The Antivirus Era Is Over
technologyreview.com
technologyreview.com
When I was using antivirus software, it never set off any alarms once. I still occasionally install and run antivirus software, it doesn't find anything, so I remove it again. I've sat in the middle of major virus outbreaks inside companies and not be affected.
I have no idea how people manage to get infected. Every time I read about some malware scare, I look at how it spreads and think to myself "but... why would you do that?".
In the 80s we had boot sector viruses that would bite you as soon as you inserted a disk, and disks where the only way of exchanging data. You couldn't protect against those without antivirus.
But today most malware seems self-inflicted, and only spreads through naivety, ignorance and laziness.
Sure, I could still get infected tomorrow. After 25 years of computing it's bound to happen to me at some point. But it will most likely be because I did something I shouldn't have, not because I don't have adequate anti-malware protection.
But today most malware seems self-inflicted, and only spreads through naivety, ignorance and laziness.
I assert that stereotypical "stupid users" were indeed the cause of most virus spreading in the 1980's and 1990's. There is still a fair amount of "stupid user" stuff happening these days, such as clicking on a link in an email to log into your bank account. (1)
However, these days, I'm also worried about exploits against browsers. If you have your system infected by just by visting a webpage, I don't consider that the user's fault.
Every year that goes by, the browser gets more complex (like recent support for 3-D rendering), and the attack surface increases. I'm glad that most browsers are fairly secure, but they're not perfect now, nor are they likely to be in the near future.
(1) It continues to annoy me that two of my banks will send out legitimate emails (new bill, etc.) that have clickable links in them. If the banks would stop putting links in their emails, and try to educate their users to not click on links in emails, that would reduce the problem.
I'm starting to consider a lot of these exploits and security problems to be the developer's fault. Too many attack vectors are well-known, and should be accounted for in the design of software.
For example, overflow exploits: Why, in this day and age, do we still default to writing software that works with untrusted data in languages that don't enforce bounds checking? C++ has many virtues in many situations, but it's not a language for writing web browsers. For performance-critical modules that are small enough to make serious code auditing feasible, sure. But as the primary implementation language it's just one big vector for attack that pervades the entire codebase.
This a million times. It never ceases to amaze me when I see this. It shows even the banks don't understand security!
until I connected my laptop to the network at school.
I didn't notice anything strange until a month later when I reinstalled WinXP (was doing it regularly for speed). My mistake was that I installed Winamp and other software from kits on a shared folder (full access for everybody) on my laptop, before installing the AV. That's when all hell broke loose: the kits were injected by some virus and got activated only when were run
tl;dr: Thing is even "power-users" can get it wrong. Is it really worth it risk so much, for so little?
PS: referring here strictly to platforms that need AVs
Now, this doesn't mean that antivirus is useless, or that the antivirus era is over--by the logic of this post, the antivirus era was over the minute it began. What it means is that antivirus is a tool that helps protect you against "stupid"/mass malware, but not a tool that gives you any kind of "complete" or "100%" protection (although every AV vendor will certainly try to convince you that their products do), and this is particularly true--today as it was 10 years ago--when it comes to malware that isn't widely distributed, or, put more fashionably, "targeted malware" and "advanced persistent threats" (hence: malware which belongs to a "family" that hasn't been caught, analyzed, and added to a binary/behavioral signature/heuristic database of some kind beforehand.)
Sure, antivirus has never been 'complete' protection but, speaking from a lot of firsthand experience, some of it used to be pretty darn good compared to lately. Now even 10-15% protection from AV sounds like a stretch. Hence, in terms of the soho PC segment I've dealt with day to day, I'd say The Antivirus Era Is Over And It Has Been For Awhile.
I'm not going to dispute that AV vendors have become complacent recently, but 10-15% is on the low side. Most families of widespread malware are detected by most solutions within a few months (yes, that slowly.) It's probably around 80-85%, but, at the same time, 90%+ of the really dangerous (and especially targeted) malware is more often than not in the remaining 15-20%.
Ultimately, what this article and your comment insinuate is that you can uninstall antivirus and be "just as safe." That is not true (except in rare cases where the AV software itself is vulnerable and provides a way to escalate privileges.) I'm all for getting rid of shoddy blacklisting, but we need a replacement, such as innovations in OS security models (a la Chromium OS.)
