Live data from Hacker News

Ask HN: Is no anti-virus software still best practice for mac?

news.ycombinator.com

61–70 of 78 posts

Re: Ask HN: Is no anti-virus software still best practice for mac?

#61
post #18

My approach is to make my PC disposable. With all cloud services its a lot easier than it used to be. IE * Working code in github * Photos in offline multiple HDD * Docs in cloud servers and important ones printed out. This way I dont really care if I get a virus, or gets stolen, or destroyed in fire or HDD crash etc. I actually locked myself out of my encrypted laptop and it didnt really matter - I just reinstalled…

> This way I dont really care if I get a virus, or gets stolen...

If you get infected with a keylogger or a backdoor tool you're going to care. It doesn't matter how encrypted your hard drive is.

Re: Ask HN: Is no anti-virus software still best practice for mac?

#62

Have one but never needed it so far - or it didn't catch the virii ;) I use bitdefender at least it's quite unobtrusive on mac (sick of the windows version!). Sophos is free and afaik not too bad if you need one: https://home.sophos.com/free-mac-antivirus Further I use: - https://objective-see.com/products/knockknock.html - https://objective-see.com/products/oversight.html - https://objective-see.com/products/blockbl…

I use bitdefender as well, but lately I started deactivating "autopilot" (auto scanning folders in the background) because it pushes my cpu usage to > 100% regularly while I am using my Mac.

Re: Ask HN: Is no anti-virus software still best practice for mac?

#63

you need AV on your corporate macs. No excuses. For those in "my enterprise doesnt need AV, because AV is stupid" camp: In the last week, the enterprise AV: * Blocked 15 cryptominers * Blocked 3 email based ransomware attachments * Blocked 6 phishing emails * Blocked 3 installs for MacKeeper (PUA) * Found 4 other adware-type infections on hosts Without it, these things would have hit the organisation. AV -- it will c…

AV detection rate is not very good. And of course targeted stuff can just test against your av.

Yes, lowest hanging fruit, I know. So at this point you have to start managing your compromises instead of altogether preventing them.

Re: Ask HN: Is no anti-virus software still best practice for mac?

#64

One of the best anti-virus tools on any platform is a good adblocker (I prefer ublock origin). It completely removes large classes of infection sources (malvertising, fake download buttons, etc). Then disable macros in office products. If every IT department did that, they’d have much more time for useful work. Whether you use antivirus or not, use an adblocker. Keeping broken monetisation strategies alive is not you…

I really wish we could disable macros, but it turns out the hoops we'd have to jump through just so accounting could continue to do their jobs wasn't worth the effort.

I'm sure some academic out there will berate me for not insisting that we disassemble an entire department's workflow and rewrite it in SQL with some web frontend, but I work in the real world where costs need to be justified and the truth is they couldn't be. There were much simpler and cheaper ways to mitigate the threats we were worried about.

Ad blocking interferes with the Marketing Department occasionally but covers such a huge range of problems that it really is worth it.

Re: Ask HN: Is no anti-virus software still best practice for mac?

#65

It is my considered opinion that "no anti-virus" is still the best practice for nearly everything. About the only place it makes any sense is in your email filters or anywhere else the public can send random bullshit. At best they incur an ever present performance hit while only catching the lowest of low-hanging fruit. At worst they are constantly getting in your way with false positives (which train you to ignore a…

At worst, AV is an increase in attack surface, as detailed in the CIA wikileaks.

There was precisely nothing regarding exploiting AV vulns in the CIA leaks.

The leaks did contain some really basic obfuscation techniques to defeat AVs, but that's nothing new.

Re: Ask HN: Is no anti-virus software still best practice for mac?

#66
post #18

My approach is to make my PC disposable. With all cloud services its a lot easier than it used to be. IE * Working code in github * Photos in offline multiple HDD * Docs in cloud servers and important ones printed out. This way I dont really care if I get a virus, or gets stolen, or destroyed in fire or HDD crash etc. I actually locked myself out of my encrypted laptop and it didnt really matter - I just reinstalled…

> This way I dont really care if I get a virus, or gets stolen... If you get infected with a keylogger or a backdoor tool you're going to care. It doesn't matter how encrypted your hard drive is.

Practically speaking, how many key loggers and backdoor tools are detected by AV?

Re: Ask HN: Is no anti-virus software still best practice for mac?

