I genuinely don't see the added value of antivirus corporations in this or anywhere else. Better tactics are:
- patch
- educate wife and children
I genuinely don't see the added value of antivirus corporations in this or anywhere else. Better tactics are:
- patch
- educate wife and children
How, exactly, would you have educated her?
I'm guessing you don't have teens who have to have the latest mod for every game they play. Giving up a very real download for the slight chance of a virus is a risk they are very willing to make.
I remember in the early days of exploitative XDCC botting, practically all of the most exploited ip ranges were scholastic; new devices each semester, often given to teens as a present.
I'd highly recommend reading up on Stuxnet and the work done by security firms (many of whom would qualify as antivirus corporations) to identify the source, spread, impact, and intent behind one of the most advanced technical attacks ever identified.
Fun Wired article on the topic: https://www.wired.com/2011/07/how-digital-detectives-deciphe...
Also a book: http://a.co/0WGJm1H
Not sure what to think of these people
In a nutshell, your user account has all your data, all your session cookies, all your logins and passwords, all your documents.... Everything.
And what can root/Administrator do? That's right, play with device drivers and systems stuffs. Once you have the primary user's account, unless it's a multiuser system, it's game over.
Just with user creds, I can start encrypting files to #evil_private_key , emailing browser data, keylogging, screencapping, data injection, and being a general nuisance.
The only good defense I've seen to this is what Qubes incorporates: Zones. It's virtual machines, with unique unspoofable borders, that you can configure to only allow the minimum amount of permission the container needs. Bank Zone only needs to talk to bank and financial websites. It doesn't need sound, or direct graphics access. Tor Zone allows talking through TCP on specified ports to and from, to allow Tor across system.
In that case, yes a specific system could be compromised, but using containers like that keeps damage limited.
UAC is particularly bad in that it also produces problems with older applications and causes other applications to pop up UAC dialogs frequently. It's a huge annoyance with little security impact.
At worst it may make malware harder to remove if I do get infected - but in my experience, 99% of the malware you find kicking around on the internet isn't rootkit loaded 0 days - it's script kiddies crapping out iStealer to dump browser passwords or darkcomet to run DDoS botnets.
Users simply should not log in as Administrators for day-to-day use. Anything requiring Administrator permissions should force a full log out, and change of identity. UAC doesn't educate users. Users should either be locked out of dangerous operations, or not locked out.
Administrators should take action only when there's the awareness that their decisions could result in the need to perform a full re-install of the system, without internet access.
This is the "nuke from orbit" gambit. It's the only way to be sure.
I'm in the "meh" camp here.
https://github.com/hfiref0x/UACME currently references 8 unfixed bypasses. That's so high that I don't think this is reserved for targeted infection; it might very well happen in common malware.