It is not the first time that someone in the software world has come out to question the usefulness of the latest antivirus, and we are sure it will not be the last. Initiatives such as Google's Project Zero cast doubt on the quality of the code used in security solutions, and now ex-Mozilla engineer Robert O'Callahan joins the claim, suggesting we abandon all third-party antivirus on Windows 8.1 or higher, leaving only Windows Defender working in the background.

Former Mozilla Engineer Says Drop Your Antivirus—Except Windows Defender
Windows Defender

The changing threat landscape

Computers have changed a lot in recent years, and so have the Web, software in general, and of course digital security threats. Before, the average virus looked to infect a few executable files and hop from one PC to another on floppy disks. Today, they take half a hard drive hostage, demanding a Bitcoin payment in exchange for its release. The arms race is losing its balance, and the malicious developers out there are getting better and better. This landscape forces us to interrogate our classic security solutions, and what we see is not good. Last Wednesday, Forbes reported that a team of engineers found more than 200 vulnerabilities in eleven Trend Micro products over six months. The company was quick to fix them, but that is not the point: its software protects computers. Those bugs should not have been there in the first place.

Former Mozilla Engineer Says Drop Your Antivirus—Except Windows Defender
A very superficial search on Project Zero. All fixed, but...

The case against third-party antivirus

Which brings us to the recent statements from Robert O'Callahan, a former Mozilla engineer who on his personal page suggests abandoning right away all third-party antivirus on Windows 8.1 or higher, leaving Windows Defender to work on its own. His statements are supported by the significant number of bugs found by Google's Project Zero in programs from many companies. ESET, Symantec, Avast, Trend Micro, AVG, Comodo, Avira, Kaspersky... all have at least one entry, and they make us wonder where the audits are. According to O'Callahan, the bugs not only open new attack vectors, but their developers do not follow standard security practices. The exception here appears to be Microsoft, whom he considers "competent".

In essence, the problem is that certain antivirus can compromise browser security. Mozilla invested a great deal of time and effort to make ASLR work well in Firefox, but some products broke that by injecting unsupported DLLs into its processes. And on more than one occasion, antivirus blocked updates for Firefox, Chrome, and Windows itself. O'Callahan suggests keeping third-party antivirus only on systems running Windows 7 or XP (which he describes as "being a little less doomed"). For the rest, Windows Defender should be enough.

Official site: