21 ms·
Do you need antivirus software in 2024?
- saagarjha 2y agohttps://news.ycombinator.com/item?id=40100430 https://news.ycombinator.com/item?id=40100430
- beachy 2y ago> Readers considering antivirus software should also be aware that such software – ironically – presents a risk just by its very nature. My stepfather went to a grey power meeting (a kind of seniors meetup) and the speaker of the day terrified everyone there with talk of viruses. When I next saw him he proudly told me no longer had any fear of viruses - in fact he had installed 7 different anti-virus products just to be safe. When I asked him where he had found them, he told me he simply googled for them (or maybe yahoo-ed back then) and downloaded them straight off the interweb. I simply could not persuade him that that was not a wise strategy.
- Rinzler89 2y agoThere is a 62 year old man in Germany who went and got 217 Covid vaccines in the span of 29 months.[1] Covid was probably afraid to catch him. Funny how with Germany's extensive paperwork bureaucracy where every little detail must be recorded and tracked, the healthcare workers couldn't catch this guy earlier. [1] https://www.bbc.com/news/health-68477735 https://www.bbc.com/news/health-68477735
- jv95 2y agoGermany made a lot of mistakes over COVID. There were several cases of testing center scams where people reported more tests than they actually administered. No proof required. There is not a lot of bureaucracy surrounding vaccinations at least not from a patients point of view. So if you forgot or lost your vaccination pass you could probably just get another shot especially if you’re older/at risk.
- moritzwarhier 2y agoNot sure why you arw being downvoted, the testing center scams are estimated to have cost more than a billion euros [^1] and from the experiences I had, the people that ran them, and their sheer abundance, this number is probably a very conservative number, and it doesn't include yet all the ones that operated on the brink of scamminess. There wasn't a need to completely and obviously fake the numbers to funnel a lot of public money into your pockets, often without providing any tangible benefit (no qualified personnel, unreliable tests, inadequate execution). Way into 2021 many streets in the city I live in had one improvised testing center next to the other, mostly ran by people without any medical qualification, using tutorials from the internet and a process almost designed for corruption, where setting up a test center was a state-funded get-rich-quick scheme for quite a while. [1] https://www1.wdr.de/nachrichten/landespolitik/betrug-corona-schnelltests-keine-nachkontrollen-100.html https://www1.wdr.de/nachrichten/landespolitik/betrug-corona-...
- bakuninsbart 2y agoVery rarely do I defend the last government of Germany, but the strategy was to give centers a good margin and low bureaucratic hurdle to maximize the number of testing centers and ensure that everyone can get tested everywhere. Given the seriousness and uncertainty of the situation at the time, I think that was a good call. And there was required documentation, it was just not checked at the time. Once the situation settled down, the state started clawing back fraudulent claims.
- fransje26 2y ago> There is not a lot of bureaucracy surrounding vaccinations at least not from a patients point of view. So if you forgot or lost your vaccination pass you could probably just get another shot especially if you’re older/at risk. That was by design, to facilitate and speed-up the vaccination process, and in the context, there was nothing wrong with that approach to keep the population safe and the country running.
- StrauXX 2y agoPrivacy and lack of digitization is big in Germany. There no central vaccination database or similar. You can have an "Impfpass" (vaccination pass) which is a piece of paper with stamps and signatures for your vaccinations. But no one would bat an eye if you "lost" it.
- BjoernKW 2y ago> Funny how with Germany's extensive paperwork bureaucracy where every little detail must be recorded and tracked, the healthcare workers couldn't catch this guy earlier. It's precisely because of this extensive paper-based bureaucracy such things happen, not despite of it. German bureaucracy is a complete and utter mess. By and large, it's a self-perpetuating end in itself that doesn't serve any purpose other than keeping itself (and the people and organisations involved in it) alive. Which is more, due to the Germany aversion towards digitization and digital processes (with a misconceived notion of privacy commonly known as "data protection" in Germany often used as an excuse) the data recorded by those bureaucratic processes basically is stored in a gargantuan pile of paper nobody is able to make sense of.
