Last employer moved to McAfee "because active malware protection". Basically, AMP is a set of rules you can apply to disk accesses per application -- like for instance, "no application can delete PDF files from My Documents" (this is one of the "anti ransomware" rules).
It wasn't too bad with just the signature-based virus scan, but the updater and AMP were horrendous. The PCs (3.6GHz 8-core Xeon workstation with SSD, 16GB+ RAM and a ludicrously powerful 3D card) went from booting in 30 seconds to taking 15 minutes to boot. Eclipse took another five to start. When AMP was deployed to the JIRA server, JIRA refused to start (Atlassian Support suggested AV exceptions which IT refused).
IT response: close out any AV related ticket with "You will not be receiving a hardware upgrade and the AV is mandatory."
Six weeks later, IT was outsourced and the response became "we don't have permission to change AV settings" (BigCo politics).
Four more weeks later and the electronics lab was crippled as Labview got detected as malware by AMP.
A fortnight after, half the technical team handed their notice in.
It wasn't the only reason this FTSE100 was constantly outrun by its competitors, but it was certainly a contributing factor.
I was thankfully able to strip McAfee out because it was monstrously terrible.
Still, corporate IT has enforced a browser plugin and tray app called Triton AP-Endpoint and Triton Forcepoint Endpoint.
It's sole purpose is to block you from moving any sensitive data to external drives. I, up until now, have had 0 problem removing any materials to any drives anywhere. I don't think it works very well. It does however chew through my 2015 MB pro battery and cause the fan to nearly continually run and even at times overheat.
I think I could remove it, too—but am mildly concerned they'll get a notification and come start inspecting things.
And yet... it's like scaffolding in NYC[2]. Absolutely useless[3]. But if you are all for removing it, and a brick falls and hurts someone, heads will roll. Quite a quandary I - and other C-levels - face.
[1] https://www.computerworld.com/article/3089872/security/secur... [2] Another contrarian passion of mine. [3] Bricks do fall and hurt people. But no more than scaffolding itself falls with the same effect.
It totally makes sense to lock down machines that can access production, but for development? Just let people use what they like. You'll have less work for IT, happier developers, and an easier time recruiting talent.
Macs do not allow running unsigned software by default, and no one runs antivirus on Mac, ever. So even if they were commonly being infected, which they aren't, the person above would have organizational indemnity if someone were infected because they're following industry best practices by not running antivirus on Mac.
If you want, you can further restrict Macs to only App Store software, which is heavily sandboxed. Then you can go even further by not allowing the individual users to install software on their own, if you really want to be draconian about it.
Unless someone is being individually targeted, running very outdated software, or is intentionally trying to get themselves infected, it will not happen. Even if all three conditions are true, it's still very unlikely.
Anyone who says otherwise is just fear mongering. That same level of fear mongering could point to the dozens of pieces of malware that have been released for Linux.
I say this as someone who uses a Linux laptop for work and a Windows desktop at home. I don't have a dog in this fight. I do, however, try to stay very informed about the state of software security.
My company-issued MBP is running something called "Cylance Protect" (and "TrendMicro" earlier). And also something called "Forecpoint DLP". I have no control over any of that, software just appears and disappears. I think it's done by something called "Jamf".
I don't really care either way. The only thing I actually use on the Mac is Chrome for email/calendaring/vidconf and some intranet sites. Actual work is all on Linux servers via ssh (and even that has "ClamAV" antivirus running). So I'm just using it as an expensive terminal/chromebook.
We also have the Forcepoint nonsense.
Working at a large company (also not one of the famous silicon valley tech companies) and if you get a macbook, they are managed remotely and have BitDefender installed.
Also, p4merge is the best merging utility for any VCS, and I always install it alongside git if I work in Windows.
What makes it "the best" ? Honest question, i found it kludgy and settled for Kdiff3.
Enterprise volume licenses. It probably cost them less than the time/money they'd lose if you spenta few minutes trying to figure out how to open some file sent by non-devs.
Nice graphical tooling and sane developer experience.
Perforce integrates very nicely with a whole bunch of third party tools in a way git does not, and is on the whole a lot easier to use for most people than git (and I'm saying this as someone who doesn't like Perforce at all)
Said as someone who likes perforce. Having hundreds of developers working with large binary files was incompatible with git until very recently.
