Microsoft Admits That Third-Party Antivirus Is More Effective Than MSE


Recommended Posts

Well this seems to have gone round in circles a few times. Microsoft could easily make MSE nearer in detection rates to the other AV alternatives it`s just this would take a fair amount of resources. They would need a dedicated team scouring malware domains, testing, creating and releasing signatures on an hourly basis. Also people/automation working on better detection of malware families so specific sigs don`t need creating.

One thing to remember when talking about bloat, memory usage is only a small part of the story. Some AV`s will keep the majority of their sigs in memory if available (up to a certain amount) whereas others will have to access them from disc and we all know accessing something from memory is quicker! So just because your AV uses a miniscule amount of memory doesn`t mean it is light. Normally you`ll have to try it for yourself as different settings can also have a big impact, scanning on execution, reading, writing, etc, etc...

 

As has been said before the most important part of the whole equation sits right between your ears ;)

 

I do seem to have had to clean quite a lot of computers with MSE on lately, more so (it seems) than when it was first released. This may be due to the fact Defender is now included in 8/8.1 so the writers make sure it isn`t detected!

I'm talking about average users that use Windows not Linux users. :p

 

I know. I was teasing. I am still amazed that we need anti-virus in this day and time, regardless of the OS. I am sitting here at work on my Windows box now.  

That would be because people are scum bags. It's not a technical question.

 

If we want people to be able to do stuff with their computers, we have to deal with others being *******s.

I know. I was teasing. I am still amazed that we need anti-virus in this day and time, regardless of the OS. I am sitting here at work on my Windows box now.

Yeah I guess! It isn't really something that should be needed, but unfortunately it is due to virus writers and due to the fact that more than fifty percent of users don't take care when on the internet. :/

Yeah I guess! It isn't really something that should be needed, but unfortunately it is due to virus writers and due to the fact that more than fifty percent of users don't take care when on the internet. :/

 

I don't think it is needed. I'm of the opinion that a lot of what these anti-virus do is scam people into believing they need them. Also, people would rather have convenience over security. That said, Google makes Chrome OS so that it scans the system at startup and if any system file is not right then it gets replaced with the correct one. They all could do that.

That said, Google makes Chrome OS so that it scans the system at startup and if any system file is not right then it gets replaced with the correct one. They all could do that.

Interesting idea, but I see two flaws with that concept on a "full" desktop OS. One is the obvious, if malware takes that scanner out or tricks the scanner into thinking a file is good then it's rendered useless. For me the bigger problem would be performance though.. ChromeOS is basically a browser and is quite lightweight, so there wouldn't be that much to scan. Waiting on a complete system scan for a full blown desktop operating system is going to have a huge hit on startup time, regardless of which OS it is. I'd be willing to bet something that like would get disabled by the majority of users just because of the inconvenience of waiting for a few minutes for their system to boot versus a few seconds.

Interesting idea, but I see two flaws with that concept on a "full" desktop OS. One is the obvious, if malware takes that scanner out or tricks the scanner into thinking a file is good then it's rendered useless. For me the bigger problem would be performance though.. ChromeOS is basically a browser and is quite lightweight, so there wouldn't be that much to scan. Waiting on a complete system scan for a full blown desktop operating system is going to have a huge hit on startup time, regardless of which OS it is. I'd be willing to bet something that like would get disabled by the majority of users just because of the inconvenience of waiting for a few minutes for their system to boot versus a few seconds.

Windows 8 essentially does that with secure boot.

 

It checks that the files are signed etc >.< Has the same effect.

I don't think it is needed. I'm of the opinion that a lot of what these anti-virus do is scam people into believing they need them. Also, people would rather have convenience over security. That said, Google makes Chrome OS so that it scans the system at startup and if any system file is not right then it gets replaced with the correct one. They all could do that.

Suppose.

The only problem with that is since Windows Updates replace system files and it might mistakenly think the files replaced is bad, which would cause some problems. 

Windows 8 essentially does that with secure boot.

It's already been beaten, never mind that only somewhat helps systems that actually use it and have it enabled to begin with, namely people running into problems running a non-Windows OS.

Interesting idea, but I see two flaws with that concept on a "full" desktop OS. One is the obvious, if malware takes that scanner out or tricks the scanner into thinking a file is good then it's rendered useless. 

 

That's why the scanner doesn't need to be local but in the cloud, or at least somewhere that nothing can ever touch it.

