4 ms·
Speaking as someone who knows something about these things, it is clear that you are not as informed as you are making yourself out to be. There are two reason
by tsally 16y ago
Speaking as someone who knows something about these things, it is clear that you are not as informed as you are making yourself out to be. There are two reasons why I say that. (1) Your knowledge of the AV industry is outdated. McAfee has actually been trending upwards in recent years. (2) A 97% detection rate is obviously bullshit. If any product achieved a detection rate anywhere close to that number, the false positive count would be through the roof. As this incident makes clear, the cost of a false positive can be astronomically high. Again, any AV product advertising or claiming 97% detection is bullshit. Any AV engine can achieve that number if accepts an unrealistic number of false positives. The fact that you even quoted that number makes me question your qualifications for giving advice about AV.
For non technical people reading this thread, the general sentiment of other commentators is correct. Most AV is garbage. It will protect you from about a 1/3 of what is out there at the cost of computer performance. Make an educated decision about whether to run it at home or not. On your corporate network, do whatever your security guy tells you to do.
- thaumaturgy 16y agoNot that I'm all that interested in getting into a pissing contest with Some Guy From The Internet, but: 1. I've been doing virus and malware cleanups for people since -- well, since 1995 or so, at least. 2. I've recently begun presenting seminars on basics for novice computer users. 3. I was among the first to clean up the rather nasty kbiwkm rootkit a while back. One of my clients was infected with it before there had been an a/v response, and before anything could be learned about it anywhere. 4. I've recently begun to get contacted internationally (well, from Canadian individuals, anyway) to clean up websites infected with various sorts of nasty bugs. 5. Most importantly, I follow the results and reports from av-comparatives.org religiously; they're not affiliated with any particular antivirus vendor, product, or group, their tests appear to be very thorough, their methods appear to be fairly rigorous, and they provide reasonable results for a number of different metrics related to antivirus products, all in a regularly-released report that's quite readable. 6. I started a company three years ago to address the various flaws that I saw in the I.T. industry, one of which was the number of people that got hit with viruses over and over again. I have a very, very low rate of repeat virus cleanups for my clients, many of whom are novices that are particularly susceptible to multiple computer virus vectors. You might feel like being snarky and saying that I never hear back from them because they don't care for the service, but then again, I'm currently experiencing my third straight year of 300% growth, and most of my "marketing" comes from word-of-mouth. But, I don't have a blog, so of course I'm not an expert. Carry on. edit: ohbtw, two of today's systems that were infected with rogue antivirus also had up-to-date and active McAfee installations, which isn't at all unusual. But, yeah, you're right, it's much better now than it used to be.
- tsally 16y agoFirst, congratulations on your success with your business. 300% growth over multiple years is very impressive. Second, I didn't mean to be negative or snarky (I can be abrasive sometimes, so sorry about that). It's just that no one experiences detection rates that high in the real world. If AV actually worked that well, it would be incredible. I'd be the first person to publicize it. In regards to AV Comparatives, I responded to why their tests aren't relevant in in the real world here: http://news.ycombinator.com/item?id=1284321 http://news.ycombinator.com/item?id=1284321. The bottom line is that detection rates as high as 97% are generally regarded by industry experts as inflated (John Viega says in one of his books that some people estimate actual detection rates to be around 30%). AV companies themselves would never use that number as a part of their marketing campaigns. You'll note that on the product pages of the AV products tested, the numbers aren't listed. If a 99.6% detection rate was actually. valid, don't you think it would be displayed in large and bold letters on the product page? I'm not saying people shouldn't run AV, but we need to be honest about the actual capabilities of these products. Even if actual detection is only 30%, 30% is better than 0%.
- jwecker 16y agoIf I'm reading this report right there are several that hit 97% with low false positives. http://www.av-comparatives.org/images/stories/test/ondret/avc_report25.pdf http://www.av-comparatives.org/images/stories/test/ondret/av... The methodology is linked in the document. I mean, it's certainly at least less of a conjecture than your "he doesn't know anything because these things are obviously BS" argument.
- tsally 16y agoI'm familiar with the report. Programs that were detected as false positives include: * the task manager * Quicken * ATI Drivers * the GIMP * other antivirus programs (including products from Kaspery, ESET, Avast, and Trend Micro) * VLC * Cygwin * Acrobat reader * text editors (including Notepad2 and Notepad++) * TrueCrypt AV run in the real world on these settings would be disastrous. Issues with the samples used by AV Comparatives: * The malware sample size is only around 1 million. * The sample size of clean programs is far too small. * The malware samples used aren't public. We don't even know if the malware used by AV Comparatives are found in the wild anymore. More generally, evaluations like those done by AV Comparatives and similar organizations are misleading. What actually matters is the vulnerability window. This window is generally a week or two and occurs after a piece of malware is released into the wild. It is the amount of time it takes AV vendors to get a signature distributed. Most damage is done during the vulnerability window, during which infected machines will have their AV disabled by the virus. The fact that your AV can detect viruses released years ago actually doesn't have any bearing on your security; it's a meaningless evaluation of the product. You have to ask yourself, why don't AV vendors report numbers like the percentages found in AV Comparatives? They don't because they know it's bogus. Sure, most AV vendors will list AV Comparatives and others as an "award" or a "certification", but they'll never list the actual number. I think that should tell you something. In the real world no one is experiencing detection rates like those in the report. If they were, you can be sure the numbers would be part of an AV marketing campaign.