Live data from Hacker News

Avoid Non-Microsoft Antivirus Software

robert.ocallahan.org

341–350 of 388 posts

Re: Avoid Non-Microsoft Antivirus Software

#341
post #176

Earlier quoted context omitted.

Actually, I still have a problem when all my "actual searches" becomes someone else's "most valuable property". Of course there are some other less intrusive search engines (DuckDuckGo, maybe Qwant), but unfortunately they still are less efficient than Google for fine or rare searches.

When I started using DDGo some years ago I had the same problem; not quite so relevant search results. I think this is not the situation anymore, the results are very good. And you dont have to worry about security.

If the search results aren't relevant, you can always add !g to the search and force it to go to Google. They may still not be as relevant, of course, because Google can't use their data about you to filter the results to what they think you wanted. Which I'm perfectly fine with. I'm happy with the allegedly sub-par results that are displayed because of my anonymity. Others may not be.

Re: Avoid Non-Microsoft Antivirus Software

#342
post #290

Earlier quoted context omitted.

I don't think you understand how HTTPS works. > so they can scan the urls, and block some attacks The purpose of HTTPS is to provide a guarantee that your connection to Google is direct, with no intermediaries, such that (1) only Google knows your search query and (2) you get a guarantee that the received content is from Google. And you get this guarantee from certificate authorities that have a good reputation and t…

"The purpose of HTTPS is to provide a guarantee that your connection to Google is direct, with no intermediaries, such that (1) only Google knows your search query and (2) you get a guarantee that the received content is from Google." This is a popular misconception, but false. SSL creates an encrypted tunnel so that nothing "in the middle" can penetrate the tunnel (in theory), but there is no contradiction in the tw…

Cloudflare et al don't terminate TLS using their own root certificates installed on the client, which means that doesn't expose you to KCI of all servers.

And they don't MITM the TLS connection, they terminate it. The difference being that the performance is better rather than worse (so more people use TLS instead of fewer), the server is aware of this happening so it isn't fooled into thinking the connection is using more secure ciphers than it actually is, there is no third party forcing lowest common denominator security between the three, etc.

Re: Avoid Non-Microsoft Antivirus Software

#343
Here's the deal, there are two DISTINCT classes of traditional AV software. One generally sucks, the other does not.

First: free AV, generally marketed to the individual or small business. If it's free, they are making money somehow; you are almost never getting it for free out of the goodness of the vendor's heart. Most of this stuff is crap, introduces ridiculous vulnerabilities in lots of instances, and can wreak havoc on totally clean machines. For this class of AV, I 100% agree with OP; kill it with fire (aside from maybe malwarebytes).

Second: paid AV products targeted towards large businesses and the enterprise. Some of them still suck, but a lot of them are pretty good, and responsible + low impact in general. We have ESET deployed to ~700 machines and have yet to have a SINGLE problem caused by the AV while I've been here. Some of those are workstations, but a huge number are servers (granted, they get a special kind of av, not the full suite of web protection and everything).

That said, traditional AV is becoming more and more useless every month and is starting to do very little aside from catch browser toolbars, random adware, and if you don't have a firewall it can sometimes help block known bad websites (at a cost). We have also had a fair number of instances where malicious crap made it past MULTIPLE layers of email security and was caught by AV on a workstation. Malware is not distributed such that every payload has consistent content/file-hash anymore, the alternative products out there that have a chance at pseudo-reliably catching real malicious stuff are neither free, cheap, or realistically going to be deployed outside of medium to large companies.

Re: Avoid Non-Microsoft Antivirus Software

#344

Earlier quoted context omitted.

