The diagram doesn't show a data link from the AV software to the AV vendor headquarters. Is that correct?
Kaspersky in the Middle – what could possibly go wrong?
11–20 of 45 posts
Re: Kaspersky in the Middle – what could possibly go wrong?
#12https://www.reddit.com/r/programming/comments/cs2x8x/kaspers...
Re: Kaspersky in the Middle – what could possibly go wrong?
#13Which other AntiVirus vendors do this? How can you opt-out and is there a point to installing anti-virus software to begin with?
If you use Windows, use Windows Defender. It doesn't MitM your connections and has a comparable detection rates for 0days and common malware to all other modern AVs. Microsoft has put a lot of work into making Defender as secure as possible (you can even run it inside a VM so any exploit of defender is just trapped inside a HyperV VM instead of your system). There is no point in installing any other AV vendor; they a…
It's better to use lesser known antivirus products with good heuristic detection. I will not mention names but there are a number of products out there, including ones that block every executable not on a whitelist.
Re: Kaspersky in the Middle – what could possibly go wrong?
#14Earlier quoted context omitted.
If you use Windows, use Windows Defender. It doesn't MitM your connections and has a comparable detection rates for 0days and common malware to all other modern AVs. Microsoft has put a lot of work into making Defender as secure as possible (you can even run it inside a VM so any exploit of defender is just trapped inside a HyperV VM instead of your system). There is no point in installing any other AV vendor; they a…
Windows Defender is on every machine, so what would be the point of writing a virus that is detected by it? The same for Kaspersky. These programs are easy to test against and well-known. They are designed to work against old viruses that have already been detected and analyzed. It's better to use lesser known antivirus products with good heuristic detection. I will not mention names but there are a number of product…
Re: Kaspersky in the Middle – what could possibly go wrong?
#15Which other AntiVirus vendors do this? How can you opt-out and is there a point to installing anti-virus software to begin with?
Re: Kaspersky in the Middle – what could possibly go wrong?
#16Earlier quoted context omitted.
Also, Microsoft has an incentive to eliminate viruses and malware completely - to make their OS safer. Third party AV companies rely on continuing threats to stay in business. I'm not saying AV companies hold back or help malware out, I'm saying Microsoft has good reason to throw huge resources at the problem as a whole.
...and to build on your comment: Incentive to not slow down the performance of the OS while protecting it.
I got a new laptop from work recently and I didn't spend a great deal of time looking it over as i was busy and ... of course I hit some random performance problems as McAfee was abusing my machine while I was trying to work. Endlessly installing antivirus programs is getting pretty old.
Re: Kaspersky in the Middle – what could possibly go wrong?
#17Earlier quoted context omitted.
If you use Windows, use Windows Defender. It doesn't MitM your connections and has a comparable detection rates for 0days and common malware to all other modern AVs. Microsoft has put a lot of work into making Defender as secure as possible (you can even run it inside a VM so any exploit of defender is just trapped inside a HyperV VM instead of your system). There is no point in installing any other AV vendor; they a…
Windows Defender is on every machine, so what would be the point of writing a virus that is detected by it? The same for Kaspersky. These programs are easy to test against and well-known. They are designed to work against old viruses that have already been detected and analyzed. It's better to use lesser known antivirus products with good heuristic detection. I will not mention names but there are a number of product…
Re: Kaspersky in the Middle – what could possibly go wrong?
#18Earlier quoted context omitted.
To answer the last, at this point, you install (or have preinstalled) AV to comply with enterprise IT policies.
Or be protected from bank fraud. Not that the AV will stop it, but having no AV gives the banks a reason to reject the claim. At least with DB in Germany. But they accept Windows Defender!
Germany, the country of data protection, and yet their banks force you to use Google/Apple.
Oh sure, I can use terminals or pay money for a hardware device whose manufacturer has an exclusive contract with the bank, but this is absurd considering all they'd have to do is provide a channel for getting the APK straight from their own servers instead of through Google.
...or at least give me an SHA256 of the APK, so I can really be sure that when I use a 3rd party app to download it, I'm not getting a Trojan or something.
Re: Kaspersky in the Middle – what could possibly go wrong?
#19Which other AntiVirus vendors do this? How can you opt-out and is there a point to installing anti-virus software to begin with?
If you use Windows, use Windows Defender. It doesn't MitM your connections and has a comparable detection rates for 0days and common malware to all other modern AVs. Microsoft has put a lot of work into making Defender as secure as possible (you can even run it inside a VM so any exploit of defender is just trapped inside a HyperV VM instead of your system). There is no point in installing any other AV vendor; they a…
While I understand that data from well known tests may support your point, as an employee for 2+ years at a security vendor I can say with certainty that defender falls way behind when it comes to fast generic detections and response time. I quite frequently find myself copying maliciois files to my work laptop with defender activated and the detection rate is pretty poor as shown by the actual number of files that got copied. Not even mentioning how it quietly scans my files and activates itself even though I singlehandedly shut it down a minute ago
Re: Kaspersky in the Middle – what could possibly go wrong?
#20Earlier quoted context omitted.
If you use Windows, use Windows Defender. It doesn't MitM your connections and has a comparable detection rates for 0days and common malware to all other modern AVs. Microsoft has put a lot of work into making Defender as secure as possible (you can even run it inside a VM so any exploit of defender is just trapped inside a HyperV VM instead of your system). There is no point in installing any other AV vendor; they a…
Windows Defender is on every machine, so what would be the point of writing a virus that is detected by it? The same for Kaspersky. These programs are easy to test against and well-known. They are designed to work against old viruses that have already been detected and analyzed. It's better to use lesser known antivirus products with good heuristic detection. I will not mention names but there are a number of product…
I'd much rather trust MS with Defender over some lesser known AV product which likely doesn't have billions of dollars, unfathomably large samples/datasets, and extensive experience with APT's.
As pointed out, no one really has a better incentive to detect and eliminate virus's than MS does in an effort to make their OS virus free.