Entering and Breaking the Avast Antivirus Sandbox Part 2
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Entering and Breaking the Avast Antivirus Sandbox Part 2
Unofficial Hacker News client; not affiliated with Y Combinator.
x-complexity · · focus · HN ↗
They 'worked' when they initially just scanned files for known malicious signatures. Now they're the equivalent of a sledgehammer to a wall with all of the extra bells & whistles strapped to them.
Application whitelisting is the remaining way forward if you actually care about runtime security. That & locking every access point down to the bare minimum.
atoav · · focus · HN ↗
You want to keep a building secure, so you have some structure of access and key managment, who has access to what and who do you let in.
Then you let access and key managment slide, your front-desktop lets in some shady people and their is a hole in your back wall.
The solution: add scaffolding around the facade and empower some security service staff to enter every room through every window and chime in on every front desk decision.