MS Security Essentials reporting false positives in the Bitcoin blockchain
answers.microsoft.com
answers.microsoft.com
>Just for fun, there's about 8000 reachable nodes on the network at the time of writing. Assuming that a large portion of the network is unreachable (NAT, filtering, intermittent, just not listening), it's probably safe to assume there's probably at least 50,000 nodes with the complete blockchain. If we XOR just the chainstate, we cause 50000 * 430 MB of disk writes, 50000 * 430 * 2 MB read and write combined, somewhere in the region of 43TB. If we XOR the entire blockchain on disk we cause 50000 * 21000 * 2 MB of IO, around 1.95PB of RW across the wider Bitcoin network. Incredible.
It's possible I misunderstand, and overestimate the value of full nodes.
Anyway - what does being a full node entail?
It takes a few hours to a half day for the node to catch up, depending on your bandwidth and CPU, but after that it requires relatively little processing time. But you do need ~20 GB of free hard drive space for the blockchain.
http://www.eicar.org/86-0-Intended-use.html
It's detected by almost any antivirus product, on my work computer the corporate antivirus immediately quarantines a file with this content.
X 5 O ! P % @ A P [ 4 \ P Z X 5 (...)
Nowadays, MSE is still lightweight, but it sits at the bottom of every malware detection benchmark. I've been recommending MSE to everyone around me, but recently they started getting all sorts of malware despite keeping MSE up to date. All of these were easily detected and removed by avast!, BitDefender, and Malwarebytes, but MSE just sat there like a cow, oblivious to the malware's presence.
Why has Microsoft let MSE rot like this? Now that MSE is built into Windows 8, are they afraid of getting slapped with antitrust fines if they shipped an antivirus that can actually compete with third-party offerings?
This year, I'm moving my family off of MSE. So long, it was good while it lasted. But third-party antiviruses have caught up in the meantime, and now they're just as lightweight as MSE.
Don't download anything sketchy, keep an updated version of your browser, don't run yourself as root and your should be fine for 99.9% infections out there. For the rest just keep MSE around.
Maybe I should get the paid version of Malwarebytes that can also do realtime scans?
The support team was unwilling to acknowledge and escalate my report that it failed to install the correct msvcrt, it just hopes it is already present.
(Which usually isn't a big deal, but it's not a way end user software should ever fail either)
Running a multi GB backup with Microsoft's robocopy cmd utility crashes the MSE service. That's really annoying.
Given that "Microsoft Forefront" is a rebranded MSE (it can be controlled over the network), I wonder why its real-time scanner can't handle ~100MB/s IO for several hours.
[1] I helped start up this team in 2004
Like this?
There were a few others, but that's the one i remember. the part after DCC SEND doesn't matter as long as it was longer than 8 characters i think it was.
bug report e.g. http://colloquy.info/project/ticket/531
IIRC it still bites a couple of people on Freenode, but the most networks have auto-kick bots in place for these scriptkiddies.
Bad firmwares would also accept same from remote side, although supposedly it should only have come from the local side.
And how recently string سمَـَّوُوُحخ ̷̴̐خ ̷̴̐خ ̷̴̐خ امارتيخ ̷̴̐خ could crash some versions of iOS and OS X.
That's why I believe in behavioural monitoring rather than signature-based approaches, since what's malicious is really the activity itself.
Full disclosure: I used to work for an AV software company and personally think that AV is a dead technology.
We're at a point now where what may have worked as a defence against stuff being found on floppy drives just isn't able to scale for today's modern infrastructure.
AV is really a last-line of defence against being forgetful, and nothing more.
You're oversimplifying modern AV by acting like it's just a signature based file scanner. That's just a one defence of many in a good AV product.
What the problem described in the story is that files are being picked up by an overzealous AV scanner doing disk-based scanning. It's reading non-executable data as executable and throwing alerts or performing whatever actions are dictated as per policy.
AV is not there to stop zero-day attacks--if it were, I would not be having this conversation today.
What you're describing is web filtering and this can be achieved using methods either internal or external--an external example would be a solution from OpenDNS and an internal can be whatever appliance makes you happy. AV vendors have thrown in web filtering as a part of their suite, but it still relies on your system being up to date and not already infected. An external solution to your endpoint is a far better solution really.
I am not oversimplifying things when I say that AV is ineffective at stopping CryptoLocker because file-based detections are useless when there are thousands of copies of the malware generated every day.
