5 ms·
AV doesn't detect the exploit mechanism -- that's not how it works. It's only pattern matching existing binaries. The difficulty level is "recompile with small
by throwaway09223 3y ago
AV doesn't detect the exploit mechanism -- that's not how it works. It's only pattern matching existing binaries.
The difficulty level is "recompile with small changes and test that it doesn't match" not "develop a new attack vector"
It really is stupid and pointless against an attacker with even a bare minimum of competence (able to run a software build vs downloading binaries)
- IIsi50MHz 3y agoThis would fit my expectations of a classical 1990s antivirus, however I would expect modern ones to also employ heuristics against behaviours. Are you referring specific'ly to a limitation ClamAV?
- consumer451 3y agoBut AV (EPP) could detect a binary which was passed through a traditional vector, like phishing or gaining access to a "trusted" email account and attaching a compromised PDF, as a random example. Just a reminder that I was originally talking about desktop Linux, and all of the additionally installed attack surface which that entails. It would seem to me that it does not matter how "technical" a user is, they are still human, and some of the time anyone could fall for a well formed phishing attack. We all get tired, overworked, or click too fast, etc. Not running AV on a desktop OS and relying on one's own superhuman technical ability seems like the exact type of hubris that would be ripe for attack.
- midasuni 3y agoHow many genuine issues (not nonsense like “blah.con has stored a cookie” does your av pick up?
- consumer451 3y agoIt is very likely that a modern AV (I should have been saying EPP) will pick up your average re-encoded payload, or Metasploit fun time. Certainly they will pickup most known vulnerabilities. Endpoint Protection (EPP) orgs use the same CVE DBs that adversaries use. See another user's comment: https://news.ycombinator.com/item?id=38594247 https://news.ycombinator.com/item?id=38594247 Security is an onion, perfect is the enemy of good, etc... Why make it easier for the adversaries? While annoying, running EPP on your desktop OS is not exactly neuroscience. Ideally, it's furnished by the OS provider so that there are fewer parties to trust. I hate to say it, but Microsoft is now teaching by example. MS has factually one of the best-in-class Endpoint Protection agents on the market. If resources allowed, all other desktop OS providers should follow suit, otherwise they are just shirking responsibility.
- EricLeer 3y agoAny recommendations for a good AV/EPP for desktop linux (ubuntu)?
- consumer451 3y agoYou have asked the most important question. I should have asked it as well. Would love other input as I’m not an Ubuntu daily driver anymore. It turns out 22.04 has ClamAV “provided and supported,” but not installed by default. So it should easily install manually. That’s what I would go with first, as it’s officially supported. An OS vendor supporting a specific AV vendor is a really big deal imho. If that is not satisfactory by some metric, and this is just my personal and dated opinion… I used to like Eset. I was naive before, but next time I install desktop Ubuntu, I will install ClamAV immediately.
- midasuni 3y agoSo presumably you run it. How many bad things has it stopped in the last 2 months?
- Jenda_ 3y ago> attaching a compromised PDF This means either: - a 0day, which would require the AV to have a PDF parser better than the standard document viewer, and the ability to sense that this PDF is "weird" -- I would expect AV companies to publish ads "our AV has detected a 0day in XXX" - a vulnerability was recently discovered in a PDF viewer, and the AV company can push their definitions earlier than the standard "package the fixed version - send to debian-security - let users upgrade" route. This would shorten the attack window by a few hours. Again, I would expect AV companies to boast "we were X hours earlier than the official fix". Which one is the case? Or is there another option? Actually, this whole "buggy PDF parser" thing should be solved by application sandboxing -- there is no need that document viewer needs any other access to my system. Unfortunately, Linux is lagging behind. There are some AppArmor experiments with not so great UX, and then there is QubesOS, which is difficult to use. The average Linux desktop is AFAIK almost unsandboxed.
- consumer451 3y agoThank you for replying. I am now at the limits of my understanding... I only ran Ubuntu as a desktop daily driver for a year or so, and I'm a muggle, so my understanding is limited. But, is there any real-world data on how often desktop Linux users run the equivalent of: sudo apt update sudo apt upgrade sudo apt dist-upgrade versus the more automated update systems MacOS or Windows ? I am genuinely curious which ecosystem is more likely to be up to date. In my limited experience, I ran into issues updating on Ubuntu, and have not on MacOS and Windows. It seems like MacOS does it best as most applications come via the App Store, and on Windows that's in the future leaving most apps to take care of their own updates. However, Windows makes up for that a little bit with excellent, and auto-updated EPP, so that's something at least. In your view, which desktop OS is most likely to be up to date for OS and apps?
- Jenda_ 3y agoI think Ubuntu has some kind of notifier in "tray". For me, I am subscribed to debian-security mailing list and update when something that is running on systems that I manage seems to be affected. > versus the more automated update systems MacOS or Windows I'm not sure -- it is better with Microsoft Store, but other apps solve updates on their own, with various success. I have little experience with Windows and no with mac OS, so I cannot comment.
- throwaway09223 3y agoThe point is that it offers absolutely no defense against an APT -- who can simply include a binary that won't match any known exploit pattern. It is not a meaningful technical barrier. It's the equivalent of storing a big table of mean things people said in a chat and suggesting this could prevent a capable person from insulting someone. Any moderately competent person can think of a way to communicate without using previously blocked phrases with minimal effort. The AV databases are known - it is trivial to test against them to ensure a binary won't match. AV is a crude tool, good only for blocking the most basic of efforts. It has no utility against a nation state.