Antivirus software is mostly useless, hacker says


Recommended Posts

Interesting discussion with a hacker on Reddit. Microsoft Security Essentials is the most preferred and easiest to bypass (according to this guy).

Some screens: http://i.imgur.com/yxMDx.jpg

Highlights:

(R - Reddit / H - Hacker)

R: What anti virus software free/paid for presents to you the biggest obstacles?

H: Kaspersky was the most challenging at first, Kaspersky is paranoid as f...k! But it has an exploit in KIS, KAV and PURE, allowing to start malicious code in the memory context of a trusted system process unnoticed. Kaspersky won't interfere if it thinks it's the system process doing changes to the system.

R: What advice can you give to us "average" folk on how to stay secure online?

H: If the attachment is ending in .exe and pretending to be something else, it's malware for sure. If it's a .pdf it can only infect you if you haven't patched your Adobe Reader (Is now done automaticly). Cybercriminals use 0day exploits only on valueable targets like Iranian power plants or companies with intellectual properties and ****ing lot of cash.

- Facebook friends don't share funny cat pictures on randomly generated domain names.

- If your AV says it's clean or even if Virustotal gives you 0/43 it can still be malware, been there, seen that. Srsly, don't trust your AV.

- Use HBCI or similiar for online banking, it costs 30$ and is military grade cryptography (private key signing), only open source cryptography on signed hardware is 100% secure.

- Windows updates, yes, do them. If you have a pirated copy, just buy that **** or use linux.

- If you are super paranoid, buy a netbook and use a LiveCD or similiar on it whenever you put your CC information in.

- Banking on mobile phone, it's stupid, but atm 'not that dangerous as it seems', because 99% of cybercriminals can't code and there is no (serious) android or iOS malware yet on the market.

R: Does this mean Linux or MAC OSx are impermeable to malware? If so, why? If not, what's the best way Linux or MAC users see if they've been infected?

H: No, but Linux is not targeted, because it is not economical.

R: What do you use to spread?

H: Automatically backdooring warez and uploading it to one click hoster and Usenet. It's funny that even governmental agencies use warez, I found FAA.gov credentials. My momma always said, "A botnet is like a box of chocolates. You never know what you're gonna get."

R: why?

H: It first started as a challenge to circumvent AntiVirus systems, but then I realised all AV suck at detection and it's easy to make money with it.

R: how about making a better AV detection system and profiting off that?

H: AV is a completely wrong approach to security. If you need AV to feel secure you already failed.

R: First, thanks for the AMA, really interesting. Could you write some "perfect protection" AV software yourself? I bet you could make a ****ton of cash even if it is a one time sale per person. Is there hacker-folk interest in putting AV companies out of business by giving away or selling cheap, far superior, protection? Would it be more fun to screw over big companies who sell snake oil?

H: Most "hacker-folk" kinda work at AV companies already. There is already a company going the "elimate it at the root" approach: http://www.triumfant.com . But it's not that easy, the big companies have the moneys, Symantec has the colorful commercials, McAfee has the governmental contracts for voting machines AV (Mr. McAfee has btw the same lifestyle as your average Russian Spam King: 66 years old, huge house in a tropical country, 17 year old girlfriend, lots of unregistered weapons lol). It's not about the product itself, it's about power and influence. Read about the "HBGary federal accident" or watch the Defcon 19 video with "Aaron Van Barr (totally not Aaron Barr, because he wasn't allowed to be there :p)". Changing the security industry is like changing the copyright system.

R: you're the reason we can't have nice things.

H: People who can just about start Facebook and put in their credit cards are the reason such things exist. Antivirus companies selling snakeoil and lull consumers into absolute security are another one.

Read more:

http://www.reddit.co...t_operator_ama/

  • Like 2

I kinda disagree. Sure, hackers who know their stuff can get around AV, but I've seen others, as well as experienced myself, when Nod32 catches a virus in an email attachment, thus saving me from ever having to see it in my system. Am I 100% protected? of course not, but just like condoms, and everything else...you can never be 100% safe from anything. I think a reputable (kaspersky/nod32) antivirus app, along with a decent firewall, and a HUGE dose of common sense and logic are your best tools for staying safe from malware/viruses.

  • Like 2

I stopped using antivirus programs a decade ago, just a waste of resources. Never had a virus anyway or any other malware, I don't know how people even get this stuff on their systems. Common sense is the best antivirus.

Yeah,

Like you'd know if you were infected or not if you don't have anything to scan with! Always love it when people say I've never been infected with anything then admit to being dumb enough not to even have any protection!

Whether they're worthless or not, something is better than nothing and if you're worried about resources on todays computers, you shouldn't even own a computer anyway!

