Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

"Flattery is all right -- if you don't inhale." -- Adlai Stevenson


computers / microsoft.public.windowsxp.general / It might be time to stop using antivirus - use a sandbox instead

SubjectAuthor
* It might be time to stop using antivirus - use a sandbox insteadAnonymous Remailer (austria)
`* Re: It might be time to stop using antivirus - use a sandbox insteadJ. P. Gilliver (John)
 +* Re: It might be time to stop using antivirus - use a sandbox insteadMayayana
 |`* Re: It might be time to stop using antivirus - use a sandbox insteadR.Wieser
 | `- Re: It might be time to stop using antivirus - use a sandbox insteadPaul
 `- Re: It might be time to stop using antivirus - use a sandbox insteadMr Pounder Esquire

1
It might be time to stop using antivirus - use a sandbox instead

<9a2748e15ba6954b3eec181458cfdd7c@remailer.privacy.at>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1129&group=microsoft.public.windowsxp.general#1129

  copy link   Newsgroups: microsoft.public.windowsxp.general
From: mixmaster@remailer.privacy.at (Anonymous Remailer (austria))
Subject: It might be time to stop using antivirus - use a sandbox instead
Message-ID: <9a2748e15ba6954b3eec181458cfdd7c@remailer.privacy.at>
Date: Fri, 6 Aug 2021 03:40:01 +0200 (CEST)
Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!news.mixmin.net!sewer!news.dizum.net!not-for-mail
Organization: dizum.com - The Internet Problem Provider
X-Abuse: abuse@dizum.com
Injection-Info: sewer.dizum.com - 2001::1/128
 by: Anonymous Remailer ( - Fri, 6 Aug 2021 01:40 UTC

Freebie Sandboxes

https://sandboxie.en.softonic.com/

http://www.toolwiz.com/lead/toolwiz_time_freeze/

https://arstechnica.com/information-technology/2017/01/antivirus-is-bad/

Update your software and OS regularly instead, practice skeptical computing.

Former Firefox developer Robert O'Callahan, now a free agent and safe
from the PR tentacles of his corporate overlord, says that antivirus
software is terrible, AV vendors are terrible, and that you should
uninstall your antivirus software immediately�unless you use Microsoft's
Windows Defender, which is apparently okay.

A couple of months back, Justin Schuh, Google Chrome's security chief,
and indeed one of the world's top infosec bods, said that antivirus
software is "my single biggest impediment to shipping a secure browser."
Further down the thread he explains that meddling AV software delayed
Win32 Flash sandboxing "for over a year" and that further sandboxing
efforts are still on hold due to AV. The man-in-the-middle nature of
antivirus also causes a stream of TLS (transport layer security) errors,
says Schuh, which in turn breaks some elements of HTTPS/HSTS.

These are just two recent instances of browser makers being increasingly
upset with antivirus software. Back in 2012, Nicholas Nethercote,
another Mozillian working on Firefox's MemShrink project said that
"McAfee is killing us." In that case, Nethercote was trying to reduce
the memory footprint of Firefox, and found that gnarly browser add-ons
like McAfee were consuming a huge amount of memory, amongst other
things. If you venture off-piste into the browser mailing lists, anti-
antivirus sentiment has bubbled away just below the surface for a very
long time.

The problem, from the perspective of the browser makers, is that
antivirus software is incredibly invasive. Antivirus, in an attempt to
catch viruses before they can infect your system, forcibly hooks itself
into other pieces of software on your computer, such as your browser,
word processor, or even the OS kernel. O'Callahan gives one particularly
egregious example: "Back when we first made sure ASLR was working for
Firefox on Windows, many AV vendors broke it by injecting their own
ASLR-disabled DLLs into our processes." ASLR, or address-space layout
randomisation, is one of the better protections against buffer overflow
exploits.

Furthermore, because of the aforementioned knotweed-style rhizomes of
antivirus programs, the AV software itself presents a very large attack
surface. As in, without AV installed, a hacker might have to find a
vulnerability in the browser or operating system�but if there's AV
present, the hacker can also look for a vulnerability there. This
wouldn't necessarily be a problem if AV makers made secure software, but
for the most part they don't (except for Windows Defender, because
Microsoft is "generally competent," according to O'Callahan).

