5 ms·
Here's one of the reason not to install antivirus software: if a malicious adversary finds a vuln in the AV or hacks C&C servers, you have a nice backdoor you i
by ingenter 11y ago
Here's one of the reason not to install antivirus software: if a malicious adversary finds a vuln in the AV or hacks C&C servers, you have a nice backdoor you installed to "protect" yourself.
- flashman 11y agoDepends on your threat model. I'm more worried about something nasty in one of the many pieces of random software I download from the internet than my AV being compromised.
- hellbanner 11y agoUnfortunately our standard web browsers are insecure because of the way Javascripts work.
- chc 11y agoIn practice, JavaScript on the Web doesn't seem to be very high on the list of malware vectors.
- hellbanner 11y agoIsn't this what XSS is.. ?
- pestaa 11y agoAny scripting language can be properly sandboxed, JavaScript being no exception.
- dietrichepp 11y agoI hear a lot of people talk about security but very few people talk about threat models. We need more of this.
- shabble 11y agoAre there any good introductory taxonomies or categorisations of threats and potentially appropriate responses? The obvious distinctions that spring to my (uninformed) mind are: active (mitm, injection) vs passive (snooping, traffic analysis), targeted/opportunistic (maybe insider/outsider too?), and perhaps level of available resources (on the s'kiddie - lone hacker - collective - governmental spectrum, or something) I guess the biggest problem with not having a coherent threat model is that you can end up putting too much effort into the wrong things and have a false confidence in your security. Weakest links, and all that.
- Spearchucker 11y agoSTRIDE is the acronym used at Microsoft to categorize different threat types. STRIDE stands for: Spoofing Spoofing is attempting to gain access to a system by using a false identity. This can be accomplished using stolen user credentials or a false IP address. After the attacker successfully gains access as a legitimate user or host, elevation of privileges or abuse using authorization can begin. Tampering Tampering is the unauthorized modification of data, for example as it flows over a network between two computers. Repudiation Repudiation is the ability of users (legitimate or otherwise) to deny that they performed specific actions or transactions. Without adequate auditing, repudiation attacks are difficult to prove. Information disclosure Information disclosure is the unwanted exposure of private data. For example, a user views the contents of a table or file he or she is not authorized to open, or monitors data passed in plaintext over a network. Some examples of information disclosure vulnerabilities include the use of hidden form fields, comments embedded in Web pages that contain database connection strings and connection details, and weak exception handling that can lead to internal system level details being revealed to the client. Any of this information can be very useful to the attacker. Denial of service Denial of service is the process of making a system or application unavailable. For example, a denial of service attack might be accomplished by bombarding a server with requests to consume all available system resources or by passing it malformed input data that can crash an application process. Elevation of privilege Elevation of privilege occurs when a user with limited privileges assumes the identity of a privileged user to gain privileged access to an application. For example, an attacker with limited privileges might elevate his or her privilege level to compromise and take control of a highly privileged and trusted process or account. They use the DREAD model to calculate threat impact (risk). You can get the risk rating for a given threat by asking the following questions: Damage potential How great is the damage if the vulnerability is exploited? Reproducibility How easy is it to reproduce the attack? Exploitability How easy is it to launch an attack? Affected users As a rough percentage, how many users are affected? Discoverability How easy is it to find the vulnerability? Therese's more detail in chapter 3 [1] (threat modelling) of the book Improving Web Application Security: Threats and Countermeasures [2] Note the book was published 12 years ago. [1] https://msdn.microsoft.com/en-us/library/ff648644.aspx#c03618429_011 https://msdn.microsoft.com/en-us/library/ff648644.aspx#c0361... [2] https://msdn.microsoft.com/en-us/library/ff649874.aspx https://msdn.microsoft.com/en-us/library/ff649874.aspx
- hellbanner 11y agoWhat was the software.. Adaware, I believe, would block a fair bit of spyware.. except for the companies that it made deals with.
- deleted 11y ago[deleted]
- eeeeeeeeeeeee 11y agoYes, but it's a bit paranoid. Windows and Office are likely going to give you more entry points than the net gain you get from having antivirus/malware protection.
- meowface 11y agoThat's bordering on complete paranoia. You can make this argument for any software you install with auto-update capabilities... which is likely significantly more than half the software the average person has. Your AV company's infrastructure is probably a lot more secure than the infrastructure of browser plugins you use and games you play.
- kbenson 11y agoIf, like our phones, workstation software actually had to request specific access at install or use, then it would be much more dangerous if software that needed quite extensive access was exploited like this. But we don't. Our workstations are actually fairly dumb in this regard. Why is that? Note: Newer Windows an Mac systems might have this with their stores, I don't know. But a store isn't a requirement for this, so why have we had to wait so long?
- qq66 11y agoIt's not paranoia to be deeply concerned by the security implications of a ton of auto updating software from dozens of vendors sitting on hundreds of millions of machines.
- leni536 11y ago>Your AV company's infrastructure is probably a lot more secure than the infrastructure of browser plugins you use and games you play. Well I'm not a security expert and I'm using Linux, so I don't use a Windows antivirus obviously. A quick test trying to download free or trial Windows antivirus software (I'm not willing to pay for this simple experiment): Kaspersky: - google Kaspersky - google result leads to http site, all the way to the download of the trial version it's http (I'm sure at least 80% of users don't notice this) - try to type in manually https://www.kaspersky.com - it redirects to http://www.kaspersky.com !!!! Ok let's try Avast, it's popular, isn't it? - ok it's all https, http redirects to https, it could even have HSTS, didn't check. - download links to http CNET site ... - I have to allow half the World's third party js to get to the download. - It's of course http, - Manually rewrite it to https (not straightforward, it's behind a redirection), invalid certificate (issued to a248.e.akamai.net instead of software-files-a.cnet.com - Its installer is probably loaded with CNET crapware anyway Downloading Avira worked fine though, I only tried these three. These companies are supposed to be security vendors, this is freaking ridiculous.
- x0n 11y agoI also knew a guy who wore a seat belt and it broke his neck when he crashed his car into a tree. I still wear a seat belt.