AVG can sell your browsing and search history to advertisers
wired.co.uk
wired.co.uk
A couple I've dealt with in the last six months:
McAfee Antivirus causes applications built with Unity 4 to fail when they call WWW.LoadFromCacheOrDownload() on a large asset bundle. This API call downloads a temp file and then renames the file to move it into the cache. But McAfee also opens the file for a virus scan. For a large file, the virus scan may not complete before Unity tries to rename the file, so the rename fails and you never get the asset bundle.
For one client I fixed this by patching Unity's .exe file to add a retry loop on the rename call. Unity 5 also works around this issue with the same retry loop.
AVG Antivirus causes updates to fail for applications that use wyUpdate. wyUpdate calls the CreateMutex() function in the Windows API to make sure another updater instance isn't already running. Bizarrely, when AVG is installed, CreateMutex() returns the wrong value, so wyUpdate thinks another instance is running and bails out. No updates for you!
Going back a few years, I tried NOD32 after some friends recommended it. It seemed fine, except the Alt+Tab key no longer worked. It was a known bug, unfixed for some time.
About 5-6 years ago, McAfee had a known bug - unfixed for nearly a year - than under some circumstances it would erase the entire hard drive. This was the ultimate in virus protection!
http://www.cplusplus.com/forum/beginner/67634/
https://groups.google.com/d/topic/mingwusers/kFrCqECTY_Y
Along the same lines, it's rather common that keygens/cracks/patches are detected as false positives too:
http://underlore.com/anti-virus-community-creates-false-posi...
1: Reflections on Trusting Trust: https://www.win.tue.nl/~aeb/linux/hh/thompson/trust.html
That is unavoidable if the scanning engine is trying to apply heuristics to pick up on attacks (or variants thereof) that are not in its database yet, especially with cracks and other patches: changing the behaviour of executables the way they do is by its nature similar to what viruses and worms are attempting to do.
So I ran the app under the amazing API Monitor [1] and enabled logging for MoveFileA(), MoveFileW(), MoveFileExA(), MoveFileExW(), and similar "move file" APIs. It showed a failure on a MoveFileExW() call with the address of the call.
We'd found that Unity 5 didn't have the same problem (but we weren't ready to migrate to Unity 5 yet), so I also ran a Unity 5 test app under API Monitor and found the same failure on MoveFileExW(), along with several retries on the call until it succeeded. This told me just what I needed to patch the call for the Unity 4 app.
For the issue with AVG and wyUpdate, since wyUpdate is open source I just ran it under the debugger, and as luck would have it, the failing mutex.WaitOne() call was near the beginning of Program::Main() in the C# code [2].
(I mentioned WinMain() and CreateMutex() previously - I was writing that from memory and double-checked it now.)
[1] http://www.rohitab.com/apimonitor
[2] https://github.com/geary/wyupdate/blob/master/Program.cs#L40
But now, the "attack surface" has expanded inexorably to the point where the alternative to AV appears to be... none.
So this just seems to be the modern Internet, where the average user is more or less at the behest of rackets not much better than the rackets that control botnets if they aren't actually infected by them.
I've heard some botnets patch the system and expel other intruders. Yes, now, "everything is free... infection and protection equally".
Is there an alternative?
The Windows security model is not the broken mess it once was when properly used so the key problem is user behaviour particularly home users running as full admin, installing random crap without thinking about it (or simply not knowing any better), just clicking through any warnings they do get, and so forth.
If enough of that sort of user migrates over to Linux and kicks it into working the way they want (i.e. the bad way they used to work under Windows) you'll no doubt see the number of effective exploits balloon massively.
Jeff Wayne's Martians were right: "The problem is, of course, the humans."
Although this is very much about Linux on desktops.
Linux: easy things are easy, normal things require some googling, hard things are hard.
