back to article BOFH: SOOO... You want to sell us some antivirus software?

"Yes, but with our antivirus software you can be guaranteed that we will track and locate 98.97 per cent of all known viruses," the caller says. "Tell me, where did you get the 98.97 per cent from?" "What do you mean?" "Well you say 98.97 per cent - not 99 and not something like 96, so you've obviously got a reason for it …

Page:

  1. J P
    Stop

    Stop it; this is wrong - Friday is BOFH day...

    1. Will Godfrey Silver badge
      Thumb Down

      Shhhhh.

      I'd rather have BOFH on Saturday than have no BOFH at all.

  2. Anonymous Coward
    Anonymous Coward

    He's spoken to Symantec and McAfee then?

    1. bleh_meh

      and Kaspersky, and Trend, and Avira, and Micro$oft, and everyone else!!

      1. Richard 12 Silver badge
        FAIL

        Bloody useless, the lot of 'em

        For example, Symantec blocks the installation of some of our software.

        We've reported it several times, we've sent them the installers, we've sent them logs from our customers, and they refuse to acknowledge that there just might possibly be an issue with their software.

        So we've simply had to advise those customers to drop Symantec. Which they have, because our software is genuinely useful while theirs is...

        Saved them a lot of money as well.

    2. CoolKoon

      Yep, my words exactly :D (been there, used that)

  3. Dr. Mouse

    BOFH on Saturday is WRONG! Please stop it!

    BOFH is a Friday lunchtime thing.

    1. Anonymous Coward
      Anonymous Coward

      Nooooo don't stop the BOFH! What are you saying man!!!

    2. Primus Secundus Tertius

      El Reg is desperate to liven up its weekend section. Maybe one day they will give up on a bad idea.

  4. Anonymous Coward
    Anonymous Coward

    He described Panda Enterprise edition perfectly... Still trying to get that crap off a server from 8 years ago... Its easier to do virus cleanup than anti-virus cleanup

    1. CoolKoon

      Nah, it's a piece of cake. You boot the system in safe mode, rename the AV folder, boot into normal mode and volia! Good as new ;)

    2. Hans 1
      Windows

      You do know regedit.exe, do you not ? There is a almost useless "Find" option in there, what it does does help in getting <whatever_the_kids_installed> off of the computer.

      I use two combinations:

      Find <folder_name>|<program_name>

      while (! EOF)

      {

      if (keyname.isHighlighted)

      { hit(DEL);}

      else if (Value.isHighted)

      { //some uid

      hit("<-"); //left arrow key

      hit("<-");

      hit(DEL);

      }

      hit("F3");

      }

      Delete folders on FS.

      Works for me - takes time, though :-(

      On Mac, I throw /Applications/<application_folder> into the bin, search for plists and throw them in the bin.

      On linunx, it is just "apt-get remove --purge <program_name>", but I digress.

  5. gryphon

    Deary Me

    Simon seems to be getting rather mellow in his old age.

    Certainly not as vitriolic as AV companies actually deserve

  6. Peter2 Silver badge

    So, fellow BOFH's a few questions if I may.

    1) Who thinks AV is even slightly effective? (When Symantec says AV only protects against an attack 45% of the time I think we can all agree theres a problem?)

    2) Who drops any email attachments that are vaguely executable at the firewall/before it reaches the lusers?

    2B) Have you figured out a way to open a zip/rar/oddarchivetype, and then drop the ones containing executable code?

    3) Who has SRP's set up to prevent the users from running a virus imported by CD/USB/SOMEHOW?

    4) How do you deal with PDF's? My personal bugbear, you can't just drop them because about 5% are actually legitimate, but the other 95% are exploiting the swiss chese security in Adobe. So far EMET5 appears marginally effective at mitigation when the users open them. I did try replacing Adobe reader with foxit reader, however foxit reader appears to be substantially less stable than adobe.

    1. Phil W

      The answer to 2,2b and 4 is use something like MailScanner on your edge mail transport, drop all exes and zips, the AV scan it does on the rest should take care of the rest including PDFs but you could drop them to if you want since MailScanner will notify the users when it's blocked their attachments, so they can ask you to release it if it's a false positive.

      The answer to 1 and 3 are the same. Who cares? Put the most acceptable AV of your choice on end user machines for some protection but have them keep all their work on a file server. If their PC gets infected nuke it, re-image and away you go.