  • Like 2

I was using anti-virus on my Mac before I re-installed to run Mountain Lion. And I must admit, everything he's saying is what I've already figured ... I simply don't need Anti-virus. I don't download illegal software, I only download from the Mac App Store or in rare cases, apps such as Skype from the official source. I don't click on ANY links on Facebook. I don't open myself to any scamming because my bank account is locked with a hardware pin device that I need to use to purchase items and use internet banking, and without that device linked to the PIN on my card, it's not possible to do anything with the account. Which can be annoying but is very secure.

So yeah ... I always install AV on friends and family machines because I know they're not going to be as sensible. But when you know enough about what you're doing and you use all legit stuff via secure servers/sources, you really can't fail. Or at least if things did go wrong, they'd be a one in a billion chance.

Boasting about having common sense instead of using antivirus is like boasting about having sex without using a condom. (you never know the stranger you slept with had AIDS or not and same applies to the world of cybersecurity.)

I still use them on Windows - though I am still using XP. When I used windows full time, I used to get a malware pop up being denied about once every 2 months. So I do feel somewhat protected - though better protection is using a sandbox.

On the flip side of the coin. Maybe this hacker is thinking that if reader would believe's the fact that A/V software is useless and decide to stop using A/V thus making the hackers life easier to infect devices....

I was using anti-virus on my Mac before I re-installed to run Mountain Lion. And I must admit, everything he's saying is what I've already figured ... I simply don't need Anti-virus. I don't download illegal software, I only download from the Mac App Store or in rare cases, apps such as Skype from the official source. I don't click on ANY links on Facebook. I don't open myself to any scamming because my bank account is locked with a hardware pin device that I need to use to purchase items and use internet banking, and without that device linked to the PIN on my card, it's not possible to do anything with the account. Which can be annoying but is very secure.

But that wouldn't stop random ad banners from infecting you via some 0day exploit or some other plugin vulnerability.

The site doesn't have to be dodgy in and of itself, but they might not whitelist advertisers as opposed to blacklisting bad ones - or their ad company may not be performing this kind of scrutiny with their advertising clients.

I believe an MMA site called BloodyElbow had an issue in the past, at least one of my friends were able to narrow that site down to one of the most likely candidates. That doesn't mean they are a malicious site, if they were in fact the source then they just had some bad luck with a banner - not their direct fault.

But my point is, you'd call a site trustworthy even if they don't scrutinise every ad banner, and the banners could potentially still infect you.

Boasting about having common sense instead of using antivirus is like boasting about having sex without using a condom. (you never know the stranger you slept with had AIDS or not and same applies to the world of cybersecurity.)

That's absolute rubbish. Having common sense is like having sex with a girl you've been married to for years. She may go places you don't know but you can be more sure that she's not screwing around ... so you don't wear a condom.

Going to warez sites, bit torrent, and other places like that, or opening EXE files which say they're music files is the equivalent of screwing a hooker unprotected. That's the difference.

That's absolute rubbish. Having common sense is like having sex with a girl you've been married to for years. She may go places you don't know but you can be more sure that she's not screwing around ... so you don't wear a condom.

Going to warez sites, bit torrent, and other places like that, or opening EXE files which say they're music files is the equivalent of screwing a hooker unprotected. That's the difference.

Please try to read it again. I said strangers and not girlfriends. And stranger refers to the random usb drive or a website site you happen to be on by mistake or on purpose.

I must say I am losing faith in MSE lately, after seeing multiple viruses just disable it like nothing on some computer's I've cleaned.

I cleaned a rogue program and a rootkit off my grandfather's PC yesterday (The malware was S.M.A.R.T. Check, Tells you your drive is failing and tried to get you to pay for it. It also tries to simulate data loss by setting all your files and shortcuts to hidden. It totally disabled MSE and I ended up having to re-install it after I removed all the malware) MSE is a nice program, and from the av tests I've seen it has fine detection rates, but it seems to have really poor protection vs viruses disabling/removing it which is making me consider recommending other av's over it.

It also seems like a/v's in general aren't too great at detecting the "new wave" of malware these days (mostly rogue programs/trojans/rootkits). So many times, I've seen various a/v programs not block/detect these at all. Apps like malwarebytes have much more reliable detection/removal of these types of infections.

Not using an AV and claiming common sense is hypocritical.

Sure, avoid warez sites, email attachments, and other obvious things, but what happens if you visit a trusted site that was infected/hijacked ?

Common sense is to have an AV 'AND' avoid known sources for getting infected, the excuse of claiming it to be a waste of resources expired when your P133 was binned. Seriously, with 4-16GB RAM and Dual-Oct core CPUs, how can it waste resources ?

