Showing posts with label Symantec. Show all posts
Showing posts with label Symantec. Show all posts

Tuesday, September 27, 2016

Norton Internet Security - Final Words?


Again I ran into a customer who almost insisted on keeping "his" Norton Internet Security package against my recommendation. I decided to write yet another diatribe against NIS and the reasons behind my stance.

This morning I got the current edition of a computer related newsletter that covers this very issue more concisely and better than I ever could. The text about NIS is buried in the article under the sub-heading "Why doesn’t Fred ever mention Norton/Symantec?". I want to save you the trouble of having to read (or skim) through the quite technical and lengthy discussion of file name length limitations that is the first part of the article; later in my article (what you are reading) I will quote the complete part about NIS as Fred Langa wrote it.

Who is Fred Langa? Here is the "About Fred Langa" copied directly from Windows Secrets:
Fred Langa is senior editor. His LangaList Newsletter merged with Windows Secrets on Nov. 16, 2006. Prior to that, Fred was editor of Byte Magazine (1987 to 1991) and editorial director of CMP Media (1991 to 1996), overseeing Windows Magazine and others.
In short and simple words: Fred Langa is a veteran in the field of PCs and IMHO one of the most trustworthy authors about PCs out there!

Now to above mentioned quote about Norton Internet Security products. The only alteration: I shortened the name of the original questioner for obvious privacy reasons to just the initials.

Why doesn’t Fred ever mention Norton/Symantec?

P F wonders about a long-standing omission in this column.


“Is there a reason we never hear about Symantec/Norton Internet Security from Fred Langa?”


Yes, there’s a reason, Paul. The omission is quite deliberate.


I absolutely loved Norton software way back when Peter Norton was running the company. But after Symantec bought him out in the 1990’s (keeping the “Norton” name, but little else) Symantec/Norton products gained a reputation as bloated and slow; and periodically they contained extremely serious flaws.

Symantec has addressed some of the bloat problems in recent years, but shockingly severe problems still crop up.
For example, as recently as this past summer, researchers found truly frightening, flagrant flaws in all Symantec/Norton antivirus software. Some security researchers said those flaws were “as bad as it gets.”
I agree with that assessment: Due to these flaws, even an unopened email or an unclicked link could compromise your PC at its deepest level!
For more specifics, see the U.S. Government warning, “Symantec and Norton security products contain critical vulnerabilities,” the Fortune Magazine article, “Google found disastrous Symantec and Norton vulnerabilities,” and the Ghacks.net article, “Google shames Symantec for security issues.” A web search will turn up lots of other coverage, too.
Those egregious vulnerabilities were patched, but they never should have happened in the first place — especially in a nominal “security” product.
And note: That’s just one recent problem. There have been numerous other problems extending back for years. For example, I just did a general web search on ‘norton security’ problems, and found over 13 million hits!
The above are objective facts you can check for yourself. But what follows is my personal opinion:
I think running Symantec products is worse than running no security software at all. With no security software, at least you know you’re not protected. But millions of Symantec/Norton customers think the software is keeping them safe, when there’s strong evidence that it might actually be creating new vulnerabilities and system problems that wouldn’t otherwise exist. To me, that’s unconscionable in security software.
I haven’t had any Symantec products on my PCs since the early 1990s, and I don’t see that changing any time soon. I’ve seen too many problems with Symantec/Norton’s software.
Your experience might be different, and you’re certainly free to use what you like.
But now you know why you don’t see any coverage of Symantec products from me.
Personally I fully and wholeheartedly agree with Fred Langa!

As usual I welcome comments and suggestions right here in the blog. Thank you in advance.

Stay safe.

Monday, July 4, 2016

Norton "Security" Software - REALLY INSECURE


It is a shame that "the media" ignore these facts and thus allow millions of computer users to live with unsafe computers.

A few quotes from The Register's recent article
  • Scores (or thousands, or millions) of enterprise and home Symantec users are open to remote compromise through multiple now-patched (where possible) wormable remote code execution holes described by Google as 'as bad as it gets'.
  • They [the security flaws] don’t require any user interaction, they affect the default configuration...
  • Victims would not even need to open the malicious files to be compromised.
  • Some of those [affected] platforms cannot be upgraded. 
Towards the end of the article The Register seems to quote six actions users should take to secure their systems. Four of those six are impossible to even think of for normal home users; they require corporate installations and corporate management structures that just are non-existent in home installations.

