Live data from Hacker News

MS Windows Defender and DeCSS

arch13.com

51–60 of 211 posts

Re: MS Windows Defender and DeCSS

#51
post #31

Do tech aware people like nearly everyone in this forum, need Defender (or another AV) to run at all? How many people here completely or partially stop it from running?

It was really infuriating to disable, FWIW. I spent hours fighting with it one day. The UI doesn't let you fully disable it: you have to use registry keys and the group policy editor. The end result has this hilarious property where it is flagging the fact that I disabled it as tampering that might indicate malware? I don't know if I even can disable that part... and I apparently didn't even succeed fully anyway as I…

> I don't know if I even can disable that part

It's tamper protection, you can disable it. (I hate it too.)

Re: MS Windows Defender and DeCSS

#52
I'm so happy to see a thread on Windows Defender, because my org recently switched antivirus software and I can't wait to tell you how bad it is !

There's a hidden feature in Defender, that will delight any user : it can turn your 15" MacBook Pro into a full breakfast machine. Want pancakes ? Start a zoom call.

While you wait for your favorite video conference app to start, don't hope to finish your docker pull/save/build in less than 30 times its usual time. Your laptop I/O will be so cripled that you might get better bandwith with a floppy disk drive (I'm exagerating a bit, but that's how it feels to go from 120MB/s to 4MB/s on a SSD).

Our Mac IT is completely powerless. I never thought I would ever regret getting rid of Symantec. I was wrong.

Re: MS Windows Defender and DeCSS

#53
post #44
post #7

His comment in /r/sysadmin: "Setting a Windows Defender exception to the folder does not prevent the quarantine from occurring. I re-ran this test three times trying exceptions and even the entire NAS drive as on the excluded list." Windows Defender is overriding the user whitelist?

Microsoft knows better. We are here to protect you.

People who ignored the AV exception requested by Kaseya didn't get a surprise ransomware in their systems

Re: MS Windows Defender and DeCSS

#54
post #31

Earlier quoted context omitted.

It was really infuriating to disable, FWIW. I spent hours fighting with it one day. The UI doesn't let you fully disable it: you have to use registry keys and the group policy editor. The end result has this hilarious property where it is flagging the fact that I disabled it as tampering that might indicate malware? I don't know if I even can disable that part... and I apparently didn't even succeed fully anyway as I…

should only take a moment in the group policy editor. you can actually filter settings by name to zero in on things quickly. the only real cosmetic change i can see is for instance on the virus & threat protection page in windows 10, it says in red at the top of the window: Your Virus & threat protection is managed by your organization.

windows defender was one of the (many) reasons I gave up on windows and replaced the last windows machine I had with a Mac Mini. (FC33 on my main)

Very similar experience here, coupled with windows defender randomly switching itself back on and quaranteening half my (completely benign) development folder.

The last time it did that I spent an entire afternoon trying to get it disabled and get my files back onto the machine with only limited success.

I think it may be a windows home vs windows professional thing.

But rather than wrestle with it further I just gave up. Only thing I had left that really needed windows was word and excel which ironically actually now work better and crash less on the mac mini than they ever did on windows.

Re: MS Windows Defender and DeCSS

#55
post #7

His comment in /r/sysadmin: "Setting a Windows Defender exception to the folder does not prevent the quarantine from occurring. I re-ran this test three times trying exceptions and even the entire NAS drive as on the excluded list." Windows Defender is overriding the user whitelist?

ughhh this is why i ended up completely disabling it

Re: MS Windows Defender and DeCSS

#56
post #16

Earlier quoted context omitted.

In addition, Windows also quarantines and deletes innocuous Windows activation crack tools that contain no malware whatsoever, but can be used to activate Windows independently of Microsoft. It's really amazing the attitude Microsoft takes regarding hardware that isn't theirs, including the nonconsensual forced autoupdate.

Oh no, they’re making the world safer by encouraging the adoption of the latest security patches and bug fixes? And giving away best-in-class security software that you can disable at any time? How evil. You must really have loved the days of Norton Antivirus.

you may have misread the parent comment? it is deleting things completely unrelated to malware

Re: MS Windows Defender and DeCSS

#57

Do tech aware people like nearly everyone in this forum, need Defender (or another AV) to run at all? How many people here completely or partially stop it from running?

i have been using no av on my main machine for a long time. in the rare cases i was doing RE or sketchy execution, vm or dedicated offline old machine

Re: MS Windows Defender and DeCSS

#58

Earlier quoted context omitted.

Deleting both the exe and the source code makes a false positive seem rather unlikely to me.

The source code in question appears to have been obfuscated (possibly just for brevity). I'd guess the Defender signature in question was written around the packer/obfuscator.

Wanna bet the signature is the hex key?

Re: MS Windows Defender and DeCSS

#59

Earlier quoted context omitted.

I don't believe they use regular expressions.

Why not? I.e. is that from experience on working on anti malware remediation systems?

What would it match against? ASCII strings? Add a whitelisted string and make your malware pass.

The heuristics are much more complex than that, cf. spamassassin rules.

Re: MS Windows Defender and DeCSS

#60
post #16

Earlier quoted context omitted.

In addition, Windows also quarantines and deletes innocuous Windows activation crack tools that contain no malware whatsoever, but can be used to activate Windows independently of Microsoft. It's really amazing the attitude Microsoft takes regarding hardware that isn't theirs, including the nonconsensual forced autoupdate.

I was under the impression that with Windows 10 we shifted to the product being the users data. The customers are now advertisers.

From what I’ve understood, that is a correct impression.
Post reply on HN