Live data from Hacker News

MS Windows Defender and DeCSS

arch13.com

21–30 of 211 posts

Re: MS Windows Defender and DeCSS

#21

To be fair, this does look like a false positive. In general, the desktop antivirus space in 2021 is a mess. Because of the sheer number of malware, and some obfuscation techniques used by some of it, antivirus software has to use very broad regular expressions for describing the malware, counterbalanced by huge whitelists of known mainstream software. If you don't qualify as a "mainstream software vendor", simply bu…

I don't care how broad your definition is, it shouldn't include the mp4 files in my hard drive.

Er, doesn't that assume that the mp4 files on your hard drive can't genuinely be infected with viruses? Why is that assumption true?

Re: MS Windows Defender and DeCSS

#22

Do tech aware people like nearly everyone in this forum, need Defender (or another AV) to run at all? How many people here completely or partially stop it from running?

I had to get signed permission from our IT contractors to disable it. But then again, I was trying to get a PDF of a Categorical Logic paper from an Italian university’s website and the filters kept blocking for pornography and sending emergency messages to the contractor to audit my computer.

Sounds weird... Do you know to what extent those are correlated? That is: is the contractor told every time the filter thinks it has found adult entertainment? Or was your case exceptional?

Re: MS Windows Defender and DeCSS

#23

To be fair, this does look like a false positive. In general, the desktop antivirus space in 2021 is a mess. Because of the sheer number of malware, and some obfuscation techniques used by some of it, antivirus software has to use very broad regular expressions for describing the malware, counterbalanced by huge whitelists of known mainstream software. If you don't qualify as a "mainstream software vendor", simply bu…

Deleting both the exe and the source code makes a false positive seem rather unlikely to me.

The source code in question appears to have been obfuscated (possibly just for brevity). I'd guess the Defender signature in question was written around the packer/obfuscator.

Re: MS Windows Defender and DeCSS

#24
post #16
post #7

His comment in /r/sysadmin: "Setting a Windows Defender exception to the folder does not prevent the quarantine from occurring. I re-ran this test three times trying exceptions and even the entire NAS drive as on the excluded list." Windows Defender is overriding the user whitelist?

In addition, Windows also quarantines and deletes innocuous Windows activation crack tools that contain no malware whatsoever, but can be used to activate Windows independently of Microsoft. It's really amazing the attitude Microsoft takes regarding hardware that isn't theirs, including the nonconsensual forced autoupdate.

Oh no, they’re making the world safer by encouraging the adoption of the latest security patches and bug fixes? And giving away best-in-class security software that you can disable at any time? How evil. You must really have loved the days of Norton Antivirus.

Re: MS Windows Defender and DeCSS

#26
post #7

His comment in /r/sysadmin: "Setting a Windows Defender exception to the folder does not prevent the quarantine from occurring. I re-ran this test three times trying exceptions and even the entire NAS drive as on the excluded list." Windows Defender is overriding the user whitelist?

For future reference, that comment seems to be at https://old.reddit.com/r/sysadmin/comments/oof29b/windows_de...

Re: MS Windows Defender and DeCSS

#28

To be fair, this does look like a false positive. In general, the desktop antivirus space in 2021 is a mess. Because of the sheer number of malware, and some obfuscation techniques used by some of it, antivirus software has to use very broad regular expressions for describing the malware, counterbalanced by huge whitelists of known mainstream software. If you don't qualify as a "mainstream software vendor", simply bu…

> In general, the desktop antivirus space in 2021 is a mess. Because of the sheer number of malware, and some obfuscation techniques used by some of it, antivirus software has to use very broad regular expressions for describing the malware, counterbalanced by huge whitelists of known mainstream software.

Why do they have to use regular expressions?

Re: MS Windows Defender and DeCSS

#29

Earlier quoted context omitted.

Sadly it’s often a contractual / insurance requirement.

At home?

If anything I think it makes more sense to have higher security requirements for a computer that will be primarily used outside of a controlled corporate network.

Re: MS Windows Defender and DeCSS

#30
post #16
post #7

His comment in /r/sysadmin: "Setting a Windows Defender exception to the folder does not prevent the quarantine from occurring. I re-ran this test three times trying exceptions and even the entire NAS drive as on the excluded list." Windows Defender is overriding the user whitelist?

In addition, Windows also quarantines and deletes innocuous Windows activation crack tools that contain no malware whatsoever, but can be used to activate Windows independently of Microsoft. It's really amazing the attitude Microsoft takes regarding hardware that isn't theirs, including the nonconsensual forced autoupdate.

I was under the impression that with Windows 10 we shifted to the product being the users data. The customers are now advertisers.
Post reply on HN