Antivirus is 'completely wasted money': Cisco CSO


Recommended Posts

ZDNet Australia

Companies are wasting money on security processes ? such as applying patches and using antivirus software ? which just don't work, according to Cisco's chief security officer John Stewart.

Speaking at the AusCERT 2008 conference in the Gold Coast yesterday, Stewart said the malware industry is moving faster than the security industry, making it impossible for users to remain secure.

"If patching and antivirus is where I spend my money, and I'm still getting infected and I still have to clean up computers and I still need to reload them and still have to recover the user's data and I still have to reinstall it, the entire cost equation of that is a waste.

"It's completely wasted money," Stewart told delegates.

He said infections have become so common that most companies have learned to live with them.

/snip

I must agree to an extent.

It would be much more beneficial for companies to invest in something like DeepFreeze.

I think the best approach to these threats is hybrid solution. No one solution is 100% effective.

However, saying that Antivirus is a waste of money is a very brave and IMHO plain silly thing to say.

He's got a point, but saying it's a waste of money is stupid. I can agree that when a PC is infected, it is in most cases best to reinstall it. But antivirus programs also have an importan proactive role. It stops most viruses from infecting and spreading to other corporate computers etc.

i had a virus on my home laptop a little while back.. it somehow managed to get past norton 2008 with all the updates... i contacted norton and they told me i'd have to pay ?70for them to get rid of it...... i told them where to stuff it and just formatted lol...

its bad that because their system which is meant to prevent viruses failed, that they wanted to charge me so much money!

I have to disagree with the statement, although the context in with which it is made, is certainly true.

If i was spending money on Anti-Virus products and still getting infected then yes that would constitute a waste of money, but at the same time, how many issues has that Anti-Virus product protected against.

You have to ask yourself how the machines are being compromised, is it thorugh Malware installing from websites, is it because of an Operating System vulnerability.

Both of these can be countered, using Proxy Servers to filter out those websites that are known to host malicious code, and educate employees on a secure computing policy, secondly ensure that the operating system has the lastest security patches applied to it.

Of course no process is 100% secure, all we can ever do in this game, is to apply best practice and hope for the best.

LOL That's why I use ClamWin on Windows... That way I don't need to pay for virus scanners... As for other malware, I don't do anything that would cause me to get spyware, adware and such. I'm wary of JS, VBS and BAT files in Windows as well as readme HTML files containing JS, so I don't need to worry about those threats because I can dig through things to be sure that it is 100% safe. In fact, the only reason I have a virus scanner is because I use Frostwire from time to time. Otherwise, I don't have issues with torrenting Linux distros, and therefore I have no real need for a virus scanner.

Norton doesn't count as an AV.

Not in my opinion. There are far superior free Programs such as Avast, and AVG. A friend of mine has never used a AV program and he has never been infected. I just use Avast with the Standard Shield only.

:D Neither should McAfee. It's more like malware the way it takes up CPU cycles and resources.

IMHO It's (1)Avast (2)Kaspersky (3)NOD32.

I agree with that first part of your post, but that second part is flatout absurd!

Sould be (1)Kaspersky, (2)NOD32, (3) Avast

Said by Gary7

"Not in my opinion. There are far superior free Programs such as Avast, and AVG. A friend of mine has never used a AV program and he has never been infected. I just use Avast with the Standard Shield only."

How would your friend know if he's ever been infected or not, if he's never used an AV? Those kind of statements are also flat out absurd!

That it's still possible for viruses to corrupt your system doesn't mean that antivirus products are a waste of money, just as how locking the doors of your home won't prevent all robbery attempts but that doesn't mean locking the doors is a waste of time. It truly wouldn't surprise me if John Stewart lost his job because of his patently stupid remark.

Vista is so secure you won't even need to worry about security as Vista protects you well if you LET it and not change silly system settings.

I have not even installed an AV on permanent time since I see them as waste of time and money. I know I am not infected because I install an AV from time to time to check for viruses. At the moment I am setting up a USB stick system maintenance software that will check for viruses as well as cleaning up junk.

Avast is bad. Even though my friend had it installed he still got infected with a virii. When he switched to AVG, he found two worms and a trojan.

And the exact opposite can and has happened for other people. No AV will catch everything and this applies even more so to free solutions. You get what you pay for.

I've always seen people be infected no matter what AV program they are using, most of the time it comes down to user stupidity. I currently don't use an av program but scan online monthly and I have not had a virus in years.

@ Sharad I've never had a very good experience with AVG on many computers I have used it on it generally doesn't seem to detect nearly as much as Avast! and Avira do, and it gets false positives far too often for my liking. I definitely agree with VRam, no program catches everything, I always have to use a combination of programs or look for manual fixes or specialized programs when I have to clean someones infected computer (And they almost always have an active av running)

Edited by ViperAFK

I will agree partially with the idea that most antivirus programs are a waste of money (I go for the free ones, which can be just as effective), however, claiming that installing patches is ineffective is downright idiotic.

