Earlier quoted context omitted.
Microsoft doesn't exactly have a great record with root certificates either. >Emergency Windows update revokes dozens of bogus Google, Yahoo SSL certificates https://arstechnica.com/security/2014/07/emergency-windows-u... They revoked certs like this silently in the past which makes it even worse.
Got an example? I haven't heard anything about this and I'm genuinely curious.
Avoid Non-Microsoft Antivirus Software
121–130 of 388 posts
Re: Avoid Non-Microsoft Antivirus Software
#122I've also read various reports of security problems with AV software, so I'm not comfortable recommending anything third-party.
Defender + uBlock is a pretty simple and effective combo.
Re: Avoid Non-Microsoft Antivirus Software
#123Earlier quoted context omitted.
Microsoft doesn't exactly have a great record with root certificates either. >Emergency Windows update revokes dozens of bogus Google, Yahoo SSL certificates https://arstechnica.com/security/2014/07/emergency-windows-u... They revoked certs like this silently in the past which makes it even worse.
You can manage pre-installed root certificates manually in Windows. As far as I've seen, there was nothing sinister in default Windows root CA list.
Re: Avoid Non-Microsoft Antivirus Software
#124Earlier quoted context omitted.
> In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users. It doesn't have to be insecure. If the software that does the MITM checks the certificates correctly, I don't see how it would be worse than letting the browser handle it. Not that I'd ever use an antivirus, of course.
It actually is worse. The problem comes "what does the interception do when it encounters an invalid certificate"? So for example a self-signed cert. does it a) create a "valid" cert itself, hiding the error from the user? This is obviously dangerous b) create an "invalid" self-signed cert. This is messy as a user will then see a self-signed cert from the A-V vendor, which they may be more or less inclined to trust c…
Re: Avoid Non-Microsoft Antivirus Software
#125Earlier quoted context omitted.
Microsoft doesn't exactly have a great record with root certificates either. >Emergency Windows update revokes dozens of bogus Google, Yahoo SSL certificates https://arstechnica.com/security/2014/07/emergency-windows-u... They revoked certs like this silently in the past which makes it even worse.
You can manage pre-installed root certificates manually in Windows. As far as I've seen, there was nothing sinister in default Windows root CA list.
>As far as I've seen, there was nothing sinister in default Windows root CA list.
Are you in any way related to MS or is your memory just very short?
>Emergency Windows update revokes dozens of bogus Google, Yahoo SSL certificates
https://arstechnica.com/security/2014/07/emergency-windows-u...
Re: Avoid Non-Microsoft Antivirus Software
#126Re: Avoid Non-Microsoft Antivirus Software
#127I contacted Symantec and had to uninstall Norton Security and install Norton Antivirus for the windows firewall to be activated.
Re: Avoid Non-Microsoft Antivirus Software
#128What's more, as third party antivirus software becomes increasingly irrelevant, many of these companies resort to harmful and even actively malicious tactics to stay in business. On the more benign end, you see an increase in 'safe web browsing' and such tools that parse javascript while browsing and somehow attempt to make it.. safer, I guess. My main experience with these things is when they randomly decide to bloc…
> I should say here that I fully expect someone reading this has managed to uninstall an AVG toolbar with no issues. They have multiple different auxiliary tools to their antivirus, and I'm not sure specifically which one(s) caused me trouble personally. I can say this: I never had a problem with uninstalling a browser toolbar, or restoring the default search engine in the browser. What I always have problems with, i…
Re: Avoid Non-Microsoft Antivirus Software
#129Earlier quoted context omitted.
No, I don't think so and if it does, please tell me which browser does it so I can keep away from it, because that defeats the purpose of TLS. Either way, Bitdefender installs their own root certificate and generates their own for google.com. I've got proof if you want.
Chrome, Firefox. Probably more. https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NS...
Re: Avoid Non-Microsoft Antivirus Software
#130Earlier quoted context omitted.
_Everyone_ is collecting our data nowadays. Who's left to sell it to?
Not everyone. FOSS doesn't.