5 ms·
I've been running Windows without AV for over 10 years, so it's not even really necessary if you know what you're doing. The only anti-virus measure that I tak
by WayneDB 13y ago
I've been running Windows without AV for over 10 years, so it's not even really necessary if you know what you're doing.
The only anti-virus measure that I take is to upload unknown executables to http://www.virustotal.com/ http://www.virustotal.com/
- pwniekins 13y agoI suppose your AV free windows theory takes into account popular web sites infected with drive by exploit kits?
- brianpgordon 13y agoAn up-to-date Firefox plus NoScript gives me peace-of-mind on that front.
- thirsteh 13y agoAs far as you know. Even the dumb malware writers don't write stuff that pops up floating skulls and "OwNEd by CyBeRKiLLeR" messages anymore. It's all about staying on the machine, and staying silent. I hate this "I've been running without AV for ages, and I never saw any viruses" argument. Of course you didn't. Making you aware hasn't been the motive for a long, long time. It's virtually impossible to run a Windows (or Linux, or Mac) installation with the usual suspects--Java, Flash, Adobe Reader, etc.--without being exposed to good old, non-targeted malware. Take into account that most of it is distributed from "good" sites, and "if I don't see it, it must mean there's nothing there" and "I never go to any risky sites" prove pretty silly. I'm not saying that AV is the best solution, or even a good one--indeed it can even be what contains the vulnerabilities used to take over a machine--but there is a reason it exists. Let's not pretend that AV solves all ones problems, but let's also not pretend that it's completely ineffective. It's only ineffective if there really is no other (probable) way for things it detects to get through--which there is on most desktop operating systems unless you (manually) go to great lengths to isolate the different things you do. There are ways to make AV moot, but it rarely comes built-in or without user overhead/experience requirements. (Ironically, in Windows 8 anti-virus comes built-in.)
- stinos 13y agofor your 3rd paragraph: I'm not sure I'm following you - are you saying that virtually every machine is infected? How come? btw I have been running without AVG for ages on all kinds of systems. Once in a while I'm checking if my habits are still ok and run a bunch of standalone scans. They never find a single thing. Does that mean they all suck hard and that my machines are infected by newer and more invisble things than they can find? (note this is an honest question. I have no clue.)
- Piskvorrr 13y agoAs I understand this, virtually every machine gets exposed to the garden-variety malware; whether it's vulnerable to the given exploit is a different matter (look at the obsolete Java and Flash plugins eeeverywhere). Moreover, it is also important whether the exploit has an appropriate payload for the given system (I have yet to see e.g. a browser-vector transmitted payload which would run on Linux - which says something about its marketshare, not necessarily about its security). And of course "absence of evidence is not evidence of absence," so either the scans suck hard, or you're clean; but barring a more specific (and probably not fully-automated) inspection, there's no way to tell.
- thirsteh 13y agoYou hit the nail on the head.
- WayneDB 13y agoAnd I hate the "I can't imagine how to do this, so it's not possible" argument. We have syslogs going back 7 years. You want to come audit our network? I'll bet you all of the money in my bank account that you find nothing. > with the usual suspects--Java, Flash, Adobe Reader, etc... Nobody in my house runs those. > It's all about staying on the machine, and staying silent. They have to communicate over the network at some point though. Otherwise, it'd be useless. So yeah - as far as I know - and that's pretty damn far.
- 13y ago
- jmspring 13y agoEarliest defense for making sure windows doesn't get infected - NAT, don't leave a windows machine on a public IP... I actually miss the old versions of McAfee vscan and equivalents. Light weight, checked things over (yes, it wasn't active, might miss corrupting programs, etc...), but if you know what you are doing, like above mentions, you can be pretty safe on windows. That said, I'm mostly a mac/'nix house hold these days.
- thirsteh 13y ago> Earliest defense for making sure windows doesn't get infected - NAT, don't leave a windows machine on a public IP... Yes, but a basic one. You'd prevent something running on port X from being exploited directly. Doesn't do anything against other methods, like getting you to open a shady PDF or SWF file. > That said, I'm mostly a mac/'nix house hold these days. If you're running a window manager, there's virtually no difference between them and recent versions of Windows. If anything, Windows has the upper hand on the non-headless side. It's nice to be able to say "At least I'm not on Windows anymore", but it is no reason whatsoever to not be as vigilant. The primary reason why you're not targeted as much on OS X or Linux is not that they have a much smaller attack surface than Windows (anymore.) It's that it doesn't make economic sense for an attacker to target Linux users if they are less than 2% of the desktop computer market share, and they generally consist of tech-savvy (e.g. more likely to use NoScript, or spot shady processes than normals).