OTOH I'm utterly unimpressed with the state of all antivirus programs. Most of 'em these days are just a tad too paranoid, flagging completely inoffensive items as malware.

I agree with that first part of your post, but that second part is flatout absurd!

Sould be (1)Kaspersky, (2)NOD32, (3) Avast

Said by Gary7

"Not in my opinion. There are far superior free Programs such as Avast, and AVG. A friend of mine has never used a AV program and he has never been infected. I just use Avast with the Standard Shield only."

How would your friend know if he's ever been infected or not, if he's never used an AV? Those kind of statements are also flat out absurd!

No they are not absurd. I guess you have never heard of on-line scanning. Check it out most AV companies have one. That is how he would know!

Well, he is right about the Anti-virus industry not being able to keep up, since Viruses constantly appear, change and evolve.

The problem with his statement is, tons of people don't get infected with the latest and best virus attacks out there, but they pick up all the

trash littering the Internet. You have all these dodgy sites with tons of spyware/malware, you have dodgy files from P2P Software and and whatnot.

All this trash can still effective ruin your Computer and make you waste a lot of time trying to salvage everything, so I still believe a decent Virus scanner is a must to have.

Just too bad so many people tend to use these free alternatives which usually doesn't even find half of what a quality brand would - So they are lured into a false sense of security. The same with On-line scanners, they are pretty much useless in my book, since the most important aspect of Anti-Virus is the proactive defence - Stopping the virus before it enters your PC. As soon as a Virus or Infection has hit your PC, it usually takes a lot more than a simple Virus scan to remove it effectively.

I remember one of my friends always touted what a safe surfer he was, how he never have had a virus. We tried a few On-line scanners which found nothing, totally clean. So I installed a Trial version of NOD32 and it actually found 4 infections, where he was only able to get rid of 3 - We also found out, one of his frequently visited websites had a virus embedded in some flash ad, which he would never really know about if the software hadn't told him.

So he decided to reinstall Windows and start to use Anti-Virus software.

With a bit of knowledge and a decent Anti-virus, It's not wasted money, it can actually save you some time and worry.

Whilst he does have a point, it is a bold claim to make.

You have to think of where does most malware come from. It's from people accepting every single activex control they see, opening every file/running every executable they can get their hands on etc. Yep, people's stupidity. Don't do that, and there is a much much smaller chance you will get malware. Sure it doesn't mean you won't get any, just means the chances of you getting one is a lot less.

Programs like DeepFreeze help a lot too, though can be a pain sometimes but then thats the price of security nowdays.

One word: Linux

Too many companies use Windows for no good reason and it's sad that they don't have better advisers.

I love Linux as much as the next guy... Ok... Perhaps a bit more than the next guy. ;)

But to say that many companies use Windows for "no good reason" overlooks the darn "legacy apps" issue. Some apps (even obscure ones) require Windows to run (not Linux/wine).