Worked out of the box for me (sound autoconfigured, sleep via thinkpad acpi autoconfigured, intel gpu autoconfigured, external monitor via thunderbolt autodetected, one network printer/scanner autodetected via bonjour, other network printer/scanner had driver package from the vendor on the web, were projectors ever a problem?).
Did I do something the wrong way?
Linux also works really well if your hardware isn't bleeding edge.
The part where Linux becomes hard to use and requires expertise is learning the new UX, understanding what software and tools are no longer available and figuring out how to live and work with the alternatives that exist.
The degree of technical proficiency that you have is probably relevant to your "out of the box" experience - you are reading and posting on HN, which means that your level of technical knowledge is probably higher than most users given the typical audience of this site.
chrome is google's tool to control browser apis and to fight apple (viz who is attempting to move app-like functionality into the browser, vs who is keeping that inside apps for their leading app store). It also gives them various other capabilities: monitoring browsing (site suggestion), monitoring ssl cert corruption, etc. And it's their attempt to replace the OS with a browser ala chromeos.
safari is similar: apple's ability to control the internet and how it evolves, including veto power over apis that strategically threaten their business
so too ie/edge, both historically (stifling development of js and internet apis, activex) and now with their still leading os marketshare
and even firefox only lives as long as yahoo, microsoft, or google find them useful, since one of those three basically pays all the bills with search revshare deals. So you could consider even ff as their bulwark against being recognized as a monopoly
The general public also has no idea how difficult it is to make software. Frequently even programmers don't see software as that difficult - witness how many times someone has to raise the 'mythical man-month' or similar.
The only thing that could top it would be allegations that Bohemia Interactive are selling military simulators to North Korea. :)
I am glad that they reversed those decisions.
* Gary Kovacs: Former Mozilla CEO: https://www.linkedin.com/in/garykovacs
* Harvey Anderson: Former Mozilla Chief Legal Counsel: https://www.linkedin.com/in/harveyanderson
* Todd Simpson: Former Mozilla CIO: https://www.linkedin.com/in/tgsimpson
* Rick Fant: Former Mozilla VP of Marketplace: https://www.linkedin.com/in/rickfant
The above just indicates that some people might start to prefer, over time, a cushier job at a less-scrupulous corporation.
The company is a joke like all the other toolbar companies. I wrote to a number of financial journalists at the WSJ a few years ago begging them to write an expose on these firms and Google's compliance in allowing them to exist. No one ever wrote me back.
I've been uninstalling AVG and replacing it with Microsoft Security Essentials. I know a lot people will be upset over that because [their favorite AV] catches X% more viruses and malware than MSE. But you know what - MSE is light, made by the same company who made the OS, and catches most of the common viruses.
Well JS is fine as long as the browser is up to date. Normal people aren't going to be hit by zero-days.
Normal people still use IE. There are definitely plenty of IE zero-days out there that have hit normal people. Mozilla also announced a month ago that an exploit using a FF zero-day was running in the wild.
Even then - an antivirus program is unlikely to stop such an intrusion. It's just utterly ineffective, and I got viruses before despite having an anti-virus. Also, my anti-virus always deleted my hacktools and own programs which was a nuisance. Hence I don't use it anymore.
My wife constantly gets all sorts of crap on her machine. I have tried to explain to her the difference between popups that says she has a virus on her computer and OS alerts, but it just goes right over her head.
Citation needed.
I'm not sure where to go from here.
Linux.
I don't think it will be much longer until I actually make the switch.
if you don't, and you don't do webbrowsing from inside windows then I can't imagine the need for anti-virus.
90% of attacks are trojan horses (fake/embedded pirated software usually) and the remaining 9.9% is browser attacks.
I doubt anyone is defeating your firewall/NAT box to get a direct connection to your windows machine, and even if they did they'd have to find a service they can exploit.
:)
For some extra polish when running Linux VMs under VirtualBox on Windows, set the virtualisation mode to kvm and use virtio network device.
Security starts with the user.
