Failure in Tech Journalism: Getting the Truth about Antivirus Software
raywoodcockslatest.wordpress.com
raywoodcockslatest.wordpress.com
There are a lot of issues with the industry around antivirus/security vendors. It is a very gross industry for a lot of different reasons, but the trying to tie that into how Google is evil and also tech journalism is corrupt and unfit makes the author come across so much weaker.
I’m also a little confused as to why the author, already unhappy with the free version of the product, decided to pony up for the paid version in the first place.
Semi-related: AV software plays a huge role in the security ecosystem and it’s value is unmistakable in that context but it is worth considering how we get there. The way AV software is sold and marketed is generally some of the slimiest, especially the non-big name stuff. We all benefit from the very wide net they cast in a collective sense but from the end-user perspective, especially as a technically savvy user, the cost seems outweighed by the benefit. Personally I’m of the mind that if anything is questionable I’ll run it through virustotal on-demand and make a judgement from their but also if I’m wondering that deeply enough I’m just as inclined not to touch something potentially volatile. This doesn’t work for a layperson but the stuff built in to windows is honestly more than enough for a casual user. If things have progressed beyond that, they need professional help anyways.
The truth is, that with the right behaviour you probably don't need any AV product. Don't click on weird links, use adblockers, don't open weird documents especially when they come via mail, keep your OS and software up to date, etc.
For all the other stuff (zero days) AV software won't help you and in fact AV software will often even increase the attack surface of your system (remote code execution via AV-buffer overflow is not a rare thing to happen).
On my Windows machines I am not using AV software since roughly a decade and I have not had a single issue. Telling people that they can click around carefree if only they have an AV software installed is irresponsible IMO. AV software is not a substitute for education.
You may have been infected by a botnet and your machine may be doing things without you knowing.
It is possible of course to have some countermeasures (integrity checks, baseline checks) but this is hard work.
Obviously, it's one of those things that is rarely done by the people who use fancy security products.
.. because it’s hard
E.g.: Botnet traffic is often “strange” and easy to recognize
In a home setting, I do not see how manually analyzing the network logs can help (not to mention that most of the traffic is encrypted). You then have integrity checks on files, IOCs you need to check your files against etc.
Basically this means you have to rewrite an EDR from scratch.
Fancy security products are not always a way to check a box in an audit it also means using a product that you otherwise would need to either write, or put together from many pieces.
Just look at wazuh (open source EDR+) and when you go past the intro you ht some hard walls (especially with updating IOCs from external sources).
Security is really hard, but doing it yourself is really, really hardest.
At home, OS and software updates combined with network monitoring should be sufficient for the more common threat models.
One needs to draw a line somewhere.
EDRs are complex and often fail to protect business systems when professionally managed. I do not believe it's worth wasting time on that at home.
I haven't used an AV since before Microsoft Defender. I don't even remember. I had no need and considered them a scam, but I'm aware that lots of people are literally helpless against them.
That out of the way, I did catch a few things occasionally, but not even once a rare. Before there were SSDs it was actually really easy to spot when your system behaved differently, simply because the system started acting differently.
I'm sure, or hope, you remember times before the were SSDs. Things took time to load. Windows took time to pop up. One could hear his harddrive doing it's work.
And that's how I spotted a virus I've caught from * microsoft.com, somehow, I don't know. Suddenly the system's timing was complete off. Things took a quarter second more longer to load, irregular hardware accesses, etc.
So I took a look into the task manager (TM) and noted that there was a program that sounded "off". It didn't feel like it belonged there. I had a rough instinct about what's running in the background in a normal system, so that definitely helped.
I even got rid of it manually and because I can type pretty fast I'm going to share the rest of this story. ^_^
It was actually pretty easy. Killing the process in the TM made it restart again automatically, so I've went out seeking the file in question. If my memory serves me right it was pretty easy, using the TM itself.
Sadly there's no great hacking story behind this. Accessing the executable in question wasn't possible while it was running, so I've made a command line ready to rename the file when I've killed it. That was pretty much all it took and after a few attempts I've nailed it.
Deleted it from the harddisk and that's the end of it.
So ... you can notice based on the timing of things happening on your computer. When they feel off, then there's a good chance something's unusual. Same goes for your computer temperature and fans spinning.
When you notice that your fans are spinning up more often, or your internet is suddenly slower, then you should check if there's something wrong with your system.
There are tons* of data points one can use to assess if the system is acting normally, you just have to notice them. :D
I'm sceptical. Conventional cybersecurity wisdom is to take a serious approach to both keeping nasties out of your systems, and limiting the damage that may arise if/when nasties make their way in.
(I'm using nasties to cover everything from infected files to unauthorised SSH sessions.)
> For all the other stuff (zero days) AV software won't help you
That doesn't sound right. Trivially, AV will help you against all malware that the AV is able to protect against. If you always do a perfect job at keeping that stuff out of your systems, then sure, AV adds no value, but I wouldn't assume that the premise holds.
> AV software will often even increase the attack surface of your system
True, and this is especially troubling considering AV code tends to run with high privileges, but that doesn't show that AV generally does more harm than good. The balance presumably depends on the quality of the AV you're using.
> AV software is not a substitute for education.
No one is suggesting that it is, they're saying it's a useful additional measure for some systems.
Yup, that is sort of true. However, I would not recommend to go unprotected to my friends.
I reckon there are some terrible AVs, some that should not exist anymore.
Yet, an AV can be taught to stop a zero day faster than an OS update. If you happen to step over a zero day, an AV software will find the file's signature faster than you restarting your computer to install the update, whether you have Windows, Linux or macOS. Windows Defender is just dumb, regarding to features and performance.
My selection criteria is to not trust anything outside of Virus Bulletin's VB100 and AV TEST's certification. These are independent reviewers.
The problem is that you're not accounting for ads, which have been used often enough as distribution networks for zero-day exploits, and other forms of drive-by infection. A virus scanner can't help against the zero-days itself, but the payloads are usually the same generic bullshit that will be picked up.
Whatever you do, don't use McAfee. And definitely don't use some other random software you found online no matter what the reviews say. This type of software is always incredibly invasive. There is almost zero reason to give this much power over your system to another third party.
Boot to Firefox was improved by at least 30 seconds, navigating the file explorer felt much smoother and security was probably improved as well.
For home users, I don't see any reasons to use a third party antivirus nowadays.
AVs and other "security products" massively increase attack surface (sometimes by literally disabling protections that the OS itself has, but usually by just being buggy and insecure in itself and doing things in obviously bad and insecure ways to be faster) and have been leveraged in so many attacks now that it's truly remarkable that there is zero change in how people think about it.
RKHunter doesn't look so bad but malware is such a non-issue on Linux if you stay away from wordpress and npm so I don't even bother.
!?
A great many US products and services have similar approachs. Think ISPs, gyms, the NYT, etc.
I agree the behaviour is scummy, but no need single out Romania for it.
I'm really not seeing the difference between their actions.
If people want good journalism, get it from a good publication with real editorial firewalls and standards. If you're reading blogs, you're going to get blogs.
They tend to hook into system calls and slow down the computer in hard to diagnose ways. Sometimes they don't implement the hooks correctly and cause subtle bugs on top of the slowdown.
I only use built in ones (such as Windows defender) which at least have the pushback of some other teams that own the APIs that are intercepted and tend to strike a better balance.