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • For some reason I suddenly have the urge to go shopping at Sears.
    • So I did a quick test based on 3+ different public instances from the litany at searx.space ... and it spins everything rather differently. It seems that SearXNG is a meta-search engine (queries multiple search indexes rather than only Google's or Bing's or Wikipedia's or Reddit's) that operates in two modes: > public instances ... each instance opens itself to outside users who piggyback on its cached search history; this instance's own identity becomes known/tracked but end-users are hidden similar to an anonymization proxy; this instance's querying of major search indexes may be API based [rated limited, blocked, etc.]). > private instances ... your private install/instance that itself queries multiple (configurable) search indexes of crawled web content; every major Search Engine associates all traffic to your private instance (so your traffic is tracked via network usages) but client-side tracking (your own browser/computer specs) is flushed because it's a "server" doing the querying rather than your browser. My test asked the same 1 question to the 3+ engines and they all returned vastly different results: some had CAPTCHA failures against Google, some had failures against Wikipedia, and the actual results were also different -- some had auto-complete enabled, others returned a wikipedia highlighted excerpt despite the Wikipedia failure (hinting at results being cached from previous keyword matching), and others just gave an Are-You-Human non-CAPTCHA loop before returning random results. So this begs the caveat: Search query results will vary based on which instance is used because every instance queries the other search indexes separate (and thus its results are influenced on that instance's aggregate search history and index-access limitations). The major distinctions for SearXNG versus DDG or Brave: > The search UI is 'untracked' since no UI trackers are baked-in which would phone home or lay cookies into your browser (for DDG/Brave usage stats), > There is no 'crawler' that canvasses the Internet to discover fresh content (it leaves that to the major search indexes), > Queries multiple search indexes ("meta-search engine") based on the configurations and usage history of the server instance, > Privacy-friendly due to its ability to shield user tracking via standing up a non-local server instance connectable to major VPN providers: queries would all appear to come from general VPN/Proxy providers rather than your private instance (whether installed locally or on your own VPS in the cloud). PS: I've previously come across specialized search engines of this nature that indexes searches across media assets like YT, OF, etc. SearXNG seems to be a good backbone...if the rate-limiting/captcha/etc. issues were resolved.
    • For a guy who claims to hate Farage and the ignorant, gullible, rightwing racist skinheads sponsored by Putin that his lies represent, you sure are quoting them time and time and time again, mate. I guess you're conveniently ignoring the fact that your country and commonwealth just happened to work much better when it was still part of the E.U.? Denial isn't just a river in Egypt.
    • Do you live in the U.K? Do any of the people here that are against the UK leaving the E.U, live in the U.K? If not then why are you bothered? If you do live here then it is a different thing . Brexit was a good idea, should have done it years before, it was done badly, but the idea was good. You are saying the same thing as remainers do, oh we did what Putin wanted, we listened to the lies and Farage. I hate Farage and never believed most of what he said, certainly did not believe the £350m a week for the NHS. But we did pay a lot of money to the E.U and yes some of it came back, but what is the point of paying it out for only some of it to come back? Get out of the E.U, no money to them and in theory we can use the money to do things in the country. I said in theory, but our governments are a total and complete waste of space. No matter what colour rosette they wear. You and others say it was a mistake and yet the two main parties in the U.K are not looking at rejoining the EU, I wonder why that is? I was not tricked by anyone. Makes no odds now, we are out and have been for 10 years, what we need is a decent government to run the country. All they do is shout at each other like a load of kids and seems to do nothing and make this country more into a police and nanny state. Getting more like China all the time.
    • 4TB TEAMGROUP MP44Q, 2TB T-Force G50, and 2TB WD My Passport SSDs drop to great prices by Fiza Ali Prime Day may be over, but there are still worthwhile storage deals available, including discounts on SSDs for shoppers who missed the event or are looking to upgrade their storage solution. Particularly, 2TB Western Digital My Passport, 2TB TEAMGROUP T-Force G50, and 4TB TEAMGROUP MP44Q SSD are selling at great prices with up to 23% off. The 2TB TEAMGROUP T-Force G50 is an M.2 2280 PCIe 4.0 x4 NVMe SSD with sequential read speeds of up to 5,000MB/s and sequential write speeds of up to 4,500MB/s. The drive has an endurance rating of 1,300 TBW (terabytes written) and features a DRAM-less design. The company specifies a mean time between failures (MTBF) of 3 million hours. The drive includes an "ultra-thin" graphene heat spreader that helps dissipate heat without significantly increasing the drive's thickness. It also supports S.M.A.R.T. monitoring, allowing compatible software to monitor drive health and operating status. The SSD is rated for operating temperatures from 0°C to 70°C, with a storage temperature range of -40°C to 85°C. The drive is backed by a five-year limited warranty as well. 2TB TEAMGROUP T-Force G50 SSD: $269.99 (Amazon US) The TEAMGROUP MP44Q is an M.2 2280 PCIe 4.0 x4 NVMe SSD that delivers sequential read speeds of up to 7,000MB/s and sequential write speeds of up to 5,900MB/s. It uses 3D QLC NAND flash memory to provide 4TB of storage capacity for games, applications, media files, and other data. The drive has an endurance rating of 2,000 TBW and an MTBF of 1.6 million hours. The SSD features a DRAM-less design and supports TEAMGROUP's S.M.A.R.T. monitoring software, allowing users to monitor drive health, temperature, and remaining lifespan. For thermal management, the MP44Q also includes an "ultra-thin" graphene heat spreader. It is designed to operate at temperatures between 0°C and 70°C and can be stored at temperatures ranging from -40°C to 85°C. The SSD is also backed by a five-year limited warranty. 4TB TEAMGROUP MP44Q SSD: $478.99 (Amazon US) The 2TB WD My Passport SSD connects via a USB-C port using the USB 3.2 Gen 2 interface. It delivers sequential read speeds of up to 1,050MB/s and sequential write speeds of up to 1,000MB/s through NVMe technology. In terms of security features, the drive includes password protection with 256-bit AES hardware encryption. The SSD is also designed to resist shock and vibration and is rated to withstand drops from heights of up to 6.5 feet. The recommended operating temperature range is 5°C to 35°C, while the non-operating temperature range is -20°C to 65°C. This drive is also backed by a five-year limited warranty. 2TB Western Digital My Passport SSD: $279.99 (Amazon US) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
  • Recent Achievements

    • Week One Done
      flexorcist earned a badge
      Week One Done
    • One Month Later
      Woland13 earned a badge
      One Month Later
    • Week One Done
      Woland13 earned a badge
      Week One Done
    • One Year In
      bernmeister earned a badge
      One Year In
    • Week One Done
      Scoobystu earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      492
    2. 2
      +Edouard
      225
    3. 3
      PsYcHoKiLLa
      147
    4. 4
      Steven P.
      75
    5. 5
      FloatingFatMan
      71
  • Tell a friend

    Love Neowin? Tell a friend!