<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Antivirus Fight Club</title>
	<atom:link href="http://www.asktheadmin.com/2007/08/antivirus-fight-club.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.asktheadmin.com/2007/08/antivirus-fight-club.html</link>
	<description></description>
	<lastBuildDate>Fri, 03 Feb 2012 06:08:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>By: Joe admin</title>
		<link>http://www.asktheadmin.com/2007/08/antivirus-fight-club.html/comment-page-1#comment-3526</link>
		<dc:creator>Joe admin</dc:creator>
		<pubDate>Thu, 16 Aug 2007 02:05:00 +0000</pubDate>
		<guid isPermaLink="false">http://ata.inspiritnetworks.com/2007/08/antivirus-fight-club-2.html#comment-3526</guid>
		<description>thank you for the great story. i love reading your blog please keep up the amazing stories.</description>
		<content:encoded><![CDATA[<p>thank you for the great story. i love reading your blog please keep up the amazing stories.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.asktheadmin.com/2007/08/antivirus-fight-club.html/comment-page-1#comment-3523</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 15 Aug 2007 20:05:00 +0000</pubDate>
		<guid isPermaLink="false">http://ata.inspiritnetworks.com/2007/08/antivirus-fight-club-2.html#comment-3523</guid>
		<description>why can i talk about antivirus fight club</description>
		<content:encoded><![CDATA[<p>why can i talk about antivirus fight club</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Karl L. Gechlik</title>
		<link>http://www.asktheadmin.com/2007/08/antivirus-fight-club.html/comment-page-1#comment-3522</link>
		<dc:creator>Karl L. Gechlik</dc:creator>
		<pubDate>Wed, 15 Aug 2007 19:11:00 +0000</pubDate>
		<guid isPermaLink="false">http://ata.inspiritnetworks.com/2007/08/antivirus-fight-club-2.html#comment-3522</guid>
		<description>Sloth is right - it is not a measure of the product but how the normal user will install it.&lt;br/&gt;&lt;br/&gt;Dude buys software&lt;br/&gt;Dude installs software&lt;br/&gt;Dude forgets about software until it is time to renew&lt;br/&gt;&lt;br/&gt;Dude is your average end user.</description>
		<content:encoded><![CDATA[<p>Sloth is right &#8211; it is not a measure of the product but how the normal user will install it.</p>
<p>Dude buys software<br />Dude installs software<br />Dude forgets about software until it is time to renew</p>
<p>Dude is your average end user.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Slothman</title>
		<link>http://www.asktheadmin.com/2007/08/antivirus-fight-club.html/comment-page-1#comment-3521</link>
		<dc:creator>The Slothman</dc:creator>
		<pubDate>Wed, 15 Aug 2007 19:05:00 +0000</pubDate>
		<guid isPermaLink="false">http://ata.inspiritnetworks.com/2007/08/antivirus-fight-club-2.html#comment-3521</guid>
		<description>ninja &amp; anon:  If you&#039;re right, and some settings needed to be configured, then I would call that a fair test.&lt;br/&gt;&lt;br/&gt;Simply put, most average people will simply install a product and assume it is set right.  They are not uber-admins like us who tinker and dick around until we have things tight.&lt;br/&gt;&lt;br/&gt;And no test is truly unbiased.  It just isn&#039;t.  It&#039;s like statistics, you pretty much always end up with the result you were looking for by excluding things that you don&#039;t want to muck up the works.</description>
		<content:encoded><![CDATA[<p>ninja &#038; anon:  If you&#8217;re right, and some settings needed to be configured, then I would call that a fair test.</p>
<p>Simply put, most average people will simply install a product and assume it is set right.  They are not uber-admins like us who tinker and dick around until we have things tight.</p>
<p>And no test is truly unbiased.  It just isn&#8217;t.  It&#8217;s like statistics, you pretty much always end up with the result you were looking for by excluding things that you don&#8217;t want to muck up the works.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: NinJaAdmiN</title>
		<link>http://www.asktheadmin.com/2007/08/antivirus-fight-club.html/comment-page-1#comment-3520</link>
		<dc:creator>NinJaAdmiN</dc:creator>
		<pubDate>Wed, 15 Aug 2007 16:52:00 +0000</pubDate>
		<guid isPermaLink="false">http://ata.inspiritnetworks.com/2007/08/antivirus-fight-club-2.html#comment-3520</guid>
