110
post #92

Earlier quoted context omitted.

Yes. Also, let's finally start a public discussion about AV companies making money by selling data (they do, either all of them or most). Of course that being able to peek into https traffic gets them more data (specific urls, not just whole sites).

_Everyone_ is collecting our data nowadays. Who's left to sell it to?

But not everyone has access to all of your browsing history; especially across browsers and devices.

There's Microsoft, Google, and/or Apple have that. The profit models of these big companies create some disincentives on onselling this data.

AV providers are often on much smaller margins and the return from selling this data or building their own products on it is much higher.

I wouldn't be surprised if ISPs and VPNs also sold on data.

Post reply on HN