Live data from Hacker News

Ask HN: Is no anti-virus software still best practice for mac?

news.ycombinator.com

31–40 of 78 posts

Re: Ask HN: Is no anti-virus software still best practice for mac?

#31

It is my considered opinion that "no anti-virus" is still the best practice for nearly everything. About the only place it makes any sense is in your email filters or anywhere else the public can send random bullshit. At best they incur an ever present performance hit while only catching the lowest of low-hanging fruit. At worst they are constantly getting in your way with false positives (which train you to ignore a…

“Most people aren't as dumb as your ego likes to imagine them to be. They may not know the details of how their computers work but they know sketchy looking crap when they see it.” That’s simply not true. Like, at all. If it were, then viruses and malware wouldn’t be spreading like they are, especially phishing campaigns. I know many very smart people who have been compromised. I also take issue with the word “dumb”…

> I also take issue with the word “dumb” — “smart” people can be caught off guard as well.

Yeah, exactly my point. People aren't as dumb as you think they are because you and I are just about as dumb, we just think we're better than them because we understand some things they don't.

And more to the point, the thing about successful malware and phishing campaigns is that AV already does a shit job of stopping them. If you are inclined to believe something is legit, you're going to tell your AV or filter to shut the hell up and just do it anyway. The AV adds practically nothing and does it at a real cost.

Re: Ask HN: Is no anti-virus software still best practice for mac?

#32

It is my considered opinion that "no anti-virus" is still the best practice for nearly everything. About the only place it makes any sense is in your email filters or anywhere else the public can send random bullshit. At best they incur an ever present performance hit while only catching the lowest of low-hanging fruit. At worst they are constantly getting in your way with false positives (which train you to ignore a…

“Most people aren't as dumb as your ego likes to imagine them to be. They may not know the details of how their computers work but they know sketchy looking crap when they see it.” That’s simply not true. Like, at all. If it were, then viruses and malware wouldn’t be spreading like they are, especially phishing campaigns. I know many very smart people who have been compromised. I also take issue with the word “dumb”…

I agree with what you're saying, but it's worth noting that the kinds of attacks you're talking about cannot be reliably stopped by anti-virus.

Instead, they're stopped by almost constant security training. And, I'd argue that if your security training is good enough to get people to recognize phishing, spearphishing and the ilk, it's good enough to get them to recognize the kinds of low hanging fruit that reactive anti-virus software protects against.

Re: Ask HN: Is no anti-virus software still best practice for mac?

#33

It is my considered opinion that "no anti-virus" is still the best practice for nearly everything. About the only place it makes any sense is in your email filters or anywhere else the public can send random bullshit. At best they incur an ever present performance hit while only catching the lowest of low-hanging fruit. At worst they are constantly getting in your way with false positives (which train you to ignore a…

> Most people aren't as dumb as your ego likes to imagine them to be. They may not know the details of how their computers work but they know sketchy looking crap when they see it.

Dumb isn't the word I'd use. If there were a less demeaning way of saying unaware, or ignorant, of black hat / scam trends, that's the wording I'd use.

Most people, including myself, are pretty bad a calculating risk when doing innocuous things like checking e-mail, logging in to websites or visiting a site with stealthy malicious content.

Re: Ask HN: Is no anti-virus software still best practice for mac?

#34
post #18

My approach is to make my PC disposable. With all cloud services its a lot easier than it used to be. IE * Working code in github * Photos in offline multiple HDD * Docs in cloud servers and important ones printed out. This way I dont really care if I get a virus, or gets stolen, or destroyed in fire or HDD crash etc. I actually locked myself out of my encrypted laptop and it didnt really matter - I just reinstalled…

Why would you have bothered encrypting the laptop if everything is in the cloud/elsewhere anyway?

Re: Ask HN: Is no anti-virus software still best practice for mac?

#35
post #3

I don't run traditional antivirus but I do run: https://objective-see.com/products/blockblock.html (free) Detects when software attempts to install itself to run at startup and lets you block the registration. https://www.obdev.at/products/littlesnitch/index.html (paid) detects, reports, blocks applications connecting to the internet. https://adguard.com/en/welcome.html (paid) High quality adblocker for safari.

I am super skeptical about ad guard and I'm looking for someone to allay that skepticism. It's just... too clean. I don't trust software this perfect, especially since it's made in Russia and sees all the internet traffic on my computer.

I didn't know it was made in Russia! Up until now I've had a good experience, and trusted reviews.

But as an experiment I just tried removing the little snitch filter that lets adguard create all outgoing connections. it looks like adguard will request some or all requests that my web browser makes (like, it'll also request JS from slack or facebook). This might be because it detects and blocks crypto miner JS, or maybe some other heuristics. So far it hasn't tried to phone home but it's hard to look for that with little snitch when it's trying to connect to every site I browse to.

Re: Ask HN: Is no anti-virus software still best practice for mac?

#36
I never used any third-party antivirus software. AFAIK both Windows and macOS have built-in antivirus software, although I think that it's not required either. Properly patched software to minimize risk of RCE vulnerability and brain to avoid running untrusted programs should be enough.

Re: Ask HN: Is no anti-virus software still best practice for mac?

#37

I never used any third-party antivirus software. AFAIK both Windows and macOS have built-in antivirus software, although I think that it's not required either. Properly patched software to minimize risk of RCE vulnerability and brain to avoid running untrusted programs should be enough.

macOS does not have built-in antivirus software, hence the question.

Re: Ask HN: Is no anti-virus software still best practice for mac?

#38
post #18

My approach is to make my PC disposable. With all cloud services its a lot easier than it used to be. IE * Working code in github * Photos in offline multiple HDD * Docs in cloud servers and important ones printed out. This way I dont really care if I get a virus, or gets stolen, or destroyed in fire or HDD crash etc. I actually locked myself out of my encrypted laptop and it didnt really matter - I just reinstalled…

Why would you have bothered encrypting the laptop if everything is in the cloud/elsewhere anyway?

You would still want to encrypt since sensitive data might be cached on the hard drive in plain text or credentials stored in an insecure way.

Re: Ask HN: Is no anti-virus software still best practice for mac?

#39
Are these machines part of a cardholder data environment (as defined by PCI-DSS)?

If the answer to that is 'yes', honestly, just suck it up and install it. It will be cheaper, easier and far less annoying to install some AV in your CDE than to have to explain why you didn't in the event of a breach.

(Note --- Post breach audits are my personal definition of hell.)

Otherwise, anti-virus is reactive and tends to protect against the lowest hanging fruit, all while introducing a real cost to everything else you do on that machine. Personally, I'd skip AV and just do a bit of security training.

Re: Ask HN: Is no anti-virus software still best practice for mac?

#40

you need AV on your corporate macs. No excuses. For those in "my enterprise doesnt need AV, because AV is stupid" camp: In the last week, the enterprise AV: * Blocked 15 cryptominers * Blocked 3 email based ransomware attachments * Blocked 6 phishing emails * Blocked 3 installs for MacKeeper (PUA) * Found 4 other adware-type infections on hosts Without it, these things would have hit the organisation. AV -- it will c…

This [1] post last year pointed to Google Project Zero, which found dozens of exploits in popular AV software. What if your third-party AV is your lowest hanging fruit? How many issues did your AV itself cause? How would you know?

[1]: https://robert.ocallahan.org/2017/01/disable-your-antivirus-...

Post reply on HN