HomeinetThe truth about Antivirus discrimination

The truth about Antivirus discrimination

Which antivirus do you use? Are you sure it's reliable? If so, what do you base your answer on? Over the weekend, one of Google's top security researchers, our well-known Mr. Tavis Ormandy, published something on his blog that many people will not like. His publication criticized antivirus certifications that award meaningless awards to flawed security products.Antivirus

His problem stemmed from the fact that at this year's RSA security conference held in early March, Verizon's ICSA Labs awarded Comodo the 2016 Excellence in Information Security Testing Award.

The irony of course in this case is that Mr. Ormandy had discovered several security vulnerabilities in Comodo's Antivirus products.

The researcher first discovered that Comodo's products (antivirus and integrated security suites) add insecure browser extensions that disable Same-Origin Policy, a key security feature in web browsers. He also discovered that Comodo's scanning process does not enable ASLR protection, and the antivirus generally makes incorrect use of ACLs (access control lists).

Comodo runs VNC on each computer and the password is:

Comodo's secure browser does not provide security

Later, he also discovered that one of Comodo's tech support tools, which is enabled by default in some of the company's security products, was using an insecure VNC with weak credentials.

The issues don't stop there. Mr. Ormandy discovered additional bugs that allow an attacker to see a victim's keystrokes just by scanning a file.

So based on the above, it should come as no surprise that Mr. Ormandy has a problem with Verizon honoring Comodo with an award for excellence in information security.

But in addition to Comodo, Mr. Ormandy also mentioned the criteria Verizon used to certify Comodo with high information security standards.

When Verizon published its methodology for awarding the awards, Mr. Ormandy pointed out that it was extremely simplistic.

Most antivirus products can pass the certification requirements as they describe basic antivirus functions, half of which are related to UI features.

Zero Day in Trend Micro software

Some of the certification “criteria” include:

  • “Enable and disable malware detection” (it’s a basic start/stop button for the scanning process),
  • “Retrieve and apply the latest version and signatures via the Internet” (the antivirus should be able to receive updates),
  • “On-Demand Detection” (the antivirus should scan while it is already running and on a file that is entering the computer),
    and
  • “Reports without false positives” (well, ok!)
    .
    It should be noted here that Mr. Ormandy’s criticism was not only directed at Verizon’s award to Comodo, and he stated that antivirus products, in general, are insecure.

"All major security vendors are using ancient codebases without awareness of modern security practices, and hacking is back to 1999," the researcher said.

Two zero-days in products from security company FireEye

The researcher seems to be right, backing it up by providing reviews for a slew of security applications. Mr. Ormandy discovered security issues in security products from companies including Avast, Malwarebytes, Trend Micro, AVG, FireEye, Kaspersky, and ESET.

Zero-day exploit in Kaspersky antivirus
Vulnerability in ESET products, upgrade immediately

He conducted his research without access to the source code, with point-and-click security tools, and basic techniques that every security researcher learns.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS