That seems big. Is there any precedent on AV software vulnerabilities of this scope?
That seems big. Is there any precedent on AV software vulnerabilities of this scope?
But that being said, it's hilarious.
[1]: https://bugs.chromium.org/p/project-zero/issues/detail?id=82...
And, from Symantec's own page: Symantec strongly recommends using encrypted email for reporting vulnerability information
Continuous protection by nature opens up an enormous attack surface, and AV vendors' seem in no way up to the challenge. For this reason, in my company, security policy is to use only what's built in to each O/S.
[1] http://www.pcworld.com/article/2013580/researcher-finds-crit... [2] http://arstechnica.co.uk/security/2016/01/google-security-re...
In one case, a contractural compliance thing required that we have AV be present. We complied, but disabled the filter driver and let it scan nothing. ;)
http://googleprojectzero.blogspot.ch/2015/06/analysis-and-ex...