‹ BackHN Continuity

Thread

Entering and Breaking the Avast Antivirus Sandbox Part 2

115 points · 32 comments · safateam

  1. x-complexity · · focus · HN ↗
    Chalk another one up for "Antiviruses causing more problems than solving them".

    They 'worked' when they initially just scanned files for known malicious signatures. Now they're the equivalent of a sledgehammer to a wall with all of the extra bells & whistles strapped to them.

    Application whitelisting is the remaining way forward if you actually care about runtime security. That & locking every access point down to the bare minimum.

    1. Batman8675309 · · focus · HN ↗
      I'm a firm believer that hardware virtualization is the way forward for security. Qubes OS has the right idea, but running an entire OS for every application is demanding.

      IMO it would make more sense to run every app in its own scaled down VM, like Microdroid for Android. Windows 10 had Microsoft Defender Application Guard for Microsoft Edge, and as far as security goes it was a fortress.

      Too bad they discontinued it, and that performance was subpar. I would have loved to see them develop the idea more.

      1. binsquare · · focus · HN ↗
        I work on making this a reality with an embeddable VM.

        Performance doesn't have to be supbar, infact with the right properties and focus on being lightweight - I see 90% of native performance.

        I work on this as context: <a href="https:&#x2F;&#x2F;github.com&#x2F;smol-machines&#x2F;smolvm" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;smol-machines&#x2F;smolvm

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.