The Insecurity of Security Software
H316 writes "BusinessWeek is reporting that, despite a number of software products meant to safeguard Windows PCs from harm, a rising number of them endanger their hosts because of poor design and flaws. From the article: 'A new Yankee Group report, to be released June 20, shows the number of vulnerabilities found in security products increasing sharply for the third straight year -- and for the first time surpassing those found in all Microsoft products.'"
Security software is insecure? Maybe it's just having a bad day and needs a hug. *hugs security software*
Be relentless!
Linux is somewhat ahead in this in that protected memory is part of its "DNA", unlike Windows which ultimately comes from the culture of DOS, which has no protected memory and is not multi-user.
But still, Linux is only just a little bit better. We need to move to real secure designs such as:
Oh god what is really scary is that I can imagine a slick salesman selling someone Antivirus-Antivirus software. It makes sense if you are a laymen.
What happens if your antivirus software is attacked? If it goes down you are vulnerable. Here is a $20 program to protect it.
Goodbye I'm off to get rich.
Well, the answer here is simple. We need more security products to secure the security products that are securing Windows!
Aside: (but related), I wonder, has anyone ever investigated, researched, done any benchmarks about how many/what percentage of CPU cylces are allocated just for virus checking (and other security checks)?
... it's pretty much brought productivity to a halt.
Well, if the antivirus scanner that the IT guy at work just put on my 2.4 Ghz. development system, I'd say it's close to 100%. Something will have to be done about it at some point
But hey. At least we don't have any viruses. Right?
Great phrase. I'll have to keep it mind.
A firewall can not protect you from yourself. Turn off what you do not need. Do not use the firewall to do your work.