      In a well managed and backed up environment viruses and malware are rarely more than a bit of a nuisance. The bigger security problem is educating and preventing your users for falling for phishing mails and the like.

      1. petur

        Yes, by all means just drop all ZIP files, also drop DOC(X), PDF,... because you never know it might be an unknown attack vector.

        You sound like the IT guys at a customer site I work right now.

        We're running around with USB sticks to move files around because that's the only thing that seems to work (*). Personal USB sticks, of course.

        Yes, what could possibly go wrong?

        (*) given that contractors are not allowed on the customer network, I have to do with a separate ADSL for my connectivity (which is a blessing because there's no firewall).

        1. Peter2 Silver badge

          If you trouble yourself to read my original post, you'll notice I drop files with executable files attached. As an office shouldn't have any legitimate programs delivered by email, this means the couple of thousand exe, bat, vbs, pif, scr files we receive daily are invariably viruses.

          1. Adrian 4

            "As an office shouldn't have any legitimate programs delivered by email"

            Eh ?

            Maybe an accountants office, or something equally pointless. But most offices contain at least a smattering of actual workers, who like most people need to communicate arbitrary files. We don't appreciate you taking out all the useful bits.

            You'd be one for swapping all forms of cutting tool for plastic scissors, wouldn't you ?

            1. Peter2 Silver badge

              The useful bits are files for word, excel and PDF's, with assorted images etc. I can't see any legitimate reason why an office worker would need to receive binaries via email as a part of their work. Care to share?

              Personally, I think 100% of incoming binaries are unsolicited malware of some description, and dropping them is a perfectly rational way of reducing the number that make it through to the end users.

              1. perlcat

                @Peter2

                I love your sweeping generalisation that all exe's are bad. I work as a sysadmin, and trolls like you are why I have to first zip exe's using weird compression, rename them to .tiff, open with a hex editor and insert 1029 bytes of tiff file information at the top, just so I can transfer a file, remove the 1029 bytes, rename to whatever zip format and uncompress them and do my job. Pray to whatever gods you believe in that I never discover what kind of car you drive, where you eat, or where you sleep. Revenge is a dish best served totally unbeknownst to the target.

              2. Anonymous Coward
                Anonymous Coward

                Personal experience-

                I've had a few appliances over the years (UPS/generator monitoring cards, environmental sensors on the raised floor, upstart company's wizbang gizmo) where for whatever reason the catastrophic error reporting was an email to us and the vendor with a zipped log/crash file.

                Our policy was to nuke any zip file in inbound or outbound email, and at least one vendor nuked them inbound so those logs never saw the light of day when the magic blue smoke escaped the appliance.

          2. CoolKoon

            Well guess what - in the corporate environment I work at the damned AV monstrosity is set to full paranoia mode - it filters out even Unix shell scripts. And no attachment releasing option either. If I want a file delivered by a HW vendor (it happens fairly often in fact), I'm out of luck. And chaotic as it is, I'm not even sure which team do I have to talk to to ask for some tweaking (well, theoretically I could try the helldesk, but no, thanks, I'd rather shoot myself in the foot). And don't even get me started on the enterprise AV policy they pushed out regarding "unwanted programs" (e.g. those idiots have included even stuff like bash.exe, which renders Cygwin unusable on the machines running the AV i.e. every corporate machine)......

            1. dan1980

              Here is the thing . . .

              Security is a matter of balancing protection with convenience and usability (and cost). Always has been, always will be.

              There is no one-size-fits-all solution here and different scenarios and businesses will warrant accepting some additional risk for the sake of productivity or vice-versa.

              It is my experience that if you make things too restrictive, users will get around the system in order to do what they want/need to do. If you set your password policy too strictly, requiring 20+ character passwords changed every month, most users will end up using weak, easily-remembered passwords, thus negating the benefits of a strong password policy in the first place.

              Just so with AV restrictions as users will send files via personal e-mail, bring in CDs and USB sticks, use services like Dropbox and generally side-step the problem. What this often leads to is company data being handled by and stored in non-company systems, which is not a great situation.

              Sure, you can try banning all (say) webmail URLs but then what happens when you instructed to allow Gmail so the CFO can view and synchronise an external calendar. And so it goes.

              The important part in all this is to make sure the users are well-informed and understand why things are the way they are. Teach them good practices and keep them educated about any current trends or dangers because no matter how good your precautions, the best defence is a well-educated user.

