Please create an account to participate in the Slashdot moderation system

 



Forgot your password?
typodupeerror
×
Security Microsoft Windows

You Don't Need an Antivirus (Except Microsoft's Built-in on Windows), Says Former Firefox Developer (ocallahan.org) 352

Former Firefox developer Robert O'Callahan believes that antivirus software is not necessary, AV vendors are of little help, and that you should uninstall your antivirus software immediately. From a blog post: Users have been fooled into associating AV vendors with security and you don't want AV vendors bad-mouthing your product. AV software is broadly installed and when it breaks your product, you need the cooperation of AV vendors to fix it. (You can't tell users to turn off AV software because if anything bad were to happen that the AV software might have prevented, you'll catch the blame.) When your product crashes on startup due to AV interference, users blame your product, not AV. Worse still, if they make your product incredibly slow and bloated, users just think that's how your product is.
This discussion has been archived. No new comments can be posted.

You Don't Need an Antivirus (Except Microsoft's Built-in on Windows), Says Former Firefox Developer

Comments Filter:
  • i do all my porn and risky surfing on a VM on my main computer that i keep shut off unless i'm using it. and i avoid virtually all chrome extensions unless they are from someone i trust with a real corporate email in the contacts.

    • by Anonymous Coward on Friday January 27, 2017 @10:30AM (#53748381)

      Another benefit of using a virtual machine is just powering it off when you are finished and having it reset to the last snapshot. Every month or so apply patches and move your snapshot forward.

      • Just curious, does MS allow now for you to make a copy of your windows for a virtual machine as long as it's on the same machine or do you need to purchase to licensees for it?

        • by ls671 ( 1122017 )

          It has been a while for you, hasn't it? They usually don't give you a Windows CD anymore when you buy a PC/Laptop so I couldn't tell you how to install the Windows version you paid for when buying the computer on anything...

          • by dwywit ( 1109409 )

            Laptops generally come with a "media creator" tool to burn a set of installation discs. Some desktops, too.

            Bonus - the toshiba tool creates an activated version of Win 7. That *could* be used to install many VMs, but I wouldn't know about that.

            • VM's have a different hardware signatures from the host, and the Windows media most likely (or in my case: certainly) won't run. And, if it runs, it won't be "genuine". Maybe the pro edition has a virtualization extension that allows you to run VMs, Those who know, please tell.
          • They usually don't give you a Windows CD anymore when you buy a PC/Laptop so I couldn't tell you how to install the Windows version you paid for when buying the computer on anything...

            Microsoft makes iso images available. The vendor probably provided a key some where.

        • Hyper-V is free on Win8/10 pro.
    • by CaptnCrud ( 938493 ) on Friday January 27, 2017 @11:08AM (#53748649)

      I do the same thing, except I have the song ~smooth operator by sade playing in the background when im in "secure" mode.

    • by antdude ( 79039 )

      Don't some malwares infect hosts from VMs too these days? :(

  • by Anonymous Coward

    ...VIRUS CLEAN ANTIVIRUS

  • by The-Ixian ( 168184 ) on Friday January 27, 2017 @10:27AM (#53748361)

    The writing has been on the wall for a while now. You rarely get "just AV" when you install an AV product these days. You end up with a whole suite of value added applications like password managers, system optimizers, registry cleaners, web site scanners, IPS and content filters, etc.

    The reactionary system we have been living in was never very good. Relying on signatures to detect malware is a fundamentally flawed system. As the operating systems and, more importantly, the applications that run on them become increasingly secure, the need for the signature-based AV systems declines.

    Any AV software company has seen this coming for a long time. At least I would hope they have.

    • Re: (Score:3, Insightful)

      by Anonymous Coward

      Part of it had to do with running most users with administrative privileges, and Microsoft created this mess by making the systems hard to use if you didn't have administrative privileges.

      I know people even today who turn off UAC the first chance they get because they are so annoyed by the prompts.

      • I ran a large shop when UAC first hit, and I immediately disabled it.

        As you know, all it does is ask the nagging question, "Are you sure?"

        My people were lawyers, paralegals, secretaries and staff.

        They were never sure because the goddam thing gave them NOTHING to consider.

