Jump to content

It might be time to stop using antivirus


Jamesinlos

Recommended Posts

 

           Update your software and OS regularly instead, practice skeptical computing.

 

      Former Firefox developer Robert O'Callahan, now a free agent and safe from the PR tentacles of his corporate overlord, says that antivirus software is terrible, AV vendors are terrible, and that you should uninstall your antivirus software immediately—unless you use Microsoft's Windows Defender, which is apparently okay.

 

 A couple of months back, Justin Schuh, Google Chrome's security chief, and indeed one of the world's top infosec bods, said that antivirus software is "my single biggest impediment to shipping a secure browser." Further down the thread he explains that meddling AV software delayed Win32 Flash sandboxing "for over a year" and that further sandboxing efforts are still on hold due to AV. The man-in-the-middle nature of antivirus also causes a stream of TLS (transport layer security) errors, says Schuh, which in turn breaks some elements of HTTPS/HSTS.

 

  These are just two recent instances of browser makers being increasingly upset with antivirus software. Back in 2012, Nicholas Nethercote, another Mozillian working on Firefox's MemShrink project said that "McAfee is killing us." In that case, Nethercote was trying to reduce the memory footprint of Firefox, and found that gnarly browser add-ons like McAfee were consuming a huge amount of memory, amongst other things. If you venture off-piste into the browser mailing lists, anti-antivirus sentiment has bubbled away just below the surface for a very long time.

 

 The problem, from the perspective of the browser makers, is that antivirus software is incredibly invasive. Antivirus, in an attempt to catch viruses before they can infect your system, forcibly hooks itself into other pieces of software on your computer, such as your browser, word processor, or even the OS kernel. O'Callahan gives one particularly egregious example: "Back when we first made sure ASLR was working for Firefox on Windows, many AV vendors broke it by injecting their own ASLR-disabled DLLs into our processes." ASLR, or address-space layout randomisation, is one of the better protections against buffer overflow exploits.

 

Furthermore, because of the aforementioned knotweed-style rhizomes of antivirus programs, the AV software itself presents a very large attack surface. As in, without AV installed, a hacker might have to find a vulnerability in the browser or operating system—but if there's AV present, the hacker can also look for a vulnerability there. This wouldn't necessarily be a problem if AV makers made secure software, but for the most part they don't (except for Windows Defender, because Microsoft is "generally competent," according to O'Callahan).

 

Back in June last year, Google's Project Zero found 25 high-severity bugs in Symantec/Norton security products. "These vulnerabilities are as bad as it gets," said Tavis Ormandy, a Project Zero researcher. "They don’t require any user interaction, they affect the default configuration, and the software runs at the highest privilege levels possible. In certain cases on Windows, vulnerable code is even loaded into the kernel, resulting in remote kernel memory corruption." Over the past five years, Ormandy has found similar vulnerabilities in security software from Kaspersky, McAfee, Eset, Comodo, Trend Micro, and others.

 

All this isn't to say that you (or your parents) shouldn't use antivirus software, but you should certainly be aware that using antivirus software doesn't necessarily make your computer any more secure. In some cases, AV might make your computer less secure, and cause a deleterious effect on system performance—and, if you believe the browser makers, the continuing popularity of AV software might have a gnarly knock-on effect on other developers, too.

 

The nail in the coffin, according to O'Callahan, is that software vendors rarely speak out about antivirus issues "because they need cooperation from the AV vendors." He then links to a mailing list thread in 2012, where he suggests keeping a list of the AV software that interferes with Firefox. Later in the thread, Mozilla PR swoops in and tells him to knock it off.

 

Antivirus software is so ingrained with Windows users, and synonymous with the concept of "good security," that software makers have their hands tied. "When your product crashes on startup due to AV interference, users blame your product, not AV," O'Callahan says. "Worse still, if they make your product incredibly slow and bloated, users just think that's how your product is ... You can't tell users to turn off AV software because if anything bad were to happen that the AV software might have prevented, you'll catch the blame.

 

To make a very long story short, here's the solution:

 

    As always, irrespective of whether you decide to use AV, regularly updating your OS and software is one of the best ways to keep your computer safe. This also means that you should stop using Windows 7 or 8 and update to Windows 10.

 

    This is from a very reliable source and not some hearsay. If you follow this advice and keep your PC updated, you will not encounter any problems, especially not after the Windows Creators Update with the 1703 OS does an outstanding job. There's really no need to let AV systems give hackers a chance to get into your system. 

Link to comment
Share on other sites

On ‎24‎/‎04‎/‎2017 at 10:21 PM, Jamesinlos said:

As always, irrespective of whether you decide to use AV, regularly updating your OS and software is one of the best ways to keep your computer safe. This also means that you should stop using Windows 7 or 8 and update to Windows 10.

Oh really.............:wacko:

On ‎24‎/‎04‎/‎2017 at 10:21 PM, Jamesinlos said:

This is from a very reliable source and not some hearsay. If you follow this advice and keep your PC updated, you will not encounter any problems, especially not after the Windows Creators Update with the 1703 OS does an outstanding job.

Does not appear to be Microsoft's current view - http://www.theregister.co.uk/2017/04/26/stop_downloading_win10_creators_update/ 

:w00t:

Link to comment
Share on other sites

Yeah, Windows Defender: free, no nagging or ads. Not THE best but good 'nuff: https://www.howtogeek.com/225385/what’s-the-best-antivirus-for-windows-10-is-windows-defender-good-enough/ Once a week scan w/ Malwarebytes, maybe occasionally w/ Super or AdwCleaner. Avoid dodgy sites (use MVPS Hosts file), be careful what attachments you open, avoid phishing scams. I'm a big believer in the MVPS Hosts file, very helpful: http://winhelp2002.mvps.org/hosts.htm. Been doing this for years, can't remember the last time I had a virus.

 

 

Link to comment
Share on other sites

Any anti virus is only as good as what you say yes or no to, 

90% of viruses/malware etc are a direct result of trying to get something for nothing or get something that is illeagal.

Years ago a virus would find you, attached to an email, on a friends usb stick etc. Those old delivery methods are not that common now days. Now days, most malicious content is actually introduced by the user in the pursuit of free music, movies, software, free access to a paid service or a free clean up/tune up software.

Link to comment
Share on other sites

Well...two points:

 

1) I drive Linux and have never found a virus on my machine. I do scans every month or so but have never found one. Linux doesn't even come with antivirus software because it's not really necessary. So if you can stomach installing an operating system, that's one way to breath easier. Most spyware and viruses are designed for the Windows world anyway.

 

2) Windows 10 has viruses pre-installed by Microsoft, like the built-in keylogger, that sends your keystrokes back to Redmond, and tons of other privacy invasive software. I wouldn't trust Microsoft to protect you. They're on your computer to harvest you, in the form of advertising revenue.

 

Just my 2 sense.

Edited by dblaisde
Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.







×
×
  • Create New...