Live data from Hacker News

McAfee quarantines svchost.exe on millions of WinXP machines worldwide

andreyf.tumblr.com

91–100 of 113 posts

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#91
post #90

Earlier quoted context omitted.

That's like saying that having sex without a condom is safe as long as you have certain 'usage patterns'. Chances are you have contracted something, but just don't know about it. The OS X and linux boxes are pretty safe, but if you use your windows machines online you're bound to have been bitten by drive by malware at least once. Unless those machines have never been used to surf the web. Even very reputable sites h…

That's like saying that having sex without a condom is safe as long as you have certain 'usage patterns'. Erm. Sex with one partner who is not promiscuous and doesn't have a disease is pretty safe without a condom. That's a usage pattern, right?

[deleted]

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#93

Earlier quoted context omitted.

> McAfee has just demonstrated a computer autoimmune disease. My goodness, what a fascinating idea. (And a search suggests the you are the first person in all of history to think of that.) When will the biological parallels end? Will we someday get viral transmission of OS code snippets from one machine to another, leading to improved OSs? The mind boggles ....

Sounds reasonable. Maybe a virus will carry a usable Windows API into *nix so windows viruses can do something? I know this wouldn't work at first glance, but there's probably something along those lines....

People tried running windows viruses under wine, but the success rate was not that great.

(I can't copy and paste URL on thic stupid cell phone, so ask google for "virus wine linux" for the details.)

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#94
Some virus guy wrote about the problem of the economic model of major antivirus vendors. Corporate profit interest go against making a decent long lasting antivirus and instead benefit from incremental constant updates. That's why they mostly avoid behavioral analysis and localhost security checks. Instead they just use brute force pattern matching and constant updates.

A subscription model is detrimental to users' security. But try to explain that to your PHB who reads websites and magazines making money on advertisements from the industry.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#95

Earlier quoted context omitted.

Finance professionals most probably have no idea how important specific [fill-in-the-blank] news Yes, they do. There are lots of hedge funds that do nothing but analyze news feeds and trade on them all day long.

...unless their computers are down. :) Seriously though, although there are plenty of algorithms that crawl news all day and trade accordingly, I still think there is money to be made by watching the news with a financial eye. After reading Google's "A New Approach to China" post (which I saw on HN minutes after it was posted), I specifically remember thinking it would be a good time to go long BIDU. And of course, k…

By definition itself, you can't predict black swan. As they say, day trading is not about making successful moves. It is about making successful moves even when you account for commissions. Reasons everyone is not doing automated trading is because commissions eat up any profit that you can expect to make.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#96

Why does AV software not have a secure checksum-based whitelist? It is not as if Microsoft keeps the important system files secret.

A guess: presumably whatever checksum they invent will have a severe risk that hackers will reverse engineer it and then devote their vast botnets to manufacturing virii that give the same checksum thus handing them even more control.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#97
post #40

Crazy to think about the consequences of a mistake like this. This was sent by a friend to an email list I'm on: "Well, consider this community hospital fubared. IT dudes running around pulling out their hair. If it wasn't affecting patient care it would be a humorous scene-but I can't check xray's, or labs or anything. Took out a horrendously bloody gallbladder this morning, and I can't tell (labwise) if she's still…

Wow. Kinda makes me wonder if we should be using general-purpose computers for so many things. The anti-virus is kind of a major single point of failure for machines that need to do just a few specific things.

reminds me of this funny XKCD http://xkcd.com/463/

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#98
post #87
post #56

Earlier quoted context omitted.

Speaking as someone who knows something about these things, it is clear that you are not as informed as you are making yourself out to be. There are two reasons why I say that. (1) Your knowledge of the AV industry is outdated. McAfee has actually been trending upwards in recent years. (2) A 97% detection rate is obviously bullshit. If any product achieved a detection rate anywhere close to that number, the false pos…

If I'm reading this report right there are several that hit 97% with low false positives. http://www.av-comparatives.org/images/stories/test/ondret/av... The methodology is linked in the document. I mean, it's certainly at least less of a conjecture than your "he doesn't know anything because these things are obviously BS" argument.

