Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #206102 > unrolled thread

Group thoughts on: Anti-virus tools

Started bydeb <deb@rangingthoughts.org>
First post2019-03-10 16:00 +0100
Last post2019-03-12 11:40 +0100
Articles 16 on this page of 36 — 18 participants

Back to article view | Back to linux.debian.user


Contents

  Group thoughts on: Anti-virus tools deb <deb@rangingthoughts.org> - 2019-03-10 16:00 +0100
    Re: Group thoughts on: Anti-virus tools Sven Hartge <sven@svenhartge.de> - 2019-03-10 16:10 +0100
      Re: Group thoughts on: Anti-virus tools Paul Sutton <zleap@disroot.org> - 2019-03-11 12:00 +0100
        Re: Group thoughts on: Anti-virus tools Curt <curty@free.fr> - 2019-03-11 13:10 +0100
          RE: Group thoughts on: Anti-virus tools Michael Grant <mgrant@grant.org> - 2019-03-11 14:00 +0100
    Re: Group thoughts on: Anti-virus tools Reco <recoverym4n@enotuniq.net> - 2019-03-10 16:30 +0100
      Re: Group thoughts on: Anti-virus tools Richard Owlett <rowlett@cloud85.net> - 2019-03-10 16:40 +0100
        Re: Group thoughts on: Anti-virus tools Reco <recoverym4n@enotuniq.net> - 2019-03-10 17:40 +0100
          Re: Group thoughts on: Anti-virus tools Joe <joe@jretrading.com> - 2019-03-10 18:20 +0100
            Re: Group thoughts on: Anti-virus tools Stefan Monnier <monnier@iro.umontreal.ca> - 2019-03-10 19:50 +0100
            Re: Group thoughts on: Anti-virus tools mick crane <mick.crane@gmail.com> - 2019-03-10 20:50 +0100
              Re: Group thoughts on: Anti-virus tools Joe <joe@jretrading.com> - 2019-03-10 21:20 +0100
            Re: Group thoughts on: Anti-virus tools Reco <recoverym4n@enotuniq.net> - 2019-03-10 21:00 +0100
        Re: Group thoughts on: Anti-virus tools Curt <curty@free.fr> - 2019-03-10 17:40 +0100
          And now, from the Nice people? Re: Group thoughts on: Anti-virus  tools deb <deb@rangingthoughts.org> - 2019-03-10 18:20 +0100
            Re: And now, from the Nice people? Re: Group thoughts on: Anti-virus  tools Felmon Davis <davisf@union.edu> - 2019-03-10 21:10 +0100
            Re: And now, from the Nice people? Re: Group thoughts on: Anti-virus  tools Brian <ad44@cityscape.co.uk> - 2019-03-10 21:20 +0100
              Re: And now, from the Nice people? Re: Group thoughts on: Anti-virus  tools Ric Moore <wayward4now@gmail.com> - 2019-03-12 05:20 +0100
            Re: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools deloptes <deloptes@gmail.com> - 2019-03-11 08:40 +0100
              Re: And now, from the Nice people? Re: Group thoughts on:  Anti-virus tools Curt <curty@free.fr> - 2019-03-11 09:30 +0100
                Re: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools deloptes <deloptes@gmail.com> - 2019-03-11 23:20 +0100
                  Re: And now, from the Nice people? Re: Group thoughts on:  Anti-virus tools Curt <curty@free.fr> - 2019-03-12 10:00 +0100
                    Re: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools deloptes <deloptes@gmail.com> - 2019-03-12 19:50 +0100
            Re: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools Stefan Monnier <monnier@iro.umontreal.ca> - 2019-03-11 13:40 +0100
              Re: And now, from the Nice people? Re: Group thoughts on:  Anti-virus tools Curt <curty@free.fr> - 2019-03-11 14:50 +0100
                Re: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools Stefan Monnier <monnier@iro.umontreal.ca> - 2019-03-11 16:50 +0100
                  Re: And now, from the Nice people? Re: Group thoughts on:  Anti-virus tools Joe <joe@jretrading.com> - 2019-03-11 19:20 +0100
    Re: Group thoughts on: Anti-virus tools Gene Heskett <gheskett@shentel.net> - 2019-03-10 16:40 +0100
    Re: Group thoughts on: Anti-virus tools Mart van de Wege <mvdwege@gmail.com> - 2019-03-10 19:00 +0100
      Thanks Mart -- Re: Mart -- [Solved] [Well, not solved,. but sickened  by] Re: Group thoughts on: Anti-virus tools deb <deb@rangingthoughts.org> - 2019-03-13 00:30 +0100
        Re: Thanks Mart -- Re: Mart -- [Solved] [Well, not solved,. but  sickened by] Re: Group thoughts on: Anti-virus tools Brian <ad44@cityscape.co.uk> - 2019-03-13 00:40 +0100
    Re: Group thoughts on: Anti-virus tools Stefan Monnier <monnier@iro.umontreal.ca> - 2019-03-10 19:50 +0100
    Re: Group thoughts on: Anti-virus tools deloptes <deloptes@gmail.com> - 2019-03-11 08:10 +0100
    Re: Group thoughts on: Anti-virus tools didier gaumet <didier.gaumet@gmail.com> - 2019-03-12 09:50 +0100
      Re: Group thoughts on: Anti-virus tools Alessandro Vesely <vesely@tana.it> - 2019-03-12 13:20 +0100
    Re: Group thoughts on: Anti-virus tools mick crane <mick.crane@gmail.com> - 2019-03-12 11:40 +0100