        They would stop all work and get my permission to proceed, which was a smart move on their part. If things went sideways, ...

      • Microsoft created this mess by making the systems hard to use if you didn't have administrative privileges.

        That's just not true. On their 95/98/ME line, yes. On their NT-based line, that is their more secure/multiuser/real variant of the OS, they've always enabled non-admins to have the features you would expect. Including, for example, installing apps only for their use, or installing apps that wrote to config files in the user accounts. When they released XP, merging the NT/95 lines, they released doc

    • That explains McAffee AV's behavior.

      "You can pry this OS from my cold, dead hands!"
    • Relying on signatures to detect malware is a fundamentally flawed system. As the operating systems and, more importantly, the applications that run on them become increasingly secure, the need for the signature-based AV systems declines.

      I 100% agree with you. Unfortunately it is regulated industries that are keeping this crap afloat.

      Security != Compliance

    • >As the operating systems and, more importantly, the applications that run on them become increasingly secure...

      What decade and century do you think we're in?
    • Fully agree w/ this. In fact, for all the bellyaching over Windows 10, one thing they did right - put in the ultimate antivirus in Windows Defender, which comes w/ it. No more paying annual subscriptions to Norton, Kaspersky, ES-ET, Malwarebytes, et al

      One of the rare good things to come out of this mess

  • AV Free for years (Score:4, Insightful)

    by Anonymous Coward on Friday January 27, 2017 @10:30AM (#53748379)

    Further, any software you install likely creates new security holes in your system. By installing an AV you are likely opening up more holes then you are closing.

    There are three main sources of security holes:
    1) Holes in the OS that the OS manufacturer needs to close
    2) Holes in installed software that the software manufacturer needs to close
    3) Holes in the user's general security intelligence.

    None of those are solved by adding ANOTHER software suite.

    • Re:AV Free for years (Score:5, Informative)

      by tepples ( 727027 ) <.tepples. .at. .gmail.com.> on Friday January 27, 2017 @10:40AM (#53748459) Homepage Journal

      Holes in the user's general security intelligence.

      None of those are solved by adding ANOTHER software suite.

      Not even whitelist-based security tools that allow only vetted applications to run? I thought that was the point behind Apple's App Store, game consoles' app stores, and the PC Matic tool for Windows.

      • by Dr_Barnowl ( 709838 ) on Friday January 27, 2017 @10:56AM (#53748565)

        Problem with whitelisting is that it destroys your computer.

        It's not a computer any more. It's an appliance.

        Which is fine for people you can only trust to run an appliance, but it prevents anyone from programming aka becoming more productive.

        It's a nice little racket - it guarantees the IT dept. a job (they were charging £2,000 to vet programs for distribution at my last place), it gives the "real" programmers more work, but it stops users reaching enlightenment and getting the computer to do what it's for - lots of repetitive tasks in an automated manner.

        ---

        Aside from that, whitelisting software has been responsible for some of the more spectacular performance drops I've seen - like taking a process that writes around 30,000 files and increasing it's runtime from 2 minutes to 15 minutes, taking an operation that subject matter authors were doing when they felt like it and making it a tea-break thing, totally wrecking productivity.

        • an appliance [...] prevents anyone from programming aka becoming more productive [and] stops users reaching enlightenment and getting the computer to do what it's for - lots of repetitive tasks in an automated manner.

          Which elicits a big "So?" from appliance fans.

          The majority of the population do not read Slashdot. I imagine that most either A. use computing devices for entertainment rather than "becoming more productive" or B. prefer to outsource the programming to a specialist rather than "reaching enlightenment" themselves. For evidence of these, look at the popularity of iPod touch, iPhone, iPad, PlayStation 3, Xbox 360, PlayStation 4, and Xbox One. For evidence of preference of delegation to a specialist, look at th

        • by Sigma 7 ( 266129 )

          Problem with whitelisting is that it destroys your computer.

          It's not a computer any more. It's an appliance.

          Which is fine for people you can only trust to run an appliance, but it prevents anyone from programming aka becoming more productive.

          With modern computers, I see no reason why this is an issue.

          It is trivial to have a whitelist system that can be disabled for developers that want to program. Google Android does this, and I see no reason why future computers can't be setup this way either.

