5 ms·
You’d be surprised how many “virus scanners” are implemented with poorly coded C parsers running as privileged user with no sandboxing… just saying, kind of ask
by ipython 3y ago
You’d be surprised how many “virus scanners” are implemented with poorly coded C parsers running as privileged user with no sandboxing… just saying, kind of asking for trouble.
- nickpeterson 3y agoI remember awhile back the lead of the chrome dev team getting into a twitter fight with some engineer from a popular antivirus tool because, as I recall, AV tools are basically just more attack surface. I tend to agree.
- ethbr0 3y agoWindows/client AV tools have a who-watches-the-watchers problem. If you're trying to detect threats that exploit OS, you need to be even lower level. But if you're lower, then you're an even more inviting target. Unfortunately, add on that no customer makes a profit off their IT security org. Which disincentivizes excellence and incentivizes feature check-boxing at the lowest price point. Which ultimately produces a highly privileged piece of software developed on budget salaries. One reason MS security was a game changer (once the company got off its butt and admitted security was an existential threat to their OS sales) -- they could afford to burn great magnitudes of money to deliver. (No offense intended to any of the amazingly brilliant non-MS Windows AV folks out there)
- eecc 3y agoIndeed it does happen https://www.cvedetails.com/vulnerability-list/vendor_id-26/product_id-9767/Microsoft-Windows-Defender.html https://www.cvedetails.com/vulnerability-list/vendor_id-26/p...
- spookthesunset 3y agoI’m still not entirely convinced that virus scanners do anything useful at all besides hog resources.
- firecall 3y agoMalware Bytes helps identify, stop and remove malware Crypto Miners! In my social circle, the kids Gaming PCs getting infected is very common. Recently one of my boxes got hacked via a QBitTorrent exploit, and I didnt have Malware detection running, other than the built in W11 system. I installed Malwarebytes and it detected and correctly removed the malware crypto miner. FYI they exploited QBT via the web interface, which had default settings, but wasn't exposed via port forwarding to the web. It might have been via UPNP, which was enabled. No idea - but it's a common exploit used to DL a torrent then run a post DL script .bat file to DL and run a crypto miner. I'd literally had QBT running on Windows for a couple of weeks, having switched from a dockerized setup on a Mac Mini. How Windows allows the running of a .bat file to DL an .exe that can run a crypto miner is just a bonkers lack of security! Naturally I had to nuke the box from space anyway :-)
- samstave 3y agoYou dont have to answer, curious - how old are you? (you speak with a fluidity I did in my gaming heyday - but I am over the global heap at this point.)
- Thorrez 3y ago>How Windows allows the running of a .bat file to DL an .exe that can run a crypto miner is just a bonkers lack of security! Is it any different from Linux allowing the running of a .sh file to DL an ELF executable that can run a crypto miner?
- eecc 3y agoYeah, all these cool kids showing off their shell skills with their new js frameworks distributed like ‘curl https://djdhdhdb/dish.sh https://djdhdhdb/dish.sh | sh’
- squeaky-clean 3y agoI think a big difference here is Linux distros don't include an active anti-virus while Windows does.
- rocqua 3y agoA virus scanner needs to implement parsers for so many different formats on the budget of a medium software company, with a pressure to deliver fast. the chances of not making any mistakes are small, and antivirus needs to run with high privileges.
- hulitu 3y agoThe parsers do not need "system priviledges" to run.