Live data from Hacker News

Avoid Non-Microsoft Antivirus Software

robert.ocallahan.org

111–120 of 388 posts

Re: Avoid Non-Microsoft Antivirus Software

#111
post #92

Earlier quoted context omitted.

Yes. Also, let's finally start a public discussion about AV companies making money by selling data (they do, either all of them or most). Of course that being able to peek into https traffic gets them more data (specific urls, not just whole sites).

_Everyone_ is collecting our data nowadays. Who's left to sell it to?

Not everyone. FOSS doesn't.

Re: Avoid Non-Microsoft Antivirus Software

#112

Ok, disclaimer first: I've previously worked at Kaspersky Lab (incident response division). Now, I want to say that many of the incidents that we have investigated, would have been prevented by anti-virus software (in many cases AV software was deliberately disabled by user). And I'm talking about incidents that resulted in million-dollar thefts - not just cases of some user getting cryptolocker on their home compute…

Any AV software is better than having none but that's not the point of the article. It specifically recommends Microsoft's AV and to stay clear of all the others.

I'm sure it's hard on all the AV vendors out there but with Microsoft Essentials and Windows Defender I don't see the need for a third party AV.

Re: Avoid Non-Microsoft Antivirus Software

#113
post #106

Ok, disclaimer first: I've previously worked at Kaspersky Lab (incident response division). Now, I want to say that many of the incidents that we have investigated, would have been prevented by anti-virus software (in many cases AV software was deliberately disabled by user). And I'm talking about incidents that resulted in million-dollar thefts - not just cases of some user getting cryptolocker on their home compute…

I'm pretty sure no AV would help against targeted attacks on high profile target. If you have multi-million business to secure, you play at totally different risk model.

That's exactly what I had in mind when I read the GP. If third party AVs have a large and complex codebase with unknown or even known security flaws, they won't help much against targeted attacks or make them even easier.

On the other hand, AV usability is so bad you can't expect it to help "normal" people. All those popups do more harm than good when people start ignoring them.

Re: Avoid Non-Microsoft Antivirus Software

#114

Who writes all these viruses ? I mean, I've experimented with assembler when I was a teenager and I may have developed some kind of program which could replicate itself.. but I highly doubt today's viruses are written by teenagers... Who and why do people write viruses ? Is this a thing at all or are all the viruses written by the Antivirus makers themselves ? More 'threats' is good news for the A/V makers so why not…

Confirm that AV vendors are writing the viruses themselves in order to boost their sales? Good luck with that.

There are plenty of reasons why people write malware/viruses, often for financial reasons. The old days of a teenager writing some virus in assembly to infect bootsectors for the lulz is way past us. Today you're looking at malware, often exploiting social engineering, to create botnets for DDoS, spam, boosting social profiles, etc.

Occam's razor helps :)

Re: Avoid Non-Microsoft Antivirus Software

#115

Earlier quoted context omitted.

Microsoft doesn't exactly have a great record with root certificates either. >Emergency Windows update revokes dozens of bogus Google, Yahoo SSL certificates https://arstechnica.com/security/2014/07/emergency-windows-u... They revoked certs like this silently in the past which makes it even worse.

Got an example? I haven't heard anything about this and I'm genuinely curious.

Added a link to the post.

Re: Avoid Non-Microsoft Antivirus Software

#116

Earlier quoted context omitted.

Microsoft doesn't exactly have a great record with root certificates either. >Emergency Windows update revokes dozens of bogus Google, Yahoo SSL certificates https://arstechnica.com/security/2014/07/emergency-windows-u... They revoked certs like this silently in the past which makes it even worse.

Any references, because I don't know what you're talking about? I'm not a Windows user, haven't been a Windows user since 2001, my AV experience has been with the PCs of my family, whom I'm trying to keep safe. But even if I were a Windows user, if you can't trust Microsoft, you can't trust their OS, at which point it would be better to use something else because security really depends on how trustworthy that OS and…

Added a link to the post.

Re: Avoid Non-Microsoft Antivirus Software

#117

I will consider this. I " maintain " my relatives computers which is basically to install an anti-virus and adblock. They still get those sketchy messages from friends from time to time though, which is the main reason that I keep them with an AV. Is this correct? Does AV improve security for people who cannot differentiate between a .pdf and an .exe? Personally I don't use an AV, I am a bit paranoid and technical co…

I don't use an AV either, but I'm very careful with the things I download (and I don't download new stuff very often).

My relatives, on the other hand, will click just about anything that says "click me" (even more if it says they will win a prize or something).

Windows Defender is great and it's enough for me but my relatives need something that cover more areas. Any way you can think of tricking them, they will fall for it. Even with AV, they routinely install malware (those that are too new to be in the AV database or using new techniques not covered by heuristics).

As far as I know, my relatives don't do anything but sit in front of their computers trying to install malware ;)

Re: Avoid Non-Microsoft Antivirus Software

#118

Ok, disclaimer first: I've previously worked at Kaspersky Lab (incident response division). Now, I want to say that many of the incidents that we have investigated, would have been prevented by anti-virus software (in many cases AV software was deliberately disabled by user). And I'm talking about incidents that resulted in million-dollar thefts - not just cases of some user getting cryptolocker on their home compute…

Kaspersky is the worst of them:

https://www.bloomberg.com/news/articles/2015-03-19/cybersecu...

Re: Avoid Non-Microsoft Antivirus Software

#119
post #51

Some good points. The antivirus software itself is probably an interesting attack vector. However I don't like the assertion that Microsoft scanners are sufficient without some evidence (and In wouldn't be shocked if the MS-AV software itself was exploitable, too). At least run some tests and compare a couple of state of the art products. The situation is generally bad, AV vendors are often shady. However I think "ve…

Most computer users are not competent enough to use their machine properly (and need stronger AV to protect them). What makes you think they have the technical capability to "vet their AV vendor"?

Those users usually rely on some support structure which I assumed was the intended audience of the article. At least I wouldn't expect my parents to even search the internet for some article that tells them to turn off all antivirus except Defender.

Re: Avoid Non-Microsoft Antivirus Software

#120

I also want to raise an alarm about a current AV practice, not mentioned in the article: AV products like Bitdefender will MITM your HTTPS connections by installing their own root certificates, by default and without warnings In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users. And consider that I, a highly technical and security conscious software dev…

> In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users. It doesn't have to be insecure. If the software that does the MITM checks the certificates correctly, I don't see how it would be worse than letting the browser handle it. Not that I'd ever use an antivirus, of course.

It actually is worse. The problem comes "what does the interception do when it encounters an invalid certificate"?

So for example a self-signed cert. does it

a) create a "valid" cert itself, hiding the error from the user? This is obviously dangerous

b) create an "invalid" self-signed cert. This is messy as a user will then see a self-signed cert from the A-V vendor, which they may be more or less inclined to trust

c) Pass the traffic through without inspection, missing any potential threats

And that's just one case. SSL/TLS interception is very hard to get right and easy to make the user's security worse as a result.

Post reply on HN