Kasper-Spy: Kaspersky Anti-Virus Puts Users at Risk
heise.de
heise.de
My company has Windows Defender (which does a fine job by itself), McAfee, and CyberArk EP (which AFAIK, just does exe vetting on-demand).
I start my laptop up and it uses 50% of it's 32GB of RAM (not cache!) from a cold boot. Granted there are some IIS services and whatnot dev tools running but still.
Plus the kernel just hangs every other day for a couple minutes. Yay!
At my last job they also used McAfee in addition to Defender but I found a way to uninstall it. And the local IT guy gave me a pass when his management console said mine was unprotected.
They configured Symantec also to scan files by every modification _and_ access. If something happens a lot during compilation it is disk I/O with a lot of small files.
Not to mention they staple additional anti-malware solutions like CA Carbonblack, Microsoft EMET and Avecto Defendpoint on top of it. Probably every Windows API call is hooked multiple times. Horrible is it.
Why isn't Windows Defender good enough?
Every enterprise deploying such software is expected to pare back the behavior to accommodate their specific risk profile, and in particular, to ensure that any high-performance tooling or internal software is exempted from most types of real-time protection. This is obviously much easier said than done in the real world, but it doesn't have to be an all-or-nothing proposition.
Well, since Microsoft offered free AV and then bundled with Windows, I'v never looked back and felt kind of relieved I don't have to install 3rd party AV. Defender just doesn't get in the way.
I trust Microsoft to do the right thing more than other AV vendors that put Value substracted features: ads, disturbing, user-hostile notifications, performance degrading bling-bling (toolbars...) etc.
If I really want to check some file, i'll let VirusTotal.com scan it via every AV product they are aware of.
One of many instances where MS takes the "I know best" approach. You want to write a good anti-malware program, try not behaving like malware.
The reason they make it hard to remove is (1) otherwise malware could easily disable it and (2) must people should not be trusted with such decision anyway.
Also, have you ever tried to remove Norton AV??
The consumer AV (Norton)? Hah, the thing is meant to trick/convince/harass you to keep paying up and make it difficult.
I stopped taking any software’s reputation for granted.
like spybot does it, but they are not opensource. ClamavNet is, but I never tried them.
So it wasn't exactly hidden, it was just a bad solution that could be disable deep-down some menu (but not hidden, as it was in the apropiate options).
They've still got some brilliant malware re & analysis guys and their lab is an excellent one, but I wouldn't use them.
No, not exactly. In reality the software worked as intended and sampled an unidentified program that it considered malicious. It just so happened to be a piece of NSA malware contained on a NSA employee's computer (who re-enabled KAV on his machine after infecting it with a fake Office activator). The US government needed a quick scapegoat and thus they picked the spooky russian company instead of their own employee.
After the allegations were made, Kaspersky opened itself up for third-party auditing of its internal processes, relationship with the government and the events surrounding the above, of which it provides regular updates of: https://www.kaspersky.com/blog/internal-investigation-prelim... https://www.kaspersky.com/blog/transparency-status-updates/2...
They're also moving all data processing to Switzerland, way outside of the reach of the Russian government.
[1] https://www.theregister.co.uk/2018/09/26/nsa_worker_jailed/
Just more political warfare bullshit.
I'm impressed the Kaspersky is going to these lengths to remove the means for the US government to baselessly criticize simply because they originate from a country that the US loathes.
Furthermore, the fact that the Russian government is seemingly okay with this simply adds to everything the Russian government is doing to nullify any of the attempts the US is making to accuse them with unproven lies.
One of these days, I hope that the US government loses it's grip on the planet, so that they have to play fair, instead of simply doing whatever they want because they're the de facto singular superpower in terms of military power and intelligence capabilities.
(1) TLA guy had TLA developed malware on his laptop
(2) Kaspersky recognized possible malware and uploaded it to their system for further analysis.
(3) TLA from another country has hacked Kaspersky system and alerts Americans that their malware is out.
(4) TLA tries to hide their incompetence by accusing Kaspersky of working with FSB to hack US computers.
I'm with the Russians on this one.
I dare suggest that even Microsoft isn't that much better.
The idea you can avoid getting infected by not opening suspect files is naive and generally comes from someone who hasn't tried to hack a system (even their own or a sandbox).