Schneier on Security: Is Antivirus Dead?
schneier.com
schneier.com
Now, this may be a bit off-topic, but does anyone know about which software he's talking ? I personally find that most of the virus scanners try desperately to let you know how effective they are, constantly notifying what they have done to help you, to validate their existence.
On the other hand, you have the more minimalistic virus scanners, like ClamAV, but I really can't tell if they're effective or not. I fear they are not.
Anyone has recommendations for a good virus scanner that doesn't suck ? Perhaps pg can make this a request for startups, please ? It's about time this whole industry stopped sucking. :)
Seems a bit excessive.
A better bet would be F-Prot or Nod32 which seem far lighter and a tad more quiet about their business except when a malware is actually found (which is also customizable I believe).
However, I see a hard task ahead of any startup that wants to come up in this field. Writing sig definitions for the 100000+ viruses already difficult is a massive initial undertaking. The older players already have most of it written down but a startup would have to put in a ton of effort just to catch up.
You download an app/email attachment etc, check it and then install/open it.
Vista sort of has this but it doesn't clear the suspicion, so if you download a simple utility (or even a help file) it will warn you every time you open it - unless it comes inside an installer.
http://www.microsoft.com/Security_Essentials/
It runs unobtrusively in the background (only a tray icon), is simple to use, and doesn't install additional cruft (e.g., the AVG IE toolbar).
AV software gives you a false sense of security, imo.
O RLY??
I beg to differ. I've seen the PCs of friends and relations reduced to a pitiful level of performance by well known so-called "security" software.
My dad keeps trying to install security software which he discovers through pop-ups on Korean websites.
Fortunately, I bought him a Mac, and most of that stuff is a *.exe file. Unfortunately, this is not enough! :(
It's the same as human viruses. If you do things that are safe, you dramatically reduce your chances of infection.
* Spyware
* Viruses
* Remote Control Trojans
* Exploits that involve executing pre-installed code that you don't use regularly
Thanks to all the marketing hype around disclosing and announcing vulnerabilities, there are (according to some industry analysts) between 200 and 700 new pieces of Badness hitting the Internet every month. Not only is "Enumerating Badness" a dumb idea, it's gotten dumber during the few minutes of your time you've bequeathed me by reading this article. """- http://www.ranum.com/security/computer_security/editorials/d...
And this doesn't even start counting applications, and their update and patch mechanisms.
Its still a losing battle though. Run http://technet.microsoft.com/en-us/sysinternals/bb896645.asp... for a few minutes, and look at how many actions are being taken, just when your computer is supposedly idle. Trying to whitelist each and every one of those would be massive overhead.
I've found (personally, this isn't for everyone) is to run with as minimal AV as possible (Right now, SSE), and if I notice anything out of the ordinary run an offline virus scan. I usually do this with Bart-PE, although I've been working on another method for it. Expecting an infected OS to report that it is infected isn't the best idea, it is too easy to fake the results. Doing a scan of the system while the OS is not running tends to be more reliable and remove any problems a lot easier. I'm currently working on a system which will PXE boot once a month, do a virus scan or two (with different, fully updated scanners), defrag, checkdisk and do a general cleanup.
There might also be naughty reasons to do these things
Delete files in the application's working directory, read files from the application's working directory or public areas, contact websites, read keyboard when this application is the focus, send email.
It isn't nearly as dangerous. Sure, you've still got the computer contacting webistes and sending email, but that isn't a terribly large risk. There is still a need for blacklisting that sort of activity. As far as reading sensitive information, however, as long as working directories are categorized well, and used by any applications dealing with anything sensitive, it isn't a problem.
"And whitelists aren't a panacea, either: they don't defend against malware that attaches itself to data files (think Word macro viruses), for example."
If you use a service like gmail then you can't even send certain attachments. I couldn't send .zip files the last I checked. Plus spam filtering has gotten better.
I think white-listing could go a very long way towards solving the problem.
How can a whitelist prevent attack vectors as varied as opening a PDF file designed to exploit your PDF reader? The user cannot always be vigilant enough to know that site X is giving him a malicious file to open. Hell, site X might actually be a legitimate site that has itself been attacked and exploited...
However, I can't receive zip files through my work email which is a policy decision made by our network admins. (You can rename it .zipX or something like that and it will go through. They have been burnt by users clicking on any random attachment and getting Trojans and viruses.)
I don't seem to be able to send an exe through GMail though.
Two-factor can only go so far, as it only limits the window of opportunity to between log in and log out.
While I, and most technical people, guard our computers carefully and wouldn't use a computer owned by someone else for anything but anonymous web browsing, the average user is quite happy to use some terminal in an internet cafe.
I see he recommends Malwarebytes' Anti-Malware: http://www.malwarebytes.org/mbam.php
However this looks like more of a scanner than a white-listing software. The other two he recommends look to be commercial only?
Any suggestions? Looking for Windows 7 64 bit capability. Thanks