You don't even leave the built-in Windows Security (or Defender) running on Windows?
I haven't noticed any performance impact or false positives in the years it's been running, and it is supposed to be highly effective. Better safe than sorry I guess.
Although I have never had a virus in 30+ years.
Is there even an option to disable it? I disabled what I could on my VM and it still eats up all my CPU and memory (I should maybe get a faster laptop, but it works fine for everything except this, and I only rarely need it to test something).
I would love to know too how to disable it completely.
And you can disable it, but only with hackistry.
"Although I have never had a virus in 30+ years. "
And this might translate to: you never had a virus you were aware of.
Most professional virus are quite silent and don't want to be noticed by doing noisy stuff. Their point? Spreading everywhere, until they find a high value target. But I doubt windows defender is a defence against those.
But a criminal gang won't risk attention, to steal some bucks of a poor linux hacker, who potentially will raise hell, to find out how that steal happened.
Which is the reason linux is more secure in the first place - there is simply plenty of easier prey elsewhere.
- Every time you open a network drive in Windows Explorer, it will (sometimes?) partially download the contents to scan for viruses. It was noticeable on wifi.
- If you run grep in a large repo (in the multi-GB range), it will scan each file before letting grep access it. Ripgrep is multithreaded, but that didn't matter since Defender seemed to be single-threaded. I could see it pegging just one core as it made sure none of those text files had a virus.
I ran Process Hacker, which had a tray icon you could quickly hover to see what's using CPU. I noticed Defender slowing things down often enough that it had to go.
Antivirus is not an effective way to protect against Zero-day exploits. Antivirus is effective against known threats, but zero-days are new threats that antivirus programs are not designed to detect.
In general, it's important to remember that malware involves multiple separate steps, typically today something like the initial exploit, a downloader, and persistence, which may retrieve additional payload binaries. Even if your antivirus is completely unaware of the original exploit, it may detect the downloader or persistent binary. This common problem (for malware authors) has lead to work on things like fileless persistence but those methods are more difficult and less reliable, so a lot of malware still needs to drop a persistent binary somewhere and use one of a fairly limited number of methods to get it to start again in the future. This is a huge opportunity for antivirus to detect a problem no matter the original exploit, and one of the things that antivirus is most effective at.
There is also heuristic-based protection, and in practice few host-based security solutions are purely signature-based. Heuristic protection has significant limitations but can be effective, especially for common malware patterns like loading drivers (no longer as common on modern Windows due to restrictions on driver loading). Heuristic-based systems tend to make enemies of their users though since it's difficult to tune them to be at all effective without a noticeable false positive rate. You see this a lot with packer detection: a lot of AV products use heuristic methods to recognize common packers (obfuscators), with the result that some self-extracting executables and commercial obfuscated binaries will also be detected. There's a lot of interest in machine-learning heuristic detection, but the false positive issue limits its use so far.
So there's an infinite supply of bad binaries and AV companies are by definition, behind. Basically selling snake oil that promises to help, but never will.
The reason is maybe the least satisfying of all. Because there is a rule somewhere saying that all workstations have to have an antivirus, Linux or Windows, same rules. Since "apt install clamav" is easier than arguing against the rulemakers again, that's what we did. And it is also not completely stupid, Linux viruses exist, and detecting malware on unaffected system is good too, because chances are that uncaught files will end up on vulnerable systems later. But really, the main reason we installed an antivirus to comply with some corporate rules.
It's very important to distinguish between what is actually required for compliance, and what is being done in the name of compliance, and make sure that "compliance" isn't just abused to shut down discussions easily.
SOC2 does not have any criteria specifically requiring antivirus software.
The actual requirements are more generic; for example CC6.8: "controls to prevent or detect and act upon the introduction of unauthorized or malicious software". That doesn't even sound like an unreasonable requirement to me.
If your company reads "no computer without antivirus" into that, that's on your company (and what they put in their SOC2 Type 1). Of course AV manufacturers will gladly agree that it should be read that way, and auditors will be more familiar with that approach. But if you can achieve the same in a different way, that's ok too - you just have to write it down that way. And the auditors can be reasoned with - their focus is anyway more to verify that you can show evidence (e.g. screenshots) of actually doing what you wrote down.
On servers, it picked up a few exploitable (but uninstalled) packages from our Debian mirror, and a few EICAR files. So, no actual threat averted.
* A better application firewall (like Little Snitch for macOS, OpenSnitch looks promising)
* Sandboxing by default (falling a bit behind macOS, bubblewrap is a good solution)
* Better package management (Nix is SOTA, but we need better tools to monitor upstream against malicious commits)
* Better monitoring tools (that take advantage of eBPF and report suspicious activity)
Imagine you are running a compromised package installed with e.g. pip. This could provide a last line of defense when it tries to steal your data, if it's not supposed to make certain connections.
