Antivirus software could make your company more vulnerable
csoonline.com
csoonline.com
As a more savvy user, I did not desire the typical AV bloatware (Norton, McAfee, etc) stealing up half my cycles and spinning the hard drive without pause. I knew enough not to try and 'open' resume.doc.exe.
However, AV's have trimmed down, SSDs are becoming more common place, and it seems the biggest attack vector is browser based. For the last few years, I've run a few different AVs (Kaspersky, ESET, Bitdefender are decent).
I run adblockers, don't install Flash games or Applets, but it is nearly impossible to stop all browser based attacks. I'm not sure the AVs have helped much, but they give some sort of psychological benefit, at least.
There really is no good solution anymore unless you're willing to give up 90% of the web (via NoScript or using a primitive console based browser). I believe the future for tech-aware users will be browsers in some sort of container / VM that reset themselves upon each session, with absolutely no control to the file system or data from other sites.
Is this the case for Apple's OS well (Yosemite or whatever its called nowadays)?
As an aside I am thinking about installing a light UNIX distro on my netbook. Win 7 is so painful with only 1GB of RAM. (I love being poor student).
Now I got some money so I can either buy a new laptop for $350 or attempt to save some money by installing a light UNIX distro. Problem is, I dont want to learn another OS.
I find this a very dangerous way of thinking. You use the placebo (well, not even a placebo, just useless) and then you stop worrying that much about opening downloaded files, checking their hash if you trust the source, visiting dodgy websites...
An analogy taken to the extreme, would be to smoke and binge drinking without worries because you're taking homeopathic "solutions" (sic).
Installing an AV doesn't automatically reduce your defenses. Only if you over-trust it.
Recent news might point otherwise and there's a debate about it. Does an antivirus really protect you from a real threat? On the other hand, as you're running extra software you're increasing your attack surface, which makes you more vulnerable.
I've seen very clever people pointing to the latter and marketing efforts to make me believe the former. Still, haven't made up my own opinion. In any case, I stick to just Windows Defender and EMET (https://support.microsoft.com/en-us/kb/2458544) to mitigate.
Or you could set-up a linux box just for web browsing.
No matter what you do eventually you will get infected by some exploit. Be it Flash, Java, some pop-up ad, or just an email sent to your email client that exploits it.
I got a lawyer still runs XP and Vista and uses ClamAV because it is free. I worry that her systems might be infected, but her husband runs the tech support for their firm. She used to have employees steal data via floppy disks, and these days a simple virus infection can steal data.
Scary. Small law firms are a prime target for cryptolocker-type attacks. In that case you need a solid backup / restore system.
I don't know how they are set up for backups. I only know they use XP and Vista and ClamAV looking at their desktops.
Be careful which you choose. Some of them are extremely primitive compared to the major GUI browsers. For example, I was shocked to learn recently that there is no upstream for w3m, and that w3m doesn't do SSL out-of-the-box. And yet, w3m is used to render HTML by all sorts of other console-based applications.
https://www.qubes-os.org/screenshots/
https://www.qubes-os.org/intro/
and the (microkernel-based) Genode OS with somewhat similar approach:
http://genode.org/documentation/release-notes/15.11#Rigid_se...
http://genode.org/documentation/release-notes/15.11#Genode_a...
and finally NixOS/Nix, which I hope will at some point become integrated in some way with the above OSes (as well as many others):
Maybe a more secure os? I gather Chromebooks or Linux work quite well
I wonder if anyone's tried making something that looks like regular Windows but it actually Windows running in a VM under Linux. Might be a way to make something hard to hack but usable by people who only know Windows? Maybe it could have something like Git for versioning the Windows images so you could just roll back to when Cryptolocker got installed?
When I get some time I'd like to clean up my air-gap browser, which was a webcam looking at a laptop with a browser open, where mouse and keyboard actions were translated at the Webcam into bluetooth messages which drove the laptop. Not very practical but wonderfully tin-hattish.
The long and nasty history of RCE flaws, not just horrible stuff like this but subtler stuff buried in the file format parsers, is all the data I feel like I need.
AV is complex code that handles huge amounts of untrusted data, so it's a major increase in attack surface. Also, it cannot work, as it's an instance of blacklist security, which never works. So, no upside, huge potential downside.
...and it also recently introduced HVMI (Hypervisor-based Memory Introspection)
technology that completely isolates the antimalware solution by deploying it in
a Type 1 hypervisor outside of the operating system.
"This kind of isolation separates the antimalware engines from rootkits or
exploits running in the user environment," the company said.
This completely misses the point. Yes, it protects the AV from exploits in other user software, but it makes exploits in the AV software itself even worse.1. http://appleinsider.com/articles/15/08/10/mackeeper-to-pay-o...