Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is like the government randomly placing dynamite in a very small percentage of fire extinguishers. The overwhelming majority of people will not be affected by this, but it shakes confidence in an important safety item and may encourage large numbers of people to stop using AV software, to the detriment of their own computers and networks in general.

So, what AV software is safe?



This "leak" seems to be a way to hit at Kaspersky. It seems like Western governments are really out to get them eh? It's like these bozos aren't in our pocket so let's try to destroy their credibility in hopes that companies will switch to Western companies for their security products whom we can then control using security letters etc.


You might want to look carefully at the history of Kapersky before you cast them into a white knight role. Would you blindly trust a company with known KGB and FSB ties?


No one's a saint, everyone's a sinner. We're casting the spotlight a certain way. I am sure it works equally well the other way. The point being there should be choice, not unilateralism like the Five Eyes want. It's all business, and never nothing personal. If you don't want Russia to have your secrets because they have something to gain, then by all means avoid the Russians. But it's for sure the case that Americans and the British will take your secrets and give them to their own industries for competitive advantage... while wagging their finger at everyone else for doing the same.


Still more reliable than Norton Anti Virus


Depending on your definition of "safe" the answer may very well be "none of them".

Antiviruses are bad, and it's not because they do their job bad. It's because the whole concept doesn't work.


If you're safely browsing, then all the AV program does is provide another point of entry for compromising software.

The safest AV is no AV.


That's not entirely true. Even if I behave completely above-board, it's possible that some site I visit has been compromised by hackers. Without some kind of protection, I could then be damaged by malware.


How can a compromised site damage your machine, given that you keep your browser updated?


Isn't that the whole point of 0-day bugs? That they work against fully updated browsers?


And how would an antivirus save you against such a bug in the browser?


By detecting some typical exploit pattern, the exploit kit itself, the malware the exploit eventually ends up downloading and executing, or even the malicious host itself. There might be other ways too, but those at least are the most typical ways.


An antivirus definition file is a lot easier to update than a browser component that is exploited. The latter generally involves a lot more testing, whereas the former is essentially just metadata.


Trust free systems are an ideal.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: