Avast: a Chromium fork with critical security checks removed
code.google.com
code.google.com
cf: "Chromodo" and the vulnerabilities disclosed by this same researcher[0]
[0] https://code.google.com/p/google-security-research/issues/de...
EDIT: And let's not forget TrendMicro's recent blunder with the enabled-by-default HTTP server for "Password Manager" that is installed as part of their antivirus program.[1]
[1] https://code.google.com/p/google-security-research/issues/de...
In the case of the browsers, it "only" the bits they tampered with that's more insecure. For their own stuff, anti-virus, firewall and what not, they've "tampered" with the entire code base.
In the case of Microsoft, their motivation is to make Windows work better, in the case of OSS the motivation is often to scratch personal itches, both of these motivations trend towards positive results.
In the case of 3rd party security software vendors, their motivation is usually to upsell you from whatever version you are using to a higher level of "security", so it is in their best interest to go nuts with false positive reports (eg. finding some browser cookies in a scan, posting up such severe looking warnings that you'd think your system is rooted), bog your system down, etc.
(See: https://www.reddit.com/r/YouShouldKnow/comments/40zh69/ysk_t... https://www.av-test.org/en/antivirus/home-windows/)
Think about it: all this stuff is costing them money, and that reduces their profitability. What is it gaining them? Nothing.
Why? Simple: if customers get pissed off, what are they going to do, switch to Linux or Mac? Maybe a few, but the vast majority will just put up with it and gripe and complain. They're never going to leave Windows, so it would make sense for Microsoft to screw them over.
You might be interested in reading up on tavis Ormandy and his adventures with Sophos antivirus. He was able to find several holes in sav with [allegedly] very little effort. Which was especially comical because they could be used to pwn Sophos' network firewall product which is used by enterprises.
Oh, I got paid for the time, but which is more satisfying and looks better on my resume: "Hacked around antivirus bugs" or "Built a cool and awesome feature"? :-)
Here's my previous rant on the topic with specific details:
https://news.ycombinator.com/item?id=10248084
And a mention of one of the debugging techniques that was helpful here:
- what changes have been made in the fork? - can I (or people in the software development community) see the source code? - what peer review policies are applied to changes made in the fork? - when (not if) something goes wrong, what policies and mechanisms are in place to fix it?
... just to name a few. No software is perfect. No engineer is perfect. There will always be bugs. There should just be an expectation that people will take reasonable precautions.
Those are the most important parts, assuming the user is above the level of downloading and executing malware by themselves.
At least that protects you from theft. I can keep all my files backed up, but that doesn't protect the data in them from being compromised.
If anything, you need to start recommending encryption to your friends if they aren't going to use an Antivirus.
It's also highly unlikely that the teams putting out shitty consumer-facing antivirus magically write awesome code for the enterprise versions.
The nastiest of the nasty stuff that's going to log keys, steal info, and so on, tends to be zero days. And after that article that showed how dismal the design of the popular antivirus apps is, there's an argument to be made that using them reduces your security.
The antivirus engine is the same and the only differences are how it's packaged. They're still shoveling obtrusive, crap software onto your system, just being less obvious about it.
The only reason to have Symantec Corporate Edition Antivirus installed on your system is because your company signed a deal to use Cisco VPN & Endpoint Protection and you're literally forced to use it.
What mostly everyone fails to understand is that antivirus software is not effective as a _preventative_ measure. What they are good at is detecting that you're already infected, but they all have terrible rates of false-positives. Nothing out there is much effective at protecting you from 0-day, despite industry claims to the contrary.
User training/habit modification is the only effective measure at preventing infection (besides being behind a default-deny firewall, but that's not something consumers will do). 99.9999% of infections require user interaction (and the ones that don't require it become instant international news). Adblockers get you most of the way there and do a better job at prevention than antivirus software.
Flaws in AV software have been exploited by rootkits before. AV software is just another point of failure.
That's a very poor detection rate. I mean, I can confirm that at least 12 nasty malware programs weren't detected by a very widely used AV suite!
Its user interface deliberately does not give its users the proper context to evaluate the severity of a problem. The change came after they made a concerted effort to monetize the app.
MBAM is good at a lot of things (it has traditionally been on top of modern registry hooks and ransomware loaders where other vendors consistently drop the ball) but just because you saw 45 things flagged red doesn't mean you had 45 bits of hostile executable code on your system.