If you check it out, we'd love feedback!
My gripe with flatpak is that it mixes up a (imo bad) way of packaging with sandboxing.
In fact there are some proposals to add sandboxing to nix, which is the antithesis of flatpak, using bubblewrap.
Firejail is a more usable alternative and comes with very sane default rules, e.g. only allow Firefox to see the Downloads directory in home.
However, it has a much larger attack surface than bubblewrap [1].
Has anyone ever caught a thing with it running? It's exclusively a checkbox item for security. Does nothing but take up RAM. Tell me otherwise.
If you run it behind a NAT, you'll need to run an internal virus database server. They rate limit downloads per IP. So fetch theirs once per day, serve as much as you want internally.
Groups doing Windows malware are routinely doing things like reverse engineering vulnerabilities from binary diffs within hours of Microsoft releasing a patch. If they would spend even a fraction of the skill and effort on targeting Linux desktop users, plenty of Linux users would be owned fast. And unlike with Windows, the Linux community as a whole hasn't spent years evolving ways to respond to this quickly (with the notable exception of _offering_ security updates to address vulnerabilities quickly... through some channels and not others, and many users update twice a year at best).
How much software from hundreds of third-party repos (e.g. AUR) and third-party package managers (e.g. pip) do devs use? Taking over an abandoned package (maybe a dependency of a more popular package), or worse actually legitimately maintaining a package for half a year before adding the malware, isn't hard. And once the malware is on the computer, there are few safeguards for the actual data (malware can probably encrypt $HOME or exfiltrate ~/.ssh/*).
The Linux ecosystem is more than the kernel; it's everything other than the kernel that needs hardening. Especially the culture; the "it can't happen to us" attitude needs to go.
And the other half have ClamAV? Why _wouldn't_ they be targeted, surely a large number of proprietary technologies are developed on linux
No malware can reach every system, especially in the Linux world which is so fragmented. Users will only use repos relevant to them - for example, Fedora users won't use AUR/PPA, malware on crates.io would only reach Rust developers etc. Also, it would be much harder to get malware into any distro's primary repos than dedicated "lower standards" repos like PPA/COPR/AUR, which many users simply don't use. And realistically malware authors will only be able to infect some packages, and for some time.
They are also vocal about changes so when someone notices something in their package it will be shared quickly.
What else do I need to be worried about using linux?
the latter might be via a local kernel compromise, but that's challenging if calling home is hard. otoh, sudo is often installed...
As for Linux... I was trialing something at a last job and it slowed compile times to 1/3 of the speed and did some other things. Glad I could save my coworkers the experience by writing a detailed report of why this is a bad idea for dev machines.
PDF's for example can embed JavaScript.
Clam alerts to those with malicious payload.
I am sure there are false positives but I don't want anything embedded in my PDF's.
I use xPDF reader and feel relatively safe. It does only the bare basic.
Nevertheless I like knowing whats lurking inside my PDF's on my disk.
Deleting any PDF with embedded JS is fine with me.
For that I salute you ClamAV.
Two issues that have been pit falls on windows. The user puts too much trust in said AV system, not understanding its limits and capabilities, subsequently stopping doing his own due diligence in the vast depths of the net.
Also, historically AV programs were used to breach systems. They usually enjoy a high level of access, but the team behind these programs isn't magically bigger than any other piece of software. As such a target for attackers, who study the AV software to circumvent it and as a result, may stumble one ways to use it as an attack vector.
e.g. historically anti-virus engines have had bugs where e.g. when they search inside of a .zip file; their .zip parser was susceptible to a buffer overflow that would have allowed a malicious file when scanned to run arbitrary code.
e.g. some anti-virus software has a daemon that runs on localhost with an exposed port. This port receives RPCs. websites in your browser have been able to make requests to the anti-virus daemon.
You can have false positives and false negatives, which can cause even more problems and train people to ignore whatever the antivirus says.
The antivirus can cause security problems as well, things like man in the middle proxies to scan HTTPS traffic, but they "forget" to check the certificates, which handily disables the entire point of HTTPS.
Basically it's makes security worse, and consumes resources that would be better used elsewhere, like say with a whitelist.
Why does this matter? Most malicious things someone would want to do don't require root. eg. VNC, DDoS, mic / webcam capture, token stealing, keylogging, ransomeware, stealing ssh / pgp keys, adware, backdoored web browsers. And for the small percentage that do you can just backdoor sudo or make a fake system update dialog that captures the user's password to let you have root whenever you want.
I'm not sure if by virus you mean some specific definition, but malware can still result in a very long and painful day/week/whatever with just access to your home directory and nothing else.
