Live data from Hacker News

Avoid Non-Microsoft Antivirus Software

robert.ocallahan.org

311–320 of 388 posts

Re: Avoid Non-Microsoft Antivirus Software

#311
Reading trought the comments, i see that a lot of people don't like antivirus, but what alternative we have, is mcrosoft antivirus really a better alternative.

I personaly have avast installed and i don't like it very much, i find it too invasive (it keep prompting to delete an firefox addons from test pilot, for example) and i always disable https scanning, but from comparison that i found online, seem that microsoft AV do much worse in respect to others.

what HN crow suggest to protect a Windows machine (win10), is microsoft AV really better or just like the others?

Re: Avoid Non-Microsoft Antivirus Software

#312
Reading trought the comments, i see that a lot of people don't like antivirus, but what alternative we have, is mcrosoft antivirus really a better alternative.

I personaly have avast installed and i don't like it very much, i find it too invasive (it keep prompting to delete an firefox addons from test pilot, for example) and i always disable https scanning, but from comparison that i found online, seem that microsoft AV do much worse in respect to others.

what HN crow suggest to protect a Windows machine (win10) ?

Re: Avoid Non-Microsoft Antivirus Software

#313

I also want to raise an alarm about a current AV practice, not mentioned in the article: AV products like Bitdefender will MITM your HTTPS connections by installing their own root certificates, by default and without warnings In the name of "security", this undermines the very purpose of what HTTPS is about, knowingly endangering their users. And consider that I, a highly technical and security conscious software dev…

We recently published a paper on this exact issue and quantify the degree to which AV / corporate middlebox systems degrade the security of HTTPS connections. The tl;dr is that we find an alarming amount of MITM on the public internet (5-10%), mostly due to AV/middleboxes, and they almost always degrade the security of the connection.

*https://jhalderm.com/pub/papers/interception-ndss17.pdf

Re: Avoid Non-Microsoft Antivirus Software

#314
post #7

This is my advice to everyone I know that gets a new Windows PC. Windows 10's built-in protection is more than adequate, and catches the majority of bad software - anything more is unnecessary, and many of the AV vendors are predatory.

My advice is similar these days when someone is buying a new PC, with the additional push that everyone should buy a "Signature Edition" PC [1]. Microsoft requires "Signature Edition" machines to be sold without additional software/bloatware. Friends/relatives can most easily buy such PCs from the Microsoft Store, but also some Best Buys and office stores will sell them if you ask.

[1] https://www.microsoftstore.com/store/msusa/en_US/cat/categor...

Re: Avoid Non-Microsoft Antivirus Software

#315

What always bothered me about MS Windows was that for a long time one HAD to use 3rd party AV SW. This should have been MS's responsibility from the very beginning. I don't go to third parties for seatbelts and anti-lock brakes when I buy a car. I shouldn't have had to use a 3rd party AV SW.

Microsoft had an injunction from the anti-trust lawsuit that they couldn't bundle AV with Windows because that would be "anti-competitive", which is why Security Essentials had to be downloaded for XP/Vista instead of just coming installed. Lucky for all of us the statute of limitations on that decision finally expired.

I agree, something like AV should be a function of the OS, not a "competitive" (race-to-the-security-theater-bottom) bolt-on from some third party.

Re: Avoid Non-Microsoft Antivirus Software

#316

Earlier quoted context omitted.

Short story to support your articles. I used a fake name on FB since the first day I signed up along with a photo of my favorite rock star. About a year ago, someone outed me and FB locked my account and said unless I emailed them a copy of my drivers license or some form of identification that proved who I was, they would keep my account locked. I thought, "Whatever, I'll just fire up a new one." This past month I s…

Sure that's scary. But it also sounds like 'anti-fraud'. How could we distinguish the two? They're slammed if they want authentic accounts; they're slammed if folks create large numbers of spam accounts. How do we suppose they could win in this scenario?

Just do like most of the social media accounts do.

Have algorithms that detect spam? Let users report on accounts being used to spam other users?

Sure, if I'm someone abusing the system, this should be easy to ferret out without having to surrender all your personal information and identifying markers just to make a SOCIAL MEDIA platform free of spam.

Re: Avoid Non-Microsoft Antivirus Software

#317

I got for free Norton Security with my new Dell laptop. On installing I was unable to enable windows defender or firewall. Norton takes over the security by default. I contacted Symantec and had to uninstall Norton Security and install Norton Antivirus for the windows firewall to be activated.

The first thing you should do with a PC is to delete all partitions and install a fresh OS. Even if you aren't installing Linux, you should download untampered Windows 10 (the same edition that the PC came licensed for) from Microsoft and do a fresh install without OEMware.

Or make sure you buy a "Signature Edition" PC in the first place, which is Microsoft's program for "junk free" systems [1] you can find in Microsoft Stores or if you ask the right Best Buy or office store.

[1] https://www.microsoftstore.com/store/msusa/en_US/cat/categor...

Re: Avoid Non-Microsoft Antivirus Software

#318

Earlier quoted context omitted.

That communication belongs to the company, the session is work product on a company owned device. Feels squeamish if you didn't think about it that way, but is implied by almost every employment agreement. This is quite different than the AV vendor who does not own your communication from your own device.

I still wish most companies knew/had a better "best practice" than just MITM interception certificates, because that is potentially brittle and is an threat to corporate security. If you already have all of your machines MITMed, then an attacker could gain access to the existing MITM certificate and who would ever know. I know I'm a relative minority in the corporate IT world, but as a software developer downloading/…

>because that is potentially brittle

It is. I do work in a Fortune 500 occasionally, and have to use their MITM gateway (websense SSL intercept).

They haven't yet fixed the internal cert to not use SHA-1.

If you're using something other than a corporate windows desktop + browser, you have to install the root certificates manually.

They have to make manual exceptions for sites that do certificate pinning. When they miss a site, it creates issues. Github is broken for me...I have to use crazy workarounds.

If there were a movement to enable certificate pinning everywhere, it would be very disruptive for the Corporate MITM vendors.

Edit: They also have irritating "content filters". So, if I'm tasked to research options for a project, like say a VPN, I can't search from their network. It blocks pages talking about VPNS because there's a policy to block "websense proxy avoidance".

Re: Avoid Non-Microsoft Antivirus Software

#319

Earlier quoted context omitted.

Any AV software is better than having none but that's not the point of the article. It specifically recommends Microsoft's AV and to stay clear of all the others. I'm sure it's hard on all the AV vendors out there but with Microsoft Essentials and Windows Defender I don't see the need for a third party AV.

Forget even Windows Defender. The one and only "AV" a normal user will ever need is… Google Safe Browsing. Seriously. Anything you download is already checked with Google, why waste CPU cycles on checking it again locally?

You need an antivirus that can watch running programs for bad behavior. Polymorphic viruses have been around for decades and will defeat any simple blacklist. And the halting problem means you can't possibly categorize every program as being harmful or not by static analysis.

Re: Avoid Non-Microsoft Antivirus Software

#320
post #4

> At best, there is negligible evidence that major non-MS AV products give a net improvement in security. I apologize for present anecdote when data is needed but I manage a Windows network with 100+ users and on a daily basis, Kaspersky catches 5-10 emails from Outlook that have nasty attachments. It prevents my users from opening these innocuous looking but nasty Invoice-Jan-2017.docx files. Without a good AV there…

Does anyone on your network have a valid reason to execute Office macros? If not, disable them via group policy. Solves so many problems. See what @SwiftOnSecurity has to say on the topic, they manage thousands of users and it seems to work excellently.

This is the site she runs, with configuration guides. https://decentsecurity.com/
Post reply on HN