Hacker News new | ask | show | jobs
by mikeash 3999 days ago
You're correct but this is not an argument against screening on the distribution end. Not everybody will do this and if you can protect them from problems due to their own lack of screening then you should.

Just because you can avoid problems on one end if you do everything right doesn't mean you shouldn't also try to avoid problems on the other end.

1 comments

This very specifically is an argument against scanning on the distribution end.

A false sense of security hurts more than deleting STONED.EXE (and likewise, all other malware caught by signature) helps.

Point to a modern virus scanner and also list what you've found in the archive. That gives a good baseline for people to check against without promising to have made anything safe to touch without scanning.