Back in June last year, Google's Project Zero found 25 high-severity
bugs in Symantec/Norton security products. "These vulnerabilities are as
bad as it gets," said Tavis Ormandy, a Project Zero researcher. "They
don�t require any user interaction, they affect the default
configuration, and the software runs at the highest privilege levels
possible. In certain cases on Windows, vulnerable code is even loaded
into the kernel, resulting in remote kernel memory corruption." Over the
past five years, Ormandy has found similar vulnerabilities in security
software from Kaspersky, McAfee, Eset, Comodo, Trend Micro, and others.

All this isn't to say that you (or your parents) shouldn't use antivirus
software, but you should certainly be aware that using antivirus
software doesn't necessarily make your computer any more secure. In some
cases, AV might make your computer less secure, and cause a deleterious
effect on system performance�and, if you believe the browser makers, the
continuing popularity of AV software might have a gnarly knock-on effect
on other developers, too.

The nail in the coffin, according to O'Callahan, is that software
vendors rarely speak out about antivirus issues "because they need
cooperation from the AV vendors." He then links to a mailing list thread
in 2012, where he suggests keeping a list of the AV software that
interferes with Firefox. Later in the thread, Mozilla PR swoops in and
tells him to knock it off.

Antivirus software is so ingrained with Windows users, and synonymous
with the concept of "good security," that software makers have their
hands tied. "When your product crashes on startup due to AV
interference, users blame your product, not AV," O'Callahan says. "Worse
still, if they make your product incredibly slow and bloated, users just
think that's how your product is ... You can't tell users to turn off AV
software because if anything bad were to happen that the AV software
might have prevented, you'll catch the blame."

As always, irrespective of whether you decide to use AV, regularly
updating your OS and software is one of the best ways to keep your
computer safe. This also means that you should stop using Windows 7 or 8
and update to Windows 10.

When it comes to keeping your personal data safe, the problem is a
little more complex: all of the sandboxing and antimalware software in
the world won't save you from a well-executed phishing attack, or if a
database that contains your details is breached. For that, you should
use unique passwords, a physical security key where possible, and
generally be very wary of offering up any kind of personally
identifiable data.

Re: It might be time to stop using antivirus - use a sandbox instead

<YIhGJaNu4KDhFwEI@255soft.uk>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1130&group=microsoft.public.windowsxp.general#1130

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!feeder1.feed.usenet.farm!feed.usenet.farm!border1.nntp.ams1.giganews.com!nntp.giganews.com!buffer1.nntp.ams1.giganews.com!nntp.brightview.co.uk!news.brightview.co.uk.POSTED!not-for-mail
NNTP-Posting-Date: Thu, 05 Aug 2021 22:36:54 -0500
Message-ID: <YIhGJaNu4KDhFwEI@255soft.uk>
Date: Fri, 6 Aug 2021 04:36:14 +0100
From: G6JPG@255soft.uk (J. P. Gilliver (John))
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: It might be time to stop using antivirus - use a sandbox instead
References: <9a2748e15ba6954b3eec181458cfdd7c@remailer.privacy.at>
Organization: 255 software
MIME-Version: 1.0
Content-Type: text/plain;charset=us-ascii;format=flowed
User-Agent: Turnpike/6.07-M (<rmnDLoQj8kCR7AEglFYACAswEi>)
Lines: 12
X-Usenet-Provider: http://www.giganews.com
X-Trace: sv3-8g3LxmAvTLIBtFIm9N3v1/BMH0y2cr6YVT7LQY9S/z4LKbmCoCDUkRSYRXhB7zmJRCl7kk4oZspwEis!WNothD/VULOsRhrx4/grC206QzGty8/ylomPq5Ny1BxJfTsPtzKGUDJ8He+wbJbb0/h7yz+1
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
X-Original-Bytes: 1483
 by: J. P. Gilliver (John - Fri, 6 Aug 2021 03:36 UTC

On Fri, 6 Aug 2021 at 03:40:01, "Anonymous Remailer (austria)"
<mixmaster@remailer.privacy.at> wrote (my responses usually follow
points raised):
[]
>https://arstechnica.com/information-technology/2017/01/antivirus-is-bad/
.................................................^^^^
[]
He's at it again.
--
J. P. Gilliver. UMRA: 1960/<1985 MB++G()AL-IS-Ch++(p)Ar@T+H+Sh0!:`)DNAf

"Bother,"saidPoohwhenhisspacebarrefusedtowork.

