This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

A bad review on ARStechnica

Researcher advises against use of Sophos antivirus on critical systems | Ars Technica

Any thoughts?


This thread was automatically locked due to age.
  • All software has vulnerabilities; all of them need patching.  Note the last line of the article:

    "It's unclear if Ormandy has analyzed the security of other antivirus products so he can arrive at an assessment of how they compare to Sophos. He didn't respond to an e-mail seeking comment for this post."

    Symantec (amongst other software vendors) have had vulnerabilities discovered and fixed in the past, some quicker than others, etc.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

  • The scope of the vulnerabilities was a bit concerning, and I was surprised to see the AV client overrides/disables many of Windows own built-in mitigation techniques (ASLR, SmartScreen). 

    I guess the upside is Sophos now has a chance to patch the disclosed vulnerabilities (and from what I understand they have already patched most of them?).
  • If you check the above article, the 10.2 client that is now active for UTM endpoint clients does appear to have everything patched.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.