edit: clarification
edit: clarification
To borrow a phrase from the /g/ community, I run Common Sense 2014 platinum edition. I.e. I don't download stuff from sketchy websites in general, I don't click email attachments, I don't use the Java web plugin, I do use things like Adblock and Noscript, etc.
If I do end up with a possibly suspicious file it gets sent off to a multi-scanner environment like VirusTotal or Jotti where I can get about 30 different opinions simultaneously.
The last few infections I've gotten were due to doing something boneheaded. Running something from a torrent without checking it first, or turning my browser security off temporarily and forgetting to reenable it.
However, I'd also run EMET to make it a bit harder for an exploit getting past NoScript to operate correctly.
I know, security is all about layers, but the usability and performance tradeoff gained for this paper tiger protection is not worth it, in my mind.
http://www.av-test.org/en/antivirus/home-windows/windows-7/
http://www.av-test.org/en/antivirus/home-windows/windows-8/
How old is your PC that modern antivirus software noticeably slows it down?
On the other hand, my work laptop is Red Hat 6 and Linux, Mac, or Windows, we're required to run Symantec by corporate policy. Then again I work for a security company, so...
That's ridiculous. It has been a hell of a long time since antivirus applications affected the performance of a machine that way. The performance impact on any remotely modern machine is negligible.
And under no circumstance is it 'better off with the virus instead'.
Really, look at what they do. They pre-emptively scan every executable program you run at the least. Unless you're on an SSD, and probably not even then, this is a blocking operation that is impossible to not notice.
I think the main problem with antivirus on modern hardware is that commercial entities selling antivirus have to add bells and whistles. Few people would be willing to pay $x a year for a program they aren't even aware of running. So, that $x program makes sure you see it frequently by adding progress displays, toolbars, task bar items, etc. they also make sure they have stuff to report, even if that includes meaningless stuff such as registry keys on Windows. Detecting that meaningless stuff takes time, too.
I think you're spot on, but from the scope of a user who knows 90% of that stuff is BS, it's just another bullet point in the list of why I don't run AV software.
Earlier this year my Windows 7 machine with a Xeon W3565 (3.20 GHz) and 6GB RAM was slowing down noticeably every time Symantec Endpoint Protection 12 downloaded new definitions--something it did twice a day. I would consider this a reasonably powerful machine, and the slowdown had an effect on my ability to work.
Sense the tone. My tongue is clearly planted firmly in my cheek, and if you're too literal to recognise that, at least err on the side of not downvoting.
For the record, it's been about 4 years since I used antivirus software on Windows, maybe things have improved since then.
Do you have the benchmarks to support this claim? Unless things have improved considerably in the last year, simply doing a "git clone" took measurably longer even on a machine with an SSD. Microsoft Security Essentials had by far the lowest impact but it was still easily visible.
Keep in mind that when New York Times was hacked a while back that 50 kinds of malware was found, and only one of them was detected by multiple AV products.
So depending upon AV to protect you is fraught with peril.
Consider the possibility that adding AV to your system increases the attack surface. Does anyone remember the Michelangelo Virus from a while back? A well-known firm' AV software caused more damage than the virus itself. (It wiped out the boot sector.)
Don't count on AV to protect you.
I worked for 5 years in the trenches in the anti-malware industry and countless times I've seen antivirus software completely hose up computers and worse: having its own insecurity and hooks into the Windows API used directly to infect a system (I'm looking at you, AVG circa fall'09).
Most importantly, no antivirus seems to do a very good job of dealing with emerging threats and malware is rapidly getting more sophisticated than the AV vendors can cope with. The major problems these days all seem to come down to an insufficiently secured operating system.
The only real, effective antivirus is user education.
1. i.e. not Outlook managed by an enterprise IT department
As long as linux isn't too mainstream, it will be less a problem. But you could still use ClamAV if you share some files with other computers.
edit: Also, i'm not sure i agree with you that Windows being the most widely used OS is the reason for the proliferation of viruses for that platform. As i understand it (not wanting to start a flamewar here, i genuinely don't know), it also suffers from some poor security architecture -- but maybe my information is outdated. But sure, the fact that "everyone" uses it makes it a more valuable target, of course.
The single best advice to not getting infected is to not do stupid stuff.
As for Windows being unsafe, sure, it's easier to propagate stuff since you have root access. But like I said, viruses on OSX do exist.
I also stated i do not run external-facing services. That applies to the Samba example, too (although i was fibbing: i allow keypair-only login via sshd).
yes, that's what I meant.
I don't do much locally other than write code. I use Web IDE's, Web Editors, Online Markup, Stream via HTML5... Not much to download now-a-days.
[0] https://hn.algolia.com/?q=tptacek+antivirus#!/comment/foreve...