          • by tepples ( 727027 )

            It is trivial to have a whitelist system that can be disabled for developers that want to program.

            But it's not trivial to keep malware developers from social engineering naive end users into turning on developer mode.

      • I thought that was the point behind Apple's App Store

        Just another trust model. You're giving up control over your system to some curator and trusting them keep you safe.
        Of course nothing is perfectly safe [sophos.com]

  • AV is a joke (Score:4, Insightful)

    by n0w0rries ( 832057 ) on Friday January 27, 2017 @10:32AM (#53748389)

    I started removing AV from clients computers years ago. All it does is slow your PC down. Every time I had to deal with an infection, the PC involved had AV, that was sometimes very hard to remove.

    malware removal services should just be a tax on the easily confused.

    • Re:AV is a joke (Score:5, Informative)

      by FyRE666 ( 263011 ) on Friday January 27, 2017 @10:42AM (#53748473) Homepage

      Exactly. I do the same, if we get a new PC with commercial AV installed (usually some trial) it's the first thing I uninstall to installing improve disk performance by 50-100%. The Windows 10 built-in AV works fine and doesn't make a PC perform like it has a 5400rpm drive from 2001, instead of a modern SSD.

      • I don't mind the performance loss. It's the not losing files that I care about.

        Kind of like how AV tools lock new files for scanning after creation, except that MS Office apps write to temporary files before renaming at the end, and a lovely little timing based issue then results in the locked files being synchronised causing you to end up with a corrupted set of .TMP files where your documents should be.

        AV can go to hell.
        Mind you so can Offline Files in Windows, it's equally buggy.

  • by entropy01 ( 2618347 ) on Friday January 27, 2017 @10:36AM (#53748435)
    I don't use AV, but the average person still needs it. The average person either doesn't know or doesn't care what they are clicking on. As part of a layered defense strategy for the average user, it is still needed. Personally, I don't like AV stealing my CPU cycles. I use other methods, common sense chief amongst them, to prevent infection.
    • by DarkOx ( 621550 ) on Friday January 27, 2017 @11:09AM (#53748653) Journal

      The average person does need A/V but the built in stuff that come with Windows is more than adequate. Signatures are really only good if they are nearly to the moment up to date and with the present rate of churn on the internet that model just does not really work. To the degree it does still work Microsoft does as good a job as anyone. Its the heuristic side where there is still some effectiveness but even the high dollar stuff like Cylance falls down more than it succeeds. They claim 99% and maybe that is true if you just grab random malware off the internet and throw it at their stuff. We did some internal testing with more recent exploit code from metasploit and what have become downright common powershell and rundll payloads; if all we did is make the most trivial modifications to them we saw more like a %2 detection rate, other endpoint packages did about the same as well.

      Long story short A/V won't protect you from even a broadly targeted (hey I know these guys are using windows 8 because I Trojaned my "stat button" replacement app for windows 8/8.1, now I'll just wait and here and see how my hosts join my botnet) attack using updated tools. It certainly won't help you against an actual targeted attack.

      Should everyone leave Windows Defender on, yes its free and MS has done a pretty good job making sure their own AV package does not foul up their own OS. I would NOT recommend any third party A/V solution at this point for individuals or SMBs. There might be some residual value in endpoint packages for larger businesses but there is an equal strong cases for going without and focusing on a systems management solution instead where you simply make sure everything is patched and you have tight control over what gets run. Unfortunately Applocker bypasses are fairly trival now so you do need a third party solution800,000 to take a true white list approach.

  • Ad Block (Score:5, Insightful)

    by EvilSS ( 557649 ) on Friday January 27, 2017 @10:38AM (#53748439)
    These days one of the best AV products is a good ad blocker. I can protect myself from sketchy downloads: don't download sketchy software or from sketchy sites. I can't prevent some asshat from exploiting a zero day in a browser through an ad on a mainstream site, except by blocking all ads on all sites.

    *Yes, trusted sites can be comprised and it's happened in the past where downloads were infected but the odds that I'll download that software during that window where the infected files are being handed out are about the same as me getting stuck by lightning.
    • Re:Ad Block (Score:5, Insightful)

      by interkin3tic ( 1469267 ) on Friday January 27, 2017 @11:00AM (#53748593)
      I use addblock, ghostery, and noscript to protect myself from viruses

      "YOU'RE KILLING THE INTERNET!"

