I have felt the current anti-virus approach is unsustainable and less secure than we think for some time. But recent news events have really driven home the issues. (I personally think anti-virus is dead…yep, dead)
Some points to ponder:
It’s less secure than we think because of the “zero-day” problem that nobody really likes to talk about – under a signature-based approach I can only detect what is in the signature file. An antivirus vendor has to “capture” a virus to create a signature – and then distribute the updated signature to me before I am actually protected. So we think because we run AV software we are protected – we aren’t. (continue reading…)