- fransje26 2y agoMy favourite example of the self-perpetuating nature of German bureaucracy is the story of the chinese tourist who, asking for directions in some administrative building, got mistaken for a refugee. It took more than a month, including placement in a refugee centre, before the administrative wheel stopped turning and it was realised that he was, in fact, only a tourist visiting Germany.
- OKRainbowKid 2y agoDo you have a source for that story? Asian refugees are pretty rare here, so it's interesting how they would confuse them for one.
- fransje26 2y agoHere you go: (I miss-remembered the duration. He was in the treadmill for two weeks.) https://edition.cnn.com/travel/article/chinese-tourist-mistaken-refugee/index.html https://edition.cnn.com/travel/article/chinese-tourist-mista... https://www.dw.com/en/chinese-tourist-mistaken-for-a-refugee-after-filing-wrong-german-paperwork/a-19459411 https://www.dw.com/en/chinese-tourist-mistaken-for-a-refugee...
- JohnClark1337 2y ago[dead]
- methuselah_in 2y agoDepends on mood. With windows now stock antivirus engine is enough! On Linux never required. If you are not surfing porn and visiting few old sites and just keep an eye as well not required!
- j4hdufd8 2y ago> On Linux never required Oh okay! Would you mind running a really cool program I have here for you?
- abhinavk 2y agoIf you stick to your distribution repositories, flathub/snapstore and never run `curl | bash` from untrusted sources, you would be fine. And if I have to run your bespoke program, I will use a sandbox or VM whether an antivirus is running or not.
- chgs 2y agoAnd if you do your AV program wouldn’t catch it anyway.
- m000 2y agoI rember many years ago trying to run netcat [1] on Windows for some tests. AV: Blocked as "hacking tool". I asked a friend who happened to have Visual Studio installed to build it for me from source. AV: No problemo! [1] https://nmap.org/ncat/ https://nmap.org/ncat/
- chgs 2y agoDid you try renaming it to “notnetcathonest.exe”?
- deleted 2y ago[deleted]
- 2y ago
- badgersnake 2y agoYou probably need it because your corporate IT department wrote a policy that says you must have it. As far as I can tell that’s the only reason. The AV scammers must have paid the SOC2 racket at lot of cash.
- chgs 2y agoThe problem is more that nobody wants to be changing policy as they won’t see a benefit and they will get blamed. Get hit by ransomware (which your AV wouldn’t detect), you get blamed for removing AV and you’re after a new job. Our password policy still demands periodic changes despite ncsc/microsoft/etc advice saying not to do that, because who wants to take the risk of changing policy.
- eviks 2y agoWhy wouldn't AV detect it? Some detect mass encryption of files and block it
- donatj 2y agoSomeone in a SOC2 meeting started making a fuss about us needing virus scanners on our Amazon Linux EC2 instances. I don’t think that got very far but… Just… Stop.
- kstrauser 2y agoThat’s absolutely a thing. It’s usually under the broader category of anti-malware. Why is the web server suddenly mining bitcoin? Edit: Source: have been through a few SOC 2 audits, enough to understand why they ask for most of the things in there. My personal thoughts on the matter aside, modern audits spend a lot more time on other malware than viruses.
- doubled112 2y agoAWS will send you an alert because your machine is behaving unusually. No need for local protection! /s sort of
- sam_goody 2y agoI installed Malwarebytes (somewhat recommended by this article) to do a one time scan on my Mac. It required me to install a service that would run always as a superuser, and would not uninstall completely. I wrote to them, and got no response. Why is that needed for a on-demand scanner? Why should I trust malwarebytes?
- _wire_ 2y agoChoosing the Uninstall option found under Malwarebytes for Mac Help menu effectively removed the service for me.
- chasd00 2y agoBy “effectively removed” do you mean literally and completely removed? I work in consulting and “effectively” gets used as a weasel word for “not really but you’ll never know the difference”.
- _wire_ 2y agoI recall looking into the details and feeling satisfied that the launch agent / daemon / helper was completely removed. But I did not perform a systematic examination of all file system state associated with the install. My point was to advise readers that there is an Uninstall option; just dragging the app to the trash is not enough. If OP has comments about specific droppings being left around, maybe in /private/var or wherever, would like to learn about it. For those unfamiliar with the recesses of macOS, there's a venerable tool called Etrecheck that is helpful for sussing out Mac config affecting security and performance.
- animal531 2y agoI'm still using Avast, but mostly just out of habit. Probably one day they'll annoy me enough with their popups that I'll just go ahead and delete it.
- latexr 2y agoAvast collected and sold user data. https://consumer.ftc.gov/consumer-alerts/2024/02/software-provider-avast-will-pay-165-million-compromising-consumers-privacy https://consumer.ftc.gov/consumer-alerts/2024/02/software-pr...
- ajdude 2y agoI'd be careful with them, they're not the same same company they used to be.
- fsflover 2y agoSee also: https://www.qubes-os.org/faq/#arent-antivirus-programs-and-firewalls-enough https://www.qubes-os.org/faq/#arent-antivirus-programs-and-f...
- carlosjobim 2y agoEvery time I've had to help a person remove viruses and malware from their computer, they've also had antivirus installed.
- paulryanrogers 2y agoNo vendor is perfect. In fact picking the top search result or ad is just as likely to provide fake anti-virus.
- carlosjobim 2y agoThese people all had anti-virus included from the shop where they bought their computer. Common names such as Norton, F-Secure, etc.
- abhinavk 2y agoYou just need the built-in Defender if you don't tread uncharted waters. On the other hand, even if you just stick to OS App Stores and popular github repos, you can still get infected without an antivirus. There are malware in Windows Store. https://www.reddit.com/r/antivirus/comments/1c690so/learned_a_lesson_never_trust_random_ass_apps_on/ https://www.reddit.com/r/antivirus/comments/1c690so/learned_...
- IshKebab 2y agoDepends what you mean by "tread uncharted waters". In my experience just browsing the web in Chrome is totally fine even on torrent sites (at least mainstream ones). Chrome vulnerabilities at this point are far too valuable to use indiscriminately. They'll be sold on the grey market to be used against journalists in the middle east or whatever. Even downloading films from bittorrent and playing them in VLC seems to be safe too, even though I would have thought that was an obvious attack vector. Maybe the social aspect if bittorrent helps a bit there. I think the most likely ways to get infected these days are by falling for fake download sites, and maybe cracked games, though I don't play those so I'm not sure.
- batch12 2y agoThere is much more value in using tools that detect anomalous behavior and living-off-the-land techniques than classic malware-by-hash.
- paulryanrogers 2y agoAren't such tools also AV? Or at least anti-malware?
- batch12 2y agoSort of, they're typically classified as xdr or similar.
- jonstewart 2y agoThis guy is just some YouTuber, right? I appreciate a website devoted to documenting the privacy nightmare and helping people with settings, but this is just bad advice. I work in the incident response field; yes, you need A/V.
- magicalhippo 2y agoHopefully things have improved, but back in 2014 Joxean Koret held a quite interesting presentation[1][2] on how a large number of AV engines had serious flaws, including privilege escalations and remote exploits. I consider uBlock Origin to be my primary "antivirus" software, though having had some infections back in the DOS days and some scares later, it feels wrong running without anything else. [1]: https://ia804703.us.archive.org/14/items/CIAVAULT7PDFFILES/2014_EN_BreakingAVSoftware_JoxeanKoret.pdf https://ia804703.us.archive.org/14/items/CIAVAULT7PDFFILES/2... (slides) [2]: https://www.youtube.com/watch?v=wVxtcQmZnK0 https://www.youtube.com/watch?v=wVxtcQmZnK0
- jonstewart 2y agoOh, not all AV is created equal and even with the good ones, sure, they're fallible. But there are still many, many incidents where people get exploited by basic malware that most AV would stop. I would not actively recommend _against_ AV.
