4 ms·
One thing to remember, is just like AV's, it's the norm for them to literally upload random archives, documents and whatever else to "Scan". There's a reason pr
by NtGuy25 5y ago
One thing to remember, is just like AV's, it's the norm for them to literally upload random archives, documents and whatever else to "Scan". There's a reason pretty much every Anglo country doesn't recommend Kaspersky for this reason. It makes you wonder the risk of China owning 100 % of Riot and the data gathering potentials. And since it's the standard industry practice, the American engineers won't even blink an eye when designing it. It's truly a national security and IP risk that alot of people don't realize.
Now I will say as someone who makes tools for and reverses their products(All in fairy land in the kingdom of tacobell in my dreams). They have pretty unobtrusive anticheat in League of Legends and mainly only hammer a whitelist. For example if you install Itunes, they will get really obtrusive with anything related to Bonjour. As well as with anything that injects into the module list.
With Vanguard, they get EXTREMELY intrusive and scan network drives, and I found VM memory pages being scanned, but i'm unsure if it's intentional or not as I didn't go to deep into it, since I don't really play shooters and mainly did it as a quick audit, unlike League of Legends. They do shut it off when you say shut it off though.
EDIT:
One thing to keep in mind. Is if they make a kernel driver which subverts the OS's control schemes(For example making a CreateFile, ReadFile, Memory write primitive, Memory read primitive. If you see this, REPORT IT. Microsoft bans these types of implementation and you can do that here. https://www.microsoft.com/en-us/wdsi/driversubmission https://www.microsoft.com/en-us/wdsi/driversubmission . It's a MASSIVE security risk and they will REVOKE the driver certification and deny loading it on Windows! Do not let them rootkit your system, know what Microsoft allows and doesn't. They do care, they've fucked over AV products before, and they will do it again. The OS Security team at Microsoft is extremely good and genuinely cares about you as a user.
- mikeiz404 5y agoSo it’s been a long, long while since I’ve explicitly run AV software but doesn’t signature, heuristic, and behavior based detection all run locally on the machine? I suppose the exception might be sandbox but from what I understand this is usually in a corporate environment where connections are MitM’d any way and potentially harmful files are run in a sandbox. Am I missing something? That being said I’m not sure very many would even notice files being exfilled by an AV especially if it were user targeted.
- NtGuy25 5y agoIt depends, but most consumer AV's upload. And alot of EDR's are implimenting cloud based detections, with the option for companies with IP risks to run an on prem version of their cloud server. A good example is this hackernews post from not long ago detailing how Windows Defender uploaded a beacon he made from a VM with no internet access (But connected to a LAN with his main computer) and exfiltrated it from there to Redmond and ran it, most likely in some automated scanner. https://news.ycombinator.com/item?id=21180019 https://news.ycombinator.com/item?id=21180019
- mikeiz404 5y agoWow that’s kind of alarming; I wouldn’t have expected that behavior from an OS provided AV (I would have assumed it would be more conservative) but maybe I shouldn’t be too surprised given the trends these days (and microsoft’s decisions with their recent OS’s too). Thanks for sharing.
- jenscow 5y agoPerhaps there are some heuristics/behaviours that cause a file to be uploaded for further investigation, to identify new threats.
- ev1 5y agoalmost every AV uploads files