Live data from Hacker News

Avoid Non-Microsoft Antivirus Software

robert.ocallahan.org

241–250 of 388 posts

Re: Avoid Non-Microsoft Antivirus Software

#241
post #92

Earlier quoted context omitted.

_Everyone_ is collecting our data nowadays. Who's left to sell it to?

Not true. Google collects your searches. They don't sell your searches, they sell whatever they infer from your searches (your compiled and quite vague profile and I know, because I interacted with their AdSense platform), because they'd be stupid to sell your actual searches, since that's their most valuable property. Does anybody else know your search history? Besides the NSA, whom I assume have access to all US-ho…

It often irks me when people say things like "Google sells all of your data to advertisers and you are the product!"

Not because there are no potential issues to discuss around ad-funded free services and data aggregation, but more because it's like clickbait (in that it oversimplifies a complex issue for emotional effect and makes discussion of actual issues more difficult).

Using algorithms to build a general profile in order to increase relevance is not the same as "selling your data". They sell access to your eyeballs in much the same way as a broadcast TV station or free alt-weekly does. The main difference is that by getting some sense of who you are and what you might be interested in, they can decrease (in theory) the amount of irrelevant ads that end up on your screen versus the traditional methods of just blanketing things with general ads or using cruder demographic info.

Lots of companies flat-out do sell your data, either in aggregate and somewhat anonymized or in full. I've not found anything yet that leads me to believe this is how Google runs their advertising business. To this day, my main concern with Google isn't so much with Google as it is with a malicious third party somehow gaining access to the info Google has on me.

Re: Avoid Non-Microsoft Antivirus Software

#242

What always bothered me about MS Windows was that for a long time one HAD to use 3rd party AV SW. This should have been MS's responsibility from the very beginning. I don't go to third parties for seatbelts and anti-lock brakes when I buy a car. I shouldn't have had to use a 3rd party AV SW.

Linux doesn't supply a 1st party AV solution either.

Windows maybe could've responded faster to the creation of so many viruses, but it takes a really popular OS for AV to become a neccesity.

Re: Avoid Non-Microsoft Antivirus Software

#243
Pretty questionable advice.

Microsoft AV is fast and non-disruptive, but is a laggard in terms of effectiveness, even by the standard of AV.

It's best used when you need to check the AV box, and it is less disruptive than other solutions.

Re: Avoid Non-Microsoft Antivirus Software

#244
post #176

Earlier quoted context omitted.

Not true. Google collects your searches. They don't sell your searches, they sell whatever they infer from your searches (your compiled and quite vague profile and I know, because I interacted with their AdSense platform), because they'd be stupid to sell your actual searches, since that's their most valuable property. Does anybody else know your search history? Besides the NSA, whom I assume have access to all US-ho…

Actually, I still have a problem when all my "actual searches" becomes someone else's "most valuable property". Of course there are some other less intrusive search engines (DuckDuckGo, maybe Qwant), but unfortunately they still are less efficient than Google for fine or rare searches.

When I started using DDGo some years ago I had the same problem; not quite so relevant search results. I think this is not the situation anymore, the results are very good. And you dont have to worry about security.

Re: Avoid Non-Microsoft Antivirus Software

#245

half offtopic: do I need an AV software on my android smartphone? Friends always ask me which they should use (because I am the "computer guy") and I tell them that I don't have one.

If you don't install pirated apps from shady sources, you absolutely do not need AV on your Android device.

My android seems to have some sneeky adware on it and I've never installed anything not for the Google or Amazon stores or written myself.

Re: Avoid Non-Microsoft Antivirus Software

#246
My main problem with this state of affairs is compliance. We have customers that require us to get certain certifications from TÜV. The TÜV asks your whole company to have certified AV Software in place on all machines. They do not accept Windows Defender as a dedicated AV Solution, or atleast did not the last time.

I'm still unsure what to tell them about our Macs and Linux Notebooks that we've acquired since the last audit.

Does anyone have a solution for this?

Re: Avoid Non-Microsoft Antivirus Software

#247
post #188

Earlier quoted context omitted.

How does this relate to the issue that antivirus companies do horrible things and hold ignorant paying users who don't even know how to pirate software, and legitimate software producers hostage like some sort of technical mafia?

