Live data from Hacker News

Avoid Non-Microsoft Antivirus Software

robert.ocallahan.org

151–160 of 388 posts

Re: Avoid Non-Microsoft Antivirus Software

#151
post #39

It's fucking disaster to read your blog in iphone, please fix it. At least disable fixed width or disable right left surfing. I am not web developer, so i may give wrong suggestions, but please fix you template it is like piece of shit( the experience)

I don't understand why i got downvoted ao badly. I didnt say anything about his blog or material in his blog, i just couldn't read/navigate his blog in my phone. The template was a total disaster

Re: Avoid Non-Microsoft Antivirus Software

#152
post #40

Earlier quoted context omitted.

Email attachments should be scanned by the mail server.

https://en.wikipedia.org/wiki/Defense_in_depth_(computing)

does not mean that the answer to "should I install this 'security' product?" is always "yes".

Re: Avoid Non-Microsoft Antivirus Software

#153
post #4

> At best, there is negligible evidence that major non-MS AV products give a net improvement in security. I apologize for present anecdote when data is needed but I manage a Windows network with 100+ users and on a daily basis, Kaspersky catches 5-10 emails from Outlook that have nasty attachments. It prevents my users from opening these innocuous looking but nasty Invoice-Jan-2017.docx files. Without a good AV there…

Does anyone on your network have a valid reason to execute Office macros? If not, disable them via group policy. Solves so many problems. See what @SwiftOnSecurity has to say on the topic, they manage thousands of users and it seems to work excellently.

Re: Avoid Non-Microsoft Antivirus Software

#154
post #113

Earlier quoted context omitted.

That's exactly what I had in mind when I read the GP. If third party AVs have a large and complex codebase with unknown or even known security flaws, they won't help much against targeted attacks or make them even easier. On the other hand, AV usability is so bad you can't expect it to help "normal" people. All those popups do more harm than good when people start ignoring them.

Well, I agree that AV most likely wouldn't protect you against targeted attacks - but most of the attacks that we investigated were targeted quite broadly - phishing email campaigns targeting financial organizations (with address lists based on some hacked legitimate resources for accountants, for example). And usually these attack succeeded because of insecure infrastructure, poorly trained admins, old, non-updating…

Maybe some of them thought they were fine if they were using AV software? I know what you mean, but the marketing departments of many AV vendors praise it like some kind of all-around solution. I'm pretty sure some people think they can get away with disabling updates etc. and than just buy AV software afterwards when they feel they can't handle their systems anymore.

Maybe the perception that you can achieve some kind of security through band-aid solutions is exactly the cause for the lacking security of many organizations?

Re: Avoid Non-Microsoft Antivirus Software

#155

I will consider this. I " maintain " my relatives computers which is basically to install an anti-virus and adblock. They still get those sketchy messages from friends from time to time though, which is the main reason that I keep them with an AV. Is this correct? Does AV improve security for people who cannot differentiate between a .pdf and an .exe? Personally I don't use an AV, I am a bit paranoid and technical co…

I don't use an AV either, but I'm very careful with the things I download (and I don't download new stuff very often). My relatives, on the other hand, will click just about anything that says "click me" (even more if it says they will win a prize or something). Windows Defender is great and it's enough for me but my relatives need something that cover more areas. Any way you can think of tricking them, they will fal…

An iOS device, or better still a Chromebook, would be pretty good for users like these.

Re: Avoid Non-Microsoft Antivirus Software

#156

I also want to raise an alarm about a current AV practice, not mentioned in the article: AV products like Bitdefender will MITM your HTTPS connections by installing their own root certificates, by default and without warnings In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users. And consider that I, a highly technical and security conscious software dev…

Yes. Also, let's finally start a public discussion about AV companies making money by selling data (they do, either all of them or most). Of course that being able to peek into https traffic gets them more data (specific urls, not just whole sites).

Some of what is was their EULA (which is subject to change), and what they collected (which is subject to change with updates):

http://www.pcmag.com/article2/0,2817,2492599,00.asp

https://www.av-comparatives.org/wp-content/uploads/2014/04/a...

Re: Avoid Non-Microsoft Antivirus Software

#157
post #87

Who writes all these viruses ? I mean, I've experimented with assembler when I was a teenager and I may have developed some kind of program which could replicate itself.. but I highly doubt today's viruses are written by teenagers... Who and why do people write viruses ? Is this a thing at all or are all the viruses written by the Antivirus makers themselves ? More 'threats' is good news for the A/V makers so why not…

If you have some time to watch a video, here's a clip of F-Secure's Mikko Hyppönen expaining some of the origins of network attacks and malware: https://www.ted.com/talks/mikko_hypponen_fighting_viruses_de...

Speaking of F-Secure, has taviso just not looked at F-Secure yet or does F-Secure not have egregious blunders?

Re: Avoid Non-Microsoft Antivirus Software

#158
post #111

Earlier quoted context omitted.

Not everyone. FOSS doesn't.

citation needed https://github.com/Homebrew/brew/blob/master/docs/Analytics....

That link says nothing about selling your data.

Also note that while Homebrew may be open-source, it is not "free software".

Post reply on HN