Not true. Google collects your searches. They don't sell your searches, they sell whatever they infer from your searches (your compiled and quite vague profile and I know, because I interacted with their AdSense platform), because they'd be stupid to sell your actual searches, since that's their most valuable property. Does anybody else know your search history? Besides the NSA, whom I assume have access to all US-ho…

It often irks me when people say things like "Google sells all of your data to advertisers and you are the product!" Not because there are no potential issues to discuss around ad-funded free services and data aggregation, but more because it's like clickbait (in that it oversimplifies a complex issue for emotional effect and makes discussion of actual issues more difficult). Using algorithms to build a general profi…

Once personal data is collected it could be abused or used in a way you object to. The abuse could be perpetrated by a third party who got access to the data legitimately or illegitimately, or by an employee of the company, or by an owner of the company.

As the target of such surveillance and data collection, you just never really know how that data will be used or who by. It's optimistic, to put it mildly, to expect that data will only be used for purposes you don't object to by good people with the best intentions.

Re: Avoid Non-Microsoft Antivirus Software

#345
post #326

Earlier quoted context omitted.

Yeah, through the new Windows control panel ("Settings" -> "Update & Security" -> "Windows Defender"). Windows will hound you about that (and there is no way I know to turn off the nag).

I thought it didn't just nag but turned itself back on after a while?

As far as I know, only if you fall for the dark pattern nag. I haven't run in to this, either because I haven't had it disabled for long enough or because Microsoft buckled and removed it.

Re: Avoid Non-Microsoft Antivirus Software

#346

Earlier quoted context omitted.

> the fact a US company probably cooperates with US intelligence “the fact” and “probably” are mutually exclusive. > plenty of examples of companies outright breaking the law I know and that’s why I wrote “usually follow the letter of the law”. Majority of the companies follow the law, however.

> “the fact” and “probably” are mutually exclusive. I don't see how; statements about probability can be factual and we have plenty of evidence that Google, Microsoft, and US telcos do; why should AV vendors be different? As far as companies usually following the letter of the law... do they? What makes you so sure?

> statements about probability can be factual

Depends.

In natural science or in medicine you can estimate that probability (because control groups, multiple experiments, statistical methods, etc). In such context, a statement about probability can indeed be factual.

In general conversation or in legal context they can’t. If you have facts, there’s no “probably” because you know for sure. And if you don’t, it can be you belief, or your personal opinion, but not a fact.

> do they? What makes you so sure?

Over my career, I’ve worked in several US software companies. Lately, I’m working with various US companies as a contractor.

Multiple times a company put a lot of efforts and money to comply with the law: we redesigned our products, moved across states, trained employees to comply with various regulations, and so on. Having friends in the industry with similar observations, I conclude such things happen all the time.

Re: Avoid Non-Microsoft Antivirus Software

#347

Any idea why the author is picking on Windows 7 here? Microsoft's free AV works as well on Windows 7 as it does on Windows 10. Perhaps it should go without saying --- but you also need to your OS to be up-to-date. If you're on Windows 7 or, God forbid, Windows XP, third party AV software might make you slightly less doomed.

Microsoft's free AV works on Windows 7, but was only installed by default starting in Windows 8.

Re: Avoid Non-Microsoft Antivirus Software

#348
post #151
post #39

It's fucking disaster to read your blog in iphone, please fix it. At least disable fixed width or disable right left surfing. I am not web developer, so i may give wrong suggestions, but please fix you template it is like piece of shit( the experience)

I don't understand why i got downvoted ao badly. I didnt say anything about his blog or material in his blog, i just couldn't read/navigate his blog in my phone. The template was a total disaster

We don't comment like that here on Hacker News, and we're also asked not to complain about downvotes. Please re-read the guidelines:

https://news.ycombinator.com/newsguidelines.html

Re: Avoid Non-Microsoft Antivirus Software

#350
post #286

Earlier quoted context omitted.

Is there any way to turn off Windows Defender without installing anything else?

Yeah, through the new Windows control panel ("Settings" -> "Update & Security" -> "Windows Defender"). Windows will hound you about that (and there is no way I know to turn off the nag).

I've heard if you disable the service directly, then the "Windows Defender reports that the service is turned off" message stops happening.

  sc.exe config "WinDefend" start= disabled
  sc.exe stop "WinDefend"
Post reply on HN