<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Matasano Chargen - Latest Comments in The AV Doth Protest Too much (Consumer Reports)</title><link>http://matasanochargen.disqus.com/</link><description></description><language>en</language><lastBuildDate>Fri, 25 Aug 2006 13:47:58 -0000</lastBuildDate><item><title>Re: The AV Doth Protest Too much (Consumer Reports)</title><link>http://www.matasano.com/log/433/the-av-doth-protest-too-much-consumer-reports/#comment-2320211</link><description>It's far worse than expected.  I've written more about this on my blog -- &lt;a href="http://sunbeltblog.blogspot.com/2006/08/consumer-reports-testing-scandal-its_25.html" rel="nofollow"&gt;http://sunbeltblog.blogspot.com/2006/08/consume...&lt;/a&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">alex eckelberry</dc:creator><pubDate>Fri, 25 Aug 2006 13:47:58 -0000</pubDate></item><item><title>Re: The AV Doth Protest Too much (Consumer Reports)</title><link>http://www.matasano.com/log/433/the-av-doth-protest-too-much-consumer-reports/#comment-2320210</link><description>Actually the point was passed a few years ago.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Chris_B</dc:creator><pubDate>Wed, 23 Aug 2006 21:36:44 -0000</pubDate></item><item><title>Re: The AV Doth Protest Too much (Consumer Reports)</title><link>http://www.matasano.com/log/433/the-av-doth-protest-too-much-consumer-reports/#comment-2320209</link><description>How does the industry respond to articles like this?&lt;br&gt;&lt;br&gt;Eighty percent of new malware defeats antivirus &lt;a href="http://www.zdnet.com.au/news/security/soa/Eighty_percent_of_new_malware_defeats_antivirus/0%2C2000061744%2C39263949%2C00.htm" rel="nofollow"&gt;http://www.zdnet.com.au/news/security/soa/Eight...&lt;/a&gt;&lt;br&gt;&lt;br&gt;This 80% number was confirmed in a posting on the &lt;a href="http://offensivecomputing.net" rel="nofollow"&gt;offensivecomputing.net&lt;/a&gt; blog which has a database of 33,000+ pieces of malware.&lt;br&gt;&lt;br&gt;Here is an anonymized quote from a friend who works at a very well known security product company, &lt;br&gt;&lt;br&gt;"At XXXXX we have a few honeypot boxes that we use to capture malware  that is actually in the wild (none of this we found it in our lab). We then run it through an engine that uses 27 different AV  products to try and identify the malware.  The results obviously vary  but out of the 27 it is common to only have 2 or 3 products actually  identify the code."&lt;br&gt;&lt;br&gt;It seems clear that catching old malware is easy and catching new malware is hard, even new malware that is a slight variation on old.&lt;br&gt;&lt;br&gt;So the efficacy of current AV must be proportional to the churn rate of malware.  The faster virus writers are able to make modifications, the more likely they are to be successful.&lt;br&gt;&lt;br&gt;The number of "hockey stick" graphs in this trend report tells the tale:&lt;br&gt;&lt;a href="http://www.viruslist.com/en/analysis?pubid=182974451" rel="nofollow"&gt;http://www.viruslist.com/en/analysis?pubid=1829...&lt;/a&gt;&lt;br&gt;&lt;br&gt;Is there a point where the current AV technology just cannot keep up with the churn rate?  Have we reached it?&lt;br&gt;&lt;br&gt;-Chris</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Chris W.</dc:creator><pubDate>Tue, 22 Aug 2006 09:22:26 -0000</pubDate></item><item><title>Re: The AV Doth Protest Too much (Consumer Reports)</title><link>http://www.matasano.com/log/433/the-av-doth-protest-too-much-consumer-reports/#comment-2320208</link><description>I agree with Chris_B that AVERT is a strong team, and I'm sure someone in the PR group at least got to edit this response before it came out.  It's not like security companies are ever in the middle of public relations problems right?  &lt;br&gt;&lt;br&gt;However, I don't think that it is relevant if AVERT or the business people came up with this response.  MFE along with the other AV companies have built a good business and they want to protect it.  As if it wasn't enough that their margins and market share are being squeezed by Microsoft, but now their product is being called into question by a group a people that review blenders and washing machines.  The AV business is full of some very smart and very proud people, and they we're just going to take this one laying down.&lt;br&gt;&lt;br&gt;Kudos to Consumer Reports for turning the standard security product review on its head and testing the core value of the product.  These types of reviews will lead to better products and more intelligent consumers.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dan Ingevaldson</dc:creator><pubDate>Tue, 22 Aug 2006 09:09:41 -0000</pubDate></item><item><title>Re: The AV Doth Protest Too much (Consumer Reports)</title><link>http://www.matasano.com/log/433/the-av-doth-protest-too-much-consumer-reports/#comment-2320207</link><description>Those of us who worked for companies McAfee devoured under the guise of NAI learned not to trust the business people there but the AVERT folks tended to be good at heart. Its too bad that they probably had to go through some of the corporate vipers in their "official" communications.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Chris_B</dc:creator><pubDate>Tue, 22 Aug 2006 02:56:05 -0000</pubDate></item><item><title>Re: The AV Doth Protest Too much (Consumer Reports)</title><link>http://www.matasano.com/log/433/the-av-doth-protest-too-much-consumer-reports/#comment-2320206</link><description>Just to be overly picky and pain in the ass, a better stock analyst rating would be&lt;br&gt;Sell&lt;br&gt;Hold&lt;br&gt;Buy&lt;br&gt;&lt;br&gt;And what the hell is up with the &lt;br&gt;Underweight&lt;br&gt;Hold&lt;br&gt;Overweight&lt;br&gt;???&lt;br&gt;&lt;br&gt;Anyway, we all know that we don't have to worry about viruses now that we are on OS X. ;)&lt;br&gt;&lt;br&gt;Lucas.-</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lucas Nelson</dc:creator><pubDate>Mon, 21 Aug 2006 23:35:14 -0000</pubDate></item></channel></rss>