I'm familiar with the report. Programs that were detected as false positives include:

* the task manager

* Quicken

* ATI Drivers

* the GIMP

* other antivirus programs (including products from Kaspery, ESET, Avast, and Trend Micro)

* VLC

* Cygwin

* Acrobat reader

* text editors (including Notepad2 and Notepad++)

* TrueCrypt

AV run in the real world on these settings would be disastrous.

Issues with the samples used by AV Comparatives:

* The malware sample size is only around 1 million.

* The sample size of clean programs is far too small.

* The malware samples used aren't public. We don't even know if the malware used by AV Comparatives are found in the wild anymore.

More generally, evaluations like those done by AV Comparatives and similar organizations are misleading. What actually matters is the vulnerability window. This window is generally a week or two and occurs after a piece of malware is released into the wild. It is the amount of time it takes AV vendors to get a signature distributed. Most damage is done during the vulnerability window, during which infected machines will have their AV disabled by the virus. The fact that your AV can detect viruses released years ago actually doesn't have any bearing on your security; it's a meaningless evaluation of the product.

You have to ask yourself, why don't AV vendors report numbers like the percentages found in AV Comparatives? They don't because they know it's bogus. Sure, most AV vendors will list AV Comparatives and others as an "award" or a "certification", but they'll never list the actual number. I think that should tell you something. In the real world no one is experiencing detection rates like those in the report. If they were, you can be sure the numbers would be part of an AV marketing campaign.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#99
post #56

Earlier quoted context omitted.

Speaking as someone who knows something about these things, it is clear that you are not as informed as you are making yourself out to be. There are two reasons why I say that. (1) Your knowledge of the AV industry is outdated. McAfee has actually been trending upwards in recent years. (2) A 97% detection rate is obviously bullshit. If any product achieved a detection rate anywhere close to that number, the false pos…

Not that I'm all that interested in getting into a pissing contest with Some Guy From The Internet, but: 1. I've been doing virus and malware cleanups for people since -- well, since 1995 or so, at least. 2. I've recently begun presenting seminars on basics for novice computer users. 3. I was among the first to clean up the rather nasty kbiwkm rootkit a while back. One of my clients was infected with it before there…

First, congratulations on your success with your business. 300% growth over multiple years is very impressive. Second, I didn't mean to be negative or snarky (I can be abrasive sometimes, so sorry about that). It's just that no one experiences detection rates that high in the real world. If AV actually worked that well, it would be incredible. I'd be the first person to publicize it.

In regards to AV Comparatives, I responded to why their tests aren't relevant in in the real world here: http://news.ycombinator.com/item?id=1284321. The bottom line is that detection rates as high as 97% are generally regarded by industry experts as inflated (John Viega says in one of his books that some people estimate actual detection rates to be around 30%). AV companies themselves would never use that number as a part of their marketing campaigns. You'll note that on the product pages of the AV products tested, the numbers aren't listed. If a 99.6% detection rate was actually. valid, don't you think it would be displayed in large and bold letters on the product page?

I'm not saying people shouldn't run AV, but we need to be honest about the actual capabilities of these products. Even if actual detection is only 30%, 30% is better than 0%.

Re: McAfee quarantines svchost.exe on millions of WinXP machines worldwide

#100
post #90

Earlier quoted context omitted.

That's like saying that having sex without a condom is safe as long as you have certain 'usage patterns'. Chances are you have contracted something, but just don't know about it. The OS X and linux boxes are pretty safe, but if you use your windows machines online you're bound to have been bitten by drive by malware at least once. Unless those machines have never been used to surf the web. Even very reputable sites h…

That's like saying that having sex without a condom is safe as long as you have certain 'usage patterns'. Erm. Sex with one partner who is not promiscuous and doesn't have a disease is pretty safe without a condom. That's a usage pattern, right?

That's your usage pattern, but it does not say anything about that partner, so it may be less safe than it appears.
Post reply on HN