 

 

For me the bigger problem would be performance though.. ChromeOS is basically a browser and is quite lightweight, so there wouldn't be that much to scan. Waiting on a complete system scan for a full blown desktop operating system is going to have a huge hit on startup time, regardless of which OS it is. I'd be willing to bet something that like would get disabled by the majority of users just because of the inconvenience of waiting for a few minutes for their system to boot versus a few seconds.

 

That's why I say people chose convenience over security. You only boot up once a day, so what if it takes a  few minutes?

That's why the scanner doesn't need to be local but in the cloud, or at least somewhere that nothing can ever touch it.

Brings its own overhead, never mind problems stemming from connectivity issues. If I take my laptop out of range from my network, how's that going to work? (Plus there's the usual "NSA backdoor!!" nonsense if somebody wants to go there, I don't but /shrug on here I'm not surprised by anything anymore, that's not directed at you.)

 

That's why I say people chose convenience over security. You only boot up once a day, so what if it takes a  few minutes?

Well that's purely personal preference of course. Me, I'll take my 15ish second boot time, and haven't had to deal with an oops as far as security goes in ~10 years, never mind it doesn't do jack for people who don't power down their system at all except maybe that once-per-month update. Out of about 15 desktop/server systems here only two ever actually get a full restart/powerdown as they don't have battery backups attached to them, barring a Windows/*Nix kernel update of course. Relying on protection that only runs once a month isn't terribly secure, especially for the malware that doesn't start up until after the system boots anyway, not all of them are rootkits.

I suppose admitting you've got a problem is the first step down the road to fixing that problem.

 

Maybe they'll devote a few more resources towards developing MSE now?

...., and haven't had to deal with an oops as far as security goes in ~10 years...

 

Same here. I rarely have any problems here at work on Windows. It's been years since we've gotten any viruses and we send and receive a ton of email every day and use a browser constantly. I've ran Windows 7 at home until recently and I've never had to install any anti-virus on it. That is what leads me to believe that a lot of this anti-virus scare is just that, a scare tactic.

If they couldn't write a secure OS, what makes you think they can plug the holes any better?

 

It's like asking an engineer why their building fell down. If they knew, they wouldn't have let it happen.

 

Also, I'm inclined to think there is some pressure to be had there >.>

Stop talking out of your ass. x86 systems by design allows any arbitrary code and deep system level access.

 

Can you write a virus for Windows RT?

 

MSE was one of the best antivirus when they put effort on it. Recently they are not focusing on it; that's why it has been going downhill. I think it is a bad decision on their part.

Did anyone really read the article? It mentions that the reason they've slipped on the tests, and why they're near the bottom is that they have shifted focus from the tests to real world threats and up and coming threats. Its says they spent a large amount of time and money on trying to pass those av tests to "look" good, while the software might actually not be that good in a real life situation.

 

So does make you think that some of the AV companies at the top may just actually be focusing on passing the tests, and dont give a crap about it working well in a normal day to day situation

I don't think MSFT ever intended MSE to replace, not even COMPETE with 3rd party AV. If we recall the dilemmas Microsoft was facing: bad publicity revolving around seemingly less secure OS than competitors and antitrust lawsuits.

 

MSE has been a very successful product for MSFT by reducing bad publicity and I think it has to stay marginal to save them from any further antitrust lawsuits.

Stop talking out of your ass. x86 systems by design allows any arbitrary code and deep system level access.

 

Can you write a virus for Windows RT?

 

MSE was one of the best antivirus when they put effort on it. Recently they are not focusing on it; that's why it has been going downhill. I think it is a bad decision on their part.

Yes you can you ignoramus ****wit.

 

You know how we know that? You can root the device, arbitrary code can then be executed.

 

More to the point, this has absolutely nothing to do with the instruction set the chip executes, otherwise Android would be malware free as well. Have I mentioned that there is Malware for ia86 chips also?

 

You are the worst kind of poster. You are simultaneously wrong and being an *******. Even better than that, you took something out of context to attack. My point was that there's a benefit to third parties being in control of the anti-malware work.

 

If Microsoft could have blocked it (or had thought to), they would have done it in their operating system. It's likely they will in future versions, but getting the people who wrote the OS to look for problems with the operating system, as I said, like asking an engineer why their building fell down. They wouldn't have built it that way on purpose.

 

Next time you want to take a swipe, at least be right.

