The business of antivirus, especially, has a huge incentive to shove it IN YOUR FACE that the software is detecting things whether they're false positives or not. This scares people into re-upping their subscription. Most computer users don't understand there can even be such a thing as false positive. For all those support calls you get, there are probably 10x that number that simply take the security software on it…
It's flat out wrong of you to say that antivirus companies don't care about FP's. There are over 25k new malware samples coming out daily, and everybody is just trying to cut through them as fast and efficiently as possible. Yes there are innocent casualties of this -- False positives -- but these are sincere mistakes . False positives are very embarrassing for the security company. It is something that can even caus…
Specifically with Norton, I've received warnings/quarantines where it's rather non-obvious and difficult to learn what the actual problem is. The program's interface allows one to click and drill down one or two levels, but the descriptions are often more non-descriptive than descriptive. And then one faces a link (which is, by the way, not tooltipped or otherwise designated as a link) that fires up your browser and takes you to a web page on the security software vendor's (in this case, Norton) web site.
Well, that's f-ing annoying. And then, to boot, often the page that is navigated to contains content that is little or no more helpful in telling you what specifically they detected or why specifically the warning/action triggered.
I recall one case in particular, where going through all this and reading between the lines, it appeared that the quarantine was the result of a "reputation" trigger. Norton wasn't familiar with the executable and it didn't have much or any presence in their reputation system, so the default action was to flag it a "high security" risk and to "quarantine" it.
I understand there is a balancing act. If you don't keep it simple and use strong enough language, Joe Blow user may start to disregard the warnings, until soon enough s/he has a real problem.
But as a more advanced user, this is completely frustrating. I want to know what the problem is, so that I can make an informed decision with regard to the "security event".
(And yes, on the Windows machine, I do run Norton. Comes with my only Internet connectivity option, anyway, and it makes an acceptable, and useful, component of a layered defense.)