How is this the same as having to run anti-virus software because the system's (i.e., Windows's) security model is broken?
> jailbreak iOS
Not sure why iOS is even relevant to my comment, since it isn't built on Linux (or even Unix).
> Security starts with the user.
This is true; a user who is bound and determined to hose their system can do it no matter what protections are in place.
But that's irrelevant to the point under discussion, which is how people who do not want to hose their system can keep it secure. On Windows, you have to run anti-virus software (and even the protection that provides is not foolproof), because the system's security model is broken. On Linux, the system's security model is functional to begin with, since unlike Windows, the system was designed that way from the ground up. So you don't need to run anti-virus software, and hence you don't have to worry about what information that software, which has a privileged position on your system, might be sending to others.
Yes, those things should be turned on by default. It is hard to educate generations used to work as root.
When people discuss UNIX security they tend to forget that worms were first targeted at them.
Also data matters more than system binaries, so it is enough to p0wn an application and suddenly $HOME is open to the world.
Then new GNU/Linux generations also seem very found of "curl ... | sh". Again opening $HOME to the world.
I also doubt everyone reads their emacs, vi, ..... packages. Again opening $HOME to the world.
UNIX does have a better security model configuration out of the box, but is just as unsafe for the regular users that just dump stuff into their PCs.
Do you still need to run anti-virus software in this configuration?
> UNIX does have a better security model configuration out of the box, but is just as unsafe for the regular users that just dump stuff into their PCs
Again, I agree, if a user wants to hose their system, Unix won't prevent them. But anti-virus software won't prevent them either.
My point is, what about the user that doesn't want to hose their system? On Linux, it's very simple: use your package manager to install software, and don't run anything that wasn't installed that way.
Just that trusted sources in Windows means not installing pirated software or that thing a friend gave because it was so cool. Or going to shady internet sites.
All things that will hose a Linux system as well.
Linux package managers are nice until one needs something it isn't there, like it happens to most average users that don't care about about FOSS and forcing themselves to alternatives.
And I never saw a UNIX that would allow to prevent users to install software locally, as Windows does with Active Directory group policies. Although I bet there are some third party commercial offerings for that.
Outside Windows I only saw that in mainframes.
What does "trusted sources" mean in the Windows world? Microsoft itself has shipped virus-infected CD-ROMs in the past.
> Linux package managers are nice until one needs something it isn't there
My sense is that, while this can happen, it's less likely to happen with the major Linux distros than it is with Windows. Major distros have tons of software in their package managers.
> I never saw a UNIX that would allow to prevent users to install software locally, as Windows does with Active Directory group policies
Um, you do realize that all it takes is not putting the user in the "sudoers" or "wheel" group (depending on the distro), right? This is routinely done in settings where only sysadmins are allowed to install software, such as universities. You certainly don't need anything as heavyweight as Active Directory group policies.
Do you also read OpenSSH and Bash source code looking for security exploits?
> My sense is that, while this can happen, it's less likely to happen with the major Linux distros than it is with Windows. Major distros have tons of software in their package managers.
Quantity != Software X that user won't do without.
> Um, you do realize that all it takes is not putting the user in the "sudoers" or "wheel" group (depending on the distro), right? This is routinely done in settings where only sysadmins are allowed to install software, such as universities. You certainly don't need anything as heavyweight as Active Directory group policies.
I can install whatever software I want under $HOME, there is nothing preventing me to do that.
I don't personally, no. But I'm confident that there are experts doing so, and that when they find an issue, it is publicized and fixed quickly, because it's considered an extraordinary and urgent event, and allowing it to continue unfixed would be unacceptable. When MS shipped virus-infected CD-ROMs, nobody thought it was unacceptable, or even abnormal.
However, if you're confident enough in Windows' security features to run without anti-virus software, that's fine. My sense is that the vast majority of Windows users are not. But the vast majority of Linux users are.
> Quantity != Software X that user won't do without.
You're going to have to give specific examples, because I just don't see this as a significant issue that users who don't want to hose their systems have to deal with on Linux. I've never come across any software I needed as an ordinary user that I couldn't find in my Linux distro's package manager. (As a programmer, I have, but that's a different case.)
> I can install whatever software I want under $HOME
Which comes under the heading of users who want to hose their systems. If you don't want to hose your system, just don't do that.
(As an aside, I think you can actually lock down executable permissions in $HOME with SELinux. But I haven't tried it myself.)
Are you using a recent version of Windows (8, 8.1, or 10)?
Do you have automatic updates enabled?
Do you have standard Windows features such as User Access Control enabled?
Do you use the computer with a standard user account as opposed to an administrator (root access) user account?
If the answers to all these questions are yes, I'd say you don't need an antivirus solution. Don't listen to the scaremongers. Microsoft has got you covered.
Run updates, don't use browser plugins, stick to applications you trust, and stay away from seedy looking sites when downloading common software. (Sourceforge comes to mind.)
For risky websites, a combination of Chrome, WOT, ublock origin, HTTPS Everywhere and Sandboxie and/or Malwarebytes Anti-Exploit (zero-day protection) should suffice.
Using a Standard (non-Admin) Windows account and being up to date goes without saying.
It's not that MS has you covered, moreso that AV vendors don't really catch new malware that has been mutated, packed, or whatever. So a more in-depth defense is better.
Not to mention that hilariously enough, AVG is literally selling user data now, which is what antivirus is supposed to protect against in the first place.
if you keep your OS and browser up to date, and don't open random sketchy EXEs, you'll be fine.
The old school Unix method works very well: Keep a list of all changes made from the base install, then periodically swap the disk out for a blank one, follow your documentation and restore non-executable user data from backup. Also has the benefit of regularly validating your documentation and testing your backups, and allows easy rollback by following the same process for major OS updates or hardware upgrades.
No where. I've been antivirus-free for the better part of a decade. 0 infections of malware of any kind.
Have a look at this link, it explains things a whole lot better than I could:
http://www.cnet.com/how-to/i-dont-use-anti-virus-software-am...
I found the Wired article by using the 'web' link we added last week to search on the title (which I had to modify a bit). If anyone can suggest a better URL, we'll change it again.
For sure there's no free lunch, but I believe you're making it too easy for AVG. An antivirus is a piece of software one normally trusts. It's a shame if this trust is misused. And let's not deceive ourselves that users will attempt to understand fully the technical stuff behind the data privacy statement they put out. While trivial for an IT person, the jargon will not be understood by non-techies.
This isn't an awful thing but it's absoultely true that we both are the product here.
The “If you aren't paying you are the product” is an anachronistic and ignorant trope leveraged in fanfolk wars. It excuses those things that are paid for and are further monetised. Take for example your music purchases and a “You might like...” suggestion list; you have paid for the system, purchased music, and surprisingly your purchases are being tracked and further monetisation is attempted. Vast troves of interaction data is accumulated and analysed ad infinitum[1].
Free lunches _do_ exist as well, as anyone with a good friend or child will attest to.
The slogans of hypercapitalism are rampant, none of which do justice to the complexities of context.
[1] Yes Apple is included in this, as we know from the extensive market research revealed via the Samsung lawsuit and the fact that Ping no longer exists.
Some people really do things selflessly, and/or in term of social welfare. Not everything is "money" or "our own future".
">>Free lunches _do_ exist as well, as anyone with a good friend or child will attest to.
Then the reply:
>> Those aren't free lunches though. They are paying with future reciprocity.
So it's directly the topic in this thread, not just some random out-of-context personal attack, and I agree with jgome.
With friends, I think, most people will agree there is reciprocity if not with money but with something else like company.
With children, it is harder to argue without introducing other concepts, but I argue that it is not altruistic and has gene reproduction as the final goal.