Page 2 of 2 — ← Prev page 1 [2]


#206177 — Re: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools

Fromdeloptes <deloptes@gmail.com>
Date2019-03-11 23:20 +0100
SubjectRe: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools
Message-ID<xABr3-5vO-3@gated-at.bofh.it>
In reply to#206145
Curt wrote:

> I don't believe he did, actually. I believe that's what Reco wrote.

but there is no secure OS, as soon as you get connected to the network, and
if you have a server with multiple users ... well. We used to put sensitive
servers in DMZ aside of the user network - for a good reason.

regards

[toc] | [prev] | [next] | [standalone]


#206183 — Re: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools

FromCurt <curty@free.fr>
Date2019-03-12 10:00 +0100
SubjectRe: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools
Message-ID<xALqp-3eP-1@gated-at.bofh.it>
In reply to#206177
On 2019-03-11, deloptes <deloptes@gmail.com> wrote:
> Curt wrote:
>
>> I don't believe he did, actually. I believe that's what Reco wrote.
>
> but there is no secure OS, as soon as you get connected to the network, and
> if you have a server with multiple users ... well. We used to put sensitive
> servers in DMZ aside of the user network - for a good reason.

I don't follow how this follows from your erroneous attribution. But if
you're saying that no OS is immune from some form of insecurity, you're
wasting your breath because that man is made of straw.

On the other hand, some operating systems are more secure than others
(*for whatever reasons*). I think that statement is statistically
verifiable. (I was going to invent one of those strained, if handy, car
analogies but thought better of it.)


> regards
>
>


-- 
“Let us again pretend that life is a solid substance, shaped like a globe,
which we turn about in our fingers. Let us pretend that we can make out a plain
and logical story, so that when one matter is despatched--love for instance--
we go on, in an orderly manner, to the next.” - Virginia Woolf, The Waves

[toc] | [prev] | [next] | [standalone]


#206195 — Re: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools

Fromdeloptes <deloptes@gmail.com>
Date2019-03-12 19:50 +0100
SubjectRe: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools
Message-ID<xAUDn-X1-1@gated-at.bofh.it>
In reply to#206183
Curt wrote:

> I don't follow how this follows from your erroneous attribution.

try harder ;-)

[toc] | [prev] | [next] | [standalone]


#206148 — Re: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2019-03-11 13:40 +0100
SubjectRe: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools
Message-ID<xAsnL-8dN-3@gated-at.bofh.it>
In reply to#206114
> Not that I'm aware of.  The thing is - instead of taking an insecure OS
> and building assorted kludges (in the form of anti-virus) around it,
> it's considered wise here to use a secure OS from the beginning.

This is misleading: all OSes are somewhat insecure, in practice.
The question is what to do when a security hole is found: plug the hole
right away, or try to recognize potential attacks via some anti-virus
software?

Of course, AV software houses can't really plug security holes in
Windows (only Microsoft can), so their livelihood depends on making
people believe that an AV is a good supplement.


        Stefan

[toc] | [prev] | [next] | [standalone]


#206151 — Re: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools

FromCurt <curty@free.fr>
Date2019-03-11 14:50 +0100
SubjectRe: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools
Message-ID<xAttv-qH-5@gated-at.bofh.it>
In reply to#206148
On 2019-03-11, Stefan Monnier <monnier@iro.umontreal.ca> wrote:
>> Not that I'm aware of.  The thing is - instead of taking an insecure OS
>> and building assorted kludges (in the form of anti-virus) around it,
>> it's considered wise here to use a secure OS from the beginning.
>
> This is misleading: all OSes are somewhat insecure, in practice.
> The question is what to do when a security hole is found: plug the hole
> right away, or try to recognize potential attacks via some anti-virus
> software?
>
> Of course, AV software houses can't really plug security holes in
> Windows (only Microsoft can), so their livelihood depends on making
> people believe that an AV is a good supplement.
>

I think the premises of your syllogism might lead some to another
conclusion---that the livelihood of the AV software houses depends upon
the innate insecurity of the Windows OS.  This kind of gentleman's
agreement seems to be one of the fundamental cogs in the great Wheel of
capitalism to which most of us are tied.

