3 ms·
> You see this most clearly in endpoint security, where "defense in depth" loaded everyone up with security and AV agents that were all riddled with memory corr
by dataflow 2y ago
> You see this most clearly in endpoint security, where "defense in depth" loaded everyone up with security and AV agents that were all riddled with memory corruption vulnerabilities
There's no way you can seriously argue AVs have caused remotely as much damage as they've mitigated or prevented. Especially not without any kind of citation to back it up.
> It has in cases prevented [...]
A lot of things go wrong "in cases". In cases, governments give poor recommendations. In cases, HN users give nonsensical opinions. In cases, police end up killing civilians instead of criminals. In cases, criminals go free because they refuse to testify against themselves. I could go on, but you could use this kind of argument to dismantle just about anything you don't like. Especially when you absolve yourself of the need to provide any kind of evidence of the relative harms.
- tptacek 2y agoNot only do I argue that, but it's a banal argument among security practitioners.
- dataflow 2y ago> Not only do I argue that, but it's a banal argument among security practitioners. Well that's great to know. Do all security practitioners also believe whatever they hear from each other without question? Or do they only expect us mortals to treat them that way?
- tptacek 2y agoIf you're not a practitioner and you'd like to learn things, I recommend asking questions, rather than saying "citation needed".