Hacker News new | ask | show | jobs
by fineman 3988 days ago
In the case the pre-screener is honest, having them pre-check the work only saves you downloading a few virus executables at the cost of some work.

If the case the pre-screener isn't honest, it's saved you nothing at all and cost you a lot because you're likely to be less cautious.

Do you remember the tagline (roughly) "Outgoing email scanned and verified by AVG"? That was 100% worthless and actually very counterproductive. Expecting someone to check leaks like that is just as bad.

Scan everything. You've got the same technology they do.

1 comments

You're correct but this is not an argument against screening on the distribution end. Not everybody will do this and if you can protect them from problems due to their own lack of screening then you should.

Just because you can avoid problems on one end if you do everything right doesn't mean you shouldn't also try to avoid problems on the other end.

This very specifically is an argument against scanning on the distribution end.

A false sense of security hurts more than deleting STONED.EXE (and likewise, all other malware caught by signature) helps.

Point to a modern virus scanner and also list what you've found in the archive. That gives a good baseline for people to check against without promising to have made anything safe to touch without scanning.