      2. Red Bren

        "have them keep all their work on a file server."

        That's been the policy at almost every company I've worked for. Along with the policy of giving staff terabytes of unusable storage on their local machines, while refusing to invest in disk space on the file servers. And the network hasn't got the capacity to cope with more than one person at a time moving data about.

        Has anyone invented network RAID yet? If every desktop in my office could contribute 1TB to a massively mirrored and striped array, I'd be delighted, even if the resulting shared drive was only 1TB. Although the network would still be a bottleneck.

        1. Hans 1

          Exactly, I do not get all this non-sense.

          I think you could do with Linux, remove the hard drives from the workstations as they arrive, setup boot from LAN, use Linux, see slax for an amazing example ... 180Mb of read-only joy, complete with office suite, browser etc. Customize your image[s] with apps you need. Build a massive RAID with the hard drives to house docs, home folders, your 4/5/6 images, and their respective backups ... remember, you do not need an image per hardware combination, more an image per target audience.

          The home folder would be a network share, ideally sshfs. You have an issue, reboot ... takes 1 minute, including download/loading of image, and the beast is clean again. If you have over 2Gb RAM in the clients, use copy-to-ram for exceptional performance ... only uses like 512Mb RAM.

          Alternative:

          FreeBSD or Solaris and a distributed ZFS file system, using all drives in all machines for storage of documents.

    2. Anonymous Dutch Coward

      @Peter2

      Re 4: you could have a look at SumatraPDF. Have you used it personnally for some years; quite happy about it.

    3. Decade
      Facepalm

      Stupid PDFs

      These days, I mostly use the PDF readers built into Firefox, Chrome, and Safari. Sometimes I use (Apple) Preview. This is on a Mac, obviously.

      What I'd like to do is banish them to an untrusted AppVM, as in Qubes OS, but I'm rather addicted to my computer having performance. Maybe next time I build a computer.

      1. Martin Budden Silver badge

        Re: Stupid PDFs

        PDF stands for Pointless Document Format.

      2. fridelain

        Re: Stupid PDFs

        Sandboxie on Windows works fine.On SELinux enabled distros there is the aptly named "sandbox". (sandbox -X for graphical apps, as by default it only allows for command line.)

        I gues there is something similar for OSX.

  7. Chris Miller
    Headmaster

    98.97%

    Obviously it has two significant figures, so it's pretty accurate

    It has four significant figures, two decimal places.

    Excellent description of AV software. though.

    1. KA1AXY

      Re: 98.97%

      Significant figures is related to precision, not accuracy. Accuracy is how well the number describes reality, which, in this case is not at all.

  8. Anonymous Coward
    Anonymous Coward

    Foxit

    I keep hearing people say it is unstable, but here is the thing, I have been using it since the dark ages and NEVER had a single issue; ADOBE on the other hand, - which I have installed because some government websites INSIST only Adobe can open their pdf attachments - buggers up every other time I try to use it.

    As for AV programs, yes, they slow everything down to a crawl; almost as bad as installing realplayer (which I foolishly did again last night).

    I have never seen a simple EULA screen effectively lock up my machine for several minutes before.

    1. Cliff

      Re: Foxit

      You installed RealPlayer last night? Is this posted through some strange time wormhole? I haven't installed RealPlayer since...must be pre-2006 as that's my oldest still-working box, and it's never had it.

      Do you mind me asking, genuinely, what for? Can VLC not play the .rm files you need?

      1. Peter2 Silver badge

        Re: Foxit

        How many computers do you have on your network, may I ask?

        I've been having pretty chronic problems with foxit reliability, which is a shame because I really liked the program as an alternative to Adobe.

      2. Anonymous Coward
        Anonymous Coward

        Re: Foxit

        I know, I was delusional, I blame the head cold and sinus irritation - the medication made it seem like a good idea.

        As for how many PCs, only a dozen, but they are all old, patched together systems made out of left-over parts and spare XP licences (+1 Win7 machine) that originally ran WinME and uses Rambus Ram); actually THREE of them originally came with WinME.

    2. Anonymous Coward
      Anonymous Coward

      Re: Foxit

      I have managed to use Foxity even with those god awful government PDF forms most of the time. I save the form - using an old version sometimes and then FOXIT that saved one. If the )(*&^%$£"! fools think I am going to print out their un-savable forms and write on them, well they have not seen the state of my writing; still I may get the hand operated on soon. I guess they do have someone who can read, though I am not sure that is always the case judging by the number of errors they manage to make processing the stuff I send them.

