I think its time that as an IT community, we explained to users that AV is bad
I've always had more problems with AV products that they've solved. I'd especially never put A/V on a server! (Unless it is a file server). What are people doing having access to upload stuff to your server anyway? Its like IE7 "secure mode" with win 2008. If you have server admins browsing for porn on your servers, then you have bigger security problems than malicious web pages. You only get viruses from two things: porn and warez. End of story. Block those sites from your corporate network.
AV slows down machines, incorrectly deletes files, installs itself into all the same hooks that viruses themselves use, and if you follow good defense rules elsewhere, then it is a non-issue (again except for end-user machines and file servers).
I'm tired of walking into a company, finding that A/V is the biggest performance problem with a server, and being thrown out like I'm raving mad. And stupid rules like PCI mandate this stuff.
The age of A/V is coming to an end. There are way more viruses being produced each year than researchers to defend them, and they are overwhelmed, and obviously making mistakes. Blacklisting has reached its limit: white-listing, lock-down, sandboxes, and secure OS design are the way forward. It will just take Luddites 10 more years to realize that.
Opinion
David McLeman
Tim Worstall
Chris Mellor
Popular Stories
Features