Having said that, the Windows 10 on my hubby's laptop has native virus-
detection software and the OS is patched frequently via the net (at
times to inadvertent ill effect, though not here, at least not yet).

>         Stefan
>
>


-- 
“Let us again pretend that life is a solid substance, shaped like a globe,
which we turn about in our fingers. Let us pretend that we can make out a plain
and logical story, so that when one matter is despatched--love for instance--
we go on, in an orderly manner, to the next.” - Virginia Woolf, The Waves

[toc] | [prev] | [next] | [standalone]


#206153 — Re: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2019-03-11 16:50 +0100
SubjectRe: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools
Message-ID<xAvlD-1zV-7@gated-at.bofh.it>
In reply to#206151
> I think the premises of your syllogism might lead some to another
> conclusion---that the livelihood of the AV software houses depends upon
> the innate insecurity of the Windows OS.

Hmm... they don't actually need that: they only need people to
think that they're vulnerable (regardless if their Windows is actually
secure or not, and regardless is Windows is more or less secure than
other OSes).

But yes, this is made easier if Windows is actually insecure.


        Stefan

[toc] | [prev] | [next] | [standalone]


#206162 — Re: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools

FromJoe <joe@jretrading.com>
Date2019-03-11 19:20 +0100
SubjectRe: And now, from the Nice people? Re: Group thoughts on: Anti-virus tools
Message-ID<xAxGO-3a9-9@gated-at.bofh.it>
In reply to#206153
On Mon, 11 Mar 2019 11:45:28 -0400
Stefan Monnier <monnier@iro.umontreal.ca> wrote:

> > I think the premises of your syllogism might lead some to another
> > conclusion---that the livelihood of the AV software houses depends
> > upon the innate insecurity of the Windows OS.  
> 
> Hmm... they don't actually need that: they only need people to
> think that they're vulnerable (regardless if their Windows is actually
> secure or not, and regardless is Windows is more or less secure than
> other OSes).
> 
> But yes, this is made easier if Windows is actually insecure.
> 

To a large extent, it is Windows users who are insecure. Even today (or
at least, three months ago) the first-time user of Windows 10 is set up
as an administrator, and no advice is offered about changing this. 

I used to help out on Windows Small Business Server newsgroup, where
many administrators/installers admitted to making all their users
administrators to reduce service calls... it was actually *necessary*
for the user of MS Office to be an administrator for the first run of
each of the components (not just the installation), or else various
files and permissions didn't get written correctly.

-- 
Joe

[toc] | [prev] | [next] | [standalone]


#206107

FromGene Heskett <gheskett@shentel.net>
Date2019-03-10 16:40 +0100
Message-ID<xA8Ip-49y-3@gated-at.bofh.it>
In reply to#206102
On Sunday 10 March 2019 10:58:12 deb wrote:

> Starting assumption: I do want to run A/V.
>
>   * I get that it may actually INCREASE attack surface.
>
>   * But I have Windows & Mac stuff going back and forth to Debian 9.8
> and just want to check.
>
>   * (Clamscan already caught 4 things)
>
>
> a. What does the group suggest running on debian beyond
>
>      - chkrootkit
>
>      - rkhunter
>
>      - ClamAV
>
> b. Does the list keep a ~ "pinned" answer for these kinds of
> questions?
>
The trouble with a pinned list is that it can't keep up with the latest 
attack methods. Clamav has silently stripped about half a megabyte of 
stuff since about the first of October last, last hit Feb 12 here.
However while I'm checking, I note that a pastebin installation 
(pnopaste) has generated about 20 megabytes of squawks, so its gone now. 
I installed it so's I'd have a local pastebin. We get too soon auld, and 
too late schmardt. Has pnopaste acted up for others?

>
> Thank you!


Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#206118

FromMart van de Wege <mvdwege@gmail.com>
Date2019-03-10 19:00 +0100
Message-ID<xAaTU-5rT-31@gated-at.bofh.it>
In reply to#206102
deb <deb@rangingthoughts.org> writes:

> Starting assumption: I do want to run A/V.
>
>  * I get that it may actually INCREASE attack surface.
>
>  * But I have Windows & Mac stuff going back and forth to Debian 9.8
> and just want to check.

When you say going back and forth, do you mean over the network?

On Linux the best solution right now is clamav, which is not 100%. Is it
an option for you to run a network based solution, like an IDS?

Mart
-- 
"We will need a longer wall when the revolution comes."
--- AJS, quoting an uncertain source.

