Entering and Breaking the Avast Antivirus Sandbox Part 2
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Entering and Breaking the Avast Antivirus Sandbox Part 2
Unofficial Hacker News client; not affiliated with Y Combinator.
x-complexity · · focus · HN ↗
They 'worked' when they initially just scanned files for known malicious signatures. Now they're the equivalent of a sledgehammer to a wall with all of the extra bells & whistles strapped to them.
Application whitelisting is the remaining way forward if you actually care about runtime security. That & locking every access point down to the bare minimum.
Batman8675309 · · focus · HN ↗
IMO it would make more sense to run every app in its own scaled down VM, like Microdroid for Android. Windows 10 had Microsoft Defender Application Guard for Microsoft Edge, and as far as security goes it was a fortress.
Too bad they discontinued it, and that performance was subpar. I would have loved to see them develop the idea more.
stingraycharles · · focus · HN ↗
How would you deal with a password manager or a clipboard in these cases, for example, without increasing friction for users ?
Batman8675309 · · focus · HN ↗
There will always be advantages and disadvantages to all of this. But the general idea is to protect the "core" OS, and for that virtualization is superior to anything else you could try really. Android and iOS are already built to isolate apps from one another. ChromeOS uses Crostini to run Linux programs in a VM, etc.
> without increasing friction
That's always the compromise with an Antivirus, isn't it? The logical thing would be to build password managers into the OS, or maybe even to handle them differently. As they are already done in Android and iOS today.