6 ms·
I work at a large company that is not one of the famous silicon valley tech companies. One of the worst parts of working there is the heap of various enterpris
by throwaway286 8y ago
I work at a large company that is not one of the famous silicon valley tech companies. One of the worst parts of working there is the heap of various enterprise anti-virus software they install on our computers. It brings huge typing and disk access latencies. Even opening files in vim with FZF is slow. I can't explain why but this makes programming so much less pleasant. I really just want to work somewhere without anti-virus.
- silviogutierrez 8y agoI'm currently picking the OS stack for all machines at my company. All guidance, even people I respect, point towards antivirus protection. Yet I lean towards nixing that. I know it's hugely ineffective. In fact, it opens up holes of its own[1]. And yet... it's like scaffolding in NYC[2]. Absolutely useless[3]. But if you are all for removing it, and a brick falls and hurts someone, heads will roll. Quite a quandary I - and other C-levels - face. [1] https://www.computerworld.com/article/3089872/security/security-vulnerabilities-in-symantec-and-norton-as-bad-as-it-gets-warns-researcher.html https://www.computerworld.com/article/3089872/security/secur... [2] Another contrarian passion of mine. [3] Bricks do fall and hurt people. But no more than scaffolding itself falls with the same effect.
- coder543 8y agoMicrosoft Defender typically doesn't hurt performance or security much. The alternative is to run Mac or Linux stacks instead of a Windows stack, of course.
- godDLL 8y agoWhile running a Linux stack may still work, your Mac info is outdated by three years, at least. Macs have entered the zoo in 2015.
- coder543 8y agoFor practical purposes, that's not true. Macs do not allow running unsigned software by default, and no one runs antivirus on Mac, ever. So even if they were commonly being infected, which they aren't, the person above would have organizational indemnity if someone were infected because they're following industry best practices by not running antivirus on Mac. If you want, you can further restrict Macs to only App Store software, which is heavily sandboxed. Then you can go even further by not allowing the individual users to install software on their own, if you really want to be draconian about it. Unless someone is being individually targeted, running very outdated software, or is intentionally trying to get themselves infected, it will not happen. Even if all three conditions are true, it's still very unlikely. Anyone who says otherwise is just fear mongering. That same level of fear mongering could point to the dozens of pieces of malware that have been released for Linux. I say this as someone who uses a Linux laptop for work and a Windows desktop at home. I don't have a dog in this fight. I do, however, try to stay very informed about the state of software security.
- __mifflin 8y ago> and no one runs antivirus on the Mac, ever. Working at a large company (also not one of the famous silicon valley tech companies) and if you get a macbook, they are managed remotely and have BitDefender installed.
- coder543 8y agoI sometimes forget how much big companies enjoy spending money. I once worked for a large company where every developer was issued a full copy of Microsoft Office, even though most of them worked inside a fullscreen Linux VM all day. Outlook was the only piece of Office that my coworkers and I used, and I would have been happier using a tab open to a webmail provider inside the VM than having to use Outlook to connect to Exchange. That was far from the only unnecessary software they paid for. Why use Git when you can pay for Perforce!
- viraptor 8y ago> every developer was issued a full copy of Microsoft Office Enterprise volume licenses. It probably cost them less than the time/money they'd lose if you spenta few minutes trying to figure out how to open some file sent by non-devs.
- setquk 8y agoI believe you mean “finished” not “out of date”.
- godDLL 8y agoActually I chose my words carefully. Even though malware guys have started targeting Macs about three years back actual infestations are uncommon.
- coldtea 8y ago>Macs have entered the zoo in 2015. What "zoo"? To this day, Macs are practically virus-less, which they always where (99.999% of the scares in the media were for trojans, and even those at worse affected something like 1-5% of the total user base) -- nothing like the good ole Windows (XP and pre) days where after 1 day surfing the web you'd have a few viruses. And of course if you go with the default options (gatekeeper, signed packages, etc) you have even less to worry about. It's also not about "market share" -- Macs had 1/4 the market share they have now in 1990-1997, but there were tons of viruses for them under the old OS. It's not like the original (pre-many security features were introduced) OS X was specially hardened or anything, but it was much more secure than Mac OS and the old Windows versions just by having a basic UNIX-style design.
- godDLL 8y ago> To this day, Macs are practically virus-less Exactly what I'm talking about. Not to this day, but to some time back in 2015. Right now any trojan toolchain on the black market comes with a Mac-targeted package.