 

  • 1 month later...

I'm not to concerned. In all the years I've been using computers, I've gotten 2 minor viruses which I've manually removed myself.

And I've been dealing with warez and such since 1995, and porn sites.

Although I in a porn sites aren't the culprits for viruses, many people think that's how you get them.

I feel very safe with MSE and Malwarebytes Pro, and my own brain. ;)

MSE/Defender is crap (and they still haven't fixed the bug that causes slowdowns in folders with a lot of EXE's after about 5 years), but it certainly beats having no antivirus at all, a lot of users are still plenty stupid and it's a good thing to have it in Windows out of the box. Of course I usually install Avast for anyone the moment they ask for my help but I can't help everyone :P

This topic is now closed to further replies.
  • Posts

    • Rufus 4.15.2393 Beta 2 by Razvan Serea Rufus is a small utility that helps format and create bootable USB flash drives, such as USB keys/pendrives, memory sticks, etc. Despite its small size, Rufus provides everything you need! Oh, and Rufus is fast. For instance it's about twice as fast as UNetbootin, Universal USB Installer or Windows 7 USB download tool, on the creation of a Windows 7 USB installation drive from an ISO (with honorable mention to WiNToBootic for managing to keep up). It is also marginally faster on the creation of Linux bootable USBs from ISOs. A non-exhaustive list of Rufus supported ISOs is available here. It can be especially useful for cases where: you need to create USB installation media from bootable ISOs (Windows, Linux, UEFI, etc.) you need to work on a system that doesn't have an OS installed you need to flash a BIOS or other firmware from DOS you want to run a low-level utility Rufus 4.15.2393 Beta 2 changelog: Add RISC-V 64 support to UEFI:NTFS Improve the guards for using the "silent" option Improve the ability to cancel during write retries Improve progress reporting for compressed image extraction Fix unrestricted XML entity expansion and integer overflow in ezxml parser (courtesy of @esadowski4) [GHSA-55r2-34wg-8mv9] Fix "silent" Windows installation failing at 75% in most cases [#2960] Fix a crash during boot when using UEFI:NTFS on Snapdragon X based ARM64 platforms [#2934] Fix the first WUE option always being checked by default [#2965] Fix an infinite loop when using Windows ISOs that contain multiple WIMs Fix "Enable runtime UEFI media validation" checkbox not always being properly enabled Other WUE improvements/fixes for OneDrive removal and username validation (with thanks to @christian8641) [#2984, #2991] Download: Rufus 4.15 Beta 2 | 1.9 MB (Open Source) Links: Rufus Home Page | Project Page @GitHub | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Tixati 3.43 by Razvan Serea Tixati is a free and easy to use BitTorrent client featuring detailed views of all seed, peer, and file transfer properties. Also included are powerful bandwidth charting and throttling capabilities, and a full DHT implementation. Tixati is one of the most advanced and flexible BitTorrent clients available. And unlike many other clients, Tixati contains NO SPYWARE, NO ADS, and NO GIMMICKS. Tixati portable version is meant to run on a USB flash drive or other portable media. It stores all its configuration files in the same folder as the executable binary files, and all file paths are stored in a format relative to the program executable folder. It is important you do not delete the "tixati_portable_mode.txt" file within the executables folder. This file is what triggers Tixati to run in portable mode. (The executable binaries are actually the same as the standard edition binaries.) When running the portable edition from a USB flash drive, especially one that is formatted in FAT16/FAT32, you may experience some lag when initially loading a new transfer. This is because initializing and allocating large files on flash-based media consumes a greater amount of time and resources compared to a conventional hard-drive. Tixati has the following features: detailed views of all aspects of the swarm, including peers, pieces, files, and trackers support for magnet links, so no need to download .torrent files if a simple magnet-link is available super-efficient peer choking/unchoking algorithms ensure the fastest downloads peer connection encryption for added security full DHT (Distributed Hash Table) implementation for trackerless torrents, including detailed message traffic graphs and customizable event logging advanced bandwidth charting of overall traffic and per-transfer traffic, with separate classification of protocol and file bytes, and with separate classification of outbound traffic for trading and seeding highly flexible bandwidth throttling, including trading/seeding proportion adjustment and adjustable priority for individual transfers and peers bitfield graphs that show the completeness of all downloaded files, what pieces other peers have available, and the health of the overall swarm customizable event logging for each download, and individual event logs for all peers within the swarm expert local file management