Malware infections aren't a singular entity anymore, they are a stew of items working together to maintain control of your system (exploit, loader, payload [usually a rootkit], defense, c&c). It's often a matter of breaking the chain of processes to 'open up the onion' and regain control of your system.
You mean like security researchers?
http://www.networkworld.com/article/3021113/security/forbes-...
Anti-Virus is little more than snake oil. If you need to secure a Windows box, get EMET and read http://decentsecurity.com and you'll eliminate most of your attack surface.
Everyone can be secure.
It is with those four words this website is founded. Computer, smartphone,
and online security does not require a degree or years of experience. All
it requires is someone show you the way.
You've been sold a lie. You can't buy computer security. It is something
obtained through configuration and knowledge. Tragically, these aren't even
hard to do or obscure to learn. But no one makes money telling you how to
use what you already have. What you need is someone who doesn't care about
your money or looking smart by spouting off fancy words of no consequence -
just that you not be a victim.
It pains me to see people who distrust and fear their computers, and who
feel powerless in that fear. Because that's not what I see when I look at
computers and phones and websites. I see tools I trust with the story of my
life, and the secrets I leave out when I tell that story to others. Everyone
should be able to feel like that.
This site does not sell anything. This site does not take donations. This
site has no one's name on it.
This site is to fix what is broken. Which is how we teach security.
If you were wondering because it looked familiar, it's run by the same person behind @SwiftOnSecurity.Tragically, I believe this is true. But it isn't a great and noble thing that people must gain knowledge to overcome their powerless fear of computer technology, it is a failure of technology creators to provide people with simple tools that they can use without fear.
The problem isn't how we teach security, because hardly anybody should have to learn security in the first place. That the mainstream public is even aware of a concern called "security" having to do with their computing tools is already a failure. I can't think of any other mainstream products that people have to be so careful with, where they are told it is their fault that they just haven't gained the expertise necessary to use it without problems.
It might take years, but I believe these initiatives will trickle up and make the software everyone uses more secure at a base, so it will require less cognitive load from the end users to communicate safely with each other.
That's the idea, anyway. Time will tell if we can succeed.
Those problems are better solved by giving developers better tools and frameworks that solve these problems for them, that are simple to use and don't introduce massive security foot-cannons.
(This comment is a minor spoiler to my current project, I suppose.)
If you try to make those things not possible then people who need them have to use a different platform, which tends to cause other people who need to interact with those people to use the same platform (and so on) until the original platform is in decline. And the effect is worse the more you lock things down. It doesn't help anybody to have an ultra-secure platform that nobody uses.
A good example is the backlash browser vendors get when they try to make TLS errors fatal (without a "continue anyway" button). Users will cry bloody murder until the option to bypass the warning screen is re-added, at which point everyone returns to clicking through all warnings and we're back at "you need to know what you're doing to have a secure machine".
Furthermore, if all the people advocating HTTPS everywhere get their wish, then the people screaming bloody murder will become even more right! If I'm trying to load the HN homepage, and heaven forfend I get a security error, you better believe I'll ignore it, because even in the unlikely case that someone is spying on me, I can't think of how someone knowing which HN threads I read is going to hurt me in some way.
I don't think the solution is to avoid HTTPS, however. I think sysadmins need monitoring and automation tools so that expired certificates can be an exceedingly rare event. Letsencrypt has taken a big step towards this by making a fully automated process to get a certificate.
> I think sysadmins need monitoring and automation tools so that expired certificates can be an exceedingly rare event. Letsencrypt has taken a big step towards this by making a fully automated process to get a certificate.
I fully agree with this. :)
This undeniably makes security easier for non-technical users, but I hardly need to point on the downside on HN: these companies get to decide what programs people can install and distribute to others. They're not held to the standards of governments like due process and accountability - even though there are probably now more Android users than citizens of any one country [1].
Kudos to anyone working on alternative ways to make security easy without these gatekeepers.
[1] 1.4bn Android users in September 2015, according to Techcrunch, vs 1.38bn estimated population of China in 2015. Android is growing faster.
Cars. Those also tend to kill people, not just wipe out some baby photos. It's not an accident that almost every country requires licensing before you're allowed to use a car.
