Live data from Hacker News

Avoid Non-Microsoft Antivirus Software

robert.ocallahan.org

181–190 of 388 posts

Re: Avoid Non-Microsoft Antivirus Software

#181
post #92

Earlier quoted context omitted.

Yes. Also, let's finally start a public discussion about AV companies making money by selling data (they do, either all of them or most). Of course that being able to peek into https traffic gets them more data (specific urls, not just whole sites).

_Everyone_ is collecting our data nowadays. Who's left to sell it to?

Everyone is collecting as much data as possible, but few are in position to get all of the users' browsing data. Even fewer (if any?) make it available for sale. So there certainly IS interest in such data.

Re: Avoid Non-Microsoft Antivirus Software

#182

Earlier quoted context omitted.

Not true. Google collects your searches. They don't sell your searches, they sell whatever they infer from your searches (your compiled and quite vague profile and I know, because I interacted with their AdSense platform), because they'd be stupid to sell your actual searches, since that's their most valuable property. Does anybody else know your search history? Besides the NSA, whom I assume have access to all US-ho…

>and their behavior has been acceptable compared with that of others like Facebook. If you have the time, would you mind expanding on why you consider Google's behavior better than Facebook's? I find myself very wary of FB but much less so of Google, but I can't really explain why.

I have the same feeling but I cannot find arguments: they make money by selling very similar materials.

I think Google only better markets its intrusions than Facebook... Something to do with the public sentence "don't be evil". Indeed "evil" is like "common sense": everybody has its own and understands what comforts him/herself. Seems like pure marketing.

Maybe someone has any argument about the reality of this different Google/Facebook privacy intrusion/protection feeling?

Re: Avoid Non-Microsoft Antivirus Software

#185

I also want to raise an alarm about a current AV practice, not mentioned in the article: AV products like Bitdefender will MITM your HTTPS connections by installing their own root certificates, by default and without warnings In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users. And consider that I, a highly technical and security conscious software dev…

Browsers grudgingly support local MITM as an ugly half-ass solution, mostly because banks require it as part of their data loss prevention measures. Since there is no OS-provided API, there is no alternative that makes corporate clients happy.

Depending on the AV vendor, the MITM implementation will "give AV access to your SSL traffic" or "allow everyone to intercept it" (Symantec).

Re: Avoid Non-Microsoft Antivirus Software

#186

Earlier quoted context omitted.

> In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users. It doesn't have to be insecure. If the software that does the MITM checks the certificates correctly, I don't see how it would be worse than letting the browser handle it. Not that I'd ever use an antivirus, of course.

It actually is worse. The problem comes "what does the interception do when it encounters an invalid certificate"? So for example a self-signed cert. does it a) create a "valid" cert itself, hiding the error from the user? This is obviously dangerous b) create an "invalid" self-signed cert. This is messy as a user will then see a self-signed cert from the A-V vendor, which they may be more or less inclined to trust c…

With Eset you get a message explaining the issue, similar to if your connection was blocked because malware was detected.

I don't think this practice is a big issue because the local machine would have to be compromised for it to be an issue, in which case it's irrelevant because the game is over already. Also the alternative is not scanning ssl traffic for malware which has it's own very real risks.

Re: Avoid Non-Microsoft Antivirus Software

#188

Earlier quoted context omitted.

lots of binaries are not only patched to circument DRM, but also to contain malware

How does this relate to the issue that antivirus companies do horrible things and hold ignorant paying users who don't even know how to pirate software, and legitimate software producers hostage like some sort of technical mafia?

Because they only became a business due to the people that were pirating software in the 80's.

Thanks to the increase of virus across MS-DOS, Atari, Acorn, Amiga and Mac operating systems, specially on boot sector floppies, the general public learned that anti-virus were required software to always have installed.

Re: Avoid Non-Microsoft Antivirus Software

#189

I also want to raise an alarm about a current AV practice, not mentioned in the article: AV products like Bitdefender will MITM your HTTPS connections by installing their own root certificates, by default and without warnings In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users. And consider that I, a highly technical and security conscious software dev…

If the alternative is not scanning ssl traffic for malware then perhaps if it's done correctly then it's not a bad compromise. For example a broken upstream cert should just be treated the same as if malware was detected. I bet good AV would update revocation lists more often than the OS & browser does too.

Re: Avoid Non-Microsoft Antivirus Software

#190
For the past years it seems like even Windows (given the large attack surface) viruses/trojans have become much less common than in the past. I think the first line of defense in web browsers and various techs like SmartScreen etc. has helped especially with fishy porn ad ridden websites wanting to download FixWindows.exe, but also that we've moved to often use cloud oriented tools. Nowadays we visit websites to get things done way more often than in the 80's / 90's when we ran executables from some friend's diskette or hard drive. And as long as we visit websites it's way too much effort to exploit weaknesses in their sandboxes that this is then almost entirely about targetted attacks.

Another example of how obnoxious it is becoming to merely _get_ to someone's computer to infect it now that users rely less on executables, is that the Fake Indian Microsoft Support Technician has become a thing. Actual humans calling other humans and hoping for the best by social engineering. This is so far fetched and works so rarely that the desperation is real.

E-mail has been another traditional way of getting to someone but that's nowadays mostly Outlook.com or Gmail.com, which have their own very efficient AV systems in place.

I guess my point with this is that even Microsoft's so-so antivirus tool (given that it's less intrusive) should indeed be enough. Hell I think a user with common sense will be fine with no AV whatsoever for longer than one may think.

Post reply on HN