Live data from Hacker News

Avoid Non-Microsoft Antivirus Software

robert.ocallahan.org

211–220 of 388 posts

Re: Avoid Non-Microsoft Antivirus Software

#211
post #82

Earlier quoted context omitted.

An extraordinary amount of Cryptolocker outbreaks were due to .docx files containing macros. Yes, it has a default behaviour of "prompt to execute macros", but it happily shows the advice in the malicious document to "please click yes at this prompt to get a free iPhone", at which point the majority of users click "yes".

.docx files can't contain macros

.docx files could contain macros just fine.

Re: Avoid Non-Microsoft Antivirus Software

#213
post #50

While many AV companies are really bad, AV per say is still an extra layer of security. Telling people to remove a layer of security is bad advice. There's a problem though and if I knew how to solve it I'd be rich!

It could be an extra level of security if they ran in userspace or in-between. But they usually have enormous permissions to operate and doesn't really count as a whole new layer.

Re: Avoid Non-Microsoft Antivirus Software

#214
post #7

This is my advice to everyone I know that gets a new Windows PC. Windows 10's built-in protection is more than adequate, and catches the majority of bad software - anything more is unnecessary, and many of the AV vendors are predatory.

It sucks that you cannot reset your Windows to MS-Vendor settings. For example if you get some Acer laptop and reset it using windows built-in functionality it'll still reset it with all the bloatware - including AV.

Uh, yes you can. Couple weeks ago I reset my Windows 10 MSI laptop to a clean state using nothing but Windows itself. Somewhere in Windows 10 restore options there's an option to format your HD and install only Windows and nothing else. You don't need a DVD nor a USB drive. A click of a button and off you go.

Re: Avoid Non-Microsoft Antivirus Software

#215
post #65

Earlier quoted context omitted.

Don't most browsers have hooks for AV (and other plugins) to get into web traffic without having to mess with TLS?

No, I don't think so and if it does, please tell me which browser does it so I can keep away from it, because that defeats the purpose of TLS. Either way, Bitdefender installs their own root certificate and generates their own for google.com. I've got proof if you want.

No, I don't think so and if it does, please tell me which browser does it so I can keep away from it, because that defeats the purpose of TLS.

AVs generally run with complete permissions, and can do everything up to and including injecting their own code inside your browser's running process. Providing them with an API doesn't weaken the security, it just reduces the chances they'll screw the browser up.

Re: Avoid Non-Microsoft Antivirus Software

#217
post #65

Earlier quoted context omitted.

Don't most browsers have hooks for AV (and other plugins) to get into web traffic without having to mess with TLS?

No, I don't think so and if it does, please tell me which browser does it so I can keep away from it, because that defeats the purpose of TLS. Either way, Bitdefender installs their own root certificate and generates their own for google.com. I've got proof if you want.

I have bitdefender and I was wondering how I can check if it does it on my pc and mac and how I can disable it (if possible). Could you help me in the right direction?

Re: Avoid Non-Microsoft Antivirus Software

#218

As someone who develops a (PyQt-based) desktop app [1], I can confirm this: My app has so far falsely been put into quarantine by Avira and McAffee. It's a pain... [1]: https://fman.io

Your app looks promising! It seems heavily inspired on Sublime and that's a very good sign. Is it available already?

Re: Avoid Non-Microsoft Antivirus Software

#219

Earlier quoted context omitted.

>and their behavior has been acceptable compared with that of others like Facebook. If you have the time, would you mind expanding on why you consider Google's behavior better than Facebook's? I find myself very wary of FB but much less so of Google, but I can't really explain why.

You're just biased, because Facebook has way more potential for doing you harm and has used your data against your interests already. Facebook manipulates the emotions of its users: http://www.forbes.com/sites/kashmirhill/2014/06/28/facebook-... MasterCard to access Facebook user data in order to make you spend more: http://www.theage.com.au/it-pro/business-it/mastercard-to-ac... Facebook ads use your face for free:…

Thanks for the links. I had heard of some of those issues but the sleep tracking and unsent text collection were new to me.

Re: Avoid Non-Microsoft Antivirus Software

#220

Ok, disclaimer first: I've previously worked at Kaspersky Lab (incident response division). Now, I want to say that many of the incidents that we have investigated, would have been prevented by anti-virus software (in many cases AV software was deliberately disabled by user). And I'm talking about incidents that resulted in million-dollar thefts - not just cases of some user getting cryptolocker on their home compute…

Any AV software is better than having none but that's not the point of the article. It specifically recommends Microsoft's AV and to stay clear of all the others. I'm sure it's hard on all the AV vendors out there but with Microsoft Essentials and Windows Defender I don't see the need for a third party AV.

Forget even Windows Defender. The one and only "AV" a normal user will ever need is…

Google Safe Browsing.

Seriously.

Anything you download is already checked with Google, why waste CPU cycles on checking it again locally?

Post reply on HN