Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months
11–20 of 40 posts
Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months
#12We've been trying to fight a security auditor requirement to put antivirus on all of our amazon amis (including linux). It's insane that anyone thinks that improves security.
Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months
#13Earlier quoted context omitted.
Is that a requirement your security auditor has, or are vendors demanding this in vendor-specific security reviews? And is this for e.g. network segmentation in PCI, or more routine assessments? Depending on what you mean, perhaps you want to get in touch if you'd like better technical due diligence :)
I have filled out a few applications for tech e&o and cyber liability insurance over the past week and they all had a question about antivirus on the servers, workstations, and phones. I answered truthfully (no) and wonder if that is going to hurt me.
If having an antivirus can create possibly more security holes than it closes - then from an insurance perspective they would not want you to have it.
i.e. if they have to pay based upon an attack - they want to ensure the lowest risk.
Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months
#14The main disadvantage security companies have is the difficulty to integrate with the core operating system. This makes it easy to third parties (e.g. malware) to use the same software for malicious applications. They based their security products in a lot of system internals tricks to make them work (e.g. API hooking, reverse engineering, drivers). Microsoft has a clear advantage in this market because they can modi…
Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months
#15We've been trying to fight a security auditor requirement to put antivirus on all of our amazon amis (including linux). It's insane that anyone thinks that improves security.
Use their same language back at them and talk about your "compensating controls". That's auditor lingo for I know A is the standard control but by doing B and/or C instead I have adequately addressed the risk.
Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months
#16The main disadvantage security companies have is the difficulty to integrate with the core operating system. This makes it easy to third parties (e.g. malware) to use the same software for malicious applications. They based their security products in a lot of system internals tricks to make them work (e.g. API hooking, reverse engineering, drivers). Microsoft has a clear advantage in this market because they can modi…
From your HN user profile, "At Nektra we are providing solutions that require Windows system internals and reverse engineering skills." http://www.nektra.com
Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months
#17We've been trying to fight a security auditor requirement to put antivirus on all of our amazon amis (including linux). It's insane that anyone thinks that improves security.
From experience many so called 'security auditor's tend not to have a clue what they're talking about technically, and operate from a playbook. They do however speak the the same language as management. Buzzword bingo, spreading FUD, selling snake oil.
The place had so many dysfunctions I'd not know how to start. I work for a much more professional outfit now with true appreciation for security and competence.
edit: there's a real gap in this non-glamorous compliance domain. if you address it and need to execute SCAP (OVAL, XCCDF) content, look to a very competent scanner vendor, jOVAL. The real challenges are in organizing and presenting consistent info across many compliance standards, OSs, cloud vendors, etc. ... and to scan entities that aren't OSs per se, and to analyze cross-domain conditions.
Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months
#18Earlier quoted context omitted.
I have filled out a few applications for tech e&o and cyber liability insurance over the past week and they all had a question about antivirus on the servers, workstations, and phones. I answered truthfully (no) and wonder if that is going to hurt me.
It will be interesting what an insurance company thinks is needed. If having an antivirus can create possibly more security holes than it closes - then from an insurance perspective they would not want you to have it. i.e. if they have to pay based upon an attack - they want to ensure the lowest risk.
With that said I prefer to view security as, "You likely will be the victim of a planned attack, so plan from there", but still. Odds are not favourable.
Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months
#19We've been trying to fight a security auditor requirement to put antivirus on all of our amazon amis (including linux). It's insane that anyone thinks that improves security.
Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months
#20We've been trying to fight a security auditor requirement to put antivirus on all of our amazon amis (including linux). It's insane that anyone thinks that improves security.
Which auditor, and for what regulation?
All auditors looking at you for this certification will ask this question.