Maybe the "this will be easy" part was that without AV software, there was a greater chance that they could just spin up Metasploit, and wouldn't even have to use one their stockpiled zero-days?
Maybe the "this will be easy" part was that without AV software, there was a greater chance that they could just spin up Metasploit, and wouldn't even have to use one their stockpiled zero-days?
The difficulty level is "recompile with small changes and test that it doesn't match" not "develop a new attack vector"
It really is stupid and pointless against an attacker with even a bare minimum of competence (able to run a software build vs downloading binaries)
Just a reminder that I was originally talking about desktop Linux, and all of the additionally installed attack surface which that entails.
It would seem to me that it does not matter how "technical" a user is, they are still human, and some of the time anyone could fall for a well formed phishing attack. We all get tired, overworked, or click too fast, etc.
Not running AV on a desktop OS and relying on one's own superhuman technical ability seems like the exact type of hubris that would be ripe for attack.
See another user's comment: https://news.ycombinator.com/item?id=38594247
Security is an onion, perfect is the enemy of good, etc...
Why make it easier for the adversaries? While annoying, running EPP on your desktop OS is not exactly neuroscience.
Ideally, it's furnished by the OS provider so that there are fewer parties to trust. I hate to say it, but Microsoft is now teaching by example. MS has factually one of the best-in-class Endpoint Protection agents on the market.
If resources allowed, all other desktop OS providers should follow suit, otherwise they are just shirking responsibility.
Would love other input as I’m not an Ubuntu daily driver anymore.
It turns out 22.04 has ClamAV “provided and supported,” but not installed by default. So it should easily install manually. That’s what I would go with first, as it’s officially supported. An OS vendor supporting a specific AV vendor is a really big deal imho.
If that is not satisfactory by some metric, and this is just my personal and dated opinion… I used to like Eset.
I was naive before, but next time I install desktop Ubuntu, I will install ClamAV immediately.
This means either:
- a 0day, which would require the AV to have a PDF parser better than the standard document viewer, and the ability to sense that this PDF is "weird" -- I would expect AV companies to publish ads "our AV has detected a 0day in XXX"
- a vulnerability was recently discovered in a PDF viewer, and the AV company can push their definitions earlier than the standard "package the fixed version - send to debian-security - let users upgrade" route. This would shorten the attack window by a few hours. Again, I would expect AV companies to boast "we were X hours earlier than the official fix".
Which one is the case? Or is there another option?
Actually, this whole "buggy PDF parser" thing should be solved by application sandboxing -- there is no need that document viewer needs any other access to my system. Unfortunately, Linux is lagging behind. There are some AppArmor experiments with not so great UX, and then there is QubesOS, which is difficult to use. The average Linux desktop is AFAIK almost unsandboxed.
I am now at the limits of my understanding...
I only ran Ubuntu as a desktop daily driver for a year or so, and I'm a muggle, so my understanding is limited. But, is there any real-world data on how often desktop Linux users run the equivalent of:
sudo apt update
sudo apt upgrade
sudo apt dist-upgrade
versus the more automated update systems MacOS or Windows ?I am genuinely curious which ecosystem is more likely to be up to date. In my limited experience, I ran into issues updating on Ubuntu, and have not on MacOS and Windows. It seems like MacOS does it best as most applications come via the App Store, and on Windows that's in the future leaving most apps to take care of their own updates. However, Windows makes up for that a little bit with excellent, and auto-updated EPP, so that's something at least.
In your view, which desktop OS is most likely to be up to date for OS and apps?
> versus the more automated update systems MacOS or Windows
I'm not sure -- it is better with Microsoft Store, but other apps solve updates on their own, with various success. I have little experience with Windows and no with mac OS, so I cannot comment.
It is not a meaningful technical barrier. It's the equivalent of storing a big table of mean things people said in a chat and suggesting this could prevent a capable person from insulting someone. Any moderately competent person can think of a way to communicate without using previously blocked phrases with minimal effort.
The AV databases are known - it is trivial to test against them to ensure a binary won't match.
AV is a crude tool, good only for blocking the most basic of efforts. It has no utility against a nation state.
Are you referring specific'ly to a limitation ClamAV?