Live data from Hacker News

Why Developers Hate Antiviruses

blog.jitbit.com

21–30 of 87 posts

Re: Why Developers Hate Antiviruses

#21
post #7
post #6

The business of antivirus, especially, has a huge incentive to shove it IN YOUR FACE that the software is detecting things whether they're false positives or not. This scares people into re-upping their subscription. Most computer users don't understand there can even be such a thing as false positive. For all those support calls you get, there are probably 10x that number that simply take the security software on it…

It's flat out wrong of you to say that antivirus companies don't care about FP's. There are over 25k new malware samples coming out daily, and everybody is just trying to cut through them as fast and efficiently as possible. Yes there are innocent casualties of this -- False positives -- but these are sincere mistakes . False positives are very embarrassing for the security company. It is something that can even caus…

I'll respond with a variation of what naner describes ( http://news.ycombinator.com/item?id=3511551 ).

Specifically with Norton, I've received warnings/quarantines where it's rather non-obvious and difficult to learn what the actual problem is. The program's interface allows one to click and drill down one or two levels, but the descriptions are often more non-descriptive than descriptive. And then one faces a link (which is, by the way, not tooltipped or otherwise designated as a link) that fires up your browser and takes you to a web page on the security software vendor's (in this case, Norton) web site.

Well, that's f-ing annoying. And then, to boot, often the page that is navigated to contains content that is little or no more helpful in telling you what specifically they detected or why specifically the warning/action triggered.

I recall one case in particular, where going through all this and reading between the lines, it appeared that the quarantine was the result of a "reputation" trigger. Norton wasn't familiar with the executable and it didn't have much or any presence in their reputation system, so the default action was to flag it a "high security" risk and to "quarantine" it.

I understand there is a balancing act. If you don't keep it simple and use strong enough language, Joe Blow user may start to disregard the warnings, until soon enough s/he has a real problem.

But as a more advanced user, this is completely frustrating. I want to know what the problem is, so that I can make an informed decision with regard to the "security event".

(And yes, on the Windows machine, I do run Norton. Comes with my only Internet connectivity option, anyway, and it makes an acceptable, and useful, component of a layered defense.)

Re: Why Developers Hate Antiviruses

#22
post #7

Earlier quoted context omitted.

It's flat out wrong of you to say that antivirus companies don't care about FP's. There are over 25k new malware samples coming out daily, and everybody is just trying to cut through them as fast and efficiently as possible. Yes there are innocent casualties of this -- False positives -- but these are sincere mistakes . False positives are very embarrassing for the security company. It is something that can even caus…

I'll respond with a variation of what naner describes ( http://news.ycombinator.com/item?id=3511551 ). Specifically with Norton, I've received warnings/quarantines where it's rather non-obvious and difficult to learn what the actual problem is. The program's interface allows one to click and drill down one or two levels, but the descriptions are often more non-descriptive than descriptive. And then one faces a link (…

I got bit by this reputation thing just this morning. I'd sent out a link to a .exe for a dead simple app (open serial port, tx commands, rx replies, output to screen) and sure enough, someone tried to download it and got blocked by Norton. I sent it in as a FP, not in the hopes they'll do anything about my little .exe, but just to make more work for them.

Re: Why Developers Hate Antiviruses

#23
post #20

I've come to the conclusion that AV software gets more attrocious the more you pay for it or the more it requires advertising every 5 minutes on television. They push it on you via scaremongering every day at least once. HOWEVER, I've been using Microsoft's free security essentials package for Windows 7 for about 2 years. It never pokes you in the eye, never lets a single thing through and doesn't screw your system r…

[deleted]

Re: Why Developers Hate Antiviruses

#24
post #20

I've come to the conclusion that AV software gets more attrocious the more you pay for it or the more it requires advertising every 5 minutes on television. They push it on you via scaremongering every day at least once. HOWEVER, I've been using Microsoft's free security essentials package for Windows 7 for about 2 years. It never pokes you in the eye, never lets a single thing through and doesn't screw your system r…

I'll look into that for the Win7 partition on my old laptop, thanks.

I do run ClamAV on my linux big box, just in case I'm passing on any Windows virii, this might be voodoo

Re: Why Developers Hate Antiviruses

#25
I was trying to install netcat on a work windows box to transfer some files (long story). Every attempt at copying the executable out of the zip file would throw up an error about the file not existing, no explanation as to why or who was causing the error. After an hour I removed the antivirus. File copied just fine after that. I guess netcat is a 'hacker tool' and not allowed on protected windows system; too bad I had work to do.

Re: Why Developers Hate Antiviruses

#26
post #6

The business of antivirus, especially, has a huge incentive to shove it IN YOUR FACE that the software is detecting things whether they're false positives or not. This scares people into re-upping their subscription. Most computer users don't understand there can even be such a thing as false positive. For all those support calls you get, there are probably 10x that number that simply take the security software on it…

Which is why MS Security Essentials really is a fresh breath of air compared to everything else (that I've tried).

Re: Why Developers Hate Antiviruses

#27

Excellent timing. I just alt+tabbed away from writing an email to McAfee because one of my users sent me a screenshot of s3stat.com with a bright red "Dangerous Site Warning" from McAfee's SiteAdvisor. Evidently, "We tested this site and found it very risky". Even though it's the public site for a 5-year-established (and popular) SaaS product. Even though it has no downloadable executables of any description. Even th…

Holy shit! Seeing your comment, I checked out two of my own sites. One hosts software that I no longer sell (www.egorg.com), and it checked out ok. Interestingly, Yahoo (my host-- hey, it was my first! And paypal integrated easily! Besides, pg built the tech so...) flagged it last week during one of their auto-scans. They couldn't explain why- they just flagged it.

But here is something that is peculiar: my main company site. When I went to vlesolutions.com (ie, http://www.siteadvisor.com/sites/www.vlesolutions.com) I saw this message:

  We've tested millions of websites, but we haven't tested this one yet. Be the first one to submit feedback on it!
  
  
Maybe it is possible to wreck someone's reputation by submitting bogus feedback to a site they haven't scanned yet. I would be curious how they answer you, because I see nothing that would cause a red flag in their "tests" for your site.

Re: Why Developers Hate Antiviruses

#28
The bigger issue here is that people think there is a "perfect" world out there, that someone is obviously preventing you from reaching...

There isn't.

It's all about either keeping some type of a balance going or shoveling enough shit as to not get buried in it.

Post reply on HN