The other two require a level of know-how and technical expertise that is equally non-existent in the average home user environment.

The only consequent reaction for home user is what I preach to my customers for years:
Ditch any and all Norton products.
If you have allowed that Norton automatically charges your credit card you have to revoke that permission. You can get their phone number(s) through this web page.

Normally uninstalling them from Programs and Features in the Control Panel is not enough. I recommend to additionally run the Norton Removal Tool downloaded from this page; click on either of the links "Download@MajorGeeks".

Stay safe.

Monday, March 21, 2016

Norton Software IS RISKY!


For years I recommend to my customers and on my radio shows to stay away from so called "security products" from the big names like Norton, McAfee, Trend Micro and many others.

The makers of the Norton branded software is a company called Symantec.

Here is revealing and interesting article about Symantec and some of the major security problems in some of their software.

If you want to entrust the security of your computer to Norton software be my guest. I don't mind at all to clean up the mess.

Stay safe!

Wednesday, January 27, 2016

2016-01-28 WBKV Talking Points


Through 20 years of effort, we have successfully trained every computer user
to use passwords that are hard for humans to remember,
but easy for computers to guess.
10 most used passwords in 2015 (truly a list of shame!):
123456
password
12345678
qwerty
12345
123456789
football
1234
1234567
baseball
Please, in the interest of privacy and safety, use a password manager and let it create long passwords.
Wifatch virus actively protects its victims from other forms of malware;
It infects routers, not computers;
It is written in the Perl programming language
It targets so far only ARM (83%), MIPS (10%), and SH4 (7%) processors
It connects infected devices to a peer-to-peer network
Basically it only infects devices that are not protected at all in the first place!
A Symantec (Norton) partner company in India uncovered as major player in the all too common technical support scam
Security Suites from AVG and Avast install dangerous browser add-ons!
McAfee and Norton tell Windows 10 users that they better use Internet Explorer, a browser so bad that Microsoft gave up on it!
For years I advise against ALL of the well known “security suites”, free or paid versions, no difference.




"Free" Security programs - For A Price

I stumbled over this article on How-To-Geek.

I wan to save you the hassle and time to read this lengthy article your self and will quote a few selected and IMHO most relevant snippets.

My stance toward the remaining "free" security programs as well as the well known commercial offerings is known; I have expressed this here repeatedly. So let's begin:

  1. Free antivirus applications aren’t what they used to be. Free antivirus companies are now bundling adware, spyware, toolbars, and other junk to make a quick buck.... At one point, free antivirus was just advertising, pushing users to upgrade to the paid products. Now, free antivirus companies are making money through advertising, tracking, and junkware installations.
     
  2. Comodo ... change[s] your web browser’s search engine to Yahoo! and bundles the GeekBuddy paid tech support software. It also bundles other Comodo products you might not want, including changing your DNS server settings to Comodo’s servers and installing “Chromodo,” a Chromium-based browser made by Comodo. ... As the Comodo-affiliated PrivDog software contained a massive security hole similar to the one Superfish had, there’s a good chance you don’t want a bunch of other Comodo-developed software and services thrown onto your computer.
     
  3. Lavasoft’s Ad-Aware pushes “Web Protection” that will “secure your online search” by setting SecureSearch as your web browser’s homepage and default search engine. Despite the name, this isn’t actually a security feature. Instead, it just switches your web browser to use a branded search engine that actually uses Yahoo! in the background — this means it’s powered by Bing.
    If you prefer Bing, that’s fine — just use the full Bing website. You’ll have a better experience than using Lavasoft’s rebranded, stripped-down search engine.
     
  4. Avira encourages you to install “Avira SafeSearch Plus.” This is just a rebranded version of the Ask Toolbar, redirecting your search results through a rebranded version of Ask.com’s search engine. If you wouldn’t want the Ask Toolbar installed, you wouldn’t want this rebranded version of it installed either.
     
  5. ZoneAlarm also wants you to enable “ZoneAlarm Search” as your browser’s default homepage and search engine, along with installing a ZoneAlarm toolbar that is - once again - a rebranded version of the Ask Toolbar.
     
  6.  Panda {Free Antivirus] attempts to install their own browser security toolbar as well as change your browser’s search engine to Yahoo, and its home page to “MyStart,” which is powered by Yahoo. To Panda’s credit, they at least don’t attempt to trick you by offering you a renamed Yahoo search engine or home page.
     
