I have felt the current anti-virus approach is unsustainable and less secure than we think for some time.  But recent news events have really driven home the issues.  (I personally think anti-virus is dead…yep, dead)

Some points to ponder:

It’s less secure than we think because of the “zero-day” problem that nobody really likes to talk about – under a signature-based approach I can only detect what is in the signature file.  An antivirus vendor has to “capture” a virus to create a signature – and then distribute the updated signature to me before I am actually protected.   So we think because we run AV software we are protected – we aren’t.  (continue reading…)