Re: It might be time to stop using antivirus - use a sandbox instead

<sej7rc$7b8$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1132&group=microsoft.public.windowsxp.general#1132

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: mayayana@invalid.nospam (Mayayana)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: It might be time to stop using antivirus - use a sandbox instead
Date: Fri, 6 Aug 2021 07:52:19 -0400
Organization: A noiseless patient Spider
Lines: 14
Message-ID: <sej7rc$7b8$1@dont-email.me>
References: <9a2748e15ba6954b3eec181458cfdd7c@remailer.privacy.at> <YIhGJaNu4KDhFwEI@255soft.uk>
Injection-Date: Fri, 6 Aug 2021 11:53:16 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="49a67925bc89b30708dd9ebee29c7497";
logging-data="7528"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+PMwIqexnKx0aUlaX7uJhmrXDKWdegn00="
Cancel-Lock: sha1:+H8kOPYGcddXPFKYKGVBHbqKUMw=
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
X-Newsreader: Microsoft Outlook Express 6.00.2900.5512
X-Priority: 3
X-MSMail-Priority: Normal
 by: Mayayana - Fri, 6 Aug 2021 11:52 UTC

"J. P. Gilliver (John)" <G6JPG@255soft.uk> wrote

| On Fri, 6 Aug 2021 at 03:40:01, "Anonymous Remailer (austria)"
| <mixmaster@remailer.privacy.at> wrote

| He's at it again.

Interesting. The last one was carl@MIT. This one was
already in my block list. I don't know how long it's been
there, or why. I only see your post. Maybe it's an army
of Chinese spammers trying to get us to install their
malware.

Re: It might be time to stop using antivirus - use a sandbox instead

<sejl81$1s3n$1@gioia.aioe.org>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1133&group=microsoft.public.windowsxp.general#1133

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!aioe.org!BHGTVyTGRwF2ntnqLVfpDg.user.46.165.242.75.POSTED!not-for-mail
From: address@not.available (R.Wieser)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: It might be time to stop using antivirus - use a sandbox instead
Date: Fri, 6 Aug 2021 17:41:26 +0200
Organization: Aioe.org NNTP Server
Lines: 12
Message-ID: <sejl81$1s3n$1@gioia.aioe.org>
References: <9a2748e15ba6954b3eec181458cfdd7c@remailer.privacy.at> <YIhGJaNu4KDhFwEI@255soft.uk> <sej7rc$7b8$1@dont-email.me>
Injection-Info: gioia.aioe.org; logging-data="61559"; posting-host="BHGTVyTGRwF2ntnqLVfpDg.user.gioia.aioe.org"; mail-complaints-to="abuse@aioe.org";
X-Newsreader: Microsoft Outlook Express 6.00.2900.5512
X-Notice: Filtered by postfilter v. 0.9.2
X-MSMail-Priority: Normal
X-Priority: 3
X-RFC2646: Format=Flowed; Original
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
 by: R.Wieser - Fri, 6 Aug 2021 15:41 UTC

Mayayana,

> Interesting. The last one was carl@MIT.

The two he send after that came from (two different) "remailer" newsservers.
Its rather possible that Eternal September blocks those - and for good
reason.