I must say I am losing faith in MSE lately, after seeing multiple viruses just disable it like nothing on some computer's I've cleaned.

I cleaned a rogue program and a rootkit off my grandfather's PC yesterday (The malware was S.M.A.R.T. Check, Tells you your drive is failing and tried to get you to pay for it. It also tries to simulate data loss by setting all your files and shortcuts to hidden. It totally disabled MSE and I ended up having to re-install it after I removed all the malware) MSE is a nice program, and from the av tests I've seen it has fine detection rates, but it seems to have really poor protection vs viruses disabling/removing it which is making me consider recommending other av's over it.

It also seems like a/v's in general aren't too great at detecting the "new wave" of malware these days (mostly rogue programs/trojans/rootkits). So many times, I've seen various a/v programs not block/detect these at all. Apps like malwarebytes have much more reliable detection/removal of these types of infections.

That data loss malware sounds funny lol, gonna try infect some friends of mine rofl

While I do agree that common sense is one of the best methods for protecting against malware, it's beyond me why someone would go about without AV...let's say something gets past your common sense? or if someone else uses your computer for "urgent" business and ends up going to a site with even the simplest of malware? IMO, better safe than sorry :)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Weekend PC Game Deals: Cyberpunk 2077, Split Fiction, Sonic Racing, and more by Pulasthi Ariyasinghe Weekend PC Game Deals is where the hottest gaming deals from all over the internet are gathered into one place every week for your consumption. So kick back, relax, and hold on to your wallets. The Epic Games store brought along two games from wildly different genres this week for PC gamers to claim. Robobeat is a rhythm-based action game that lets you become a bounty hunter that can wall run, slide, and bunny hop around his opponents. All you have to do is stick to the beat for the built-in or custom songs. Next, Citizen Sleeper is a sci-fi RPG adventure taking place in a ruined space station. It uses tabletop RPG-inspired elements like dice rolls and timers to change up how players approach its activities, factions, and storylines. The Citizen Sleeper and Robobeat giveaways end on June 25. On the same day, RollerCoaster Tycoon 3 and Voidwrought will become the next freebies. The bundle space expanded with two more collections from Humble this week too. The June 2unes bundle is up first, carrying plenty of rhythm games. This carries Kill the Music and Rhythm Witch in the $5 starting tier, followed by Trombone Champ, Spin Rhythm XD, and Thumper in the $7 tier. Paying at least $12 gets you the complete bundle, which adds on Kalpa: Cosmic Symphony, Everhood 2, NOISZ, and Sixtar Gate: StarTrail. The next bundle is for virtual reality fans. This carries Among Us 3D: VR and Zero Caliber VR for $10. The next tier brings in Tactical Assault VR, Ancient Dungeon, and Arizona Sunshine Remake for $15. VTOL VR, Zero Caliber 2 Remastered, Metro Awakening, and Thief VR land to finish things off for $18. Free Events It's a big week for free event fans, as Valve kicked off another one of its Next Fest events. This one carries thousands of gameplay slices from upcoming indie games The promotion is set to run until June 22. Standard free events are also ongoing this weekend. This includes the sci-fi grand strategy experience Stellaris from Paradox and the hit SEGA management game Two Point Museum. Asymmetric multiplayer horror title Dead by Daylight and the hit mech shooter MechWarrior 5: Mercenaries are also free-to-play over the weekend. Big Deals The Steam Summer Sale is a week away from launch, but there are plenty of publishers already putting their wares on sale to prepare for the event. Here's our hand-picked big deals list for this weekend: Battlefield 6 – $34.99 on Steam Sonic Racing: CrossWorlds – $34.99 on Steam Split Fiction – $32.49 on Steam Arma Reforger – $27.99 on Steam Sniper Elite: Resistance – $24.99 on Steam DayZ – $22.49 on Steam Two Point Museum – $20.09 on Steam Atomfall – $19.99 on Steam No More Room in Hell 2 – $19.49 on Steam Cyberpunk 2077 – $17.99 on Steam Sonic Frontiers – $17.99 on Steam Dinkum – $15.99 on Steam Stellaris – $14.99 on Steam Hi-Fi RUSH – $14.99 on Steam My Little Puppy – $14.99 on Steam FINAL FANTASY XII THE ZODIAC AGE – $14.99 on Steam SONIC X SHADOW GENERATIONS – $14.99 on Steam EA SPORTS FC 26 – $13.99 on Steam STAR WARS Jedi: Survivor – $13.99 on Steam FINAL FANTASY VII REMAKE INTERGRADE – $13.99 on Steam FINAL FANTASY XV – $13.99 on Steam It Takes Two – $11.99 on Steam FINAL FANTASY X/X-2 HD Remaster – $11.99 on Steam Axiom Verge 2 – $9.99 on Steam [REDACTED] – $9.99 on Steam Sniper Elite 5 – $9.99 on Steam Holdfast: Nations At War – $9.99 on Steam Arma 3 – $8.99 on Steam The Callisto Protocol – $8.99 on Steam A Way Out – $8.99 on Steam LIGHTNING RETURNS: FINAL FANTASY XIII – $7.99 on Steam MechWarrior 5: Mercenaries – $7.49 on Steam Slackers - Carts of Glory – $7.14 on Steam MIMESIS – $6.99 on Steam Need for Speed Unbound – $6.99 on Steam FINAL FANTASY XIII – $6.39 on Steam Sniper Elite 4 – $5.99 on Steam Tyranny – $5.99 on Steam Immortals of Aveum – $5.99 on Steam Far Cry 3 – $4.99 on Steam Zombie Army 4: Dead War – $4.99 on Steam Sonic & All-Stars Racing Transformed Collection – $4.99 on Steam Mass Effect Legendary Edition – $4.79 on Steam Titanfall 2 – $4.49 on Steam SimCity 4 Deluxe Edition – $3.99 on Steam Far Cry 3 - Blood Dragon – $3.74 on Steam Wreckfest – $2.99 on Steam Crime Boss: Rockay City – $1.99 on Steam theHunter: Call of the Wild – $1.99 on Steam The Saboteur – $1.99 on Steam Battlefield 1 – $1.99 on Steam Sonic Mania – $1.99 on Steam Golf With Your Friends – $1.49 on Steam Sid Meier's Alpha Centauri Planetary Pack – $0.99 on Steam Dungeon Keeper 2 – $0.99 on Steam Populous: The Beginning – $0.99 on Steam Citizen Sleeper – $0 on Epic Store ROBOBEAT – $0 on Epic Store DRM-free Specials The DRM-free store GOG has already kicked off its own summer sale. Here are some highlights: S.T.A.L.K.E.R. 2: Heart of Chornobyl - $41.99 on GOG Indiana Jones and the Great Circle - $41.99 on GOG Cronos: The New Dawn - $35.99 on GOG SILENT HILL 2 - $34.99 on GOG SILENT HILL f - $34.99 on GOG Kingdom Come: Deliverance II - $29.99 on GOG MENACE - $29.99 on GOG Cairn - $23.99 on GOG Frostpunk 2 - $22.49 on GOG The Alters - $20.99 on GOG Resident Evil Classic Bundle - $20.99 on GOG System Shock 2: 25th Anniversary Remaster - $17.99 on GOG Banishers: Ghosts of New Eden - $16.99 on GOG Legacy of Kain: Defiance Remastered - $16.25 on GOG METAL EDEN - $15.99 on GOG REPLACED - $15.99 on GOG Hollow Knight: Silksong - $14.99 on GOG Tomb Raider I-III Remastered Starring Lara Croft - $11.99 on GOG Chants of Sennaar - $11.99 on GOG Alpha Protocol - $9.99 on GOG DREDGE - $9.99 on GOG Crow Country - $9.99 on GOG Warhammer 40,000: Dawn of War - Anniversary Edition - $2.99 on GOG Keep in mind that availability and pricing for some deals could vary depending on the region. That's it for our pick of this weekend's PC game deals, and hopefully, some of you have enough self-restraint not to keep adding to your ever-growing backlogs. As always, there are an enormous number of other deals ready and waiting all over the interwebs, as well as on services you may already subscribe to if you comb through them, so keep your eyes open for those, and have a great weekend.
    • Lilly-Livered American Media Are Scared
    • Really? Despite the memory price rises, nothing can kill it? I thought something would.
    • I think there will be a 27H1 for actual users of 26H1 The 25h2 supports ARM too : Snapdragon X, Snapdragon X Plus and Snapdragon X Elite
  • Recent Achievements

    • Week One Done
      Genuinetonerink- Dubai earned a badge
      Week One Done
    • One Month Later
      Genuinetonerink- Dubai earned a badge
      One Month Later
    • One Year In
      hhgygy earned a badge
      One Year In
    • One Month Later
      AMV earned a badge
      One Month Later
    • Week One Done
      AMV earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      514
    2. 2
      +Edouard
      171
    3. 3
      PsYcHoKiLLa
      82
    4. 4
      Steven P.
      74
    5. 5
      Michael Scrip
      72
  • Tell a friend

    Love Neowin? Tell a friend!