What would happen if your ~/.aws folder was piped to pastebin? Even if you're using short-lived STS sessions with ephemeral keys, I imagine most people would still find themselves in a world of hurt.
How about sending interesting files from your browser's userdata directory? All your cookies, your browser's password manager, possibly copies of your third-party password manager's cache (even if it's all encrypted), copies of cached files, your Downloads directory.
Perhaps in some distros, but not so much elsewhere.
> Do you need to touch AWS infrastructure from the same account, host, vm as you read email or surf the web?
In short: Yes.
> do these environments need full, direct internet access?
Not sure what you mean by the environment, but in general, yeah - a whole bunch of tooling these days is basically unusable without internet access.
It's also reasonably common for an exploit to become known by AV vendors and have signatures released before it's been widely patched. Turnaround time from a major exploit becoming known to the industry to a signature release by AV vendors can be as short as a day, especially with the significant intelligence sharing that now happens in the AV industry. AV vendors sometimes release signatures before the exploit is publicly known as a result of information-sharing agreements, although this is a touchy issue because the signatures themselves become a form of public release. While keeping software up to date tremendously reduces risk, there is still a window of opportunity.
XKCD 1200[0] disagrees:
> If someone steals my laptop while I'm logged in, they can read my email, take my money, and impersonate me to my friends, but at least they can't install drivers without my permission.
Mobile OSs are way ahead in terms of security and the other two major desktop Os also does at least some mitigation against potential attacks. Yet our .ssh folder, web cache, backups everything can be read/written from the same user account one uses for npm installing any random package which has the potential to just encrypt your whole home directory..
TPMs and Passkeys are also a good refuge - Just keep private material off the device.
What I'd like to see is a boundary between system installed packages (which I implicitly trust, but worried about malicious commits upstream, as others have noted) and other code, such as installed via pip, npm, cargo etc.
While it's feasible for me to audit a single shell script, or a PKGBUILD from AUR, it's pretty impossible for modern lanaguage package managers.
[0] https://www.bleepingcomputer.com/news/security/antivirus-and...
[1] https://rack911labs.ca/research/exploiting-almost-every-anti...
Where I’d prefer to see time going is basically two areas: rather than trying to catch every possible bad thing, only allow know okay binaries to run (the hard part being supporting software developers), and extensive sandboxing to catch up with Apple. It’s hard to block every possible bit of bad code but we can minimize a lot of the damage if, say, a malicious PDF file didn’t mean the attacker could just read AWS credentials or SSH keys.
The other benefit is that AV software has a history of security problems. Most of that is that the vendors still use C like it’s the 90s and putting complex binary decoding logic into a privileged context is a recipe for bugs.
Virus companies seem to focus much more on marketing then technical excellence. They typically run with full privs, regularly download code/rules from a central server, and are often written poorly. Seems like the industry is awash in security issues: buffer overflows, false positives, false negatives, not checking signatures on downloaded rules/code, and breaking various APIs, network protocols, etc by playing man in the middle. Even things like proxying SSL to scan traffic for SSL downloads ... but failing to check the cert.
So I see little value in running a closed source daemon from a anti-virus company to catch binaries that no serious attacker would use anyways. I trust the binaries from the OS's repos MUCH more than the antivirus programs. Similarly I don't trust IBM's BigFix that was malware Gateway used to help profit from tracking users and showing ads with their special "dock" that came installed on Windows systems. They of course made it very hard to uninstall, since that maximizes their profits.
Generally it seems like the wrong approach. If you want to do it right, have a whitelist for approved binaries. Ideally hooked up to your local mirror/repo so you can have approved signatures for all binaries BEFORE said binaries land on your Linux boxes. Spend whatever resources you would on anti-virus on patching, reporting, monitoring, firewalls, training, etc.
So in short, the questions we should be asking are:
1. How do viruses find their ways in?
2. And, what can be done (as a user or developer) to prevent that?
These are obvious, I know, and the software devs for Windows aren't deliberately writing insecure software, but these questions are ones better seen from a behavioural point of view.
I like that deep dive Clam gives you inside files. Finds lots of PDF's with JS. Naughty little kiddies.
Was this irony, or has the world become even weirder?
Nope, it's definitely the latter. Microsoft released a version of Defender for multiple platforms including: MacOS, Linux, Android and iOS. IIRC there's personal and enterprise editions both linked to 365 through "Microsoft 365 Defender".
I really can't imagine it doing much especially on iOS, it's there for the security checkbox/policy I guess.
Sources: https://learn.microsoft.com/en-us/microsoft-365/security/def... https://learn.microsoft.com/en-us/microsoft-365/security/def...