Live data from Hacker News

Avoid Non-Microsoft Antivirus Software

robert.ocallahan.org

161–170 of 388 posts

Re: Avoid Non-Microsoft Antivirus Software

#162
In principle, I agree with the article.

Personally, on Win7 I use a combination of 3 things:

- MSSE - TinyWall as a lightweight firewall - heavily modified HOSTS file

Never had malware/virus problems and sometimes I do visit shady webistes or download quirky software.

Re: Avoid Non-Microsoft Antivirus Software

#163
post #145

What's wrong with avoiding Microsoft anti-virus, too? Or os he giving this advice only because most people can't disable Microsoft's antivirus anymore, anyway?

Because my guess is that Defender is reasonably implemented and does the basics right, and therefore is significantly better than nothing for the average user. That guess is based on anecdotal observations of the quality of developers and practices at Microsoft vs what we've learned about A/V vendors via bug disclosures.

Re: Avoid Non-Microsoft Antivirus Software

#164

In principle, I agree with the article. Personally, on Win7 I use a combination of 3 things: - MSSE - TinyWall as a lightweight firewall - heavily modified HOSTS file Never had malware/virus problems and sometimes I do visit shady webistes or download quirky software.

You want to add EMET to the mix.

https://microsoft.com/emet

Re: Avoid Non-Microsoft Antivirus Software

#165
Yeah, trust Microsoft, he said:

http://www.theverge.com/2017/1/25/14381174/microsoft-thailan...

Isn't it funny how at the same time someone is recommending to not trust other anti-viruses because they MITM you with their own certificates, Microsoft is doing the same god damn thing, or worse (allowing a whole country to spy on you through it, and not just itself).

> “This program is an extensive review process that includes regular audits from a third-party web trust auditor.

Is that the same auditor that audited WoSign as well?

https://blog.mozilla.org/security/2016/10/24/distrusting-new...

Why hasn't Microsoft started requiring Certificate Transparency yet for all certificates? Maybe then I'll believe them when they say they're sure nothing wrong is going on here.

Re: Avoid Non-Microsoft Antivirus Software

#166

Earlier quoted context omitted.

So to do that it's going to stop the users browsing session, redirect them to a local web page and then present something to let them make a decision about carrying on? not the best user experience in the world.. But remember like I said that's just one example of why it's a bad idea, there's others, e.g. what do you do about EV-SSL certificates? You can't fake the browser element for them (remember this is the case…

Of course there are lots of what-ifs, but how do you tamper with HTTPS traffic if you don't MITM?

Easy, you don't tamper with HTTPS traffic, it's innately a very bad idea.

Consider the goals that are trying to be achieved. You're attempting to stop the user either downloading malicious content or perhaps getting hit with a browser exploit or possibly you're trying to stop users going to a "bad" site.

The first one can be covered off with traditional on-access scanning of files.

The second one is much better addressed by improvements in browser sandboxing or general app. security.

The third one can be handled at a DNS level with reputation based block lists.

Re: Avoid Non-Microsoft Antivirus Software

#167
post #155

Earlier quoted context omitted.

I don't use an AV either, but I'm very careful with the things I download (and I don't download new stuff very often). My relatives, on the other hand, will click just about anything that says "click me" (even more if it says they will win a prize or something). Windows Defender is great and it's enough for me but my relatives need something that cover more areas. Any way you can think of tricking them, they will fal…

An iOS device, or better still a Chromebook, would be pretty good for users like these.

I don't even live in the same country so it's more of a "when you are around can you check this please?"

Re: Avoid Non-Microsoft Antivirus Software

#168

Earlier quoted context omitted.

citation needed https://github.com/Homebrew/brew/blob/master/docs/Analytics....

That link says nothing about selling your data. Also note that while Homebrew may be open-source, it is not "free software".

What makes it nonfree?

Re: Avoid Non-Microsoft Antivirus Software

#169
post #92

Earlier quoted context omitted.

_Everyone_ is collecting our data nowadays. Who's left to sell it to?

Not true. Google collects your searches. They don't sell your searches, they sell whatever they infer from your searches (your compiled and quite vague profile and I know, because I interacted with their AdSense platform), because they'd be stupid to sell your actual searches, since that's their most valuable property. Does anybody else know your search history? Besides the NSA, whom I assume have access to all US-ho…

>and their behavior has been acceptable compared with that of others like Facebook.

If you have the time, would you mind expanding on why you consider Google's behavior better than Facebook's? I find myself very wary of FB but much less so of Google, but I can't really explain why.

Re: Avoid Non-Microsoft Antivirus Software

#170

Ok, disclaimer first: I've previously worked at Kaspersky Lab (incident response division). Now, I want to say that many of the incidents that we have investigated, would have been prevented by anti-virus software (in many cases AV software was deliberately disabled by user). And I'm talking about incidents that resulted in million-dollar thefts - not just cases of some user getting cryptolocker on their home compute…

Any AV software is better than having none but that's not the point of the article. It specifically recommends Microsoft's AV and to stay clear of all the others. I'm sure it's hard on all the AV vendors out there but with Microsoft Essentials and Windows Defender I don't see the need for a third party AV.

IMO, I think common sense, basic hygiene practices, a minimal education and a decent firewall goes a longer way, being much better than an AV could.

For example the most common way people get infected is by installing software from unreliable sources and by not keeping their computer up to date. I'm pretty sure that learning to regularly update your OS and browser, learning to search, recognize and use the official sources for software, to stop doing software piracy for that matter, learning to not click on .exe files received in emails and to be suspicious of all attachments, learning to uninstall everything that infects your browser with useless plugins, I'm pretty sure such simple knowledge would cut 99.9% of all incidents.

Most software vulnerabilities in the wild are not novel, "zero day" exploits are not that common. This is why even though I hate Microsoft's recent update policies, on the other hand I understand their newfound aggressiveness in pushing those updates, as it is really frustrating that users ignore update warnings. I also appreciate Chrome's fast updates, which encouraged Firefox to do the same.

Post reply on HN