I spent about 30 minutes this weekend helping my sister-in-law debug a slow internet. My observations were that attempting to do anything resulted in about a 5-10 second pause, and general sluggish response when trying to anything online. I disabled anti-virus, etc. and it was still slow. I tried Edge and everything was super-fast.
Digging further, the issue was McAfee Safe Search (powered by Yahoo). It was singlehandedly adding 5-10 second lag on every mouse click and character typed in the browser. Disabling and blocking that resolved everything.
I think my favorite part of it is that the issue itself of blocking everything for network calls is like one of the first things I learned about Windows programming in the early 2000's.
It's not just rogue AV software. Buggy, insecure AVs are a big problem too. They're attack surface! Especially when running parsers and interpreters for untrusted inputs in kernel space.
(Granted, I'm a complete layperson in computer security, so there's likely something I'm missing.)
You repeat yourself sir
Personally I think that it’s ridiculous that these huge orgs fail to address the actual underlying issue, excel macros. But hey, it’s easier to fight the Symptome than to deal with the root cause, especially if the latter would impact established work flows god knows how far down the line.
There's a reason companies use excel.
I think one's need for a security product should match one's exposure to issues - it depends on your org. For a very long time I was not a fan of anti-virus, in 2022 I'm back to liking anti-virus (more like EDR these days).
Notably, autolaunching USB drives is also no longer the default option for USB devices. The user has to specifically choose what action happens when the device is first plugged in (and by default, that choice only applies to the current instance; the user must manually choose to have the choice apply the next time the device is plugged in).
Back when “I love you” virus started, we had pointed out something simple as “open for read” vs “open as in run/execute” should not have had the same interface.
All the new security enhancements we have today - don’t run as admin, alerts to request privileged access, sandboxing - all of them existed for a decade, but the software vendors never had the guts to weigh security higher than UX
Even the script kiddies fall into that trap, my old school got infected by a .pdf.js.js ...
For me makes a lot of sense being able to sell a software subscription instead of a one time product sell, and for the other hand making available to use in any device in the world with internet connection.
This also can be done like Chrome apps (like Docs) or some Electron apps (like Spotify), where you can use content without Internet for some time without any problem.
For a mechanic who is looking for the amount of torque needed on a bolt this could be perfectly viable, for example.
We're going to start talking past each other pretty quickly if you think this is worthy of a (software) service subscription. Torque specs belong in a manual (ideally on corporate intra-net or paper); I'm talking about when the engine is deeply unhappy, and you need more to go on than a driver reporting a yellow check light.
In the case of the latter, I'd say it absolutely deserves to be a 20 year old program (which tend to be lighter) that runs entirely offline. The last thing any garage wants to do is chase hardware requirements or search for a wifi signal either out in the yard, or in between hoists, lifts, and miscelleaneous heavy equipment / tooling - all of which tend to trash a wifi signal.
AWS even offers "Workspaces" as service for this.
Though it doesn't solve the "without the internet" problem.
All that other crap does the exact same stuff to other programs that malware does, except they do so in the name of "security."
Yet Mozilla contributes to the terrible shit that Google Safe Browsing is doing to independent and open source developers hosting their software.
I’ve been using Linux/Mac exclusively for the past 10 years and never even considered it.
Insecurity policies is correct, what you mean is protecting managers a* aka the antivirus failed on us ;)
I'm CERTAIN there are massive hidden costs in fan replacement and Laptop repairs and nothing useful discovered as a result.
What happened to defense in depth with all of the layers you can introduce?
Surely if you run a Linux server, you might want a secure password for it, or better yet, key based authentication. Port knocking? Why not, throw it in there as another layer. Maybe deny authentication on an IP range basis? Why not. What about fail2ban or some other solution like that to disallow brute forcing? Sure. Or maybe require using a VPN to connect to it at all? Even better! Actually, even running your SSH server on a non-standard port will be enough to get rid of some attempts to brute force the password.
Sure, key based auth makes many of those moot points so i probably have the order of some of those steps wrong, but surely there's a lot of merit in combining whatever solutions you can to make the end result more secure, right? Hell, if you're running a web service of some sort or an application for yourself, adding basicauth in front of it at a web server level is enough to act as a safety net should the auth functionality of the actual application be broken, until you patch it.
So why should Windows be any different? If i'm stuck using that OS, i'd surely want to use whatever software is available to me to make the uphill battle towards something vaguely secure more doable, no?
What happened was antivirus itself became your biggest attack vector, so you were more secure without it. Plus Microsoft actually cares about security now, which wasn't the case 10+ years ago.
Enabling protected folder access and process isolation in Windows 10 is also a good idea.
UAC still pops up whether you use an admin account or not - it just requires the admin password when you use a standard account (which is, of course, still more secure). But the real advantage is that the account you are using does not have those admin privileges in the first place.
The other big advantage is that if this account is compromised in anyway (say if you used the same password to login to Chrome and Windows on your standard account) the hackers only get the password to your non privileged account. Of course this can be mitigated as well by really good password policy but I find for the average user they often re-use passwords and separating the two accounts forces them to often re-use the one that matters least.
Sure, any program can delete the Documents folder, but how can you prevent that from happening?
The tradeoff for having AV is having a giant application in admin land which increases the surface area available for an attack. Combine this with the that fact you don't get much protection because a virus can just be modified until the AV doesn't detect it and AV's just aren't worth it. This trade off made sense 20 years ago because OS's were less secure so you were increasing your surface area by relatively less than you are now.
AV software, including Defender, is not useless, it is actively harmful because it prevents people from running legitimate software without any recourse for non-experts or the original developer.
Never again.
MSE is really all I've used since binning AVG which turned into bloatware.
I feel your pain. We have a load of other crap loaded such as Umbrella that is supposed to protect us from harmful websites. It does stuff like intercept DNS lookups etc. It's such a pile of shite and doesn't work properly when I need VPN into our cloud infrastructure. When it's configured so badly it feels really anti-work. But hey ho, "security reasons".
Even if you as an exec know they are security theater you are forced to comply due to these certifications.