17 ms·
They've done a wonderful job convincing the majority of people that anti-virus is something that you absolutely need, full stop. Once you have that ingrained in
by halestock 10y ago
They've done a wonderful job convincing the majority of people that anti-virus is something that you absolutely need, full stop. Once you have that ingrained in someone, they'll put up with all the annoyances.
- jonknee 10y ago> They've done a wonderful job convincing the majority of people that anti-virus is something that you absolutely need, full stop. I think Microsoft did that for them by being so terrible at security for so long. Windows Defender came out 5 years after XP shipped and several years after average XP systems were riddled with malware.
- WorldMaker 10y agoMicrosoft had a statute of limitations against shipping anti-virus with the operating system because it was "anti-competitive" according to the EU/DOJ anti-monopoly decisions. Anti-virus wasn't seen as a core security need for an operating system at the time, because the third party AV vendors fought hard for that and used the "Browser Wars" as justification to do that.
- jonknee 10y agoThen they should have made a much more secure operating system. You only need an AV if your OS has already failed.
- WorldMaker 10y agoDepending on your definition of "AV", of course, but: intrusion/threat detection is a need for every modern OS in some capacity regardless of how "secure" the OS is or not. Even if you have the most secure kernel and no threat might ever escape user space, you'll still have pissed off users when they find out their stuff is all up for ransom or deletion. "AV" is a component of a secure operating system, not an "add on" you only need for a "bad operating system".
- khana 10y agoIf only!
- drdaeman 10y agoNo OS security can beat user stup^W cluelessness or accidental mistakes. Also, sometimes trusted providers get hacked and malware is distributed in disguise.
- tw04 10y agoSo literally every OS of any notable use in the world has failed then? Because I'm not aware of any widely deployed OS that hasn't had a successful exploitation written for it.
- sqeaky 10y agoMost OS have some level of penetration, but it is so clearly not the same with windows. Even with the latest exploits free spreading viruses on android are rare but hook a windows machine up to the Internet without a router or firewall and get a virus in seconds. Android easily outnumbers windows, by some counts 5 to 1, yet it has a smaller percentage and absolute level of malware installation. The old truism of computer security arms race is bullshit. Computers that are secure from general mass spreading infections it not even all that hard (securing from governments is much harder). Simply ignore all incoming connections and don't execute downloaded data (or give to untrusted executables. The only hard part about this is making sure that network card drivers can be trusted, this isn't hard on most operating systems, but most windows users are totally at the mercy of some low budget buggy vendor. Windows is well positioned to fail at computer security and they have done a great job at leveraging their position.
- rrdharan 10y ago> Even with the latest exploits free spreading viruses on android are rare but hook a windows machine up to the Internet without a router or firewall and get a virus in seconds. I don't buy this at all. Unless you are comparing Android with Windows XP? First of all, you'd have to go out of your way to disable the firewall on a modern Windows install. Secondly, there have been tons of Android infections: http://arstechnica.com/security/2016/07/virulent-auto-rooting-malware-takes-control-of-10-million-android-devices/ http://arstechnica.com/security/2016/07/virulent-auto-rootin... I'm sure the percentage is lower than "all infected Windows machines" but I very much doubt it's lower than "all Windows 10 installations" or even "all Windows XP SP2 + Windows 7 + Windows 10 installations with updates enabled". Nonetheless, it's definitely the case that an app sandboxing model provides some defence in depth, at the cost of reduced flexibility w.r.t. e.g. a real generic filesystem, ability to distribute/install without an app store, etc. The Windows Security Development Lifecycle material is worth reading: https://en.wikipedia.org/wiki/Microsoft_Security_Development_Lifecycle https://en.wikipedia.org/wiki/Microsoft_Security_Development... https://www.microsoft.com/en-us/sdl/ https://www.microsoft.com/en-us/sdl/ Ultimately, if you were to allow Android devices to by default, open and run arbitrary native code that users download from the internet, you'd see the same host of problems (probably much worse for the average Android device given the fragmented OS patching nightmare).
- gerdesj 10y ago> I think Microsoft did that for them I think you'll find nearly everyone in IT and certainly many public bodies, banks, utility companies and $deity knows who else, does that - recommend AV to all users. It's pretty much a mantra for IT "cognoscenti".
- deleted 10y ago[deleted]