Live data from Hacker News

Kaspersky in the Middle – what could possibly go wrong?

palant.de

41–45 of 45 posts

Re: Kaspersky in the Middle – what could possibly go wrong?

#41
post #17

Earlier quoted context omitted.

Windows Defender is on every machine, so what would be the point of writing a virus that is detected by it? The same for Kaspersky. These programs are easy to test against and well-known. They are designed to work against old viruses that have already been detected and analyzed. It's better to use lesser known antivirus products with good heuristic detection. I will not mention names but there are a number of product…

They will not only detect existing viruses. AV software has used heuristics to detect viruses for decades, and more recently ML is being used. Microsoft has really been investing in Defender and Defender ATP recently and there have been several Twitter and blog posts about the successes their ML approach is yielding, including for new viruses.

Very interesting. I am guessing there is a common set of access / instruction patterns (N number of virus samples) that they build models from?

Re: Kaspersky in the Middle – what could possibly go wrong?

#42
post #7

Earlier quoted context omitted.

Also, Microsoft has an incentive to eliminate viruses and malware completely - to make their OS safer. Third party AV companies rely on continuing threats to stay in business. I'm not saying AV companies hold back or help malware out, I'm saying Microsoft has good reason to throw huge resources at the problem as a whole.

...and to build on your comment: Incentive to not slow down the performance of the OS while protecting it.

Windows Defender is the worst-performing antivirus on the market so that logic flies out the window.

Re: Kaspersky in the Middle – what could possibly go wrong?

#43
post #42

Earlier quoted context omitted.

...and to build on your comment: Incentive to not slow down the performance of the OS while protecting it.

Windows Defender is the worst-performing antivirus on the market so that logic flies out the window.

Can you undergird this claim? (serious question, no flaming)

Re: Kaspersky in the Middle – what could possibly go wrong?

#44
post #37
post #5

Earlier quoted context omitted.

If you use Windows, use Windows Defender. It doesn't MitM your connections and has a comparable detection rates for 0days and common malware to all other modern AVs. Microsoft has put a lot of work into making Defender as secure as possible (you can even run it inside a VM so any exploit of defender is just trapped inside a HyperV VM instead of your system). There is no point in installing any other AV vendor; they a…

What would you suggest for Mac and Linux? I lot of enterprise contracts and security certifications require "anti-virus installed and up-to-date". What's the best way of meeting that checkbox for Mac and Linux laptops?

Install ClamAV but don't run the daemon?

Re: Kaspersky in the Middle – what could possibly go wrong?

#45
post #20

Earlier quoted context omitted.

Windows Defender is on every machine, so what would be the point of writing a virus that is detected by it? The same for Kaspersky. These programs are easy to test against and well-known. They are designed to work against old viruses that have already been detected and analyzed. It's better to use lesser known antivirus products with good heuristic detection. I will not mention names but there are a number of product…

You can't just wave your hand and say that some lesser known "no names mentioned" product is better than Defender because you want it to be. If you have evidence that some AV product is out-performing Defender, it's extremely selfish and negligent to keep that information to yourself. I'd much rather trust MS with Defender over some lesser known AV product which likely doesn't have billions of dollars, unfathomably l…

Fair enough, but I did give a concrete reason why I believe some "no name mentioned" products may be better than Defender and other common antivirus products.
Post reply on HN