Live data from Hacker News

Avoid Non-Microsoft Antivirus Software

robert.ocallahan.org

11–20 of 388 posts

Re: Avoid Non-Microsoft Antivirus Software

#11
post #4

> At best, there is negligible evidence that major non-MS AV products give a net improvement in security. I apologize for present anecdote when data is needed but I manage a Windows network with 100+ users and on a daily basis, Kaspersky catches 5-10 emails from Outlook that have nasty attachments. It prevents my users from opening these innocuous looking but nasty Invoice-Jan-2017.docx files. Without a good AV there…

> Invoice-Jan-2017.docx uh, docx files can hack my PC now?

Is this a bug of MS Word or docx format really has ability to become a virus?

Re: Avoid Non-Microsoft Antivirus Software

#12
post #4

> At best, there is negligible evidence that major non-MS AV products give a net improvement in security. I apologize for present anecdote when data is needed but I manage a Windows network with 100+ users and on a daily basis, Kaspersky catches 5-10 emails from Outlook that have nasty attachments. It prevents my users from opening these innocuous looking but nasty Invoice-Jan-2017.docx files. Without a good AV there…

Do you scan on the endpoints or centralized on the mail server?

Re: Avoid Non-Microsoft Antivirus Software

#13
It's irresponsible to make such a broad claim and back it up with really vague anecdotal evidence. Yes, there are a lot of lousy AV products that are at best a break-even for security, but there are some that don't suck and generally you have to pay for them - what a strange concept.

I'm not going to advocate for any particular vendor as I used to work for an AV company (and currently use a product from a competitor). But I can attest that I've used products that have caught threats that Windows Defender didn't, and many products also include a much more robust and configurable firewall.

It's annoying when someone else's lousy code breaks your own code. This happens to the sites I administer frequently, where we will randomly get blacklisted by some no-name AV product's web security feature. I understand the frustration when you have no control over this. But to conclude that all AV software is bad does not follow from the evidence given.

Re: Avoid Non-Microsoft Antivirus Software

#14
post #7

This is my advice to everyone I know that gets a new Windows PC. Windows 10's built-in protection is more than adequate, and catches the majority of bad software - anything more is unnecessary, and many of the AV vendors are predatory.

Which AV vendors are predatory? (Though Kaspersky makes me nervous).

What do you think about ESET?

Re: Avoid Non-Microsoft Antivirus Software

#15
post #9

Granny won't believe me :( she feels safer because of some popup that tells her she's safe.

This is the most authentic argument I have read so far on this subject. People do not care about vendors. People care about how they feel. For everything else going beyond the "You are safe!" popup (try to explain "DLL injection?" to your Granny! Okay, "blocking updates" she might understand) a user needs a far deeper understanding of what goes on under the hood of the OS, or practically any software based on said OS. "Uninstall AV software" does not make people feel safer, now that the narrative of "AV is making the Internet safer" is practically standard.

Re: Avoid Non-Microsoft Antivirus Software

#17
Most people forget the malware on hacked website. Browsers won't give you a warning. (OK. Chrome will show you a RED screen but not for all) They need not hack into your system. But they collected your login info, credit card. I even want to install one on my MacOS.

MS AV still too slow at the moment. In Windows 10, you could turn on Defender to run both AV at the same time.

Re: Avoid Non-Microsoft Antivirus Software

#19
What's more, as third party antivirus software becomes increasingly irrelevant, many of these companies resort to harmful and even actively malicious tactics to stay in business. On the more benign end, you see an increase in 'safe web browsing' and such tools that parse javascript while browsing and somehow attempt to make it.. safer, I guess. My main experience with these things is when they randomly decide to block bits of code on our sites, breaking functionality for no discernible purpose.

Far worse are the lengths that a company like AVG will go to to get and keep their software installed on your computer. Their browser toolbars essentially take all the dirty tricks they've apparently learned dealing with malware to.. build a piece of malware. Honestly whether it's active malice, incompetence, or lack of motivation I don't know, but I do know I've spent hours trying to extract their stuff from people's browsers. (I should say here that I fully expect someone reading this has managed to uninstall an AVG toolbar with no issues. They have multiple different auxiliary tools to their antivirus, and I'm not sure specifically which one(s) caused me trouble personally. It's also likely that they're only a _real_ pain in certain circumstances. But regardless, if you google something like 'how uninstall avg' or 'avg malware' I'm sure you'll find many more examples.)

Re: Avoid Non-Microsoft Antivirus Software

#20
post #4

> At best, there is negligible evidence that major non-MS AV products give a net improvement in security. I apologize for present anecdote when data is needed but I manage a Windows network with 100+ users and on a daily basis, Kaspersky catches 5-10 emails from Outlook that have nasty attachments. It prevents my users from opening these innocuous looking but nasty Invoice-Jan-2017.docx files. Without a good AV there…

> Invoice-Jan-2017.docx uh, docx files can hack my PC now? Is this a bug of MS Word or docx format really has ability to become a virus?

It is a feature [0]. Microsoft office products allow for "macros" which are Visual Basic code embedded within a document or a worksheet that can be used by developers to add extra functionalities to their MS files (e.g. validate all data in a work sheet after a user clicks a specific button in the worksheet).

Just like any programming language, it could be used maliciously, and there is no easy way to distinguish which macro-enabled file is safe and which isn't (without going through the code yourself prior to enabling the functionality)

[0] https://support.office.com/en-us/article/Enable-or-disable-m...

Post reply on HN