3 ms·
> Google has had security vulns too. Do you find it "ironic"[^1] that Tavis would disclose vulns in other companies software? No, the thing in this instance is
by jnky 11y ago
> Google has had security vulns too. Do you find it "ironic"[^1] that Tavis would disclose vulns in other companies software?
No, the thing in this instance is that a) Trend Micro is a dedicated "security" company and b) the vulnerabilities in its software were especially negligent.
> You really should look up the definition of this word.
One definition I found was "happening in the opposite way to what is expected, and typically causing wry amusement because of this". Considering that, I'm quite happy with my usage of the word.
That said, English is not my first language and I often see people nitpicking about this particular word. My feeling is that people understood me just fine despite of it.
- dfc 11y agoYou expected an antivirus company to write perfect code and not have any vulns? That is hilarious. Look up Fireye vs. ERNW. You will love that one.
- deleted 11y ago[deleted]
- pilif 11y ago> You expected an antivirus company to write perfect code and not have any vulns? no. But I expect them to have their shit together well enough to not be the laughing stock of the internet because of how amateurish their flaws are (come on - unauthenticated remote accessible JS shell with full local machine access? This didn't even happen to microsoft in the 90ies) AV programs are by definition in an utterly exposed spot on your machine: They run in a privileged account and they intercept all reads and writes to the disk. They also unpack every archive, parse every file, check every single byte written. An AV program is opening every mail attachment, practically inspecting and sometimes even partially running every trojan on your machine, even those you blatantly ignore as being spam. For an application in such an exposed point on your machine, I expect them to at least follow current security-best-practices, tough honestly, I would wish they would go far beyond that due to the immense risk they subject themselves to. And then we have trend micro, an AV program, which opens a remote accessible RPC endpoint which can be used by everyone. This is the exact opposite of what I'm expecting them to be doing.
- dfc 11y agoI did not realize that Trend Micro was held to such a high standard. My (uninformed) opinion of them was that they were nowhere close to best of breed. But more importantly, it seems like there is a difference between the way things are and the way you think things ought to be. Look at all of the AV industry bugs from google's project zero: Avast (9): https://bugs.chromium.org/p/project-zero/issues/list?can=1&q=label%3AProduct-Avast&colspec=ID+Type+Status+Priority+Milestone+Owner+Summary&cells=ids https://bugs.chromium.org/p/project-zero/issues/list?can=1&q... Comodo (9): https://bugs.chromium.org/p/project-zero/issues/list?can=1&q=label%3AVendor-Comodo&colspec=ID+Type+Status+Priority+Milestone+Owner+Summary&cells=ids https://bugs.chromium.org/p/project-zero/issues/list?can=1&q... ESET (3): https://bugs.chromium.org/p/project-zero/issues/list?can=1&q=label%3AVendor-ESET&colspec=ID+Type+Status+Priority+Milestone+Owner+Summary&cells=ids https://bugs.chromium.org/p/project-zero/issues/list?can=1&q... FireEye (2): https://bugs.chromium.org/p/project-zero/issues/list?can=1&q=label%3AVendor-FireEye&colspec=ID+Type+Status+Priority+Milestone+Owner+Summary&cells=ids https://bugs.chromium.org/p/project-zero/issues/list?can=1&q... Kaspersky [you will love the archive unpacking vulns] (15): https://bugs.chromium.org/p/project-zero/issues/list?can=1&q=label%3AVendor-Kaspersky https://bugs.chromium.org/p/project-zero/issues/list?can=1&q... malwarebytes (1): https://bugs.chromium.org/p/project-zero/issues/detail?id=714 https://bugs.chromium.org/p/project-zero/issues/detail?id=71... All in one list: https://bugs.chromium.org/p/project-zero/issues/list?can=1&q=label%3AVendor-Comodo%2CVendor-Kaspersky%2CVendor-ESET%2CVendor-AVAST%2CVendor-FireEye%2CVendor-TrendMicro&sort=severity&colspec=ID+Type+Status+Priority+Milestone+Owner+Summary+Severity&cells=ids https://bugs.chromium.org/p/project-zero/issues/list?can=1&q...
- pilif 11y ago> I did not realize that Trend Micro was held to such a high standard nope. Not Trend Micro. All of them. And as long as they are failing as spectacularly as you're pointing out here, my recommendation is to not use AV software and instead use whitelisting of allowed applications.