My family on the other hand can't avoid click "Yes", "ok" to anything ever asked of them on their computers. They get massively gunked up and infected and nothing I tell them changes their behavior because at a base level they just don't have the awareness. They're very smart people but what the computer is doing or might do in response to their actions is just not something they think about.
It's a good read, and it was one of the pieces that motivated me to pursue making security easier for people.
I'm trying to do the same thing with developers. :)
For one thing, last time I checked benchmarks they showed that Microsoft's anti-virus not only has worse detection results but also worse performance than some of the free alternatives.
I don't know about other antivirus software though.
Page 9 of the latest report: http://www.av-comparatives.org/summary-reports/
EDIT: And there's anti-virus software that's messing with your system's root certificates so it can MitM all your HTTPS traffic to scan it:
http://www.securityweek.com/antivirus-software-has-negative-...
the glaring security holes opened by them month after month? The HN link you're posting a comment to is about the 5th bad exploit in third-party AV this year alone.
So far nothing seems to have been found in the MS built-in one.
Installing third-party AV means that you expose yourself to targeted attacks and, if this goes on like it currently does, to drive-by attacks too as by now malware authors must have gotten the hint that searching for vulnerabilities in those various AV products is a very worthwile effort.
In general, AV products provide a HUGE attack surface: They don't just need to support natively many more file formats than any other piece of software, they also have to harden their support against exploit code purposefully written to be malicious.
And compared to many exploitable user-space applications, these AV products normally run in kernel-space, so an attacker doesn't just gain remote code execution, they gain remote code execution with admin privileges.
Slightly better snake oil is still snake oil.
It's an utter racket.
Those of us with technical inclination need to be sure to point our family and friends with less technical inclinations to the Microsoft Stores and "Signature Edition" [1] PCs, Microsoft's latest marketing term for unbloated Windows installs out of the box. Some of our friends and families may feel they have a special relationship with an existing OEM, so give them the "Signature Edition" website and have them at least bug their OEM to ship them one.
[1] http://www.microsoftstore.com/store/msusa/en_US/cat/category...
You have no idea where that computer's been before you.
Here's the ArsTechnica guide for doing a clean install of Windows 8.1 – imagine walking the average home user through this process, even before you factor in discouragements such as the likelihood of tech support blaming any problem more subtle than catching fire on your reinstall:
http://arstechnica.com/gadgets/2015/02/save-yourself-from-yo...
This, in a nutshell, is a major source of Apple selling so many iOS devices – I regularly hear people say that it's easier to have a good, secure computing experience that way and they're not wrong.
http://www.howtogeek.com/174587/refreshing-your-pc-wont-help...
http://www.howtogeek.com/216751/bloatware-banished-windows-1...
Windows 8 and 10 also have a lovely feature called the Windows Platform Binary Table. This allows OEMs to write an application into the UEFI, and Windows will automatically deploy to memory and run it with admin privileges each time it boots. The intended use was for installing drivers and anti-theft agents, but of course it was immediately used to drop bloatware/malware. This vector works even on entirely fresh installs, and there is no mitigation except obtaining a clean, signed UEFI image.
https://www.techdirt.com/articles/20150812/11395231925/lenov...
http://www.howtogeek.com/226308/the-windows-platform-binary-...
Laptop manufacturers are also to blame because product bundling and bloatware are nothing new.
Microsoft on their part could make it so that Defender worked alongside McAfee but that might encourage users to buy McAfee even more, arguably (double the protection or not knowing they are already protected).
Further info here: https://news.ycombinator.com/item?id=9653111
Then there is Superfish...
Who knows what else they are going?
Plus, e.g. Comodo gives you a firewall. While I know that Windows has a perfectly good firewall, it doesn't come with a systray icon with a button labeled "protection from active network probes: active" or whatever.
Personally, I just have a router between me and the big bad internet and use Security Essentials plus Common Sense 2012.
If you're not technically inclined there are minefields everywhere.
Only to watch him say "I want to get vlc," type vlc into Google, skip over the VideoLAN - downloads link, and click some virus-infested link further down because the title of the link was "Get vlc."
This is why the scams work.
VideoLAN - Official page for VLC media player, the Open ...
The other results are all either directly or almost directly associated with VLC. I get no scam sites in the top 10 results. Have the search results improved? Is this the effect of search personalization? What gives?
People have reported this to various slackers for years but companies like Yahoo are loathe to turn down ad revenue and they still have millions of users.
