3 ms·
Avast is not the only antivirus program that does that these days; ESET does it, and Symantec's Norton products do as well IIRC. As everything moves toward TLS,
by adrtessier 11y ago
Avast is not the only antivirus program that does that these days; ESET does it, and Symantec's Norton products do as well IIRC. As everything moves toward TLS, this is pretty much a required step on the client for "Internet Security", and the average person doesn't know or doesn't care.
Largely, you probably should not either if you are trusting the AV client with the rest of your computer. Yes, it can be fucked up and break TLS, but there are a thousand other ways a privileged executable like an AV program could fuck up a lot more of your system. For example, a bunch of CVEs were found in Kaspersky's product by Tavis Ormandy in September, and it appears that a few found in Avast have been made public within the past few days. [1]
[1] https://code.google.com/p/google-security-research/issues/detail?id=549#c1 https://code.google.com/p/google-security-research/issues/de...
- click170 11y agoSophos AV seems to go a step further, intercepting any outbound telnet connection. Good to know if your company uses Sophos and you used to use telnet for basic connectivity testing.
- magicalist 11y ago> Largely, you probably should not either if you are trusting the AV client with the rest of your computer. Yes, it can be fucked up and break TLS, but there are a thousand other ways a privileged executable like an AV program could fuck up a lot more of your system. You're right that antivirus software is more or less a sieve of a shield, but this doesn't really make sense. If AV exploits are worth fixing, then so are the exploits made available by AV certificate handling.
- adrtessier 11y agoI'm quickly understanding that I need to learn to be more specific as to what the premise of my statement is before I comment here. I agree with your point as to fixing all holes; I was making the point more toward people freaking out that these AV systems are inserting the certificates and inspecting the traffic in the first place. Sorry for the confusion.