Maybe 5+ years ago?
All my actual work was done on Unix/Unix-like machines on our own old network, something we clung on to after acquisition.
I used to really like Mac OS X, but nowadays it feels much less polished and much more annoying. It might just be nostalgia, but I remember Leopard being more responsive and having fewer pop-ups (Screw you, iCloud! I don't want to synchronise my files!).
Additionally, not sure about you, but the reason I like to develop on macs is due to the fact that I can test nix software on them. That means I am installing and running nix binaries either via browser or through package managers such as pip. There is absolutely a non-zero risk that Linux malware will somehow find its way into my development environment. I am not trying to fear monger, as I do believe macs are still generally the safest, but don’t let them lull you into a false sense of security
What "zoo"?
To this day, Macs are practically virus-less, which they always where (99.999% of the scares in the media were for trojans, and even those at worse affected something like 1-5% of the total user base) -- nothing like the good ole Windows (XP and pre) days where after 1 day surfing the web you'd have a few viruses.
And of course if you go with the default options (gatekeeper, signed packages, etc) you have even less to worry about.
It's also not about "market share" -- Macs had 1/4 the market share they have now in 1990-1997, but there were tons of viruses for them under the old OS.
It's not like the original (pre-many security features were introduced) OS X was specially hardened or anything, but it was much more secure than Mac OS and the old Windows versions just by having a basic UNIX-style design.
Exactly what I'm talking about. Not to this day, but to some time back in 2015. Right now any trojan toolchain on the black market comes with a Mac-targeted package.
This is a question of shifting liability and sharing responsibility. If a brick falls when you knew the facade needed maintenance, then the liability falls solely on the building. If the scaffolding falls, then the liability is borne by the scaffolding company, or at least shared.
If people you respect are pointing towards antivirus protection, you might also want to inquire whether they are saying this purely out of technical reasons (i.e. surface attack area, which could be debated), or if there are financial risk management factors tipping in this direction.
Since you're picking the OS for everybody in your company, which presumably includes multiple departments and staff who are non-technical, it seems like madness that you'd let them run amok without some level of antivirus.
But -- leave the poor developers alone. One hopes that the company was capable of hiring technical staff practicing basic day-to-day security hygene.
Not trying to be hostile.. but why aren't you? I've never worked anywhere that required anti-virus, so I know there are jobs out there that don't require it. In recent years I've gone so far as to take the stance that I won't use company computers at all, only my own, and I still haven't had any problems finding work.
Unless you have strict restrictions on switching jobs (eg. H1B, can't move for reasons, bad network connections so no remote work, etc.) nothing should keep you from finding better working conditions.
But big companies have internal security teams which basically handle all of this behind the scenes (until you get road blocked weeks/months when they come out of the woodwork to make your new product secure - a very necessary annoyance)
No, most people would rather install an IT certified anti-virus on their systems and keep the customer, than lose the business opportunity.
Didn't think so
But before I did that, the one-before-the-last place I've tried to work was this hostile environment where everything was Windows and MS-based, as far as what we were meant to use for work. I couldn't bring my own lappy.
I ended up writing an AutoHotkey script that would get mouse scrolling about 80% sane and manage my clipboard.
I set up a VM on our HPC cluster, on which I'd do my actual work by way of VNC and sometimes SSH. The LAN was OK, so it ended up being less laggy than Windows on my local machine.
But I suppose a local Q frontend to a VM hosted on my work lappy would have worked too. Virtualize the AV away, yeah.
Cheers.
I used to run AlwaysMouseWheel to fix up focus scrolling, but forgot to set it up after my last reinstall. Thanks for the reminder! :)
http://www.softwareok.com/?Download=AlwaysMouseWheel
As for the other stuff, ugh. I've made it a general rule not to work anywhere where I don't get root on my own box.
Do an internet search for TreeUp.
At home I run KDE Neon, when people see me use that laptop (1 y/o Asus, core i5, 8 gb ram, standard ssd) they always comment how snappy and fast everything is and ask me what laptop I use. Even my neighbor with his brand new Win10 desktop with NVMe drive and new i7 cpu.
I do this in my case but for different reasons and not performance.
Depending slightly on the company, that is often a complete and utter waste of time.