As someone who develops a (PyQt-based) desktop app [1], I can confirm this: My app has so far falsely been put into quarantine by Avira and McAffee. It's a pain... [1]: https://fman.io
Your app looks promising! It seems heavily inspired on Sublime and that's a very good sign. Is it available already?
Avoid Non-Microsoft Antivirus Software
231–240 of 388 posts
Re: Avoid Non-Microsoft Antivirus Software
#232Any relevant information about Avast? I'm using their free version for 10 years and don't have any major complains.
I've just tested it in a clean VM running Windows 7, and the MITM didn't work in current Firefox stable, but it did in IE. However, as far as I can tell, it only MITMs DV certificates, not EV. Also, when it MITMs a self-signed certificate, it generates an untrusted certificate, but it says it was generated by Avast, so the user could trust it more easily.
Also, in my experience, the free version of Avast considerably affects performance on slower machines (no SSD, earlier-gen CPU, etc.), but YMMV. It also tries to install Chrome as a default browser, a Google toolbar for IE, various "Secure browsing" extensions to other browsers and lot's of other annoying crap.
Re: Avoid Non-Microsoft Antivirus Software
#233I also want to raise an alarm about a current AV practice, not mentioned in the article: AV products like Bitdefender will MITM your HTTPS connections by installing their own root certificates, by default and without warnings In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users. And consider that I, a highly technical and security conscious software dev…
That being said, users would probably be much safer if they skipped the antivirus and just installed a decent ad blocker.
Re: Avoid Non-Microsoft Antivirus Software
#234I also want to raise an alarm about a current AV practice, not mentioned in the article: AV products like Bitdefender will MITM your HTTPS connections by installing their own root certificates, by default and without warnings In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users. And consider that I, a highly technical and security conscious software dev…
Many corporations do this on their networks so that they can inspect traffic for security purposes and outbound loss prevention. It's not uncommon today and seems to be gaining in popularity. Edit: I don't mean to imply that it's the right or the wrong thing to do (it probably depends on the situation). Just stating what I have seen in industry.
This is quite different than the AV vendor who does not own your communication from your own device.
Re: Avoid Non-Microsoft Antivirus Software
#235Earlier quoted context omitted.
Ubuntu unity sells your searches in the desktop environment by default
Not since 16
Re: Avoid Non-Microsoft Antivirus Software
#236I also want to raise an alarm about a current AV practice, not mentioned in the article: AV products like Bitdefender will MITM your HTTPS connections by installing their own root certificates, by default and without warnings In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users. And consider that I, a highly technical and security conscious software dev…
Re: Avoid Non-Microsoft Antivirus Software
#237Earlier quoted context omitted.
How does that make them the worst?
Commercial companies in free countries may be greedy or unethical, but they are generally predictable and usually follow the letter of the law. A state controlled entity in authoritarian country is another story.
Re: Avoid Non-Microsoft Antivirus Software
#238Earlier quoted context omitted.
citation needed https://github.com/Homebrew/brew/blob/master/docs/Analytics....
That link says nothing about selling your data. Also note that while Homebrew may be open-source, it is not "free software".
I confirm that he is probably right about _____collecting____ data. Yes, this most definitely includes FOSS software. If your qualifier for FOSS is not using GA or anything like that than your are right, however, most of probably still count brew as FOSS. Hope that helps.
Re: Avoid Non-Microsoft Antivirus Software
#239Earlier quoted context omitted.
It actually is worse. The problem comes "what does the interception do when it encounters an invalid certificate"? So for example a self-signed cert. does it a) create a "valid" cert itself, hiding the error from the user? This is obviously dangerous b) create an "invalid" self-signed cert. This is messy as a user will then see a self-signed cert from the A-V vendor, which they may be more or less inclined to trust c…
With Eset you get a message explaining the issue, similar to if your connection was blocked because malware was detected. I don't think this practice is a big issue because the local machine would have to be compromised for it to be an issue, in which case it's irrelevant because the game is over already. Also the alternative is not scanning ssl traffic for malware which has it's own very real risks.
Re: Avoid Non-Microsoft Antivirus Software
#240Earlier quoted context omitted.
Not everyone. FOSS doesn't.
Ubuntu unity sells your searches in the desktop environment by default
It connects on-line and off-line searches, so it shows you the result in on-line locations. The underlying assumption was that users increasingly see on-line and off-line content as all part of the same world ("their content").
The commercial aspect was that it connected to places like Amazon. It made money for Canonical by using affiliate links if the user chose to make a purchase.
That is not the same as collecting all the history of the user and (anonymising) then selling that to a third-party or presenting adverts based on that data.
The default is off as users felt searches by default connecting to external services was an invasion of privacy - that's different to "selling searches".
Frankly, this closed-off the last viable manner for desktop Linux to secure a wider revenue stream of sufficient size to drive employing enough full time developers to keep up with the other platforms, in my personal opinion. FOSS doesn't change the dynamic that full-time developers cost real money.
Source: I worked at Canonical from the early days of the desktop, for ~10 years.