Live data from Hacker News

Avoid Non-Microsoft Antivirus Software

robert.ocallahan.org

331–340 of 388 posts

Re: Avoid Non-Microsoft Antivirus Software

#331

Earlier quoted context omitted.

No Ubuntu doesn't , and nor has it every done. It connects on-line and off-line searches, so it shows you the result in on-line locations. The underlying assumption was that users increasingly see on-line and off-line content as all part of the same world ("their content"). The commercial aspect was that it connected to places like Amazon. It made money for Canonical by using affiliate links if the user chose to make…

I'm sorry, but I think I trust Canonicals' privacy policy as a source more than you: "Unless you have opted out, we will also send your keystrokes as a search term to productsearch.ubuntu.com and selected third parties so that we may complement your search results with online search results from such third parties including: Facebook, Twitter, BBC and Amazon. Canonical and these selected third parties will collect yo…

> The default was not off in 12.10

Which was four years ago. It's off now, and has been since 16.04 (the most recent LTS release, which shipped last year).

I agree the Amazon integration in the Dash was a mistake, but it's a mistake that has been fixed. It's simply not true anymore that "Ubuntu unity sells your searches in the desktop environment by default," and continuing to tell people so is deeply misleading.

Re: Avoid Non-Microsoft Antivirus Software

#332

Earlier quoted context omitted.

I'm sorry, but I think I trust Canonicals' privacy policy as a source more than you: "Unless you have opted out, we will also send your keystrokes as a search term to productsearch.ubuntu.com and selected third parties so that we may complement your search results with online search results from such third parties including: Facebook, Twitter, BBC and Amazon. Canonical and these selected third parties will collect yo…

> The default was not off in 12.10 Which was four years ago. It's off now , and has been since 16.04 (the most recent LTS release, which shipped last year). I agree the Amazon integration in the Dash was a mistake, but it's a mistake that has been fixed. It's simply not true anymore that "Ubuntu unity sells your searches in the desktop environment by default," and continuing to tell people so is deeply misleading.

You're still supporting it, so still selling: https://www.ubuntu.com/info/release-end-of-life

Re: Avoid Non-Microsoft Antivirus Software

#334

Earlier quoted context omitted.

Sure that's scary. But it also sounds like 'anti-fraud'. How could we distinguish the two? They're slammed if they want authentic accounts; they're slammed if folks create large numbers of spam accounts. How do we suppose they could win in this scenario?

Just do like most of the social media accounts do. Have algorithms that detect spam? Let users report on accounts being used to spam other users? Sure, if I'm someone abusing the system, this should be easy to ferret out without having to surrender all your personal information and identifying markers just to make a SOCIAL MEDIA platform free of spam.

I don't know this for a fact, but if I were FB I think I'd be fanatical about verifying real users to prevent people setting up social media PBNs. A holy grail of grey-hat SEO nowadays would be to control large networks of interlinked fake social media accounts, which could be used to promote content artificially. This kind of spam is potentially hard to detect since the networks could be very large and appear organic (to the point, theoretically, of having AI-driven "users" behind each one), so the first line of defence is to identify fake user accounts.

Re: Avoid Non-Microsoft Antivirus Software

#335
post #282

Earlier quoted context omitted.

Easy, you don't tamper with HTTPS traffic, it's innately a very bad idea. Consider the goals that are trying to be achieved. You're attempting to stop the user either downloading malicious content or perhaps getting hit with a browser exploit or possibly you're trying to stop users going to a "bad" site. The first one can be covered off with traditional on-access scanning of files. The second one is much better addre…

That doesn't work for corporate communications, though. There are numerous use cases where a corporation must be able to penetrate HTTPS internally in order to comply with regulations, both for direct reasons such as regulations regarding corporate communications, and indirectly for things such as internal security, protection against insider threats, and a lot of other second-order issues like intrusion detection. A…

I know corps need to do that, and they get to handle the trade-offs that it generates (although I'd argue that HTTPS interception doesn't in any way provide a panacea for the internal security issues you've mentioned).

The advantage is that they should have informed professional security people who can understand the trade-offs and make intelligent decisions about them.

Even then this strategy fails against certificate pinning which is becoming ever more common in mobile and also web space, so corps need other solutions to those problems (likely endpoint based)

However what we're talking about here is end-user A-V products and their use of HTTPS interception at a desktop level and the trade-offs that this forces on individual end users who are less equipped to handle this.

Realistically the A-V product will likely choose to cause "less noise" to the user so won't present them detailed technical information about the errors their masking, potentially making the user's security worse.

Re: Avoid Non-Microsoft Antivirus Software

#336
post #7

This is my advice to everyone I know that gets a new Windows PC. Windows 10's built-in protection is more than adequate, and catches the majority of bad software - anything more is unnecessary, and many of the AV vendors are predatory.

It sucks that you cannot reset your Windows to MS-Vendor settings. For example if you get some Acer laptop and reset it using windows built-in functionality it'll still reset it with all the bloatware - including AV.

For instances where it's not worth the time to reformat, I've always liked PC Decrapifier. Hard to forget the name once you've heard it :D

https://www.pcdecrapifier.com/

Re: Avoid Non-Microsoft Antivirus Software

#337
post #324

Earlier quoted context omitted.

Forget even Windows Defender. The one and only "AV" a normal user will ever need is… Google Safe Browsing. Seriously. Anything you download is already checked with Google, why waste CPU cycles on checking it again locally?

Google runs the largest advertising network in the world. Plenty of malware slips through the cracks every day, both downloadable apps/software/extensions as well as ads that lead to obvious scams. Facebook, Microsoft, Yahoo etc all suffer the same problems. I think these problems are likely unavoidable at that kind of scale. But I would never rely on these companies as the only (or even primary) line of defense.

Of course the primary line of defense is not running random crap executables.

Re: Avoid Non-Microsoft Antivirus Software

#338
post #328

Earlier quoted context omitted.

As I recall the early virus guys were more like vandals who wanted to cause problems for the thrill of it than guys operating international rackets like they are now. When was the last time you heard of a virus that just formatted your hard drive or whatever?

Nowadays they encrypt it instead.

Yeah, and then they ask for a ransom. Not really the same as destroying stuff just for the thrill.

Re: Avoid Non-Microsoft Antivirus Software

#339

Earlier quoted context omitted.

Besides the fact a US company probably cooperates with US intelligence, there are plenty of examples of companies outright breaking the law.

> the fact a US company probably cooperates with US intelligence “the fact” and “probably” are mutually exclusive. > plenty of examples of companies outright breaking the law I know and that’s why I wrote “usually follow the letter of the law”. Majority of the companies follow the law, however.

> “the fact” and “probably” are mutually exclusive.

I don't see how; statements about probability can be factual and we have plenty of evidence that Google, Microsoft, and US telcos do; why should AV vendors be different?

As far as companies usually following the letter of the law... do they? What makes you so sure?

Re: Avoid Non-Microsoft Antivirus Software

#340
AV causes all sorts of problems for Firefox, such as startup crashes or, in some cases, AV MITM breaking Firefox updates, leaving users stranded on old Firefox versions. In Firefox 53, Mozilla is starting to purposely make it more difficult for extensions to rummage around in native code and external software to inject DLLs into the running Firefox process:

https://blog.mozilla.org/addons/2017/01/24/preventing-add-on...

Post reply on HN