5 ms·
The real thing I've learned from this is that most malware doesn't get ring 0 access, but these "antiviruses" solutions can shutdown the whole critical infrastr
by chad1n 2y ago
The real thing I've learned from this is that most malware doesn't get ring 0 access, but these "antiviruses" solutions can shutdown the whole critical infrastructure everywhere. I've never seen malware that infected millions of devices in seconds and made them unusable for days and maybe weeks to come.
- chgs 2y agoI saw it a couple of days ago…
- Aeolun 2y agoMost people do not (deliberately) give malware root access to their PC
- karlgkk 2y ago> I've never seen malware that infected millions of devices in seconds and made them unusable for days and maybe weeks to come. Yes, well, that's because we have built much more resilient systems, of which anti-virus is a substantial part of. You could start with the Morris worm, but a more recent example would be the Stuxnet cleanup efforts (largely done with AV). AV is (thankfully) becoming less and less relevant, but it's still a valid layer of defense for many platforms.
- cqqxo4zV46cp 2y agoYeah, this logic is absolutely deranged and 100% stems from a hate of forced AV on work machines or something. Pretty much every common modern-day security defensive is reactive, in that you can point to a point in time where we didn’t have it, and can pretty easily see the consequences of that.
- ironbound 2y ago'Being ignorant is not so much a shame, as being unwilling to learn.' Back in the day, you could install windows XP and be infested in minutes https://en.wikipedia.org/wiki/Blaster_%28computer_worm%29 https://en.wikipedia.org/wiki/Blaster_%28computer_worm%29
- anthk 2y agoSasser, too.
- rightbyte 2y agoGiving someone else [edit: remote] root access to your computer is a bad idea. For Windows users it is bad enough with Microsoft. Adding another one is just adding to the risk. Centralizing power is asking for abuse.
- schiffern 2y agoSo this is an argument for only using first-party (Microsoft) security software?
- rightbyte 2y agoYe I guess so. I'd argue to use some Linux distro though to remove the root remote code execution CVE.
- chgs 2y agoYou can buy RCE malware for Linux too - including crowdstrike. If you want a third party to manage your systems then it doesn’t matter what third party you choose Personally I’d go for diversity over any specific solution. That’s a rare thing in “enterprise” world. I suspect companies with strong shadow IT which provides business value for far better than those top down enterprise led ones.
- ryandrake 2y agoI'd rather[1] give "Microsoft and only Microsoft" the ability to remotely update my system, than "Microsoft and whatever fly-by-night 3rd party 'security' companies manages to sell their malware to my boss." A big problem here is that Microsoft has normalized the idea of rando third-party software having access to ring 0 and things running at the kernel level. This is one of the reasons many Linux people argue against opaque third-party blobs running in the kernel. This should not be as routine as it is in the Windows world. Apple wisely ditched kernel extensions. 1: EDIT: Ideally, I'd rather Microsoft not have access to remotely update my system, either, but that ship seems to have sailed long ago.
- dist-epoch 2y ago
- notepad0x90 2y agonot millions but lookup shamoon. Wannacry was at 300k+ machines, it wasn't millions because one guy registered the kill switch domain within a couple of hours. Ring 0 is bad but malware do get SYSTEM all the time, they can inhibit booting at that point just the same.
- anthk 2y agoBlaster infected millions, among Sasser.