      Perhaps I should just write out the entries using my feet?

      1. Anonymous Coward
        Anonymous Coward

        Re: Foxit

        Perhaps I should just write out the entries using my feet?

        I've seen that done before today… maybe if you did that they'd get the message?

        1. Peter2 Silver badge

          Re: Foxit

          Just your home network then?

          I rolled it out to one of my branches at work. It lasted about 2 months before I got fed up with having to remote to peoples desktops to multiple hung processes sitting in the background not working.

    3. CoolKoon

      Re: Foxit

      RealPlayer?! Does that thing still exist even? Damn, I haven't seen (or heard) that term well......since forever. Why'd you do something like that?

  9. Anonymous Coward
    Anonymous Coward

    All of that SOOO true..

    .. but the most important sentence is the one that gets you downvoted every time you dare utter its harsh reality publicly:

    "INSTEAD of coming to me and telling me to do my job properly..."

    Yes, Microsoft, I'm looking at you. Since MSDOS, basically.

  10. Tannin

    This BOFH rant would be very funny, but it isn;t, 'coz it's very very true. Usually we laugh at the BOFH 'coz he exaggerates real life so cruelly and accurately, but this time it's pure and simple truth.

    On an off-topic note, Foxit used to be good. Used to be. Now it's just another slab of marketing-riddled bloatware with a screen-robbing Sinofsky-inspired UI from Bedlam. Despite having used and recommended it for quite a while, I stopped installing it a couple of years ago and switched to one of the three or four excellent little free no-BS alternatives. (My favourite is PDFExchange but there are several others which seem pretty nice too.)

    1. chris 17 Silver badge

      Just use chrome for reading pdf's

      If your just reading PDF's just use google chrome. Ok generally have 1 window with tabs of the PDFs I need to constantly refer too.

    2. Cliff

      PDFExchange is actually pretty good, I agree, but why to god do they have so many confusing and conflicting versions? I actually wanted to upgrade to a paid version for a job, but the site/version list was so confusing I gave up. Note to sales teams - don't drive potential customers away!

    3. sdalton

      PDF-wise - SumatraPDF for the Windows boxes, Zathura for *nix. Job done. Dunno about the OS X crowd, never had cause to use one for more than 5 minutes.

  11. Trygve Henriksen

    Truer words have never been spoken!

    Simon, if I ever bump into you anywhre, I'll buy you a beer!

    (And given the price of beer here in Norway, that means I appreciate this article A LOT!)

    1. Anonymous Dutch Coward

      Beer

      @Trygve Henriksen: agreed with the beer & you Norwegians (well your government) seem even more insane about levying taxes and duties on alcohol than us Dutch. My condolences.

  12. Herby

    Simple comment...

    SPAM and Virii exist because THEY WORK. Most of the attack vectors are in email (click here to win $$$) and these function because idiots will click them. Yes, to those who know better they are a scam, but for some percentage (probably the left over of 1.03%, 100% - 98.97%) they get through. With the small cost (if any) of email, this is acceptable to the scammers.

    Moral: Don't click on email attachments unless you are VERY SURE of the source, and are expecting the attachment. Gotta be careful!

    Of course it would be easier if operating system companies didn't do most of the work for the virus makers by "helping".

    1. Peter2 Silver badge

      Re: Simple comment...

      Your preaching to the choir posting that on here. :)

    2. Kevin 6

      Re: Simple comment...

      I remember about 9 years ago a place I worked IT in we had a nasty outlook e-mail virus going around. We spent almost a solid week removing it from the network (we had over 2k computers) right after we finished Our IT director sent out an e-mail to all users saying DO NOT OPEN ANY LINKS IN E-MAILS YOU ARE NOT EXPECTING OR KNOW THE SENDER to all the users.

      5 minutes later the idiot opens an e-mail attachment marked IMPORTANT OPEN IMMEDIATELY, and reinfected the entire network... We only know this as the admins installed tracking software, and were actively monitoring who was infecting the network, and it all pointed at the IT directors computer...

      1. Mad Chaz

        Re: Simple comment...

        What kind of haircut did he have? I wouldn't be surprised if it as pointy ...

Page:

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like