- sccxy 2y ago2 weeks ago new junior developer joined our company. He was really pissed that our company does not give out admin access to developers. And raised this problem in big company wide meeting and called our IT team ridiculous and told developers know how to handle computers. Week later IT team did company wide phishing test. Same new junior failed this test. Yes, even if rules are ridiculous. These rules help.
- spacecadet 2y agodont be this kid
- IshKebab 2y agoYeah but only because you shouldn't call it dumb in a company wide meeting just after you join. It is dumb, and thankfully I've never worked anywhere that denied admin access to engineers. Fine for HR or whatever.
- sccxy 2y agoActually there is special admin account, but you have to enter credentials manually. He wanted 100% admin account all the time.
- spacecadet 2y agoIn a really good org, Engineers THINK they have admin. lol.
- spacecadet 2y agoOK before you black and white nerds lose your minds, in some settings, like a startup, engineers are admins... but in general: Engineers should definitely not have "admin" access. They should have least privs for the systems and services they need access to... Dont be this either. It will end badly when you, in a stressed late night stupor, blow up your "admin" access... be smart- you honestly want least privs for your own protection!
- neallindsay 2y agoThe article seems mostly focused on Windows (which is probably appropriate), but the Mac also has built-in anti-virus called Xprotect. https://support.apple.com/guide/security/protecting-against-malware-sec469d47bd8/web https://support.apple.com/guide/security/protecting-against-...
- PlunderBunny 2y agoMicrosoft make a no-install malware scanner (The Microsoft Safety Scanner) [0]. It's very slow if you do a full HD scan, and will often report finding an issue with a file while scanning that isn't actually an issue if you let the scan complete. [0] https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/safety-scanner-download https://learn.microsoft.com/en-us/microsoft-365/security/def...
- diegof79 2y agoThe problem is that most people cannot tell the difference between a scam and a legitimate app. For example, my father wanted to watch some YouTube videos offline. He naively Googled " YouTube video download." The result was obvious: most of the links were scams. When you work on dev every day, your first option will be to search for open-source or a well-trusted source and distrust a scammy-looking website that promises you many things. After that experience, I started to see the value of Apple's App Store. Sadly, the chain of trust provided by the App Store is ruled by one company. I wonder why the industry couldn't agree on a single standard or method to do different chain of trust checks. For example, if all email clients adopt a sender identity check (like GPG), then spam and phishing will be extremely easy to eliminate. Suppose applications have a sort of group approval. In that case, the OS can warn you before trying to install or run a scammy app. (something like Apple's notarization + user vote, but without the control of a single entity). Is that a bad idea? What will be the flaws?
- eviks 2y agoEven past the pedantic that widows defender is antivirus software, the link justifying not using an alternative rates it as 54th out of 74 So the same experts the author relies on to defend the Defender have a much higher opinion of the alternatives (and Defender is very slow, why do you not care about the "average user" using average hardware enough to suggest he avoids the pains of slow computers) And recommendations in the end without real time protection is just ridiculous, so with all that I'd not rely on the author's opinion re anything security
- wasteduniverse 2y ago[dead]
- llmblockchain 2y agoI haven't used/installed antivirus (or firewall) software since 2010.
- mango7283 2y agoIn the final report on the Irish health services ransomware incident, AV did pick up early signs of the attack but they were not further acted upon - there is value to enterprise AV, provided you back it up with enterprise incident response... For home use, sure, just use defender and be careful, like the article says and you'll mostly be fine.
- Michzurn9 2y ago[dead]