- coldtea 8y agoTrojans always existed. But trojans aren't viruses, and if you don't get your stuff from shady websites you don't have much to worry about (and if you just get signed and sandboxed App Store stuff, even less or nothing to worry about).
- jaxn 8y agoMicrosoft Defender destroys WSL performance unless you create exclusions.
- setquk 8y agoThen there’s NTFS behind that. Just use a VM. Ten times faster.
- ggreer 8y agoI would recommend against antivirus. If you force developers to use an annoying configuration of a specific OS, you make it much harder to hire top talent. Why would someone work at your company when they could go to Google and use their favorite Linux tools running on their favorite model ThinkPad? It totally makes sense to lock down machines that can access production, but for development? Just let people use what they like. You'll have less work for IT, happier developers, and an easier time recruiting talent.
- ryanwaggoner 8y agoEh, I’d like to see some data on NYC scaffolds. They do collapse and hurt people, but the sheer volume of pedestrians and construction work makes me skeptical that it’s just as bad to have them as not have them. Not to mention the fact that it gives construction workers a way to not block the sidewalk with equipment and personnel.
- opportune 8y agoKeep in mind the reason guidance exists for products that aren’t really all that necessary is largely due to the massive sales teams behind those products, plus (as you mention) cover-your-ass concerns
- otoburb 8y ago>>And yet... it's like scaffolding in NYC[2]. Absolutely useless[3]. But if you are all for removing it, and a brick falls and hurts someone, heads will roll. This is a question of shifting liability and sharing responsibility. If a brick falls when you knew the facade needed maintenance, then the liability falls solely on the building. If the scaffolding falls, then the liability is borne by the scaffolding company, or at least shared. If people you respect are pointing towards antivirus protection, you might also want to inquire whether they are saying this purely out of technical reasons (i.e. surface attack area, which could be debated), or if there are financial risk management factors tipping in this direction. Since you're picking the OS for everybody in your company, which presumably includes multiple departments and staff who are non-technical, it seems like madness that you'd let them run amok without some level of antivirus. But -- leave the poor developers alone. One hopes that the company was capable of hiring technical staff practicing basic day-to-day security hygene.
- eikenberry 8y ago> I really just want to work somewhere without anti-virus. Not trying to be hostile.. but why aren't you? I've never worked anywhere that required anti-virus, so I know there are jobs out there that don't require it. In recent years I've gone so far as to take the stance that I won't use company computers at all, only my own, and I still haven't had any problems finding work. Unless you have strict restrictions on switching jobs (eg. H1B, can't move for reasons, bad network connections so no remote work, etc.) nothing should keep you from finding better working conditions.
- pjmlp 8y agoI worked in such companies, where you need to sign that you assume all legal consequences of a virus being introduced into the company network via your computer.
- eikenberry 8y agoI've never had to sign such an agreement. I'm US based, maybe this is something done elsewhere?
- pjmlp 8y agoGermany based customers.
- adamhepner 8y agoOh yes, those companies where progress takes place regardless of, not thanks to IT support...
- coldtea 8y agoYou don't sign, and leave right when they ask you to, laughing at them?
- pjmlp 8y agoMy computer was proper, those were customer sites. No, most people would rather install an IT certified anti-virus on their systems and keep the customer, than lose the business opportunity.
- godDLL 8y agoI went into construction, and then industrial alpinism with tree-trimming inclination starting 2016. But before I did that, the one-before-the-last place I've tried to work was this hostile environment where everything was Windows and MS-based, as far as what we were meant to use for work. I couldn't bring my own lappy. I ended up writing an AutoHotkey script that would get mouse scrolling about 80% sane and manage my clipboard. I set up a VM on our HPC cluster, on which I'd do my actual work by way of VNC and sometimes SSH. The LAN was OK, so it ended up being less laggy than Windows on my local machine. But I suppose a local Q frontend to a VM hosted on my work lappy would have worked too. Virtualize the AV away, yeah. Cheers.
- richjdsmith 8y agoWhat is industrial alpinism?
- heronymus 8y agoI think it means workers who, for example, climb on industrial chimneys for maintenance.
- de_watcher 8y agoBasically anywhere where you're paid for your alpinist skills. Mounting/dismounting things up there. There was an example like cleaning up the walls of an old fortress from grass.
- godDLL 8y agoI go up a rope or down a rope. Up a tree or a building, down a building/wall or a well. Do some tree trimming, sometimes construction tasks. Mounting stuff disassembling stuff, sending it down, or up another rope. Fun stuff. Do an internet search for TreeUp.
