4 ms·
With fake SSL certificates signed by "real" CAs, cross-site scripting and other advances in phishing attacks, just educating users may not be as effective as it
by daten 16y ago
With fake SSL certificates signed by "real" CAs, cross-site scripting and other advances in phishing attacks, just educating users may not be as effective as it used to be. Malware is quickly becoming advanced enough that even trained technical users may be fooled. Many attacks don't require user interaction. AV products may be slow to respond and signature matching won't catch everything, but if it catches half of what shows up on corporate networks it can still save a lot of time and money.
- mrcharles 16y agoI wonder if the value of the total things stopped by McAfee, in all its time, outweighs the purported damage of this incident. I'm thinking no.
- orborde 16y agoOn what basis do you say no? This is a single large, noticeable incident, but that doesn't mean that it outweighs millions of tiny ones prevented.