Live data from Hacker News

Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

forbes.com

11–20 of 40 posts

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#13
post #10
post #9

Earlier quoted context omitted.

Is that a requirement your security auditor has, or are vendors demanding this in vendor-specific security reviews? And is this for e.g. network segmentation in PCI, or more routine assessments? Depending on what you mean, perhaps you want to get in touch if you'd like better technical due diligence :)

I have filled out a few applications for tech e&o and cyber liability insurance over the past week and they all had a question about antivirus on the servers, workstations, and phones. I answered truthfully (no) and wonder if that is going to hurt me.

It will be interesting what an insurance company thinks is needed.

If having an antivirus can create possibly more security holes than it closes - then from an insurance perspective they would not want you to have it.

i.e. if they have to pay based upon an attack - they want to ensure the lowest risk.

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#14
post #4

The main disadvantage security companies have is the difficulty to integrate with the core operating system. This makes it easy to third parties (e.g. malware) to use the same software for malicious applications. They based their security products in a lot of system internals tricks to make them work (e.g. API hooking, reverse engineering, drivers). Microsoft has a clear advantage in this market because they can modi…

From your HN user profile, "At Nektra we are providing solutions that require Windows system internals and reverse engineering skills."

http://www.nektra.com

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#15
post #8
post #2

We've been trying to fight a security auditor requirement to put antivirus on all of our amazon amis (including linux). It's insane that anyone thinks that improves security.

Use their same language back at them and talk about your "compensating controls". That's auditor lingo for I know A is the standard control but by doing B and/or C instead I have adequately addressed the risk.

So, what would be the compensating control for infecting yourself with malware?

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#16
post #4

The main disadvantage security companies have is the difficulty to integrate with the core operating system. This makes it easy to third parties (e.g. malware) to use the same software for malicious applications. They based their security products in a lot of system internals tricks to make them work (e.g. API hooking, reverse engineering, drivers). Microsoft has a clear advantage in this market because they can modi…

From your HN user profile, "At Nektra we are providing solutions that require Windows system internals and reverse engineering skills." http://www.nektra.com

Yes, that is the reason I made the disclosure. Almost all of our work involves intercepting, modifying, and integrating third party applications with Windows when Windows doesn't provide APIs to do this.

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#17
post #2

We've been trying to fight a security auditor requirement to put antivirus on all of our amazon amis (including linux). It's insane that anyone thinks that improves security.

From experience many so called 'security auditor's tend not to have a clue what they're talking about technically, and operate from a playbook. They do however speak the the same language as management. Buzzword bingo, spreading FUD, selling snake oil.

This is so true. I worked for a small-time compliance software vendor where the domain expert was an incoherent mess (with all the buzzwords thrown in), the CEO couldn't discuss the software intelligibly, and the VP Engineering presented a demo video loop at a trade show booth showing theirself entering the company AWS credentials in clearly legible form.

The place had so many dysfunctions I'd not know how to start. I work for a much more professional outfit now with true appreciation for security and competence.

edit: there's a real gap in this non-glamorous compliance domain. if you address it and need to execute SCAP (OVAL, XCCDF) content, look to a very competent scanner vendor, jOVAL. The real challenges are in organizing and presenting consistent info across many compliance standards, OSs, cloud vendors, etc. ... and to scan entities that aren't OSs per se, and to analyze cross-domain conditions.

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#18
post #10

Earlier quoted context omitted.

I have filled out a few applications for tech e&o and cyber liability insurance over the past week and they all had a question about antivirus on the servers, workstations, and phones. I answered truthfully (no) and wonder if that is going to hurt me.

It will be interesting what an insurance company thinks is needed. If having an antivirus can create possibly more security holes than it closes - then from an insurance perspective they would not want you to have it. i.e. if they have to pay based upon an attack - they want to ensure the lowest risk.

The thing is that in most companies you're far more likely to fall victim to a simple and random malware emailed or ran by your employees, than you are to be carefully targeted by a worm based on AV vulnerabilities.

With that said I prefer to view security as, "You likely will be the victim of a planned attack, so plan from there", but still. Odds are not favourable.

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#19
post #2

We've been trying to fight a security auditor requirement to put antivirus on all of our amazon amis (including linux). It's insane that anyone thinks that improves security.

Agreed in a lot of cases. However there can be times (e.g. email attachments, file uploads) where it's a rather useful defense layer.

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#20
post #12
post #2

We've been trying to fight a security auditor requirement to put antivirus on all of our amazon amis (including linux). It's insane that anyone thinks that improves security.

Which auditor, and for what regulation?

Most certifications, and in particular, ISO 27001 asks if you have anti-malware running. Now, the thing about ISO and many of the other certifications, if you can demonstrate some mitigating control, say aggressive network monitoring, or pre-scanning files before they get loaded onto your target system, then you can pass. For example, http://www.iso27001security.com/html/27002.html on 12.2 mentions this, along with a vaguely-stated user awareness.

All auditors looking at you for this certification will ask this question.

Post reply on HN