- taneq 8y ago> I ended up writing an AutoHotkey script that would get mouse scrolling about 80% sane and manage my clipboard. I used to run AlwaysMouseWheel to fix up focus scrolling, but forgot to set it up after my last reinstall. Thanks for the reminder! :) http://www.softwareok.com/?Download=AlwaysMouseWheel http://www.softwareok.com/?Download=AlwaysMouseWheel As for the other stuff, ugh. I've made it a general rule not to work anywhere where I don't get root on my own box.
- black-tea 8y agoPlace I worked at the laptops often had one core pegged at 100% load by some disk monitor that was competing with the AV software. I left very quickly and you should too.
- winrid 8y agoWhy not compaign for the change to different AV software?
- dagw 8y agoWhy not compaign for the change to different AV software? Depending slightly on the company, that is often a complete and utter waste of time.
- black-tea 8y agoThat kind of change would either never happen or take years to happen. I haven't got time for that.
- winrid 8y agoYears? I guess we have worked at different types of companies.
- sudeepj 8y agoDo you have enough resources (and permissions) to run VirtualBox? That way you can run a VM and get complete control. You can do things inside the VM and anti-virus will not be in the picture. I do this in my case but for different reasons and not performance.
- nizmow 8y agoI've tried to do this, but I think the anti-virus software breaks performance by doing strange stuff to the disk images whenever they're being written.
- philpem 8y agoYou too, huh? Last employer moved to McAfee "because active malware protection". Basically, AMP is a set of rules you can apply to disk accesses per application -- like for instance, "no application can delete PDF files from My Documents" (this is one of the "anti ransomware" rules). It wasn't too bad with just the signature-based virus scan, but the updater and AMP were horrendous. The PCs (3.6GHz 8-core Xeon workstation with SSD, 16GB+ RAM and a ludicrously powerful 3D card) went from booting in 30 seconds to taking 15 minutes to boot. Eclipse took another five to start. When AMP was deployed to the JIRA server, JIRA refused to start (Atlassian Support suggested AV exceptions which IT refused). IT response: close out any AV related ticket with "You will not be receiving a hardware upgrade and the AV is mandatory." Six weeks later, IT was outsourced and the response became "we don't have permission to change AV settings" (BigCo politics). Four more weeks later and the electronics lab was crippled as Labview got detected as malware by AMP. A fortnight after, half the technical team handed their notice in. It wasn't the only reason this FTSE100 was constantly outrun by its competitors, but it was certainly a contributing factor.
- roboyoshi 8y agoAt this point I'm kinda glad they went all the way, because now they don't exist anymore. I just hope the idiots don't ruin another company like that.
- mirekrusin 8y agoYou can't have viruses in company that doesn't exist I guess.
- 52-6F-62 8y agoSimilar environment here. I was thankfully able to strip McAfee out because it was monstrously terrible. Still, corporate IT has enforced a browser plugin and tray app called Triton AP-Endpoint and Triton Forcepoint Endpoint. It's sole purpose is to block you from moving any sensitive data to external drives. I, up until now, have had 0 problem removing any materials to any drives anywhere. I don't think it works very well. It does however chew through my 2015 MB pro battery and cause the fan to nearly continually run and even at times overheat. I think I could remove it, too—but am mildly concerned they'll get a notification and come start inspecting things.
- teekert 8y agoPff, my entire hard drive is scanned every friday. Friday is slow day on my work laptop (Win10 with McAfee)... At home I run KDE Neon, when people see me use that laptop (1 y/o Asus, core i5, 8 gb ram, standard ssd) they always comment how snappy and fast everything is and ask me what laptop I use. Even my neighbor with his brand new Win10 desktop with NVMe drive and new i7 cpu.
- ReptileMan 8y agoInstall vmware and work in vm. The av should only check one file at opening. With ssd overhead will be minimal.
- wincy 8y agoOn the other hand, I just started at a Fortune 500 and the IT configuration has been non intrusive even as a developer. The only time I had issues (I got locked out and had to ping a support guy) was when I was using WSL trying to authenticate through the proxy and probably hammering it with weird requests which was flagged as suspicious behavior. Fair enough. But working somewhere that has their act together is a dream, and I’ve been able to be productive immediately because of good decisions in IT.
- Paul_S 8y agoSame here. It's faster to compile in a VM because the VM doesn't suffer from the antivirus bollocks. Insane.
- slim 8y agoVim uses an on disk file as a buffer. It's the .swp file. That's how you can open files larger than the available memory, and recover files when it crashes.