  7. avast!’s installer also tries to install additional software you might not want. We’ve seen Dropbox offered here in the past, but avast! attempted to install the Google Toolbar when we tried installing it.
    Programs like the Google Toolbar and Dropbox are high-quality software you might actually want, so avast! comes out looking very good compared to the other options here. But even avast! has done done some questionable things in the past — witness the avast! browser extension inserting itself into your online shopping.
     
  8. AVG has its own suite of obnoxious utilities, including the AVG Security Toolbar, AVG Rewards, AVG Web TuneUp, and SecureSearch.
     
  9. BitDefender offers a stripped-down free antivirus. ... BitDefender is still pursuing the strategy of attempting to upsell you to the paid product.
     
  10. MalwareBytes doesn’t attempt to install any extra junk on your computer, although the free version doesn’t offer real-time protection. To their credit, MalwareBytes is offering a free tool that’s useful for manual scans - it even picks up and detects [and removes!] much of the adware other programs install - and encouraging you to pay for a more full-featured product.
    This tool could be quite useful in combination with another antivirus, like Microsoft’s free Windows Defender or Microsoft Security Essentials solution. But it’s not a standalone free antivirus you can depend on, as it lacks the real-time scanning.
 Not too nice a situation out there, right? You either pay up or you have to live mostly with junk you did not want in the first place.


Don't despair, a good, time proven free solution is available since about 2009.

For now over 13 years I "fix" my customer's home computers by removing all sorts of viruses and other malicious or obnoxious software. Most of my customers call themselves "computer illiterate". All of them have lived safely with mostly little or no manual effort.

The only malware infections happen now when someone "falls" for a social engineering trick; that is in effect when the customer for a moment was inattentive. And hat is just a human weakness, I know from my very own experience.

If you want to know details about this solution plese drop me a personal email; thank you.


Tuesday, April 28, 2015

Bye bye Viruses, Hello Carelessness




It's almost like in the Everly Brothers song "Bye Bye Love" from 1957. They sang
Bye bye happiness, hello loneliness...
I am enticed to, no, don't be afraid, not sing but say
Bye bye viruses, hello carelessness...
In August 2014 I wrote in this blog the 2014 Update On Malicious Programs. Everything in this article is still valid today – which in the fast changing world of computers is astonishing all by itself. Self replicating viruses that "find and infect" our computers by their own accord have gone almost extinct.
What has massively changed though are the tricks and methods used by miscreants to foist their malicious junk software on our computers. It is so bad that I feel compelled to say
Do NOT click on any link in any email,
do NOT open any email attachment
and NEVER click in any advertisement.
Does that sound extreme to you? Good, because it is extreme. We are in an extreme situation and it's getting worse so extreme measures seem appropriate.
In the meantime you have learned to immediately delete emails with an unfamiliar sender address. But what about the email from that buddy of yours who always sends all the jokes? My advice is to IGNORE it! Just hit the Delete button. If that email really was from him and if he were a nice guy he would have told you in the email why and what he sends there. If he does not have the decency to do that you better err on the side of caution and delete that email; you may “miss” a joke but what is that compared to $100 or $200 cost for a good clean-up job?
Another way how modern malware (called PuPs) is distributed are dirty tricks pulled on us when we apply required updates. Even big, well known companies participate in these schemes; names that come to mind as examples are Oracle, Norton, McAfee and Adobe. Some visual examples are here.
And don't get me going on advertisements. Listen up:
If you see advertisements on your computer screen then you computer most likely already is compromised. Get it cleaned up!
And then the sneaky methods that well known download web sites like Download.com, Cnet.com and other use. You want to download that nice free little program and what they give you is a specially crafted downloader program that in turn is supposed to download the program you actually want. But what you get are one or several PuPs and then the program you really wanted.
The only method to help here is to watch for the tricks, traps and deceptions. 
In July 2013 I published my 10 Commandments Of Safe Computing. To heed the first of these has become more important than ever before; it reads:
Thou shalt read and think(!) before you click.
Be vigilant, pay attention to details and always remember: If it sounds too good to be true it usually is not true; especially in this day and age on the Internet.

As usual I welcome suggestions and comments right here in the blog.

Click here for a categorized Table Of Contents.



Friday, January 27, 2012

Reality Catches Up With Symantec


It has happened! I will not lie to you, some part of me is chuckling gleefully. Symantec, the maker of the (in-)famous Norton products recommends to their customers:
“Symantec recommends disabling the product until Symantec releases a final set of software updates that resolve currently known vulnerability risks,” 
This is original text from an online statement released by Symantec about their computers having been hacked back in 2006! Emphasis added by me.

