Breaking antivirus software
slideshare.net
slideshare.net
Disclaimer: I hate slideshare with passion. Presentation format and how they use HTML makes it painful to use if there are some connection issues (and their servers routinely hang on slides.
Same. I can't figure out why people trying to share their PDF slides use it, when any device more sophisticated than a flip-phone has a good built-in PDF reader.
There's definitely a pattern that AV companies put their efforts in being able to say they're #1 in outside tests or in reviews. In ye olden times someone would just take multiple vendors, scan against 1000000 old viruses and rank them based on the detection %, and as the end result the "best" (and the most sold) products ended up being resource hogs. Later reviewers took notice and started also measuring file copying performance and detection capabilities against active malware, and in a year or two many vendors adapted and improved their performance and their efforts against malware that actually is being spread.
Hopefully reviewers will take notice and include some exploitability metrics in the future so that vendors need to focus on it or go out of business.
Funny thing is that despite Bitdefender having thousands of exploitable points in their product, at the moment your average user will still be less vulnerable against online criminals than most those who don't run anything.
The only time I've ever gotten a (disruptive) computer virus was after installing Norton Antivirus. These days my goal is to ensure that I can quickly reformat and reinstall my system. I keep records of what I've installed and how I configure it.
Antivirus software is usually either dangerous, not worth paying for, or basically malware. How much anti-virus software is just resource-hogging, popup-spamming adware? No thanks.
AVs have all more or less the same signature database due to the same reason as above, most viruses are dumb and well known (most can't even be called viruses, think adware & co). IMO this the best reason for not having multiple AVs. I personally do not trust an AV for anything more than dumb signature checking (which are easily circumvented with polymorphism or sometime encryption alone) and targeted heuristics.
I also don't even want to start thinking at the mess that could be created by several AVs's injection/hooking mechanisms on the same machine.
Then again, if Microsoft is competent in how they built their AV engine, it might be properly fuzzed already. With such a wide deployment, you'd certainly want to think so...
>"There are a host of nasty intruders on the Internet including viruses, trojans, worms and spyware. Microsoft Security Essentials offers award-winning protection against these intruders without getting in your way."
To me that reads like MSE is really good at protecting your computer. Why should I as a consumer think that I need something else? They really need to message that better if that is indeed the case.
[0]: http://windows.microsoft.com/en-us/windows/security-essentia...