Do you ever run a computer without an antivirus and/or firewall?
Real-Time scanning is essential
-------------------------------------
There is a good analogy with vaccination programmes and also condom use vs abstinence around this topic.
Decent AV blocks generic attacks. I've seen a piece of malware slip though LGfL mail filter, past Symantec MSMSE into my mail store and onto my unpatched (we always run a few days behind the releases) clients, where it was identified by Sophos EndPoint Security as suspicious and blocked. A few hours later both Symantec and Sophos had specific detection for it and the mailstores cleaned themselves up.
Nothing to see here move along.
It would have been a major issue without the client protection.
You cannot trust everyone to be as careful as you, thus by allowing your computer to interact with others (websites, friends, email, even yourself when you are in a hurry) you are exposing it to risk. c.f issues with abstinence programmes in fight against STDs.
Running machines without AV also allows for pools of undetected infection, which makes it harder to prevent and deal with outbreaks. Your internet connected PC (even if it is behind a firewall) makes you a global citizen, and you have a shared responsibility to the health of your neighbours computer (metaphorically). Yes sometimes AV product cause collateral damage, however globally this is has less of an impact than running no AV at all.
For those who don't run AV on their CCTV, IPTV, Cashless Catering, Printers, Mobiles, switches(!) etc.:I suggest you consider the trend recently - infrastructure is the next target, and while it may be that national institutions will bear the brunt of the directed attacks, once released, self-replicating code could go anywhere.
The myth of Mac and Linux
--------------------------------------
Historically MS-DOS and later, Windows, would execute any code for anyone with full privileges, often simply inserting a disk would be enough. This is why UNIX/MACOS and RISCOS users used to be smug. MAC and RISCOS users were really only protected by their platform's minority status. This all changed about ten years ago with OS X, GNOME/KDE, JavaScript and Flash. However the unix based platforms still do not generally give Joe User permission to edit system files, and thus persistent malware infections are rare. However both UNIX-like systems and WinNT based systems have flaws that allow malicious code to break into the kernel and once there your machine is compromised completely, and only a full offline scan can give you any chance to clean up your system.
There is a reason that really nasty infections are called root-kits not SYSTEM-kits.
P.

0 Comments
Recommended Comments
There are no comments to display.
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now