A few things are of interest to me:
  1. They must have known about this for 6 (SIX!) years and kept it a secret.
     
  2. They write "currently known ... risks".
    They knew about the risks all along but did not care to fix them!
     
  3. They ask customers that have paid dearly for the purchase and are paying dearly for updating the software to stop using it altogether with no offer of any compensation at all.
    Pretty arrogant and overbearing if you ask me.
The short of it: I feel very relieved to now have it from the horse's mouth:
Stay far way from everything with a "Norton" label.
And applying my experiences with any other of the big name security suites (read about three examples) I now feel emboldened to say "Stay away from any of them". 

And if you want some more detail go to this FoxNews.com article.


As usual I welcome comments and suggestions right here in the blog. Thank you in advance.

Click here for a categorized Table Of Contents.


Thursday, August 5, 2010

Remarks on Security Suites

 

In the paid version of the Windows Secrets blog I read an article; among others it talks about an anti virus suite causing horribly long boot times. Due to the rules and organization of this blog I can not link directly to this part of the article. So I quote the relevant pieces here.

To set the stage: Generally I recommend to remove all those big, cumbersome and expensive security suites like McAfee, Norton, Trend Micro and so on. When I try to get the customer’s permission for this the most common question I encounter all too often is “Why?”. Here are some of the many more relevant answers, as I said above quoted from an article in the paid version of the Windows Secrets blog.

Feature duplication: 

For example, Trend Micro lists 13 major features and subsystems in its security suite, McAfee lists 14, and Symantec lists 33!

Many of these features duplicate abilities already built into Windows and the major browsers. For example, Internet Explorer and Firefox have built-in link-checkers, pop-up-blockers, parental controls, and more.

Windows itself (especially Win7) has a capable firewall built in.

Overhead:

So the large security suites are including features you probably already have, and all of these redundant features consume memory and CPU time.

Solution:

… my current favorite security tool, Microsoft's free Security Essentials (site), lists just two major functions: antivirus and anti-malware protection.

When used with Windows' built-in firewalls and a fully current browser (say, IE8 or Firefox 3.6.x), you end up with essentially the same capabilities provided by the huge commercial security suites.

Price:

What's even better, it's all free!

I hope this is enough to convince even those people that say “But I paid for it”.

As usual I welcome comments and suggestions right here in the blog. Thank you in advance.

Click here for a categorized Table Of Contents.

Sunday, June 8, 2008

On Norton (Symantec) support

Most of you might not need disk imaging programs but the experience with Symantec’s support described below IMHO has relevance for all users of ANY of the Norton labeled products.

Here is a snippet from a web page on Tech Support Alert. The context is a comparison between disk imaging programs Norton Ghost from Symantec Corp. and True Image from Acronis. The comparison was for older versions but that is not the point here. The author reported serious technical issues that, if left unresolved, would have rendered the software packages useless and outright dangerous. Here now the quote:

However this problem proved to be a blessing in disguise as it allowed me to test out the support provided by Symantec and Acronis.

Symantec support for Ghost was abysmal; an odyssey of condescending replies, canned responses and the apparent inability of the Indian support staff to understand the English language. Eventually, I wrote a personal letter to the Chairman & CEO of Symantec, John W. Thompson, asking for his help and assistance.

My plea worked and I was put in contact with an “Executive Support” group. They seemed much more anxious to help and started off well by sending me the latest version of Ghost 10.

I was optimistic that with the receipt of this new version the problems I had been experiencing with corrupted Ghost image backups would disappear. Sadly, that was not to be. Even with the latest V10 release I had more invalid backup’s, completely baffling the “Executive Support” group.

After a number of emails back and forth, they adamantly pronounce that not one but BOTH of my U320 SCSI hard drives were broken and needed to be immediately replaced! After expressing my incredulity with this diagnosis, they decided to try blaming the problem on my CPU processor. Anything it seemed other than their product. Their last email to me was pure pathos:

“Do not bother responding to this email as there is nothing else I can help you with and it will not be responded to.”

So much for Symantec "executive" level support. I was clearly on my own.

The experience with Acronis’ support was much better.

The above quote is very similar to my own experience with Symantec’s support from about 2002-2003. That was when I dropped Norton products completely.

Can you imagine what could ensue if an inexperienced, normal home computer user needs to call Symantec’s technical support?


Feel free to post any comments you might want to make.

Thank you.