Yellow Flag<p>I just replied to a blog comment, and I thought that I post my reply here as well:</p><p>I think that I have good reasons to be “against Avast,” having published seven articles on them so far. The security issues alone are bad enough. But Avast abused their position to collect and sell users’ browsing profiles. After they were caught they claimed the data to be anonymized, they claimed to only sell aggregated data – and they continue lying to this day, despite there being conclusive evidence to the contrary. While the company has been bought, it’s still the same people in charge. This sort of undermines any trust in them for anything related to security.</p><p>As the security of antivirus software goes, I’m not very fond of any as the articles in the “antivirus” category of my blog show. With Kaspersky it wasn’t only the security issues but also how they handled them, pushing out half-hearted fixes only for these to be circumvented shortly afterwards. McAfee and BullGuard had massive security issues stemming from being careless about security and not following best practices.</p><p>I’ve found a critical security issue in Bitdefender’s solution as well, but with them I at least had the impression that they were trying. Unfortunately, that’s currently the bar in the antivirus industry – at least trying to make their product secure.</p><p>Security-wise, one good thing about Windows Defender is that it only needs to do one job. It doesn’t need all the extra functionality as a selling argument. It doesn’t need to be a banking browser, it doesn’t need to be a phishing protection, it only needs to be an antivirus solution. It can keep a very small attack surface compared to all those antivirus suites, and so it does (yes, I checked).</p><p><a href="https://infosec.exchange/tags/antivirus" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>antivirus</span></a> <a href="https://infosec.exchange/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> <a href="https://infosec.exchange/tags/avast" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>avast</span></a> <a href="https://infosec.exchange/tags/McAfee" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>McAfee</span></a> <a href="https://infosec.exchange/tags/BullGuard" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BullGuard</span></a> <a href="https://infosec.exchange/tags/Bitdefender" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Bitdefender</span></a> <a href="https://infosec.exchange/tags/WindowsDefender" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WindowsDefender</span></a></p>