4 ms·
> And how do you know you have not got malware in years? Same way you can tell whether you're feeling healthy or sick. Same way you "know" something is wrong
by wfunction 12y ago
> And how do you know you have not got malware in years?
Same way you can tell whether you're feeling healthy or sick.
Same way you "know" something is wrong when your car stops running the same way it usually does.
i.e., I can't prove it one way or another, but that doesn't matter. In practice, I mentally keep a tab on how my computer is running -- my computer's CPU usage, network activity, I/O activity, internet connection speed, etc. so I can tell when something's not going right.
I don't keep crapware on my computer either, so when a process shows up that I don't recognize, then I can easily tell. I have notifications set up for newly-installed system services, so when a new service or driver is installed I get a popup for that too.
Obviously, I can't prove it's malware-free, but who cares? I don't need to.
I simply have no evidence in support of malware existing on my computer, so as far as I'm concerned, it isn't. Just like you can't mathematically prove to me that your car is OK, I can't mathematically prove to you that my computer is running OK. But that doesn't matter because I'm reasonably sure it is, and I have no evidence to believe otherwise. And that's really all that matters.
And for that matter, it's not like I could be sure I didn't have malware if I did follow those practice either. It's just a tradeoff between the likelihood of malware and the amount of convenience you're willing to give up. You can never be sure, and you don't need to.
- ayrx 12y agoYou are missing the point. If malware has root privileges, and they will if you are running everything as root, all the signs you are looking for can be masked.
- scrollaway 12y agoYou may very well be running malware you don't know about. Things that report to the NSA or to some random botnet; stuff that replaces /usr/bin/ps and /usr/bin/top to hide itself, and so on. Yes, it can do that. Because you run as root. And, no offense, but seeing your judgement regarding root and you actually thinking that sandboxing is a terrible idea because "you know better", well... I wouldn't touch your judgement with a 3 meter stick, be it on feeling healthy or on your computer running malware.