Just in:
Putting Scientific Research Agents Within Reach — SCNet.AI Accelerates AI4S Innovation Powered by AI & HPC // IMF warns Gulf flows need more time // Christopher Aleo Strengthens His Gulf Presence with a New Tourism Investment in Oman // From Millennium Xuan Paper to Contemporary Visual Storytelling: China’s Intangible Cultural Heritage Sets Off Again // Bank of China (Hong Kong) x Television Broadcasts Limited (“TVB”) “Wealth Management Expo 2026” was Successfully Held // Why a Growing Number of German-Speaking Founders Are Choosing Dubai // Golden Bridge Real Estate Unveils Special Summer Offers Across Mashriq Elite Developments on July 1, 2026 // OneGrowth 2026: Shared AI Token Era Ahead China Telecom Global Partner Conference Held // Collapse Of TMC In Bengal Has Given A Big Opportunity For A Left Turn-Around // Valve’s pricier Steam Machine tests PC ambitions // AI browsers face new credential leak warning // VinEnergo partners with SunAsia Energy to develop Solar-on-Water projects integrated with aquaculture in the Philippines // Biosphere Labs strengthens Abu Dhabi biotech hub // HKRITA Signs MoU with Jeanologia and Looptworks to Establish the Green Machine Circular Textile Ecosystem, Marking a Breakthrough in Scalable Textile Recycling // Avalanche forms payments alliance with VanEck // Varenne Capital opens Dubai base for regional push // Hong Kong celebrates surge of global enterprises driving investment and opportunities // Vinmec Launches Vietnam’s First Integrated High-Tech Robotic Surgery Network, Establishing the Country’s First Multi-Connected Robotic Surgery Ecosystem // Paddles up! Hong Kong marks 50 Years of international dragon boat thrills // Lower oil risks lift UAE wealth outlook //

​Ex top Mozilla dev to Windows users: Ditch all antivirus except Microsoft's Defender

1485637607 15553en1

15553en1.png

Former top Mozilla engineer Robert O’Callahan argues there’s little evidence non-Microsoft AV improves PC security, so stick with Windows Defender.


Image: Microsoft

Former distinguished engineer at Mozilla, Robert O’Callahan, has told users on Windows 8.1 and up to ditch any antivirus (AV) that isn’t Microsoft’s own Windows Defender.

O’Callahan, a Mozilla veteran who departed the non-profit last year, says there’s little evidence non-Microsoft AV improves PC security, while recent bugs discovered by Google’s Project Zero team show that many widely-used AV products create a greater surface for attackers to exploit.

ADVERTISEMENT

Cases in point are over 200 flaws in 11 Trend Micro products discovered by two researchers since mid-2016, as reported by Forbes last week. While Trend was quick to fix the bugs, it did raise the question why the company hadn’t found them during an audit.

“Don’t buy antivirus software, and uninstall it if you already have it (except, on Windows, for Microsoft’s),” O’Callahan writes.

O’Callahan isn’t the first to question the value of antivirus. Even Norton maker Symantec has admitted that antivirus was failing to protect users.

However, more researchers are prodding antivirus software, in part because its processes run with high privileges, but also because product features can undermine browser security features.

For example, Project Zero’s Tavis Ormandy recently outed Kaspersky for the way it implemented its scanning service for SSL/TLS connections, which resulted in browsers not flagging an error if a user connected to the wrong site.

In recent years Ormandy has found numerous critical bugs in products from just about every major vendor, including McAfee, Symantec, Sophos, and Comodo.

One reason such products can create risks, according to O’Callahan, is that antivirus vendors don’t follow standard security practices and sometimes break browser code designed to protect users from exploits, such as when Mozilla introduced Address Space Layout Randomization for Firefox on Windows.

“Many AV vendors broke it by injecting their own ASLR-disabled DLLs into our processes,” O’Callahan said.

“Several times AV software blocked Firefox updates, making it impossible for users to receive important security fixes. Major amounts of developer time are soaked up dealing with AV-induced breakage, time that could be spent making actual improvements in security.”

The ex-Mozilla engineer decided to warn users against AV after Chrome security engineer Justin Schuh blasted AV vendors for introducing numerous security issues to Chrome, breaking its security features, such as HSTS pinning, and “piling dodgy format parsing and other unsafe code into the kernel”.

The only circumstance that non-Microsoft AV might help is for PCs still running seven-year-old Windows 7, or unsupported Windows XP. In these cases, third-party AV “might make you slightly less doomed”, according to O’Callahan.

Read more on security

(via PCMag)



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


ADVERTISEMENT
Social Media Auto Publish Powered By : XYZScripts.com
Just in:
Baghdad raises stakes in OPEC quota clash // OTC & Partners Opens 2026 with Strong Cross-Border Mandates and Strategic Expansion // Europe and China Must Pivot from Tech Rivalry to “Constructive Engagement” in AI Era, Warn Leaders at CEIBS Forums // AI browsers face new credential leak warning // Hong Kong celebrates surge of global enterprises driving investment and opportunities // OneGrowth 2026: Shared AI Token Era Ahead China Telecom Global Partner Conference Held // Putting Scientific Research Agents Within Reach — SCNet.AI Accelerates AI4S Innovation Powered by AI & HPC // Lower oil risks lift UAE wealth outlook // Avalanche forms payments alliance with VanEck // Golden Bridge Real Estate Unveils Special Summer Offers Across Mashriq Elite Developments on July 1, 2026 // Rubio seeks Gulf backing for Iran accord // Vinmec Launches Vietnam’s First Integrated High-Tech Robotic Surgery Network, Establishing the Country’s First Multi-Connected Robotic Surgery Ecosystem // Global Residency by Investment: How Investors Are Choosing in 2026 // IMF warns Gulf flows need more time // Biosphere Labs strengthens Abu Dhabi biotech hub // Valve’s pricier Steam Machine tests PC ambitions // TAEF sukuk deepens Dubai debt market // Dubai Holding eyes European data centre foothold // Collapse Of TMC In Bengal Has Given A Big Opportunity For A Left Turn-Around // VinEnergo partners with SunAsia Energy to develop Solar-on-Water projects integrated with aquaculture in the Philippines //