[toc] | [prev] | [next] | [standalone]


#206201 — Thanks Mart -- Re: Mart -- [Solved] [Well, not solved,. but sickened by] Re: Group thoughts on: Anti-virus tools

Fromdeb <deb@rangingthoughts.org>
Date2019-03-13 00:30 +0100
SubjectThanks Mart -- Re: Mart -- [Solved] [Well, not solved,. but sickened by] Re: Group thoughts on: Anti-virus tools
Message-ID<xAZ0n-3VH-9@gated-at.bofh.it>
In reply to#206118
On 3/11/19 5:08 PM, Mart van de Wege wrote:
> And yeah, Debian is an upstream distribution, so you will have a lot of
> people who are being overly purist about Linux solutions, because they
> have the luxury of working in homogenous environments. Unfortunately a
> lot of them are lousy communicators.


I'll say...

:-)


Fortunately Brian has blocked me, so that will enhance the noise::answer 
ratio :-)

What a tin-foil wearing curmudgeon that one is.


At least others want to help as bit.

Thank you Mart !

[toc] | [prev] | [next] | [standalone]


#206202 — Re: Thanks Mart -- Re: Mart -- [Solved] [Well, not solved,. but sickened by] Re: Group thoughts on: Anti-virus tools

FromBrian <ad44@cityscape.co.uk>
Date2019-03-13 00:40 +0100
SubjectRe: Thanks Mart -- Re: Mart -- [Solved] [Well, not solved,. but sickened by] Re: Group thoughts on: Anti-virus tools
Message-ID<xAZa1-3Zd-1@gated-at.bofh.it>
In reply to#206201
On Tue 12 Mar 2019 at 19:20:34 -0400, deb wrote:

> Fortunately Brian has blocked me,

Eh? You'll have to explain.

-- 
Brian.

[toc] | [prev] | [next] | [standalone]


#206122

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2019-03-10 19:50 +0100
Message-ID<xAbGh-5Zi-19@gated-at.bofh.it>
In reply to#206102
> Starting assumption: I do want to run A/V.

You have it: it's called `apt` (i.e. in the world of Debian, the
response to "viruses" is to plug the hole they try to exploit, instead
of leaving those holes gaping while wasting resources trying to look for
known attacks).

>  * (Clamscan already caught 4 things)

I'll bet that none of those 4 "things" exploit a hole to which you
are vulnerable.  Hence catching those attacks has not made you more
secure: it just wasted resources.

My SSHd daemon has probably rejected more attempts to log into my system
while writing this email.  So what?  None of those attempts are real
threats, anyway, just like those 4 "things" that Clamscan says
it caught.


        Stefan

[toc] | [prev] | [next] | [standalone]


#206142

Fromdeloptes <deloptes@gmail.com>
Date2019-03-11 08:10 +0100
Message-ID<xAnep-55G-9@gated-at.bofh.it>
In reply to#206102
deb wrote:

> ClamAV

I recall 15y ago we integrated kasperky into ClamAV. Easy to integrate and
easy to use. Worked great. I left this company couple of years later, but
it will not surprise me if they are still using the same setup.

[toc] | [prev] | [next] | [standalone]


#206182

Fromdidier gaumet <didier.gaumet@gmail.com>
Date2019-03-12 09:50 +0100
Message-ID<xALgJ-3bl-1@gated-at.bofh.it>
In reply to#206102
Wikipedia makes a comparison of Linux antivirus:
 https://en.wikipedia.org/wiki/Comparison_of_antivirus_software#Linux

[toc] | [prev] | [next] | [standalone]


#206190

FromAlessandro Vesely <vesely@tana.it>
Date2019-03-12 13:20 +0100
Message-ID<xAOxY-5Dp-7@gated-at.bofh.it>
In reply to#206182
On Tue 12/Mar/2019 09:39:53 +0100 didier gaumet wrote:

> Wikipedia makes a comparison of Linux antivirus:
>  https://en.wikipedia.org/wiki/Comparison_of_antivirus_software#Linux


It's astonishing that there is an "Email Security" column, with random yes/no contents.  I wrote a note on that:
https://en.wikipedia.org/wiki/Talk:Comparison_of_antivirus_software#Email_Security


An interesting column is the "License", where there is only one.


Best
Ale
-- 

[toc] | [prev] | [next] | [standalone]


#206186

Frommick crane <mick.crane@gmail.com>
Date2019-03-12 11:40 +0100
Message-ID<xAMZb-4yJ-7@gated-at.bofh.it>
In reply to#206102
On 2019-03-10 14:58, deb wrote:
> Starting assumption: I do want to run A/V.
> 
>  * I get that it may actually INCREASE attack surface.
> 
>  * But I have Windows & Mac stuff going back and forth to Debian 9.8
> and just want to check.
> 
>  * (Clamscan already caught 4 things)
> 

I'm of the opinion that windows itself is a virus but just live with it 
and don't keep anything on it I don't mind losing.
mick

-- 
Key ID    4BFEBB31

[toc] | [prev] | [standalone]


Page 2 of 2 — ← Prev page 1 [2]

Back to top | Article view | linux.debian.user


csiph-web