If you haven't heard this argument before, you can look into "Genome" by Matt Ridley for a colorful explanation.
Bzzt.
That is where your ideological map is attempting to define the territory.
Not all qualitative expression forms a transaction of quantitative proportions as (hyper)capitalism may have one believe.
I also sincerely doubt the discussion is somehow a debate on altruism, although when lensed through capitalist ideology it leaves few other classes as option.
Again, the slogans of hypercapitalism are rampant, as we have seen with both the “free lunch” and “you are the product” tropes that lay at the foundation of this thread.
Instead, it is likely a discussion of magnitudes and trust.
To an extent, all design insists on data and knowing. Take for example a shoe; we need to know your foot size and some other contexts, possibly such as usage.
Should we know your foot size or is this an abuse?
What if we are a shoe company and choose to register your facets in a database and across our stores? Is this a magnitude of qualia that creates a problem?
Now what if we choose to sell your shoe size to another vendor that may help you with other health choices? Another shoe vendor altogether? A company that isn't a shoe vendor?
Where do we draw the dividing line here on the magnitudes?
I don't pretend the answers are easy or clear, but they certainly seem worth exploring given the context.
Selling browsing data can be a serious issue of course, not the least of which seems perpendicular to the apparent direction of the original business model.
Who are they selling to? Insurance companies that care that you browsed about HIV medication or another software firm interested in security and the types of sites you visit?
Complex stuff for sure, but certainly not something to reduce to a polemic of altruism versus capitalism?
I distinctly remember opting in to Apple's music suggestion service. Was that true for AVG's customers?
RedHat is a commercial operation that makes money by selling support contracts for GPL software they produce. But I haven't bought a support contract even though I use some of their software without paying anything, so am I the customer or the product?
Your relationship with Red Hat is very different from your relationship with Apple, Microsoft, Google, or AVG. That should go without saying, but apparently it doesn't.
Sure you are. Platforms have network effects. They're better off if you use their software than if you use Windows, even if you don't buy a support contract.
So the exchange is that you get free software and they get network effects. It's not an adversarial relationship where you have conflicting interests regarding how much they'll be paid or how much privacy they'll take from you, because network effects don't hurt you (as long as the vendor is not a monopoly) -- if you're using the software then they help you.
Sometimes there is a free lunch.
> Your relationship with Red Hat is very different from your relationship with Apple, Microsoft, Google, or AVG. That should go without saying, but apparently it doesn't.
That's the point. "If you're not paying you're the product" is thereby disproved. You can have a relationship with a commercial entity in which neither is true.
Worse, the implied alternative is also wrong. You can be paying and be the product, as you are with Windows 10.
If you want something to take home, it's this: Stop patronizing companies that convert your privacy into their money.
Of course if they aren't being clear about the data-for-product swap then I'm not in favor.
To be sure, you don't really know if you'd be fine with this because it's never been tried, and probably won't, because no company dealing user information out the back door has ever given any indication that they are open to giving up even a shred of this business line.
There used to be a distinction between services offered on the web and apps running on the desktop (spyware, illegal). Windows 10 changed all that (along with lots of help from mobile OSes). It's (constitutional) criminal behavior (eula or not) and should be classified as such.
I don't think you've paid much attention, but that had changed long before Windows 10. This is just Microsofts big foray into that dark market. For years other companies have done the same thing.
You basically repeated everything I just said. You see... I do pay attention. Along with "lots of help from mobile OSes", Microsoft's big push into embedding spyware into a Desktop OS has completely changed the game. It has given applications - running on user local machines - license to install spyware (which is still considered illegal under the law).
Granted this is a complicated issue but we shouldn't be so quick to disregard privacy rights we have fought (and died) so long for. When backdoors and spyware are embedded into a person's home computer and/or personal property (from a car to a mobile OS), we have also allowed illegal search and seizure.