Because they only became a business due to the people that were pirating software in the 80's. Thanks to the increase of virus across MS-DOS, Atari, Acorn, Amiga and Mac operating systems, specially on boot sector floppies, the general public learned that anti-virus were required software to always have installed.

So are you saying that if people didn't pirate stuff the viruses would not have spread? Presumably because they would not be using floppies as much?

Re: Avoid Non-Microsoft Antivirus Software

#248

Ok, disclaimer first: I've previously worked at Kaspersky Lab (incident response division). Now, I want to say that many of the incidents that we have investigated, would have been prevented by anti-virus software (in many cases AV software was deliberately disabled by user). And I'm talking about incidents that resulted in million-dollar thefts - not just cases of some user getting cryptolocker on their home compute…

Just to play the devils' advocate, I do think that the attitude of "never use AV products" could work in corporate environment, provided the administrators are competent and draconian enough to counter-weight the absolute incompetence of users (because, frankly, the largest attack surface is the incompetence of the user):

use security policies of the domain to only allow whitelisted applications to be run;

restrict internet use to whitelisted destinations;

configure mail servers to accept only whitelist sources, use DKIM/DMARC, and reject multipart messages.

Mandate usage of wired-only HID peripherals which are soldered to the port. Don't use wifi, and physically secure the access to network wires.

Glue shut all other computer ports.

Go all-out Saudi-arabian with people who don't comply with security policies and punish them by removing digits and public hangings for repeated offenses.

It's really that simple.

Re: Avoid Non-Microsoft Antivirus Software

#249
post #233

I also want to raise an alarm about a current AV practice, not mentioned in the article: AV products like Bitdefender will MITM your HTTPS connections by installing their own root certificates, by default and without warnings In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users. And consider that I, a highly technical and security conscious software dev…

I feel like, instead of MITM'ing all TLS connections, antivirus companies could implement this same thing in a browser extension. If good ad blockers can prevent requests for ads from being completed, an antivirus extension should be able to do something similar, without having to tamper with the TLS connection between the browser and the site. That being said, users would probably be much safer if they skipped the a…

At least with Chrome, the extension API doesn't allow you to "peek" into the content. You do have the ability to see the url before it's fetched[1], and block the fetch/redirect. But you can't see the data until it's too late.

[1]https://developer.chrome.com/extensions/webRequest#event-onB...

Re: Avoid Non-Microsoft Antivirus Software

#250

Earlier quoted context omitted.

Ubuntu unity sells your searches in the desktop environment by default

No Ubuntu doesn't , and nor has it every done. It connects on-line and off-line searches, so it shows you the result in on-line locations. The underlying assumption was that users increasingly see on-line and off-line content as all part of the same world ("their content"). The commercial aspect was that it connected to places like Amazon. It made money for Canonical by using affiliate links if the user chose to make…

I'm sorry, but I think I trust Canonicals' privacy policy as a source more than you:

"Unless you have opted out, we will also send your keystrokes as a search term to productsearch.ubuntu.com and selected third parties so that we may complement your search results with online search results from such third parties including: Facebook, Twitter, BBC and Amazon. Canonical and these selected third parties will collect your search terms and use them to provide you with search results while using Ubuntu."

Source: Ubuntu's third party privacy policy.

* The default was not off in 12.10.

I'm fine if you want to make money this way! That's why you're a company, people need to make money. My argument was that some OSS software sells your search results, one way or another. I didn't take a position in this argument (but you can hopefully guess my position).

Now, you mention that your users complained, which was true. It caused a huge amount of backlash from your established user-base, many of which contributed to OSS themselves and have seen their contributions being monetized by Canonical (which is fine too, no worries). But besides the users, it was the pressure from EFF which caused Canonical to buckle to the pressure [1].

So, I don't care what Canonical underlying assumptions were, I don't care whether it is disabled now, I don't care whether Unity showed affiliate links or not. It's all just distracting from the main point: search terms entered in Unity were send, by default, to third-party servers!

[1] https://www.eff.org/deeplinks/2012/10/privacy-ubuntu-1210-am...

Post reply on HN