Live data from Hacker News

Ask HN: Is no anti-virus software still best practice for mac?

news.ycombinator.com

71–78 of 78 posts

Re: Ask HN: Is no anti-virus software still best practice for mac?

#71
post #62

Have one but never needed it so far - or it didn't catch the virii ;) I use bitdefender at least it's quite unobtrusive on mac (sick of the windows version!). Sophos is free and afaik not too bad if you need one: https://home.sophos.com/free-mac-antivirus Further I use: - https://objective-see.com/products/knockknock.html - https://objective-see.com/products/oversight.html - https://objective-see.com/products/blockbl…

I use bitdefender as well, but lately I started deactivating "autopilot" (auto scanning folders in the background) because it pushes my cpu usage to > 100% regularly while I am using my Mac.

I fortunately do not have that problem, yet. But the autopilot stuff and other weird stuff bitdefender is doing autonomously is exactly why i may ditch it soon. Will probably switch to sophos once it happens.

Re: Ask HN: Is no anti-virus software still best practice for mac?

#72

In a corporate setting: At Etsy we use OSQuery on all of our corp machines(macOS) to help with malware/virus detection. We use community rules: https://github.com/facebook/osquery/blob/master/packs/osx-at... In addition to community rules we also curate a bunch of rules in house from malware we've discovered across our fleet. We then aggregate this info into ELK and alert on it. At Home: OSQuery as well + tiny elk st…

Can you elaborate more on your home setup?

Re: Ask HN: Is no anti-virus software still best practice for mac?

#73
You have a few different options based on the comments here like locking down incoming/outgoing traffic with little snitch or other tools out there.

I would definitely recommend Avast though if you are concerned about safety, I've used it for some time now off and on and it does a good job of filtering pretty much any file based viruses as well as internet and email based exploits.

- https://www.avast.com/en-us/free-mac-security

Re: Ask HN: Is no anti-virus software still best practice for mac?

#74

It is my considered opinion that "no anti-virus" is still the best practice for nearly everything. About the only place it makes any sense is in your email filters or anywhere else the public can send random bullshit. At best they incur an ever present performance hit while only catching the lowest of low-hanging fruit. At worst they are constantly getting in your way with false positives (which train you to ignore a…

>At worst they are constantly getting in your way with false positives

Actually, at worst, they can increase your attack surface and have, on more than one instance I can think of, introduced exploitable vulnerabilities that would not have existed without the antivirus.

Re: Ask HN: Is no anti-virus software still best practice for mac?

#75

It is my considered opinion that "no anti-virus" is still the best practice for nearly everything. About the only place it makes any sense is in your email filters or anywhere else the public can send random bullshit. At best they incur an ever present performance hit while only catching the lowest of low-hanging fruit. At worst they are constantly getting in your way with false positives (which train you to ignore a…

"Most people aren't as dumb as your ego likes to imagine them to be."

My ego doesn't have to imagine anything. People inadvertently install malware all the time. I've personally done the deed of cleaning all that garbage up on hundreds of occasions.

This doesn't necessarily mean installing AV, though; a sufficiently-motivated idiot (or someone smart enough to be dangerous) will figure out a way to disable it anyway using a random website from a Google search as a reference. It does mean either locking down access or giving the user proper education (namely: "don't install random crap from the Internet, even if the Internet tells you to do so").

Re: Ask HN: Is no anti-virus software still best practice for mac?

#76
post #68

Earlier quoted context omitted.

Got any links to articles to walk through getting this set up?

https://blog.kolide.com/monitoring-macos-hosts-with-osquery-... Hope that helps! I would also recommend joining the osquery slack: https://osquery-slack.herokuapp.com/

Thanks!

Re: Ask HN: Is no anti-virus software still best practice for mac?

#77

It is my considered opinion that "no anti-virus" is still the best practice for nearly everything. About the only place it makes any sense is in your email filters or anywhere else the public can send random bullshit. At best they incur an ever present performance hit while only catching the lowest of low-hanging fruit. At worst they are constantly getting in your way with false positives (which train you to ignore a…

Eh, your "not as dumb as you think" is unnecessarily hostile. Also, nobody except you was calling people dumb, it's some weird rhetoric. But I will say that I regularly help people including my parents who are tricked by those fake download-button ads. I'm not calling them dumb -- you were in your own premise. But that's one avenue for people to install malware on their computer. "Don't worry about it, people don't g…

>Also, nobody except you was calling people dumb

In this thread, no. But that’s a very common prevailing theme, that normal users are “dumb” compared to techies. Ask any help desk technician or desktop support employee or the BOFH or really anyone who deals with end users. Chances are they’re gonna say end users are dumb.

If anything, this persons attitude is refreshing, giving end users a bit more credit.

Re: Ask HN: Is no anti-virus software still best practice for mac?

#78
post #65

Earlier quoted context omitted.

At worst, AV is an increase in attack surface, as detailed in the CIA wikileaks.

There was precisely nothing regarding exploiting AV vulns in the CIA leaks. The leaks did contain some really basic obfuscation techniques to defeat AVs, but that's nothing new.

Sorry, I must have mixed it up with a different press release. Anyway, this is the first thing I found when trying to find it again.

https://www.wired.com/2017/03/clever-doubleagent-attack-turn...

Post reply on HN