functions which allow you to move files to a different partition even while downloading is still in progress 100% compatible with the BitTorrent protocol Windows and Linux-GTK native versions available Tixati 3.43 changelog: Several major DHT improvements Added several screening heuristics to filter malicious DHT nodes, prevent Sybil floods Rewrote DHT search algorithms to add support for multi-path lookups Improved DHT logging, more details in several error messages Extended timeout lengths for outgoing queries over I2P Added incoming query / response per second to DHT table status display Updated Regex engine to PCRE2 Faster Search function, scans channel user profiles in much less time Fixed problems with file name parsing and date handling in RSS Faster and more accurate RSS filtering and episode number detection Several optimizations to global text processing functions, such as UTF-8 cleaning, line splitting, and token parsing Complete update of port-mapping UPNP/NAT-PMP engine, added PCP support, mapping over VPN support, and more Several refinements to default gateway detection on Windows / Android, which is used for port-mapping Support for IPv6 interface-scoped addresses, which is sometimes needed for IPv6 gateway detection and port mapping Full support for PCP port remapping, added backup zero-port query in case requested port is rejected New UPNP/NAT-PMP Monitor in Help > Diagnostics New reflected local port/location tracker that analyzes DHT replies to detect true port/location and NAT mapping type New TCP/UDP Ports monitor in Help > Diagnostics, with several statistic and information tabs, and a detailed event log Calculated/reflected local port is now used for port parameter in tracker queries and peer handshake Fixed several problems with Linux Wayland compatibility Completely replaced tray icon functions in Linux, new SNI implementation is now the default with GSI backup Implemented full DBus-Menu server to be used by new SNI tray icon implementation Replaced Linux tray balloon notification DBus client Rewrote auto-shutdown DBus interface for Linux Rewrote sleep inhibit DBus interface for Linux Dropped deprecated Linux dbus-glib dependencies Completely new Windows asynchronous file handling, now using IOCP model with several block-alignment optimizations Better handling of system network resets and interface down/up cycles Added option to fully clear configuration in Settings > Import/Export Remember last option checkboxes when using Import/Export Fixed minor I2P incoming connection routing problems Much faster I2P vanity host name finder Much faster channel user vanity key finder Raised length limit for torrent tracker remote failure messages to 120 from 64 Fixed problems setting download location on a torrent before the meta info is resolved Added location/MOC paths to category pane tooltips Several minor Web Interface fixes Refinements to static and scrolling ellipsizing layout routines Several fixes and improvements to single and multi-line text edit controls Many other minor fixes throughout the user interface A major overhaul of the Android framework has also been done: API target raised to 35, page alignment set to 16K Rewrote all inset processing routines Full rewrite of foreground service, application, and main activity objects New permission request routines Added multi-cast lock request before UPNP/LPDP discovery operations Fixed file permission and locking problems when loading .torrent from web browsers Fixed problems with Z-ordering of modal / non-modal and popup windows Fixed handling of back gesture on newer OS Added status bar icon adjustment based on status bar background color Added option in Settings > UI > Behavior to continue running in tray when task removed from recents App can be closed by swiping away notification Rewrote IME interface, fixed several problems with auto-correct, on-screen keyboard visibility, and cursor positioning Added full support for Android hardware mouse and keyboard function Added full tooltip implementation for Android hovering via mouse or other cursor device Full rewrite of popup menu widgets to better support hardware pointers and keyboard Added mouse cursor updating framework for Android hovering Added Settings > Import/Export to Android builds Added language file support to Android builds Download: Tixati 64-bit | Tixati 32-bit ~20.0 MB (Freeware) Download: Portable Tixati 3.43 | 114.0 MB Download: Tixati 3.43 for Linux | Android View: Tixati Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Firefox 152.0.1 by Razvan Serea Firefox is a fast, full-featured Web browser. It offers great security, privacy, and protection against viruses, spyware, malware, and it can also easily block pop-up windows. The key features that have made Firefox so popular are the simple and effective UI, browser speed and strong security capabilities. Firefox has complete features for browsing the Internet. It is very reliable and flexible due to its implemented security features, along with customization options. Firefox includes pop-up blocking, tab-browsing, integrated Google search, simplified privacy controls, a