{"id":18043,"date":"2022-02-02T10:47:04","date_gmt":"2022-02-02T18:47:04","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/02\/02\/news-11776\/"},"modified":"2022-02-02T10:47:04","modified_gmt":"2022-02-02T18:47:04","slug":"news-11776","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/02\/02\/news-11776\/","title":{"rendered":"Windows security in \u201922 \u2014 you need more than just antivirus software"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2021\/03\/maze-1-100880563-large.3x2.jpg?auto=webp&amp;quality=85,70\"\/><\/p>\n<p><strong>Credit to Author: Susan Bradley| Date: Mon, 10 Jan 2022 06:10:00 -0800<\/strong><\/p>\n<p style=\"font-weight: 400;\">Do you need antivirus in 2022 \u2014 especially when some options now come with a cryptominer built in?<\/p>\n<p style=\"font-weight: 400;\">Several antivirus vendors \u2014 some options free, others, paid \u2014 have begun bundling their antivirus products with software that generates virtual currency. Of all of the requirements for antivirus, using excess cycles on your computer to generate crypto-coins is not on my list of must-haves.<\/p>\n<p style=\"font-weight: 400;\">Recently, <a href=\"https:\/\/krebsonsecurity.com\/2022\/01\/500m-avira-antivirus-users-introduced-to-cryptomining\/\" rel=\"noopener nofollow\" target=\"_blank\">Krebs on Security<\/a> noted that both Norton Antivirus and Avira have told users that versions of their respective software now include a cryptominer. While it\u2019s not enabled by default, it still gives me pause; antivirus is supposed to protect us from such potentially unwanted software, and these two vendors are now including it in their wares.<\/p>\n<p style=\"font-weight: 400;\">I have often thought that <em>no<\/em> antivirus software is better than the various options available. I\u2019ve tracked patch installations on Windows platforms for years and have often seen bad interactions between antivirus software and Windows updates. Early in the Windows 7 release cycle, I regularly advised users to uninstall antivirus software before applying security updates or service packs to avoid problems. Some users also saw side effects with browsers and had to uninstall or reinstall their antivirus software to get their browser working properly. (Even with Windows 10, it\u2019s important to ensure users are running a supported version of antivirus.)<\/p>\n<p style=\"font-weight: 400;\">Just think of the number of times historically that Microsoft has used <a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/important-windows-security-updates-and-antivirus-software-4fbe7b34-b27d-f2c4-ee90-492ef383fb9c\" rel=\"noopener nofollow\" target=\"_blank\">installation blocks<\/a> due to interaction with antivirus products.<\/p>\n<p style=\"font-weight: 400;\">As Microsoft explained one case in 2018: \u201cThe compatibility issue arises when antivirus applications make unsupported calls into Windows kernel memory. These calls may cause stop errors (also known as blue screen errors) that make the device unable to boot. To help prevent these stop errors, Microsoft is currently only offering the January and February 2018 Windows security updates to devices that are running antivirus software that is from antivirus software vendors who have confirmed that their antivirus software is compatible by setting a required registry key.\u201d<\/p>\n<p style=\"font-weight: 400;\">The issue then was that some antivirus vendors used undocumented code hooks \u2014 rather than hooking into the Windows firewall \u2014 to perform antivirus scans. During the installation of a service pack, these hooks into the Windows kernel would conflict with the new code and trigger blue screens or at a minimum trigger the rollback of the service pack install.<\/p>\n<p style=\"font-weight: 400;\">For smaller businesses with 300 users or less, Microsoft is in the process of testing Microsoft Defender for Business, a <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/small-and-medium-business-blog\/introducing-microsoft-defender-for-business\/ba-p\/2898701\" rel=\"noopener nofollow\" target=\"_blank\">security suite<\/a> that adds the ability to manage, track, and protect against threats in a network. In addition to scanning for, and alerting about, issues, it also provides actionable security tips unique to each platform. It will often recommend Attack Surface Reduction rules that can help make your network more secure. If you\u2019re an SMB, I recommend that you check out the preview to see if your network would benefit from the additional guidance.<\/p>\n<p style=\"font-weight: 400;\">For home users, I remain a fan of Microsoft Defender, which is built into both Windows 10 and 11. Though some would rather have a third-party vendor be on the lookout for security issues \u2014 they argue that relying on Defender is like letting the fox guard the hen house \u2014 my philosophy is that any form of antivirus is reactionary, not proactive. Antivirus is not the best tool to filter email for phishing attacks, nor is it the best tool to check where you browse online. You need security services in front of your computer, not just something that checks the software on your computer.<\/p>\n<p style=\"font-weight: 400;\">These days, security is about more than antivirus. Start with the basics, such as your email provider, and review your options. If you are still using the same ISP-based email from 20 years ago, it\u2019s time to investigate other email services that might scan and review or attacks better. And your options extend beyond just Gmail and Outlook; look to services such as <a href=\"https:\/\/protonmail.com\/\" rel=\"noopener nofollow\" target=\"_blank\">ProtonMail<\/a> for secure and encrypted email.<\/p>\n<p style=\"font-weight: 400;\">Next, use a password manager to keep track of passwords or even (gasp!) write your passwords down in a small notepad. Writing down passwords isn\u2019t the main problem these days; it\u2019s the fact that many users regularly reuse the <em>same<\/em> passwords over and over on various websites. Thus, if one site is breached, attackers can try those stolen passwords elsewhere and often get in.<\/p>\n<p style=\"font-weight: 400;\">The next key security move is to back up everything. And then back it up again \u2014 preferably using offline backup media. That way, should ransomware hit your computer, attackers won\u2019t be able to encrypt your backups, too. Don\u2019t make one backup, make several.<\/p>\n<p style=\"font-weight: 400;\">Be sure to secure your home network by ensuring your router has the latest firmware and the password for it is secured. Security blogger Corey Parker has some <a href=\"https:\/\/firewallsdontstopdragons.com\/new-years-resolutions-2021\/\" rel=\"noopener nofollow\" target=\"_blank\">great suggestions on reviewing the DHCP listing<\/a>\u00a0to see who\u2019s been logging into your home network. If you don\u2019t recognize a device listed there, disable it. If you accidentally turn off a streaming device you use every day, you can reenable it. This time, however, document what each device is so you know exactly what is connecting to your network.<\/p>\n<p style=\"font-weight: 400;\">Do update everything in a timely manner, but don\u2019t rush. We follow this rule on the Askwoody.com site all the time; I always recommend holding back a bit before updating. It\u2019s a matter of timing. You want to install security updates, just not necessarily on the first day they\u2019re out.<\/p>\n<p style=\"font-weight: 400;\">Finally, always be on the lookout for two-factor authentication, especially for key sensitive sites. Don\u2019t just rely on a password for access, ensure that you add a text message sent to your phone as the bare minimum to protect your accounts.<\/p>\n<p style=\"font-weight: 400;\">The bottom line these days is that security goes beyond just antivirus on your computer. That said, it\u2019s important to choose antivirus software <a href=\"https:\/\/support.microsoft.com\/en-US\/windows-antivirus-software-providers#avtabs=win7\" rel=\"noopener nofollow\" target=\"_blank\">supported by the vendor<\/a> and approved for your platform. And find one that keeps you safe from cryptominers you don\u2019t want on your system. Bundling in a cryptominer with the very software you purchased to keep you safe isn\u2019t the way forward.<\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3646552\/windows-security-in-22-you-need-more-than-just-antivirus-software.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2021\/03\/maze-1-100880563-large.3x2.jpg?auto=webp&amp;quality=85,70\"\/><\/p>\n<p><strong>Credit to Author: Susan Bradley| Date: Mon, 10 Jan 2022 06:10:00 -0800<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p style=\"font-weight: 400;\">Do you need antivirus in 2022 \u2014 especially when some options now come with a cryptominer built in?<\/p>\n<p style=\"font-weight: 400;\">Several antivirus vendors \u2014 some options free, others, paid \u2014 have begun bundling their antivirus products with software that generates virtual currency. Of all of the requirements for antivirus, using excess cycles on your computer to generate crypto-coins is not on my list of must-haves.<\/p>\n<p style=\"font-weight: 400;\">Recently, <a href=\"https:\/\/krebsonsecurity.com\/2022\/01\/500m-avira-antivirus-users-introduced-to-cryptomining\/\" rel=\"noopener nofollow\" target=\"_blank\">Krebs on Security<\/a> noted that both Norton Antivirus and Avira have told users that versions of their respective software now include a cryptominer. While it\u2019s not enabled by default, it still gives me pause; antivirus is supposed to protect us from such potentially unwanted software, and these two vendors are now including it in their wares.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3646552\/windows-security-in-22-you-need-more-than-just-antivirus-software.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[10516,714,24580,10525,10761,24583],"class_list":["post-18043","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-microsoft","tag-security","tag-small-and-medium-business","tag-windows","tag-windows-10","tag-windows-11"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18043","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18043"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18043\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18043"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18043"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18043"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}