#67

It is my considered opinion that "no anti-virus" is still the best practice for nearly everything. About the only place it makes any sense is in your email filters or anywhere else the public can send random bullshit. At best they incur an ever present performance hit while only catching the lowest of low-hanging fruit. At worst they are constantly getting in your way with false positives (which train you to ignore a…

“Most people aren't as dumb as your ego likes to imagine them to be. They may not know the details of how their computers work but they know sketchy looking crap when they see it.” That’s simply not true. Like, at all. If it were, then viruses and malware wouldn’t be spreading like they are, especially phishing campaigns. I know many very smart people who have been compromised. I also take issue with the word “dumb”…

I think "dumb" is the incorrect word for this context. They simply lack the awareness. Us IT folks hang around in places like HN where we constantly bombarded with advisories against viruses and online scams, and hence well-aware of them.

Re: Ask HN: Is no anti-virus software still best practice for mac?

#68

In a corporate setting: At Etsy we use OSQuery on all of our corp machines(macOS) to help with malware/virus detection. We use community rules: https://github.com/facebook/osquery/blob/master/packs/osx-at... In addition to community rules we also curate a bunch of rules in house from malware we've discovered across our fleet. We then aggregate this info into ELK and alert on it. At Home: OSQuery as well + tiny elk st…

Got any links to articles to walk through getting this set up?

https://blog.kolide.com/monitoring-macos-hosts-with-osquery-...

Hope that helps!

I would also recommend joining the osquery slack: https://osquery-slack.herokuapp.com/

Re: Ask HN: Is no anti-virus software still best practice for mac?

#69
At INRIA (a French computer science research institute), AV became mandatory on Macs last year.

A colleague of mine got hit recently by a crypto-miner on their Mac. I don't know if they had an AV, and if so, if the AV would have caught the miner. This was detected by the IT department by monitoring suspicious traffic.

I don't use a macOS so I can't really say. I see AVs as another piece of proprietary software that you have to trust, and that takes significant resources without knowing how useful they are.

On Windows, I would probably use the one from Microsoft, since it's free and since I would already "trust" Microsoft by using their OS and I would somewhat bet that it is in their interest to keep their OS safe. I can't be sure tough: why is it not integrated by default (or is it?)? To allow competition? Then is Microsoft making their antivirus less efficient so the competition is still relevant? And maybe AV is not really Microsoft's main business so their antivirus may be lacking?

On the other side, I would bet it is in the interest of other AVs to always nag you and make you feel they are present and useful more than being actually efficient for other things than high detection rates in benchmarks.

They are irritating and advertise themselves in people's mail signatures, sometimes outright lying: "this email as no viruses" - That you can't be sure, and the mail could have got a virus in its way between the sender and the recipient.

By design, AVs can't really detect new viruses and I would not feel really more confident with an AV than without because of that. AVs didn't catch ransomwares when they first appeared after all.

I don't use any antivirus. My approach to security is:

- Using only free software, as much as possible (I know, I would need to audit everything I use for this to be perfect, but I can't possibly do that).

- that is preferably installed from the OS vendor, which I have no choice to trust anyway.

- usage of an ad blocker with more filters than the default

- be careful where clicking links

- instant backups in a self hosted cloud for important things, and automatic daily snapshots of this cloud somewhere else

- and I also happen to never be browsing sketchy websites.

- all this is true on my phone as well.

One could add usage of Google safe browsing or something related for phishing. And also blocking Javascript or third party Javascript by default when browsing, which I did at some point in my life but which is not convenient for most people.

Would I recommend AV for somebody who uses an OS that is more targeted by viruses than mine, and is likely to fell in a trap (the kind of trap an AV would catch anyway)? Probably Windows Defender on Windows, for Macs I really don't know. If there is an AV provided by Apple or by some other company you trust, I guess I would go for it rather than having nothing.

You can always get viruses from the network that will silently exploit an unfixed security breach on any system, and that may remain undetected so at least, I would tell them to be careful, to keep their system updated and to make backups regularly (ideally, backups should be automatic to some extent), since AVs can't guarantee that no virus will make it.

I would make sure that they are not too confident in the AV, too.

Re: Ask HN: Is no anti-virus software still best practice for mac?

#70
post #68

Earlier quoted context omitted.

Got any links to articles to walk through getting this set up?

https://blog.kolide.com/monitoring-macos-hosts-with-osquery-... Hope that helps! I would also recommend joining the osquery slack: https://osquery-slack.herokuapp.com/

nice thanks for the assist Zach!
Post reply on HN