AV is dead because there is not enough manpower and coverage to stop things like CryptoLocker. It is better to spend those resources trying to prevent the spread of malware using other methods.
May be because I'm just biased because the damn thing used to start running every time my gaming session is heating up ...
Here's what typical AV scanners go looking for when running in their "optimal" settings:
http://community.landesk.com/support/docs/DOC-6651/diff?seco...
Not all Turing-complete languages are scanned. For example, CSS3 is Turing-complete but by default it is not looked at by AV scanners.
However, one can do some nasty things using CSS. An example would be when a troll was posted on a site that appeared to show some sort of Linux-based privilege escalation when in fact it had several <span> tags scattered about that would have not shown up in the browser but did so when text was copied.
This sort of thing can however be defeated by just scanning the web content coming through (and most modern AV software has this already), but even then an attack like that isn't simply going to be just picked up so easily.
I am well aware of where files can create havoc Turing-complete or not (such as my MP3 example), but at the very same time you're going to have headaches if you decide to scan every single file.
This again goes back to my whole point of saying that AV is a dead technology because you really shouldn't trust any file but it is not effective to scan everything either.
because something is "Turing-complete", does not imply it is capable of mischief.
something can be capable of mischief, yet not "Turing-complete."
It's true that the world is full of auto morphing malwares, but you can still detect them new variants through heuristics. Which in turn delivers the results to what is generally known as some sort of Antivirus Cloud Lookup or File Reputation Lookup.
Also the AV industry shares information between them. So in the background you don't have anymore analysts looking at every sample file. Instead there's automation that analyses each incoming sample.
The old scan databases you prefer to are usually last line of defense now days if all the other technologies before haven't been able to show the file to be known good file or bad file.
Full disclosure: I currently work for computer security company.
Heuristics are not a new thing in the AV industry and have been in the works even before the dotcom boom. Even with advances in it, it has been proven to either not scale or be absolutely worthless.
Anti-virus "cloud lookup" is just a stop-gap between signature updates. It's not a new idea and all you're doing with that is cataloging MD5s and making them available via whatever network server you choose to use. It's still a signature.
Here's a perfect example of why AV is useless: until 64-bit Windows was commonplace and before XP support was dropped, it was ineffective in stopping the likes of Aleurion (also known as "TDSS" or "TDL").
How did this malware work? Well, in its many, many different permutations, it would get dropped on a machine, become executed, and if the machine was running XP Service Pack 2 or less, it would make use of a vulnerability in the print spooler, get system-level control over the computer, and then it would infect the master boot record with its own bootloader.
How does AV remove it? Well since every time you reboot, it restores its copy of the malware, all it can do is scream that the world is falling because it can do absolutely squat about it. You have to remove it from the bootloader and then do a scan afterward while having taken the system offline.
What fixed the problem? Well applying a patch in the OS is what fixes the issue once and for all--SP3 was the easy way.
If heuristics really worked as you suggest it does, we wouldn't see Cryptolocker and the likes getting around AV. AV evasion is better than ever and heuristics have done absolutely nothing to solve the problem.
Since I don't use bitcoin, let me ask, does everyone have to download the whole blockchain to their computer in order to mine or receive/sent the coins? Wouldn't the blockchain be in XX GB size by now?
In order to have a wallet and just use bitcoin no the user does not need to download the whole blockchain depending on the wallet software. There are wallets that use public shared remote servers to access the blockchain that are reputable in the community.
https://darkwallet.unsystem.net/ (don't use yet, alpha)
Unfortunately, it appears that AV software completely ignores files larger than 32 MBytes, so it won't notice them in the blockchain— just the chainstate. And so the grand idea of putting the triggers in coinbases didn't work there.
The other fun thing is that the EICAR test trigger is too long to easily stuff in a transaction. Unfortunately there are other "signatures" which are as short as 16 bytes.
After some consideration and the feedback here https://news.ycombinator.com/item?id=7543196 I decided to inform one major antivirus vendor about it. They offered their thanks for the warning, but also the opinion that false alerts would be strongly limited since the virus signatures are in files that would generally not be scanned. The scope of this remains to be seen, but apparently at least Microsoft Security Essentials doesn't handle this entirely without problems.
> It appears to be a joke or prank, simply because this particular virus does nothing more than periodically show "YOUR COMPUTER HAS BEEN STONED" on one out of every eight computer boot-ups, and is over 25 years old.
When viruses were mainly jokes...