6 ms·
http://www.sevagas.com/IMG/pdf/BypassAVDynamics.pdf http://www.sevagas.com/IMG/pdf/BypassAVDynamics.pdf Anti-Virus is little more than snake oil. If you need t
by sarciszewski 11y ago
http://www.sevagas.com/IMG/pdf/BypassAVDynamics.pdf http://www.sevagas.com/IMG/pdf/BypassAVDynamics.pdf
Anti-Virus is little more than snake oil. If you need to secure a Windows box, get EMET and read http://decentsecurity.com http://decentsecurity.com and you'll eliminate most of your attack surface.
Everyone can be secure.
It is with those four words this website is founded. Computer, smartphone,
and online security does not require a degree or years of experience. All
it requires is someone show you the way.
You've been sold a lie. You can't buy computer security. It is something
obtained through configuration and knowledge. Tragically, these aren't even
hard to do or obscure to learn. But no one makes money telling you how to
use what you already have. What you need is someone who doesn't care about
your money or looking smart by spouting off fancy words of no consequence -
just that you not be a victim.
It pains me to see people who distrust and fear their computers, and who
feel powerless in that fear. Because that's not what I see when I look at
computers and phones and websites. I see tools I trust with the story of my
life, and the secrets I leave out when I tell that story to others. Everyone
should be able to feel like that.
This site does not sell anything. This site does not take donations. This
site has no one's name on it.
This site is to fix what is broken. Which is how we teach security.
If you were wondering because it looked familiar, it's run by the same person behind @SwiftOnSecurity.
- deleted 11y ago[deleted]
- sanderjd 11y ago> You can't buy computer security. It is something obtained through configuration and knowledge. Tragically, I believe this is true. But it isn't a great and noble thing that people must gain knowledge to overcome their powerless fear of computer technology, it is a failure of technology creators to provide people with simple tools that they can use without fear. The problem isn't how we teach security, because hardly anybody should have to learn security in the first place. That the mainstream public is even aware of a concern called "security" having to do with their computing tools is already a failure. I can't think of any other mainstream products that people have to be so careful with, where they are told it is their fault that they just haven't gained the expertise necessary to use it without problems.
- sarciszewski 11y agoI (and many others far more impressive than myself) am trying to solve this problem at a fundamental level: Give the developers tools that are secure-by-default (i.e. libsodium not mcrypt) and teach better development habits. Make it easier to do the secure thing than the insecure thing. It might take years, but I believe these initiatives will trickle up and make the software everyone uses more secure at a base, so it will require less cognitive load from the end users to communicate safely with each other. That's the idea, anyway. Time will tell if we can succeed.
- greggman 11y agoWouldn't you be better off solving it by sandboxing? Basically don't allow programs to do bad things in the first place rather than try and get all programmers to be perfect. Basically the web (and/or some phone OSes).
- sarciszewski 11y agoSandboxing is good for stopping memory corruption and privilege escalation bugs. It's not very useful for problems affecting cryptography implementation flaws, logic errors, out-of-date software, etc. Those problems are better solved by giving developers better tools and frameworks that solve these problems for them, that are simple to use and don't introduce massive security foot-cannons. (This comment is a minor spoiler to my current project, I suppose.)
- AnthonyMouse 11y agoThe problem with sandboxing is that "bad" has no formal specification. There are legitimate reasons to access contacts, intercept system calls or key presses, use raw sockets, etc. If you try to make those things not possible then people who need them have to use a different platform, which tends to cause other people who need to interact with those people to use the same platform (and so on) until the original platform is in decline. And the effect is worse the more you lock things down. It doesn't help anybody to have an ultra-secure platform that nobody uses.
- 11y ago
- greggman 11y agoI agree that as a computer literate? person I think I mostly know how to avoid viruses. I've never run any anti-virus software (could just be getting lucky). My family on the other hand can't avoid click "Yes", "ok" to anything ever asked of them on their computers. They get massively gunked up and infected and nothing I tell them changes their behavior because at a base level they just don't have the awareness. They're very smart people but what the computer is doing or might do in response to their actions is just not something they think about.
- sarciszewski 11y agoYour comment reminds me of this: http://swiftonsecurity.tumblr.com/post/98675308034/a-story-about-jessica http://swiftonsecurity.tumblr.com/post/98675308034/a-story-a... It's a good read, and it was one of the pieces that motivated me to pursue making security easier for people.
- digi_owl 11y agoSadly most of that advice will only work for those that work in IT directly. For those that use IT as a tool in the box to get something else done, or as a internet appliance, most of the suggestions will not fly. They will just hit yes on every UAC, and approve every outgoing connection.
- sarciszewski 11y agoSure, but instead of throwing our arms up and accepting defeat, initiatives like Decent Security are trying to move the needle away from "insecure by default". I'm trying to do the same thing with developers. :)
- digi_owl 11y agoI wonder if science is doing us a disservice here. I get the feeling that just a single vulnerability (no matter how complicated it may be to exploit) is enough to claim "fundamentally insecure". Meaning that we are looking at the topic like we are trying to disprove a scientific hypothesis.