Live data from Hacker News

Kaspersky in the Middle – what could possibly go wrong?

palant.de

11–20 of 45 posts

Re: Kaspersky in the Middle – what could possibly go wrong?

#13
post #5

Which other AntiVirus vendors do this? How can you opt-out and is there a point to installing anti-virus software to begin with?

If you use Windows, use Windows Defender. It doesn't MitM your connections and has a comparable detection rates for 0days and common malware to all other modern AVs. Microsoft has put a lot of work into making Defender as secure as possible (you can even run it inside a VM so any exploit of defender is just trapped inside a HyperV VM instead of your system). There is no point in installing any other AV vendor; they a…

Windows Defender is on every machine, so what would be the point of writing a virus that is detected by it? The same for Kaspersky. These programs are easy to test against and well-known. They are designed to work against old viruses that have already been detected and analyzed.

It's better to use lesser known antivirus products with good heuristic detection. I will not mention names but there are a number of products out there, including ones that block every executable not on a whitelist.

Re: Kaspersky in the Middle – what could possibly go wrong?

#14
post #5

Earlier quoted context omitted.

If you use Windows, use Windows Defender. It doesn't MitM your connections and has a comparable detection rates for 0days and common malware to all other modern AVs. Microsoft has put a lot of work into making Defender as secure as possible (you can even run it inside a VM so any exploit of defender is just trapped inside a HyperV VM instead of your system). There is no point in installing any other AV vendor; they a…

Windows Defender is on every machine, so what would be the point of writing a virus that is detected by it? The same for Kaspersky. These programs are easy to test against and well-known. They are designed to work against old viruses that have already been detected and analyzed. It's better to use lesser known antivirus products with good heuristic detection. I will not mention names but there are a number of product…

A lesser known anti-virus will also be from a smaller vendor with less resources to get 0day malware into their signature databases or maintain a good heuristic detection. A lesser-known AV with a good signature DB and heuristic engine is a unicorn.

Re: Kaspersky in the Middle – what could possibly go wrong?

#16
post #7

Earlier quoted context omitted.

Also, Microsoft has an incentive to eliminate viruses and malware completely - to make their OS safer. Third party AV companies rely on continuing threats to stay in business. I'm not saying AV companies hold back or help malware out, I'm saying Microsoft has good reason to throw huge resources at the problem as a whole.

...and to build on your comment: Incentive to not slow down the performance of the OS while protecting it.

That was what caught my eye about MS's antivirus offerings from the start. I was really impressed how well it ran without me ever noticing.

I got a new laptop from work recently and I didn't spend a great deal of time looking it over as i was busy and ... of course I hit some random performance problems as McAfee was abusing my machine while I was trying to work. Endlessly installing antivirus programs is getting pretty old.

Re: Kaspersky in the Middle – what could possibly go wrong?

#17
post #5

Earlier quoted context omitted.

If you use Windows, use Windows Defender. It doesn't MitM your connections and has a comparable detection rates for 0days and common malware to all other modern AVs. Microsoft has put a lot of work into making Defender as secure as possible (you can even run it inside a VM so any exploit of defender is just trapped inside a HyperV VM instead of your system). There is no point in installing any other AV vendor; they a…

Windows Defender is on every machine, so what would be the point of writing a virus that is detected by it? The same for Kaspersky. These programs are easy to test against and well-known. They are designed to work against old viruses that have already been detected and analyzed. It's better to use lesser known antivirus products with good heuristic detection. I will not mention names but there are a number of product…

They will not only detect existing viruses. AV software has used heuristics to detect viruses for decades, and more recently ML is being used. Microsoft has really been investing in Defender and Defender ATP recently and there have been several Twitter and blog posts about the successes their ML approach is yielding, including for new viruses.

Re: Kaspersky in the Middle – what could possibly go wrong?

#18
post #4

Earlier quoted context omitted.

To answer the last, at this point, you install (or have preinstalled) AV to comply with enterprise IT policies.

Or be protected from bank fraud. Not that the AV will stop it, but having no AV gives the banks a reason to reject the claim. At least with DB in Germany. But they accept Windows Defender!

German banks and technology are terrible! They're now using an app for authentication, that you can only get from Google's PlayStore or Apple's App Store.

Germany, the country of data protection, and yet their banks force you to use Google/Apple.

Oh sure, I can use terminals or pay money for a hardware device whose manufacturer has an exclusive contract with the bank, but this is absurd considering all they'd have to do is provide a channel for getting the APK straight from their own servers instead of through Google.

...or at least give me an SHA256 of the APK, so I can really be sure that when I use a 3rd party app to download it, I'm not getting a Trojan or something.

Re: Kaspersky in the Middle – what could possibly go wrong?

#19
post #5

Which other AntiVirus vendors do this? How can you opt-out and is there a point to installing anti-virus software to begin with?

If you use Windows, use Windows Defender. It doesn't MitM your connections and has a comparable detection rates for 0days and common malware to all other modern AVs. Microsoft has put a lot of work into making Defender as secure as possible (you can even run it inside a VM so any exploit of defender is just trapped inside a HyperV VM instead of your system). There is no point in installing any other AV vendor; they a…

I disagree with the point you made about 0days and detection rates. Defender has less false positives, but almost never catch the files that actually matter, like important 0days or antiemulation and anti-unpack files. They are pretty slow with crafting generic detections.

While I understand that data from well known tests may support your point, as an employee for 2+ years at a security vendor I can say with certainty that defender falls way behind when it comes to fast generic detections and response time. I quite frequently find myself copying maliciois files to my work laptop with defender activated and the detection rate is pretty poor as shown by the actual number of files that got copied. Not even mentioning how it quietly scans my files and activates itself even though I singlehandedly shut it down a minute ago

Re: Kaspersky in the Middle – what could possibly go wrong?

#20
post #5

Earlier quoted context omitted.

If you use Windows, use Windows Defender. It doesn't MitM your connections and has a comparable detection rates for 0days and common malware to all other modern AVs. Microsoft has put a lot of work into making Defender as secure as possible (you can even run it inside a VM so any exploit of defender is just trapped inside a HyperV VM instead of your system). There is no point in installing any other AV vendor; they a…

Windows Defender is on every machine, so what would be the point of writing a virus that is detected by it? The same for Kaspersky. These programs are easy to test against and well-known. They are designed to work against old viruses that have already been detected and analyzed. It's better to use lesser known antivirus products with good heuristic detection. I will not mention names but there are a number of product…

You can't just wave your hand and say that some lesser known "no names mentioned" product is better than Defender because you want it to be. If you have evidence that some AV product is out-performing Defender, it's extremely selfish and negligent to keep that information to yourself.

I'd much rather trust MS with Defender over some lesser known AV product which likely doesn't have billions of dollars, unfathomably large samples/datasets, and extensive experience with APT's.

As pointed out, no one really has a better incentive to detect and eliminate virus's than MS does in an effort to make their OS virus free.

Post reply on HN