9 ms·
Why Developers Hate Antiviruses
- mdaniel 15y agoI was expected the article to discuss how much the HDD on your machine thrashes (and the fans sound like a jet engine) from scanning every .class and .jar file on your machine, of which there are usually tens of thousands. And I wish I had a Euro for every client site we've had to manage where some javascript scanner thinks it's so smart and drags the performance of a web-app to a crawl.
- GeoffWozniak 15y agoOr the SVN repositories of binaries that are 4G just on the trunk branch. The HDD basically never stops.
- Nima2712 15y agoHahahahaha. --> EVERY. FUCKING. WEEK.
- icehawk 15y agoOh, and all your EXE-files will also be marked as viruses by the way (since you're most likely using a "self-executing-unpacker-code + data" architecture, which is considered a risk-factor by most antiviruses, no idea why). Because most malware does this exact thing to obfuscate its payload. Here's a good example of the relative entropy distribution of malware executables versus non-malware executables on page 26 and 27: http://www.virusbtn.com/pdf/conference_slides/2007/CaseySheehanVB2007.pdf http://www.virusbtn.com/pdf/conference_slides/2007/CaseyShee...
- bkyan 15y agoIs there really a reason to even run anti-virus software all the time as long as you don't try to open executables and macro-containing documents that didn't come from a reputable source?
- AdamTReineke 15y agoNo, because if you visit a site that successfully exploits an unpatched vulnerability in your browser (or plugins) that allows for remote code execution, you WILL be infected. I'd label myself extremely savvy and I've been hit by what I think were ads loading a Java applet that somehow broke out of the JRE and ran an executable.
- jgmmo 15y agoThis. The days of needing to allow or execute malicious executables has passed. Drive-by downloads are extremely common, they use a vulnerability - and bam they can download whatever they want to your PC -- which in turn, will download more stuff.
- InclinedPlane 15y agoI always turn off Java on the browsers I use. It's a HUGE security hole that allows for drive-by infections and the cost of not having java applet support is something I can very much live with.
- finnw 15y ago> It's a HUGE security hole That's not entirely accurate. Most vulnerabilities do get patched quickly. It's still not worth enabling it in your browser though, because so few sites use it.
- dangrossman 15y agoYes, because you don't even have to be using the computer to acquire new malware -- if Windows isn't patched and you don't have a properly configured firewall in front of the system. Simply browsing the web with fully patched Windows behind a firewall is a risk as well. Among other things, I review orders for an advertising service, 20-30 a day. Some of these orders are purposely placed to advertise sites with malicious code that installs malware. My fully patched Windows 7 system behind a firewall, running antivirus and the latest Google Chrome, gets infected with something or other on a regular basis -- at least once a month -- without me ever downloading any files. Last week it was one of those fake antivirus programs that terminates all your real antivirus programs and pops up a window saying you're infected and need to upgrade for $29.99 every 20 seconds. That one was probably a Java plugin vulnerability.
- jconley 15y agoThe business of antivirus, especially, has a huge incentive to shove it IN YOUR FACE that the software is detecting things whether they're false positives or not. This scares people into re-upping their subscription. Most computer users don't understand there can even be such a thing as false positive. For all those support calls you get, there are probably 10x that number that simply take the security software on its word and let it delete/block your application. An aptly timed popup from the antivirus vendor will appear shortly thereafter asking the user to pre-purchase 2 more years of complete computer protection! Oh, the business of fear mongering. . . EDIT: This is one of those very hard problems startups should be solving.
- jgmmo 15y agoIt's flat out wrong of you to say that antivirus companies don't care about FP's. There are over 25k new malware samples coming out daily, and everybody is just trying to cut through them as fast and efficiently as possible. Yes there are innocent casualties of this -- False positives -- but these are sincere mistakes . False positives are very embarrassing for the security company. It is something that can even cause people their jobs. Don't you think for a second that these are not looked at. I make malware definitions for a living, and you can trust me when I say that I check the FP reports first thing every morning, several times during the work day, & I check our forums every night at home to make sure we don't have any FP's rolling in. At most security software companies, FP's taken very seriously & I know that personally I would love to be able to educate Indie developers about what triggers detections and ways we can both work together to reduce them. It's easier said then done, however, and also it is delicate info that you don't really want to yell off the rooftops - because malware creators could really use the same info to their advantage.