Regards,
Rudy Wieser

Re: It might be time to stop using antivirus - use a sandbox instead

<sejvu7$tks$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1134&group=microsoft.public.windowsxp.general#1134

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: nospam@needed.invalid (Paul)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: It might be time to stop using antivirus - use a sandbox instead
Date: Fri, 06 Aug 2021 14:44:24 -0400
Organization: A noiseless patient Spider
Lines: 46
Message-ID: <sejvu7$tks$1@dont-email.me>
References: <9a2748e15ba6954b3eec181458cfdd7c@remailer.privacy.at> <YIhGJaNu4KDhFwEI@255soft.uk> <sej7rc$7b8$1@dont-email.me> <sejl81$1s3n$1@gioia.aioe.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Fri, 6 Aug 2021 18:44:23 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="1ee57a366860f85e6d00b44812cd9a2c";
logging-data="30364"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/96yIjFWPduDU1jvN9yzRGd9jnrNhNnUo="
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
Cancel-Lock: sha1:A9cb0/7bXwcT/nz1AbuZagPu0QA=
In-Reply-To: <sejl81$1s3n$1@gioia.aioe.org>
 by: Paul - Fri, 6 Aug 2021 18:44 UTC

R.Wieser wrote:
> Mayayana,
>
>> Interesting. The last one was carl@MIT.
>
> The two he send after that came from (two different) "remailer" newsservers.
> Its rather possible that Eternal September blocks those - and for good
> reason.
>
> Regards,
> Rudy Wieser
>
>

Sandboxie. Process isolation with kernel hooks.
May 23rd, 2011

https://web.archive.org/web/20130429072246/http://vallejo.cc/48

"Sandboxie is a sandbox that performs a process isolation. Its main features:
- Access control to kernel resources by direct hooks on kernel objects.
- Some ssdt and shadow ssdt hooks to control window messages.
- Some kernel registered callbacks to be notified of process creating, images loaded, …

In this article I will speak about sandoxie design and I will perform
a analysis from a security point of view."

...

"KeBugCheck is called from SbieDrv so it is only a non dangerous DoS
(we can cause it from a sandboxed process), but we can see that a
simple fuzzing causes a crash, and this fact makes me suspicious
of Sandboxie robusticity."

Summary: No security method or scheme is perfect.

Don't be too enamored of perfection, and you
won't be disappointed when you're tipped over.

If a nation state wants you to be tipped over,
you're tipped over.

If a nation state wants to scan your device, they'll
get Apple to do it :-)

Paul

Re: It might be time to stop using antivirus - use a sandbox instead

<sek0nu$748$1@dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=1135&group=microsoft.public.windowsxp.general#1135

  copy link   Newsgroups: microsoft.public.windowsxp.general
Path: i2pn2.org!i2pn.org!eternal-september.org!reader02.eternal-september.org!.POSTED!not-for-mail
From: MrPounder@RationalThought.com (Mr Pounder Esquire)
Newsgroups: microsoft.public.windowsxp.general
Subject: Re: It might be time to stop using antivirus - use a sandbox instead
Date: Fri, 6 Aug 2021 19:58:02 +0100
Organization: A noiseless patient Spider
Lines: 13
Message-ID: <sek0nu$748$1@dont-email.me>
References: <9a2748e15ba6954b3eec181458cfdd7c@remailer.privacy.at> <YIhGJaNu4KDhFwEI@255soft.uk>
Injection-Date: Fri, 6 Aug 2021 18:58:06 -0000 (UTC)
Injection-Info: reader02.eternal-september.org; posting-host="d729cce59ec900188cf321751ac5b003";
logging-data="7304"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+gMAqfzd2GSwFQk7quuNu4tdcXEbR8gi0="
Cancel-Lock: sha1:qly+dEUixov/+gF/4AMV1mTmUuA=
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.6157
X-RFC2646: Format=Flowed; Response
X-Newsreader: Microsoft Outlook Express 6.00.2900.5931
X-Priority: 3
X-MSMail-Priority: Normal
 by: Mr Pounder Esquire - Fri, 6 Aug 2021 18:58 UTC

J. P. Gilliver (John) wrote:
> On Fri, 6 Aug 2021 at 03:40:01, "Anonymous Remailer (austria)"
> <mixmaster@remailer.privacy.at> wrote (my responses usually follow
> points raised):
> []
>> https://arstechnica.com/information-technology/2017/01/antivirus-is-bad/
> ................................................^^^^
> []
> He's at it again.

+1


computers / microsoft.public.windowsxp.general / It might be time to stop using antivirus - use a sandbox instead

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor