Cisco CSO Says Antivirus Money "Completely Wasted"
mernil writes with an excerpt that kicks off a story at ZDNet Australia: "Companies are wasting money on security processes — such as applying patches and using antivirus software — which just don't work, according to Cisco's chief security officer John Stewart. Speaking at the AusCERT 2008 conference in the Gold Coast yesterday, Stewart said the malware industry is moving faster than the security industry, making it impossible for users to remain secure."
Why pay for it, when there are plenty of free alternatives?
Companies are wasting money on Windows ;)
Patching software does work though, I don't see the alternative if you have an exploitable bug in your code? You want that code fixed. It doesn't matter if no damage can be done to your system, you still want all your applications running as expected.
which is totally what she said
I read this story yesterday, and the quote is a little misleading. Here's the context: "If patching and antivirus is where I spend my money, and I'm still getting infected and I still have to clean up computers and I still need to reload them and still have to recover the user's data and I still have to reinstall it, the entire cost equation of that is a waste."
"It's completely wasted money," Stewart told delegates. Exactly. If it does not work, the money spent on it is wasted. Not exactly controversial.
Floating face-down in a river of regret...and thoughts of you...
Cisco is integrating ClamAV in to their "Cisco Security Agent" HIDS product. They clearly think AV is useful, just not other peoples' AV.
A slashdotter who didn't build his own computer is like a Jedi who didn't build his own lightsaber.
Whos says the alternatives have to be anti-virus applications? ;)