Live data from Hacker News

Avoid Non-Microsoft Antivirus Software

robert.ocallahan.org

201–210 of 388 posts

Re: Avoid Non-Microsoft Antivirus Software

#201

How about we avoid all antivirus software, integrate virtualization as a key feature of the UI of our operating system, and completely sandbox all apps. We have the technology to do this (Qubes does it now) but it's not going mainstream. I don't know why but I think this would be the end goal of computing. Completely segregate your work from your machine and only give it access to things that make sense. (Chrome does…

> How about we avoid all antivirus software, integrate virtualization as a key feature of the UI of our operating system, and completely sandbox all apps.

This is basically the end-game for Flatpak:

https://blogs.gnome.org/alexl/2017/01/24/the-flatpak-securit...

Flatpak is vendor-neutral, but it will provide the sandbox isolation that may then enable Fedora to ramp up to Atomic Workstation, a fully containerized desktop OS:

https://fedoraproject.org/wiki/Workstation/AtomicWorkstation

Hopefully we will see other Linux distributions integrate the technology as it matures.

FWIW, Microsoft are developing VM-based isolation for the browser:

https://threatpost.com/microsoft-edge-adds-app-guard-browser...

Re: Avoid Non-Microsoft Antivirus Software

#202

Ok, disclaimer first: I've previously worked at Kaspersky Lab (incident response division). Now, I want to say that many of the incidents that we have investigated, would have been prevented by anti-virus software (in many cases AV software was deliberately disabled by user). And I'm talking about incidents that resulted in million-dollar thefts - not just cases of some user getting cryptolocker on their home compute…

Kaspersky is the worst of them: https://www.bloomberg.com/news/articles/2015-03-19/cybersecu...

How does that make them the worst?

Re: Avoid Non-Microsoft Antivirus Software

#204

Earlier quoted context omitted.

Indeed it is, yet it can be used for other things as well. Such as an AV that would want to MITM everything without supplying its own CA.

Is some AV product using it for that?

Trend micro officescan, their enterprise offering, has plugins for Firefox.

Well, it had a plugin that got disabled by following Firefox updates.

Re: Avoid Non-Microsoft Antivirus Software

#205

Earlier quoted context omitted.

Not true. Google collects your searches. They don't sell your searches, they sell whatever they infer from your searches (your compiled and quite vague profile and I know, because I interacted with their AdSense platform), because they'd be stupid to sell your actual searches, since that's their most valuable property. Does anybody else know your search history? Besides the NSA, whom I assume have access to all US-ho…

>and their behavior has been acceptable compared with that of others like Facebook. If you have the time, would you mind expanding on why you consider Google's behavior better than Facebook's? I find myself very wary of FB but much less so of Google, but I can't really explain why.

You're just biased, because Facebook has way more potential for doing you harm and has used your data against your interests already.

Facebook manipulates the emotions of its users: http://www.forbes.com/sites/kashmirhill/2014/06/28/facebook-...

MasterCard to access Facebook user data in order to make you spend more: http://www.theage.com.au/it-pro/business-it/mastercard-to-ac...

Facebook ads use your face for free: http://www.itworld.com/article/2746556/networking-hardware/f...

Facebook is inventing phony likes to promote stories you've never seen to your friends: https://web.archive.org/web/20161215092610/http://www.forbes...

Facebook guesses your race and uses it for targeting: https://arstechnica.com/information-technology/2016/03/faceb...

Facebook has been the main promoter of bogus news and misinformation in 2016: https://www.theguardian.com/technology/2016/sep/09/facebook-...

Facebook has started to collect WhatsApp data, in spite of the app's original policy: https://www.theguardian.com/technology/2016/aug/25/whatsapp-...

Facebook collects the texts that you don't send: https://arstechnica.com/business/2013/12/facebook-collects-c...

Facebook tracks and builds user profiles for people without accounts: https://www.theguardian.com/technology/2015/mar/31/facebook-...

Facebook's privacy settings have been designed with black patterns, making it easy to publish by mistake: https://www.theguardian.com/technology/2016/jun/29/facebook-...

Facebook makes it easy to tell when you're asleep: https://www.washingtonpost.com/news/innovations/wp/2016/02/2...

Re: Avoid Non-Microsoft Antivirus Software

#206
post #192

Earlier quoted context omitted.

Well, I agree that AV most likely wouldn't protect you against targeted attacks - but most of the attacks that we investigated were targeted quite broadly - phishing email campaigns targeting financial organizations (with address lists based on some hacked legitimate resources for accountants, for example). And usually these attack succeeded because of insecure infrastructure, poorly trained admins, old, non-updating…

> most of the attacks that we investigated Isn't that a case of the survivorship bias? Or at least the broader case of selection bias?

What do you mean, exactly? All I want so say that while targeted attacks are the most difficult to defend against (well, by definition), it is the medium-sophistication-level attacks that cause the most damage (in my experience), just because of their volume. It's not some state-of-the-art APT malware, it's bundles of RATs + generic backdoors/keyloggers packed in SFX archives, that are usually quickly detected by most AVs (provided that AV bases are regularly updated).

Re: Avoid Non-Microsoft Antivirus Software

#207

Ok, disclaimer first: I've previously worked at Kaspersky Lab (incident response division). Now, I want to say that many of the incidents that we have investigated, would have been prevented by anti-virus software (in many cases AV software was deliberately disabled by user). And I'm talking about incidents that resulted in million-dollar thefts - not just cases of some user getting cryptolocker on their home compute…

https://arstechnica.com/security/2017/01/kaspersky-labs-top-...

Re: Avoid Non-Microsoft Antivirus Software

#208

Earlier quoted context omitted.

Kaspersky is the worst of them: https://www.bloomberg.com/news/articles/2015-03-19/cybersecu...

How does that make them the worst?

Commercial companies in free countries may be greedy or unethical, but they are generally predictable and usually follow the letter of the law.

A state controlled entity in authoritarian country is another story.

Re: Avoid Non-Microsoft Antivirus Software

#209

Earlier quoted context omitted.

I don't think you understand how HTTPS works. > so they can scan the urls, and block some attacks The purpose of HTTPS is to provide a guarantee that your connection to Google is direct, with no intermediaries, such that (1) only Google knows your search query and (2) you get a guarantee that the received content is from Google. And you get this guarantee from certificate authorities that have a good reputation and t…

>The blocking of attacks reasoning is kind of bullshit >I have yet to see evidence that AV software is doing a better job of catching those I wouldn't be so one-sided. Imagine a fresh new variety of ransomware starts spreading. No one can catch it at 0-day, but good AV can catch it at 1-st day (OK, 1-st week) and neither Google nor uBlock or the likes can't.

Do you have any evidence for these claims? What's the concrete mechanism that allows AVs to observe and react to threats earlier than Google? (Since you allow up to 1 week of reaction time, I'll assume that you're not referring to heuristic detection methods.)
Post reply on HN