- jconley 15y agoI didn't say the industry doesn't care. But, the business model relies on detecting as much as possible and shoving that in your face to get more bookings. I have no doubt you take false positives very seriously at an engineering level. However, the bottom line impact of a false positive on some indie software has to be negligible.
- jasonkester 15y agoExcellent timing. I just alt+tabbed away from writing an email to McAfee because one of my users sent me a screenshot of s3stat.com with a bright red "Dangerous Site Warning" from McAfee's SiteAdvisor. Evidently, "We tested this site and found it very risky". Even though it's the public site for a 5-year-established (and popular) SaaS product. Even though it has no downloadable executables of any description. Even though it has no non-moderated user-generated content. But it's got this: http://www.siteadvisor.com/sites/www.s3stat.com http://www.siteadvisor.com/sites/www.s3stat.com ... which is a page saying that their automated somethingorother scraped the internet and decided that my site is crazy dangerous, listing reasons such as... well, nothing actually. But look at it. It's RED! Must be bad. So even if you don't actually write software that could possibly contain viruses, you can still end up on the wrong side of the antivirus companies. nice.
- dhimes 15y agoHoly shit! Seeing your comment, I checked out two of my own sites. One hosts software that I no longer sell (www.egorg.com), and it checked out ok. Interestingly, Yahoo (my host-- hey, it was my first! And paypal integrated easily! Besides, pg built the tech so...) flagged it last week during one of their auto-scans. They couldn't explain why- they just flagged it. But here is something that is peculiar: my main company site. When I went to vlesolutions.com (ie, http://www.siteadvisor.com/sites/www.vlesolutions.com http://www.siteadvisor.com/sites/www.vlesolutions.com) I saw this message: We've tested millions of websites, but we haven't tested this one yet. Be the first one to submit feedback on it! Maybe it is possible to wreck someone's reputation by submitting bogus feedback to a site they haven't scanned yet. I would be curious how they answer you, because I see nothing that would cause a red flag in their "tests" for your site.
- freehunter 15y agoI work in information security for a company who uses McAfee products, and I share your irritation. It can be quite a chore to track down why WebWasher is blocking a site or why our SIEM has flagged a site as a botnet C&C or otherwise risky site. It doesn't help when we get business groups or developers saying "we need this site unblocked in order to see a 1pm webinar!" and it's 12:59. Site Advisor is useless.
- phzbOx 15y agoFor me it's not so much that it's not always accurate but more than it always make my computer soooo slow. And also, that I don't believe in antivirus.. Precaution is everything; One you've got the virus, unless it's a trivial or unoffensive one, better to format.
- InclinedPlane 15y agoI don't run anti-virus, the cons are too big and it's not actually a good protection over just taking common sense precautions. I've only been bitten by infections on 2 occasions over 20+ years, and anti-virus wouldn't have helped with either.
- naner 15y agoOh, man. I use Linux for my day job but keep a Windows 7 install should the need arise. An old friend sent me a link to try out a video game he and a buddy made in college. I downloaded the program, Norton deletes it immediately. It didn't recognize the application signature. (Actually, it recognized it but it wasn't popular enough -- about 100 people had apparently downloaded this game that also used Norton.) After dicking around with Norton for about 30 minutes (nearly drowning in a sea of check boxes and vaguely titled program options), and reaching the boundaries of my Google-fu I just gave up and removed Norton. Problem solved. I'm glad I'm not a startup or small company trying to ship Windows executables.
- danudey 15y agoMy first call when doing tech support at a local ISP was someone who couldn't get online. It said he was connected, his network device was working fine, he was on the WiFi and it said he had great signal, but nothing worked. I walked him through getting to Add/Remove Programs and asked him if he saw Norton Internet Security. Told him to uninstall it. Everything works. He asked if that made his computer less secure. I said 'Technically yes, but only because you can actually use the internet now.' I worked at that ISP for a week, had the same problem come up three times. My mother had the same issue, and I've had two other friends who had it. Thankfully, I knew how to deal with it because it had happened to me when I bought a Dell laptop years ago.