Compiled and ran the code and immediately Bitdefender blocked the program and put up a "Keylogger detected" message.
Microsoft built in antivirus doesn't have this kind of behavioral detection protections.
Which is quite problematic because it was a false positive. You knew and wanted that program to log key presses.
That's the trouble with aggressive heuristics. Users are going to have a program that translates keyboard layouts by hooking the key presses. Or software that comes with some fancy input device.
Then the antivirus says it's a keylogger even though they know it isn't and the user is taught to expect good rather than bad things when they press "allow" against a something-is-wrong prompt.
The alternative is that we don't see when a keylogger is being installed non-deliberately, and that would be worse IMO.
From my experience there are very few legit reasons for intercepting keys, and the use cases you mentioned are better solved by implementing a device driver (which would be signed by MS).
Allowing non-elevated code to install system hooks also enlarges the attack surface, since now a malware piece can just infect your keyboard layout translator for getting keyboard access.
Me, I would like an Intent/Permission mechanism on Windows, where certain actions like keylogging or accessing other processes memory require explicit white-listing (like on Android/iOS). Currently some actions do require a certain privilege, but that privilege is granted per-user, not per-app, so it doesn't help that much.
That's assuming you have control over what third parties who write the software have done, and needing to go through the expensive bureaucratic process to get a driver signed is a major reason why they wouldn't do it that way if there was any alternative.
> Allowing non-elevated code to install system hooks also enlarges the attack surface, since now a malware piece can just infect your keyboard layout translator for getting keyboard access.
But now you're not talking about antivirus anymore. Installing things is expected to require privileges. There is a huge difference between a password prompt that says "authenticate if you want to install" and a red alert that says "malware detected and blocked, override may cause fire and mayhem."
Which is especially problematic when it's done by third party antivirus because it means the vendor of whatever software is being misdetected as malware probably didn't encounter that in their testing.
> Me, I would like an Intent/Permission mechanism on Windows, where certain actions like keylogging or accessing other processes memory require explicit white-listing (like on Android/iOS). Currently some actions do require a certain privilege, but that privilege is granted per-user, not per-app, so it doesn't help that much.
Fundamentally non-technical people don't understand what they're authorizing. It doesn't matter how granular the choices you provide are if the person in front of the button doesn't understand the implications.
You have to be able to trust the software you run, which implies trusting the people who made it. And people keep trying to solve that problem centrally when it isn't a central problem. Microsoft can't tell you if you can trust your brother, or the girl you met at the computer club. They can't tell you if you can trust Lenovo or Sourceforge. Microsoft certainly can't tell you if you can trust Microsoft. You have to decide, or decide who to trust to decide for you. And if you aren't going to decide for yourself then the person you trust to decide can't be Apple or Microsoft, it needs to be someone you personally actually trust, because central gatekeepers can't be trusted not to act against your interest when it's in theirs.
To be fair, MS has recognized this and has been steadily improving detection rates. It has only recently been able to outdo Avast or AVG. Hopefully, this trend will continue. I imagine MS is under a lot of pressure to contain the Cryptolocker-type infections and the bad press of the past couple years is probably a motivator.
http://www.alphr.com/security/6745/best-free-antivirus-of-20...
Isn't this claim somewhat refuted by the very article you are posting against? There are other comments in this thread that explain why this doesn't make any sense eg pilif's above[1]
The comment you listed cites nothing, not sure why its so authoritative to you. All software has vulnerabilities, but where's the big attack on AV? What CVEs are we seeing in the wild, if any?
Assuming you can identify (skill) and safely sell (anonymity expertise and market savvy) a zero day, the demand for them is quite limited. (The only reason the price is so high is that the supply is just even lower.)
Additionally, if you have the market savvy to extract the maximum value for a 0day, you will quickly realize the feast-or-famine nature of unsavory income isn't great for a stable home life. You might eventually want a day job, and you can't exactly say "Oh, I helped that virus penetrate your network three years ago that you just detected last month."
So most people with Tavis's skill levels typically aren't in a hurry to go rogue.
And the ones that do are more interested in compromising bitcoin exchanges and drug marketplaces on Tor Hidden Services than they are in spreading malware to end users. (That's the advertising industry's shtick.)
https://forum.avast.com/index.php?topic=171725.0 https://blog.avast.com/2015/05/29/avast-data-drives-new-anal...