> "Ultimately, what this article and your comment insinuate is that you can uninstall antivirus and be "just as safe." That is not true..."
Agreed, but at the same time it's hard to recommend paid AV solutions that don't really work for what people perceive as 'a virus'. What I've come to do is:
* de-emphasize the importance of AV to my clients; tell them it may help but don't count on it
* recommend running the free AV of their choice
* emphasize the importance of updates
* emphasize Chrome + 'Click to run' as the primary protection approach: http://www.pcstrikeforce.com/taking-chrome-security-next-lev...
> "I'm all for getting rid of shoddy blacklisting, but we need a replacement, such as innovations in OS security models (a la Chromium OS.)"
right on
So should malware authors all figure out what Flame (or other more advanced malware) is doing, and how to do it themselves, eventually current day AV _will_ be useless.
No?
It's probably more helpful to think of these classes of malware as being "obscure" or "wide-spread" than "smart" or "stupid" (I apologize for my previous analogy.) "Advanced persistent threats" don't really exist on a higher plane than common, boring malware (although these have included some impressive payloads), they're just tailored toward something specific in most cases.
I think it's a logical impossibility that all malware should suddenly become as obscure as these were. The payload can certainly be shuffled around, but nothing stops AV from recognizing and stopping whatever mechanism decrypts and runs them. That doesn't, in any way, make AV a panacea--but that's the way it's always been.
I guess we'll have to wait and see!
That is not to say that there is no malware any more, but the infection vectors have changed. More often than not, malware will be explicitly installed by the user. More broadly, it will trick the user into doing something that is not in his best interest.
In other words: In the current age, malware is targeting users, not computers. Now we have to install virus scanners, by educating ourselves about how to spot viruses. This is a very different game from a few years ago!
By the naïve measure of "my antivirus did not ever find a virus", which might not be 100% reliable, as the article points out. However, it should identify viruses eventually, though possibly too late. But it didn't.
Anybody who has worked consumer IT can tell you, it doesn't matter how many times a person's computer has been infected despite running kaspersky, they still absolutely depend on the messages from their av program to tell them it's all good.
People would like to make behavioral stuff, but it's quite difficult. Sandboxing sounds great, but it requires more processing power to run a VM, and the biggest complaint most people have about AV software right now is that it slows down the computer, so running in a VM with a behavioral model...yeah good luck. It looks great on paper, but has no been put into good use yet.
If you like to be secure, run 2 boxen, one that has no service except a logger, log everything from your main box, only log into the logger box from console when you want to look through the logs to see if something has gone awry.
FD: I work for a security company, and no, none of our products works like that. Most (all?) customers have a higher priority on useability of their network and computers than on security.
OSes should move to the opposite strategy, enumerating exactly what is allowed, and dropping anything else by default. The challenge here is that the granularity should be small enough for this to be effective, but on the other hand this gives configuration overhead for the user. For example, the firewall could enforce that only the user's preferred email application is allowed to send and receive mail. Currently the permissions in plugins and smartphone apps are too broad to be meaningful, but they're already experienced as a nuisance, so it's a difficult problem.
when they do, it results in hackers being emo about Gatekeeper or the app store or whatever.
That being said, that makes life harder for the user.
SELinux tries to do that, on a coarse level (but can't prevent user-inflicted problems).
According to Rice's theorem, you cannot in the general case prove any run-time property of a program solely by looking at its code, which means that can't 100% reliably detect viruses simply by looking at the code.
So user eduction is important, but hard to ensure across a whole organisation for example.
Of course, the instance of the javascript VM that is running the javascript from the website does not need filesystem access, so it can be, and normally is, sandboxed.
Not necessarily: to be on the Mac App Store, an application must access only files in its own resources (configuration and so on) or through user interaction (open file dialog). If your web browser gets infected, it gets full read access on every file you willfully want it to read. Problem, you cannot have a multimedia player that opens m3u playlist files in this model: see http://mplayerx.org/leave-mas.html
It was - in difference to the snake oil antivirus software sold commercially otherwise since then - also able to protect against unknown threats by creating a security focused virtual machine inside the PC and a sandbox around applications. This was the first VM available for PCs (1995)
The only links still visible that I could quickly find are: http://www.securityfocus.com/tools/803 http://web.archive.org/web/19990117023714/http://www.acrmain...
By they way read also their blog: http://theinvisiblethings.blogspot.com/