- bwarp 15y agoI've come to the conclusion that AV software gets more attrocious the more you pay for it or the more it requires advertising every 5 minutes on television. They push it on you via scaremongering every day at least once. HOWEVER, I've been using Microsoft's free security essentials package for Windows 7 for about 2 years. It never pokes you in the eye, never lets a single thing through and doesn't screw your system resources. It just keeps out of your way. As I said, it's $0 which is how much it should cost and is supplied by the vendor which knows their own security problems the best. With respect to Linux or MacOS X, I never have installed an AV package ever.
- deleted 15y ago[deleted]
- keithpeter 15y agoI'll look into that for the Win7 partition on my old laptop, thanks. I do run ClamAV on my linux big box, just in case I'm passing on any Windows virii, this might be voodoo
- finnw 15y agoThe only trouble I've ever had with MSE is that if you edit your hosts file to block the Facebook "like" button, MSE will pop up a warning and delete the www.facebook.com entry.
- kijin 15y agoI've had this happen, too. But after the first time I told MSE that it was a false positive, it never bothered me again about the hosts file. Good doggy.
- bwarp 15y agoThat's MSE thinking that something has modified the hosts file and resetting it. I'd go for an ad blocker rather than a hosts file hack. Adblock plus works fine on Firefox and Chrome. There are TPL subscriptions for IE that block everything (google around for them).
- kruhft 15y agoI was trying to install netcat on a work windows box to transfer some files (long story). Every attempt at copying the executable out of the zip file would throw up an error about the file not existing, no explanation as to why or who was causing the error. After an hour I removed the antivirus. File copied just fine after that. I guess netcat is a 'hacker tool' and not allowed on protected windows system; too bad I had work to do.
- powertower 15y agoThe bigger issue here is that people think there is a "perfect" world out there, that someone is obviously preventing you from reaching... There isn't. It's all about either keeping some type of a balance going or shoveling enough shit as to not get buried in it.
- johngalt 15y agoIT guy here: Anti-virus tools are a net loss, but we can't remove them without appearing to be irresponsible.
- kijin 15y agoMicrosoft Security Essentials is a nice compromise if you need to appear responsible to individuals and small businesses. It gets the job done, and it's only minimally intrusive. It also comes from a company that most people tend to trust. Norton, on the other hand, is pure evil. If Microsoft bundled Security Essentials with Windows and thereby pushed all those pathetic AV vendors out of business (just like they did with web browsers), I might turn a blind eye this time and call it the lesser of two evils.
- bad_user 15y agoSure you can. Replace it with a simple app that randomly shows fake notifications for threats, with a clickable button called "remove threat" that doesn't do anything. Upon clicking, show some stats on how many fake threats were dodged. (1) you won't be seen as irresponsible anymore (2) since users will constantly receive threat warnings, they'll be more careful than usual, improving security
- polymatter 15y agoGreat idea, but like many similar ideas (eugenics, human experimentation, doctors prescribing placebos, licence to breed) too 'unethical'.
- Craiggybear 15y agoWell, if you will dabble away in Windows, this is bound to happen. Stop writing for it and it'll go away. Man: "Doctor! Doctor! It hurts when I do this!" Doctor: "Well, stop doing that ..."
- politician 15y agoDoctor: Furthermore, start doing the same thing (developing software) to the other one (Linux) because it's .. Er.. fresh. Man: Wait, but won't the other one start hurting because I'm using it more? Doctor: Oh right, I guess if everyone switching to use Linux tomorrow, then the malware authors would begin targeting it more aggressively. I supposed my anti-Microsoft rant was misplaced.
- Craiggybear 15y agoJust wrong on so many levels, I don't know where to start.
- malkia 15y agoOn Windows one can compile a DLL or EXE in such way that you can overwrite the executable while it's still running. With the Microsoft Linker this is achieved by adding /SWAPRUN:CD,NET - it means that the image might be running of CD-ROM or Network - and both can lose media connection, so copy the image in memory beforehand. This could be useful, only if it wasn't for certain Anti-viruses that treat a lot of my executables as viruses once any of these two flags are on (CD, NET or both). You can actually edit the flags on existing executable, using EDITBIN (or LINK /edit - it's the same - linker is a bit like "busybox" here). Another reason is that the antivirus we currently have installed at work slows down copying off the shared network. And because it's off the network, the antivirus has to check it everytime (unlike HDD, where it can keep some cache of what was checked).
- learc83 15y agoWhen I worked at Geek Squad during college, we used to joke that Norton Internet Security had decided the internet was too dangerous and automatically disabled it. You have no idead how many internet connection problems I solved with the Norton removal tool.