      Yeah, well the internet infected and killed one of my computers, so I'm going to be wearing an internet condom from now on. Besides, you can't tell me no one is viewing ads anymore when my aunt still is using windows XP.

      "What websites were you LOOKING at that killed your comptuer?"

      Oh the usual ones, porn, porn, yahoo, [washingtonpost.com] and more porn.

      "You pervert! Use google instead!"
      • by EvilSS ( 557649 )
        Yea I get the need to make revenue but if they won't work to make sure that all of their ads are vetted and clean, I won't stop using adblock. For some reason instead of doing this, they seem to think it's a better idea to just make the ads that people without adblock see more and more intrusive. Or do like Wired and try to get me to pay more for their website without ads than I do for their freaking paper magazine! Logic.
        • Forbes too seems to be going full on RIAA. "A fraction of people are getting our product for free. SPEND ALL THE MONEY TRYING FRUITLESSLY TO FIGHT THESE RARE PEOPLE!"

          I'm sure they have more information than I do, but I suspect they're spending more money and losing more readers doing it than they would theoretically be gaining in the first place.
          • by EvilSS ( 557649 )
            Yea that was the last straw for me with Forbes. I actually added them to my personal blocklist addon so they don't show up in google searches anymore, and I try to avoid them where i can elsewhere. They are basically a blogging platform for out of work "journalists"... sorry... freelancers these day with virtually no editorial oversight. The writers just pump out as much crap as they can to maximize their meager revenue. Then they pull that crap with their adblock blocking, and the very day they turn it on
          • I would be willing to add an AdBlock exception for Forbes if they guaranteed malware-free ads. By guarantee I mean they would compensate me monetarily for my lost time restoring my system, at say $100 per hour. Short of that, no Forbes for me!
      • "YOU'RE KILLING THE INTERNET!"

        The internet was built to withstand a nuclear attack. I'm sure it can survive the loss of ad revenue.

      • Given the nature of Ad Networks, it doesn't really matter what sites you're looking at. You could surf only perfectly reputable sites, and you'd still get pwned if you weren't blocking the ads. It's because they're using third-party distribution networks, and while certainly there are some networks that are shadier than others, I've yet to see anything that convinces me that the crooks can't get malware up on them long enough to do damage.
  • by DatbeDank ( 4580343 ) on Friday January 27, 2017 @10:39AM (#53748449)

    Let's be real with ourselves. Nowadays the vectors for attack are easily protected so long as you use a modern browser that sandboxes itself and use an ad blocker you really don't need anything more than the built in AV and firewall tools for windows. I don't even think OSX provides an AV tool.

    I haven't paid for antivirus software since 2005 which was coincidentally when I discovered Firefox and Adblocking extension.

    I'll stick with the free tools.

    • by iTrawl ( 4142459 )

      There's one more requirement: Don't download MyFavouritePokemonDesktopPal from many-pokemon.software-site.no-really.latest-software.trust-us.com

    • It's amusing that the article has an update:

      Perhaps it should go without saying --- but you also need to your OS to be up-to-date. If you're on Windows 7 or, God forbid, Windows XP, third party AV software might make you slightly less doomed.

      And how much is the check you're getting from Microsoft to shill for them encouraging "upgrades" to Windows 10? Or are you suggesting that Microsoft is deliberately failing to fully update Windows 7 in order to make it look less secure?

      • by roca ( 43122 )

        Windows 10 has some systematic security improvements that weren't backported to Windows 7. That sort of thing is often hard to retrofit without breaking stuff.

        I spent fifteen years of my life working on Firefox, fighting Microsoft tooth and nail to stop them from taking over the Internet. Nowadays I' work on debugging software that only works on Linux. So no, I've never been Microsoft's shill or anyone else's. But people running up-to-date OSes is in everyone's interests.

  • Duh (Score:4, Informative)

    by Khyber ( 864651 ) <techkitsune@gmail.com> on Friday January 27, 2017 @10:49AM (#53748515) Homepage Journal

    AV products actually make you less secure. They act as a MITM, replacing certificates with their own and totally defeating the purpose of TLS/HTTPS.

