Live data from Hacker News

Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

forbes.com

1–10 of 40 posts

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#3
post #2

We've been trying to fight a security auditor requirement to put antivirus on all of our amazon amis (including linux). It's insane that anyone thinks that improves security.

From experience many so called 'security auditor's tend not to have a clue what they're talking about technically, and operate from a playbook. They do however speak the the same language as management. Buzzword bingo, spreading FUD, selling snake oil.

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#4
The main disadvantage security companies have is the difficulty to integrate with the core operating system. This makes it easy to third parties (e.g. malware) to use the same software for malicious applications. They based their security products in a lot of system internals tricks to make them work (e.g. API hooking, reverse engineering, drivers). Microsoft has a clear advantage in this market because they can modify the OS "a piacere".

Disclosure: I provide this kind of solutions to Trend Micro, Symantec, and many other security vendors.

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#7
post #5

OT: Anyone able to copy and paste the content of the article? All I get when I go to Forbes these days is the quote screen and nothing ever loads.

If you don’t rely on a screenreader, here’s a screenshot: http://i.imgur.com/yfWL6XT.png

Otherwise nissehulth posted this useful link: http://archive.is/KsAxC

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#8
post #2

We've been trying to fight a security auditor requirement to put antivirus on all of our amazon amis (including linux). It's insane that anyone thinks that improves security.

Use their same language back at them and talk about your "compensating controls". That's auditor lingo for I know A is the standard control but by doing B and/or C instead I have adequately addressed the risk.

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#9
post #2

We've been trying to fight a security auditor requirement to put antivirus on all of our amazon amis (including linux). It's insane that anyone thinks that improves security.

Is that a requirement your security auditor has, or are vendors demanding this in vendor-specific security reviews? And is this for e.g. network segmentation in PCI, or more routine assessments?

Depending on what you mean, perhaps you want to get in touch if you'd like better technical due diligence :)

Re: Hackers Tear Apart Trend Micro, Find 200 Vulnerabilities In 6 Months

#10
post #9
post #2

We've been trying to fight a security auditor requirement to put antivirus on all of our amazon amis (including linux). It's insane that anyone thinks that improves security.

Is that a requirement your security auditor has, or are vendors demanding this in vendor-specific security reviews? And is this for e.g. network segmentation in PCI, or more routine assessments? Depending on what you mean, perhaps you want to get in touch if you'd like better technical due diligence :)

I have filled out a few applications for tech e&o and cyber liability insurance over the past week and they all had a question about antivirus on the servers, workstations, and phones. I answered truthfully (no) and wonder if that is going to hurt me.
Post reply on HN