- Nelson69 15y agoI see this a couple ways. If you pull binaries off the internet, it's hard to say you can just ignore it and don't need any protection. That is exactly the kind of thinking that got us to where we are with malware in the first place. I just can't see a downside to scanning your system once a week after hours or something like that; most of the time it will find nothing but if it ever finds anything it's probably worth it. Then I look at the products out there, there are a lot of them and they all seem terrible. We've got giant computers compared to 10 years ago and this software still takes them to their knees at times and you just want the crap to be invisible. In part I think it has to do with the all encompassing "security suite" concept where they try to be all things to all people. It does seem ripe for some disruption. I mean, like maybe using some virtualization software to have multiple "zones" or something, trusted, suspect and untrusted and some clever reverting and snap-shotting to let you run programs in untrusted environments fairly seamlessly or something. Scan it with some uberscanner and then promote it to trusted. Or something, the OS vendors will have to help and MS has created an AV cesspool.
- jff 15y agoQubes (http://qubes-os.org/Home.html http://qubes-os.org/Home.html) sort of aims to use virtualization to separate out all your software. It's Linux, though.
- derleth 15y agoOn a related note, 'personal' (that is, software) firewalls are worse than useless: http://web.archive.org/web/20100204074441/http://samspade.org/d/firewalls.html http://web.archive.org/web/20100204074441/http://samspade.or...
- mey 15y agoAs an former Windows user who never ran A/V because of the stated reasons, in my old age I've finally broken down started using one as rebuilding a box is no longer high on my priority list. If you are a home user on windows, I highly highly recommend http://windows.microsoft.com/en-US/windows/products/security-essentials http://windows.microsoft.com/en-US/windows/products/security... It's free, it stays the hell out of the way, doesn't slow the system down, and works. Edit: I do not work for Microsoft, and this post was written on a netbook running Ubuntu.
- someone13 15y agoThere seems to be a lot of hate for antiviruses here on HN. I have this question, then - what kind of features would YOU want from an antivirus? If a startup was to launch tomorrow with some sort of antivirus or similar product, what would it need to have for you to buy/subscribe/etc.?
- cagey 15y agoA flawless uninstaller!
- tikhonj 15y agoIs an anti-virus even the right approach, especially for an experienced user? Wouldn't some sort of permissions management (maybe like SELinux or AppArmor) coupled with a firewall be just as secure? Getting the majority of your software from a repository (e.g. with yum or apt-get) also seems like it would help significantly. I'm not a security expert, but it seems like you can have a perfectly secure computer without an anti-virus.
- redthrowaway 15y agoBasically, be MSE: unobtrusive. I haven't written anything for windows since high school, so I don't know how it stacks up for devs, but it's great from the user's pov. Free, lightweight, and invisible: everything I want in an antivirus program.
- X-Istence 15y agoFrom a developers standpoint, MSE is pretty damn awesome. Never had an issue with it :P
- atesti 15y agoNever delete a file automatically! Always ask and use quarantaine. MSE is madness and all the others, too because they destroy important files without asking.
- gnu8 15y ago> Because if your software has some kind of copy-protection built-in (encrypts and stores serial numbers, hides and encrypts parts of the source code to protect from reverse engineering etc.) - an antivirus will most likely detect some "very dangerous" trojan. Don't waste your time with this crap. You don't have any secrets on my computer. I will crack your DRM and reverse engineer as I please.
- justncase80 15y agoAnti-virus is a flawed idea in general. The incentives are all wrong in the business model for one thing, the other thing is that it literally cannot possible protect you from new viruses. It's just a completely flawed idea, and in practice it is a net loss.
- yason 15y agoAren't modern Windows capable of installing everything as root and keep the user account from infecting anything that is on the system level? That effectively solves the virus problem since the worst that can happen is that something unwanted runs as the user privileges or deletes/infects files in home directory. The machine itself stays clean and you can avoid full reinstalls. If the user gets a virus then all you need is restore his home directory from a clean backup. And if you want, possibly run some antivirus on anything that gets backed up, to try to make yourself feel good about backups being clean.
- AndrewDucker 15y agoI hate them because every time I compile my code dozens of DLLs get copied from folder to folder and they all get scanned _every time_. Why it can't keep a list of known good DLLs and then not rescan them, I don't know...