    • by tepples ( 727027 )

      Without using a MITM proxy, how else is the operator of a home or organizational network supposed to cache public images, scripts, style sheets, and other resources, so that multiple devices on the network don't have to redundantly download the same resources over a slow and/or capped connection to the Internet?

  • With Malwarebytes and BitDefender. I don't go for the big all-in-one "security quites", so the simpler approach works great for me.

  • by aicrules ( 819392 ) on Friday January 27, 2017 @10:55AM (#53748561)
    This story needs some APK posts.
  • by GeekWithAKnife ( 2717871 ) on Friday January 27, 2017 @11:01AM (#53748609)

    I find that SPI firewalls, execution prevention, careful permissions for limited users, NoScript and other tools are far superior to an AV.

    Liberal OS policies and platforms are not ideal for anything you;d hate to lose. Often you would not know that something malicious is running.

    With multiple layers of security on a system that does not change often you can have fine grain control of anything. An odd internet connection attempt, a never heard of before program attempting to run etc -that reasonable easy to catch.

    AV vendors have been packaging (shoving) everything included as soon as they realised AVs are done. Unfortunately the desktop class products are often more trouble than they are worth.

    That being said, I still advocate the complete security packages from AV vendors for users that know little being logging into facebook. They are clueless and could not manage a complex system a "security suite" type program is their best bet.
    • by zifn4b ( 1040588 )

      I find that SPI firewalls, execution prevention, careful permissions for limited users, NoScript and other tools are far superior to an AV.

      You're confusing AV with other types of security software. They all have a purpose for computer security but they all do different things to help with that. They are dealing with different attack vectors.

  • I run Linux, a browser with ad blocking, and a hosts file with 94.5k entries (for shady sites) that redirect to a dummy IP.

  • I run software and hardware firewalls, plus AV, Ad and script blocking. Makes my web experience much better.
  • You're credible why? (Score:4, Interesting)

    by zifn4b ( 1040588 ) on Friday January 27, 2017 @02:09PM (#53750247)
    And we should trust the developer of a browser whose development team didn't see the problem with their memory model chewing up resources until Firefox ground to halt and took an ivory tower position of something along the lines of "you shouldn't have your browser open that long." I know quite a few people who switched to Chrome over that nonsense, myself included. Why should we trust your recommendations again?
    • What is the relation between a former developer opinion about anti viruses and one of the products of the organization he worked? You're saying that if you don't agree with the memory model of Firefox, the opinion of the former developer is wrong, which is totally unrelated. Attack the message, not the messenger.
    • Sure, lets switch to a browser whose idea of tab-management is to copy IE.
    • by roca ( 43122 )

      > a browser whose development team ... took an ivory tower position of something along the lines of "you shouldn't have your browser open that long."

      That never happened. You just made it up.

  • I haven't used Antivirus Software in about 15 years, and I use a PC or similar device for 12+ hours a day. I haven't caused a single infection - the only time a computer of mine was infected was when someone snuck onto my computer to try a practical joke, loaded a porn website to set as my homepage *but did it in Internet Explorer* back in the days of IE6
    Of course, I know what to click and what not to click. I know to examine dialogue boxes and have critical thinking skills to evaluate the website I am d
  • I've never needed one.
    Then again, I run Linux.

  • Original poster here.

    My post says "Except Microsoft's", right in the title. I think that's important. I believe that Microsoft's Defender stuff is probably less bad than the other major players and worth having enabled for average users. Unfortunately that's been left out of the Slashdot summary.

    • by roca ( 43122 )

      Oh, and I also mentioned in the post that you'd be better be using a fully up-to-date OS and browser.

  • AV is just part of the reason that we use SEP. It also allows us to do things like control access to USB devices, lock down which processes can be ran, etc.

    I agree that the traditional AV portions of the product have questionable utility.

  • Why do I need antivirus on the thing I use to start Steam? We mandate antivirus on our work computers, still hasn't stopped cryptolocker from encrypting stuff on network shares.

"I got everybody to pay up front...then I blew up their planet." "Now why didn't I think of that?" -- Post Bros. Comics

Working...