Entering and Breaking the Avast Antivirus Sandbox Part 2
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Entering and Breaking the Avast Antivirus Sandbox Part 2
Unofficial Hacker News client; not affiliated with Y Combinator.
x-complexity · · focus · HN ↗
They 'worked' when they initially just scanned files for known malicious signatures. Now they're the equivalent of a sledgehammer to a wall with all of the extra bells & whistles strapped to them.
Application whitelisting is the remaining way forward if you actually care about runtime security. That & locking every access point down to the bare minimum.
codedokode · · focus · HN ↗
master-lincoln · · focus · HN ↗
fn-mote · · focus · HN ↗
How much do I need to go on? A foothold on a local computer allows the attacker to spread horizontally across your network.
It’s just a matter of time before you’re fighting real-time AI-driven attacks (most sites aren’t yet). Good luck even with your antivirus. Which I agree is going to be one of the footholds that is used against you.