streamlined browser window that shows you more of the page than any other browser and a number of additional features that work with you to help you get the most out of your time online. Firefox key features Enhanced Tracking Protection (ETP) – Blocks trackers, cookies, cryptominers, and fingerprinters by default. Private Browsing Mode – Deletes history, cookies, and temporary files when closed. Lightweight & Fast Performance – Optimized memory usage with efficient page loading. Cross-Platform Sync – Sync bookmarks, passwords, history, and open tabs across devices. Customizable Interface – Toolbars, themes, and extensions can be tailored to user needs. Strong Privacy Controls – Options to manage cookies, permissions, and site data easily. Reader Mode – Strips away clutter for distraction-free reading. Pocket Integration – Save and read articles offline with Pocket built into Firefox. Picture-in-Picture (PiP) – Watch videos in a floating window while multitasking. Extensions & Add-ons – Vast library for productivity, security, and personalization. Built-in PDF Viewer – No need for external software to view PDFs. Firefox Monitor – Alerts users if their email is part of a known data breach. Multi-Account Containers – Isolate browsing sessions (e.g., work, personal, shopping). Performance & Resource Efficiency – Uses fewer system resources than some competitors. Open Source & Community-Driven – Transparent development with global contributions. Firefox 152.0.1 fixes: Fixed frequent crashes affecting users with Intel Raptor Lake processors. (Bug 2039575) Fixed an issue on macOS where choosing a PDF option, such as "Save as PDF", from the system print dialog would send the job to your printer instead of saving a file. (Bug 2047850) Download: Firefox 64-bit | Firefox 32-bit | ARM64 | ~70.0 MB (Freeware) Download: Firefox for MacOS | 146.0 MB View: Firefox Home Page | Release Notes Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Zed 1.7.2 has landed with updated OpenCode models, bug fixes and other improvements by David Uzondu Zed 1.7.2 recently landed on the stable release channel, bringing a host of AI-related features including automatic context compaction and settings-based skill management, along with other things like better Markdown preview rendering and custom git commands in the graph view. Starting with the AI stuff, the developers introduced "/compact", a command that basically summarizes your conversation history on demand. This tool prevents your active chat window from hitting token limits by compressing older parts of the dialogue into a brief overview. In addition to that, the team relocated skill management to the settings UI, improving how the application communicates errors regarding those skills, and updated the OpenCode model roster to support DeepSeek V4 Flash, MiniMax M3, Qwen 3.7 Plus, and Nemotron 3 Ultra Free. External agent users can also monitor context window cost metrics and delete individual sessions directly from their history. Right-clicking ref labels in the git graph now opens a context menu that runs different actions against selected targets, kind of how VS Code does it. Here are some of the bug fixes this new release brings: The active agent fails to auto-select when creating a new git worktree. A scrollbar unexpectedly appears on wrapped code blocks in the agent chat. Collapse indicators for project headers appear when performing sidebar searches. Bracketed ellipsis title prefixes fail to show the ellipsis icon properly. Project icons render incorrectly in the recent projects picker. Diff hunk controls appear inside non-editable commit view multibuffers. The software update button hangs indefinitely on the downloading stage. Restoring an agent terminal in a remote project triggers a sudden crash. Splitting a pane that contains an active commit view causes a crash. Linux Wayland freezes when trying to read the clipboard from laggy external apps. Zed is a "newish" code editor trying to break the massive stronghold VS Code has on the developer community. Funny enough, the editor was created by former GitHub employees who worked on the Atom text editor (which Microsoft killed in 2022, several years after it bought GitHub). The project officially hit version 1.0 back in April, introducing platform parity for Windows and Linux alongside deep support for DeepSeek-V4-Pro.
    • 26H2 absolutely will support ARM Windows just not on devices that came with 26H1. This is evident by the fact I am running 26H2, which on my MacBook Neo and Surface Pro 12 (inch), within a VM.
  • Recent Achievements

    • One Year In
      hhgygy earned a badge
      One Year In
    • One Month Later
      AMV earned a badge
      One Month Later
    • Week One Done
      AMV earned a badge
      Week One Done
    • Collaborator
      ryansurfer98 went up a rank
      Collaborator
    • One Month Later
      Eurosoft10 earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      523
    2. 2
      +Edouard
      172
    3. 3
      PsYcHoKiLLa
      78
    4. 4
      Steven P.
      72
    5. 5
      Michael Scrip
      71
  • Tell a friend

    Love Neowin? Tell a friend!