Edit: typo

  • >spyjoshx_@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    13
    ·
    2 years ago

    I understand that antivirus software is necessary on Windows, but I’ll never understand the existence of Windows Defender. If Microsoft knows enough to prevent a virus that exploits something in windows, why are they putting their effort into an antivirus program, and not fixing ththe problem in Windows? If someone has a good explanation for this, I’d love to hear it.

    • dzervas@lemmy.world
      link
      fedilink
      arrow-up
      8
      ·
      2 years ago

      ok so let’s start with the exploits. Exploit is a bug (problem) in a piece of software that when… umm… “abused” (well the word is just exploited) it allows you to do stuff that you shouldn’t. An exploit could be live from your browser to the program you use to zip files. The top 2 reasons to use an exploit is to either get initial foothold on a machine (e.g. an exploit in a browser that would allow an attacker to execute arbitrary code when you visit their page or an exploit in winrar that when you open a zip file executes code)

      From the attackers perspective, you got in, nice. Mind you you got in through means that have nothing to do with windows (and that’s true most times, especially on desktops). but now? what?

      You hacked into the machine for a reason! You might wanna grab the browser cookies (giving you direct access to the accounts that the victim is logged into), grab some files, screenshots, passwords

      That’s where the AV kicks in. After the initial exploit the malware behaves like a normal program. But not completely. Assuming that the AV hasn’t seen the same exact malware before (which would an insta kick ban) it’s going to see a random process accessing files in chrome’s directory. HUH. ISNT THAT SOMETHING. quarantined.

      Wanna start listening to each and every keystroke? quarantined

      Meanwhile the way that the exe ended up in your system was not through an installer, you don’t provide an uninstaller and it was downloaded from www.xXxveryNicEsiteyou.got. HUUUUUUUH

      the whole process is a bit simplified of course, but it captures the general idea

      So why does linux not have an AV? FUCK IF I KNOW! It would be very, VERY useful. Writing malware that bypasses AV is an art of its own. Can be done for sure, but it’s an extra step and it’s not fun

      background: used to get paid to do shit like that (legally, pentest) and it’s a fun hobby (writing code around it, not hacking people)

      • >spyjoshx_@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 years ago

        Makes sense! I guess without an antivirus there’s no way of distinguishing legitimate activity from illegitimate activity at the system level when dealing with downloaded programs. Also, my Voyager app decided that your “link” was actually a link and tried to make an embed lol

        • dzervas@lemmy.world
          link
          fedilink
          arrow-up
          2
          ·
          2 years ago

          exactly!

          sorry if I overexplained/oversimplified a bit but I didn’t want to make assumptions ☺️

    • beefcat@beehaw.org
      link
      fedilink
      arrow-up
      6
      ·
      edit-2
      2 years ago

      because that isn’t really how these things work. It doesn’t matter how secure your operating system is, it can still get infected with malware if you let the user download and install arbitrary software. every modern desktop operating system that allows this has this hole.

      features that pop up warnings when running code not signed by the OS vendor (like Windows SmartScreen or macOS Gatekeeper) help to an extent, but are not magic bullets since users can still override them.

      at the end of the day, the best defense is to make sure you actually trust any software you download before running it.

    • sternail@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      2 years ago

      I‘m sorry you got downvoted for asking a question because you don‘t know. Good old reddit behavior…