Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My mini Ask HN:

Do you trust makers of security software?



No, absolutely not. Even if their intentions are good, they still have shown some questionable competence, for example:

http://www.theregister.co.uk/2016/03/31/trend_micro_patches_...

http://www.pcworld.com/article/3020327/antivirus-software-co...


Not very much, no.

But in the context of ransomware, the advice presented here is game-theoretically sound (and proven by thousands of years of experience in dealing with criminals demanding ransom), so I do trust it.


Not the big ones that are well-known names in the PC market. There are quite some shady security software vendors out there, and a handful very competent ones that I trust if I have to.


Can you expand on that? Who are the good ones, and the bad ones?


The bad ones are typically well-known desktop anti virus scanners that try to score by showing you a high number of threats they allegedly defeated. If you look at those threats in detail, they turn out to be browser cookies, or bookmarks, or something similarly trivial.

Identifying good vendors and products is generally harder. I've heard good things about canary.tools and bromium, for example. Both explain what they do in terms that don't make a techie roll their eyes (too much at least): https://canary.tools/#how-it-works and https://www.bromium.com/advanced-endpoint-security/our-techn...

A good (but not exhaustive) test is to look at what the vendors promise. If they promise you full protection of your machine or network, you know they are full of shit. If they talk only about one aspect (identifying attackers, reducing the attack surface on a browser), things start to look better.


I've seen Halt and Catch Fire, so no.


I trust them not to be behind ransomware.

I don't trust them to make good quality software which works quietly and efficiently in my interest.

They basically sell a security theatre product where their motivations are to popup "PROTECTED BY ____" at all times so I don't forget it exists, and to look busy - typically by scanning the same files over and over even though they haven't changed in months - and to hook into everything to add more sales buzzwords to their product.


I do love to read their analyses on APTs and things like that, but other than that, no. There's not a single security software vendor that I trust.


Yup, I trust grsec.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: