Live data from Hacker News

Kaspersky in the Middle – what could possibly go wrong?

palant.de

31–40 of 45 posts

Re: Kaspersky in the Middle – what could possibly go wrong?

#31
post #16

Earlier quoted context omitted.

...and to build on your comment: Incentive to not slow down the performance of the OS while protecting it.

That was what caught my eye about MS's antivirus offerings from the start. I was really impressed how well it ran without me ever noticing. I got a new laptop from work recently and I didn't spend a great deal of time looking it over as i was busy and ... of course I hit some random performance problems as McAfee was abusing my machine while I was trying to work. Endlessly installing antivirus programs is getting pre…

I had to help some regular computer user to clean their computer; one of the user's requests was to "fix" their McAfee, meaning, to update the subscription and solve other "security threats" (not viruses) that McAfee reported. After seeing how indecent this antivirus is, how it uses real intimidation, and is very intrusive with constant pop-ups, we settled on not continuing the subscription and getting rid of it altogether.

Re: Kaspersky in the Middle – what could possibly go wrong?

#32
post #28
post #7

Earlier quoted context omitted.

Also, Microsoft has an incentive to eliminate viruses and malware completely - to make their OS safer. Third party AV companies rely on continuing threats to stay in business. I'm not saying AV companies hold back or help malware out, I'm saying Microsoft has good reason to throw huge resources at the problem as a whole.

> Third party AV companies rely on continuing threats to stay in business. i'm pretty neutral on this topic, but doesn't this point by extension mean they have a more direct interest in discovering security flaws and publishing them rather than burying them under the rug if they haven't been seen in the wild?

I think they share the same incentives in the sense that discovering, patching and reporting flaws is the mission statement.

Where they differ, I think, is the end goal. Non-MS AV need an ecosystem where there is still active threats to make revenue. MS actively doesn't want any threats, because they would realize more profits through their OS being marketable as virus-free.

I'm not saying Non-MS AV is out there introducing threats. But, they are incentivized to play whack-a-mole with bandaid fixes (keeping the ecosystem in check but alive) whereas MS is incentivized to go after root problems (kill the virus ecosystem, profit from OS).

Re: Kaspersky in the Middle – what could possibly go wrong?

#33
post #30

Which other AntiVirus vendors do this? How can you opt-out and is there a point to installing anti-virus software to begin with?

A few years back ESET MitM traffic (this can be disabled, but was the default), I'm not sure what the situation is now as I since switched to Defender precisely because of the MitM "feature."

I'm using ESET Nod32 and it's still on by default but it can be easily deactivated in the settings panel.

Unfortunately, Defender is still the worse in system performance impact (1) and I can't bear it especially when you do `npm ci` or the like. Or if you are into gaming, launching Steam with/without Defender enabled and you see 10-20 secs launch time difference.

I don't understand why Microsoft doesn't focus on that. They reached good detection rate but the slowdown induced by Defender still make other AVs worth it (same good detection rate but with less performance impact).

[1] https://www.av-comparatives.org/tests/performance-test-april...

Re: Kaspersky in the Middle – what could possibly go wrong?

#34
post #21

Earlier quoted context omitted.

I disagree with the point you made about 0days and detection rates. Defender has less false positives, but almost never catch the files that actually matter, like important 0days or antiemulation and anti-unpack files. They are pretty slow with crafting generic detections. While I understand that data from well known tests may support your point, as an employee for 2+ years at a security vendor I can say with certain…

So presumably you have a product in mind which did catch all of these things, and are willing to point people in the proper direction?

What I can say from a more or less objective standpoint, the best vendors according to a response-time metric are Eset, Kaspersky and Bitdefender. Each of them have their own weaknesses and I do not know what is the performance impact for using them alongside defender

Re: Kaspersky in the Middle – what could possibly go wrong?

#35
post #16

Earlier quoted context omitted.

...and to build on your comment: Incentive to not slow down the performance of the OS while protecting it.

That was what caught my eye about MS's antivirus offerings from the start. I was really impressed how well it ran without me ever noticing. I got a new laptop from work recently and I didn't spend a great deal of time looking it over as i was busy and ... of course I hit some random performance problems as McAfee was abusing my machine while I was trying to work. Endlessly installing antivirus programs is getting pre…

I was dealing with MySQL running on a Windows server box with McAfee Active Response running (MarService.exe). It has a feature for tracking files created/deleted, which is accomplished by hashing all new files, saving them to its own local DB, and presumably pushing them to the management server async. The app running on MySQL frequently creates many new tables and fills them as part of SOP, so the disk was constantly hammered by both MySQL and McAfee...

Re: Kaspersky in the Middle – what could possibly go wrong?

#36
post #21

Earlier quoted context omitted.

So presumably you have a product in mind which did catch all of these things, and are willing to point people in the proper direction?

What I can say from a more or less objective standpoint, the best vendors according to a response-time metric are Eset, Kaspersky and Bitdefender. Each of them have their own weaknesses and I do not know what is the performance impact for using them alongside defender

Interesting, thanks for answering. Is this object standpoint of yours from 3rd-party studies of response-time metrics, or anecdotal data from yourself?

Also, how substantial are these differences? Is it worth (in your opinion) being MitM'd by Kaspersky to realize the supposed benefits?

Re: Kaspersky in the Middle – what could possibly go wrong?

#37
post #5

Which other AntiVirus vendors do this? How can you opt-out and is there a point to installing anti-virus software to begin with?

If you use Windows, use Windows Defender. It doesn't MitM your connections and has a comparable detection rates for 0days and common malware to all other modern AVs. Microsoft has put a lot of work into making Defender as secure as possible (you can even run it inside a VM so any exploit of defender is just trapped inside a HyperV VM instead of your system). There is no point in installing any other AV vendor; they a…

What would you suggest for Mac and Linux? I lot of enterprise contracts and security certifications require "anti-virus installed and up-to-date".

What's the best way of meeting that checkbox for Mac and Linux laptops?

Re: Kaspersky in the Middle – what could possibly go wrong?

#38
post #36

Earlier quoted context omitted.

What I can say from a more or less objective standpoint, the best vendors according to a response-time metric are Eset, Kaspersky and Bitdefender. Each of them have their own weaknesses and I do not know what is the performance impact for using them alongside defender

Interesting, thanks for answering. Is this object standpoint of yours from 3rd-party studies of response-time metrics, or anecdotal data from yourself? Also, how substantial are these differences? Is it worth (in your opinion) being MitM'd by Kaspersky to realize the supposed benefits?

The data is empirical, based on comparative results of some files I've mananged to get my hands on over the years. I can't argue on MitM, because I haven't worked with traffic and traffic analysis, but when it comes to malicious executables and exploits, it's definitely worth the mitm inconvenience.

Ironically speaking, privacy concerned users are mostly IT-versed which can evade most of malware effects by just being attentive and caucios, while my mother, for example, doesn't care about MitM'ing her traffic, while I do care about her vising some shady sites while watching her beloved internet series.

Bottom line, if you are well versed, you probably can limit yourself to the default windows defender, but when it comes to successful unreleased exploits or a computer/user that is likely to download/run unknown executables some high-end vendor might be faster than other researches

Re: Kaspersky in the Middle – what could possibly go wrong?

#39
post #4

Earlier quoted context omitted.

To answer the last, at this point, you install (or have preinstalled) AV to comply with enterprise IT policies.

Or be protected from bank fraud. Not that the AV will stop it, but having no AV gives the banks a reason to reject the claim. At least with DB in Germany. But they accept Windows Defender!

> but having no AV gives the banks a reason to reject the claim

a good reason to only do banking on an iPad/iPhone...

Re: Kaspersky in the Middle – what could possibly go wrong?

#40
post #5

Which other AntiVirus vendors do this? How can you opt-out and is there a point to installing anti-virus software to begin with?

If you use Windows, use Windows Defender. It doesn't MitM your connections and has a comparable detection rates for 0days and common malware to all other modern AVs. Microsoft has put a lot of work into making Defender as secure as possible (you can even run it inside a VM so any exploit of defender is just trapped inside a HyperV VM instead of your system). There is no point in installing any other AV vendor; they a…

I've had something similar happen, VirtualBox has measures to try to detect if it's been hijacked, by malicious software or AV (although the distinction could be argued).
Post reply on HN