		<description>Yes that last comment is true:&lt;br/&gt;&lt;br/&gt;Whilst I’m sure the tests were well intentioned, they are not particularly scientific and as the author admits, Sophos results were significantly improved if the tester turned on the relevant options, suggesting the product documentation was not consulted.&lt;br/&gt;&lt;br/&gt;Having retrieved the samples (the author having posted the malware samples on a public website!!!) it appears a few extra settings were required, in particular, one of the samples was a email stored as MIME but the ‘decode MIME’ option wasn’t turned on. Another sample was in fact a potentially unwanted application and again, the option to enable detection for PUAs wasn’t used.&lt;br/&gt;&lt;br/&gt;While Sophos performed better than many of its competitors, the sample set was far too small, the methodology was confused and the author obviously isn’t well versed in handling malware. All of this goes to show that testing anti-virus products is a lot more complex than grabbing a few samples and scanning them.&lt;br/&gt;&lt;br/&gt;I would recommend anyone wishing to compare products to look for recognised testing organisations and publications such as West Coast Labs and Virus Bulletin.&lt;br/&gt;&lt;br/&gt;So take particular care in using this biased testing.&lt;br/&gt;&lt;br/&gt;Do you just setup your AV and not configure the options?</description>
		<content:encoded><![CDATA[<p>Yes that last comment is true:</p>
<p>Whilst I’m sure the tests were well intentioned, they are not particularly scientific and as the author admits, Sophos results were significantly improved if the tester turned on the relevant options, suggesting the product documentation was not consulted.</p>
<p>Having retrieved the samples (the author having posted the malware samples on a public website!!!) it appears a few extra settings were required, in particular, one of the samples was a email stored as MIME but the ‘decode MIME’ option wasn’t turned on. Another sample was in fact a potentially unwanted application and again, the option to enable detection for PUAs wasn’t used.</p>
<p>While Sophos performed better than many of its competitors, the sample set was far too small, the methodology was confused and the author obviously isn’t well versed in handling malware. All of this goes to show that testing anti-virus products is a lot more complex than grabbing a few samples and scanning them.</p>
<p>I would recommend anyone wishing to compare products to look for recognised testing organisations and publications such as West Coast Labs and Virus Bulletin.</p>
<p>So take particular care in using this biased testing.</p>
<p>Do you just setup your AV and not configure the options?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.asktheadmin.com/2007/08/antivirus-fight-club.html/comment-page-1#comment-3519</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 15 Aug 2007 16:42:00 +0000</pubDate>
		<guid isPermaLink="false">http://ata.inspiritnetworks.com/2007/08/antivirus-fight-club-2.html#comment-3519</guid>
		<description>The testing methodology has been heavily criticised by many members of the anti-virus community and respected security testing bodies such as &lt;a HREF=&quot;http://www.virusbtn.com/news/2007/08_14a.xml&quot; REL=&quot;nofollow&quot;&gt;Virus Bulletin&lt;/a&gt;, &lt;a HREF=&quot;http://www.eset.com/threat-center/blog/?p=78&quot; REL=&quot;nofollow&quot;&gt;ESET (makers of NOD32)&lt;/a&gt;, &lt;a HREF=&quot;http://www.smallblue-greenworld.co.uk/AV_comparative_guide.pdf&quot; REL=&quot;nofollow&quot;&gt;Independent researcher David Harley (PDF format)&lt;/a&gt;, &lt;a HREF=&quot;http://www.avertlabs.com/research/blog/index.php/2007/08/12/what-a-tangled-web/&quot; REL=&quot;nofollow&quot;&gt;McAfee&lt;/a&gt;, &lt;a HREF=&quot;http://www.anti-malware.info/weblog/2007/08/another-stupid-anti-virus-test-im.html&quot; REL=&quot;nofollow&quot;&gt;Eddy Williems of EICAR&lt;/a&gt;, and &lt;a HREF=&quot;http://www.sophos.com/security/blog/2007/08/484.html&quot; REL=&quot;nofollow&quot;&gt;Mark Harris of SophosLabs&lt;/a&gt;.&lt;br/&gt;&lt;br/&gt;The ESET and David Harley papers in particular go into details as to why Antivirus Fight Club is probably not something worth paying much attention to.</description>
		<content:encoded><![CDATA[<p>The testing methodology has been heavily criticised by many members of the anti-virus community and respected security testing bodies such as <a HREF="http://www.virusbtn.com/news/2007/08_14a.xml" REL="nofollow">Virus Bulletin</a>, <a HREF="http://www.eset.com/threat-center/blog/?p=78" REL="nofollow">ESET (makers of NOD32)</a>, <a HREF="http://www.smallblue-greenworld.co.uk/AV_comparative_guide.pdf" REL="nofollow">Independent researcher David Harley (PDF format)</a>, <a HREF="http://www.avertlabs.com/research/blog/index.php/2007/08/12/what-a-tangled-web/" REL="nofollow">McAfee</a>, <a HREF="http://www.anti-malware.info/weblog/2007/08/another-stupid-anti-virus-test-im.html" REL="nofollow">Eddy Williems of EICAR</a>, and <a HREF="http://www.sophos.com/security/blog/2007/08/484.html" REL="nofollow">Mark Harris of SophosLabs</a>.</p>
<p>The ESET and David Harley papers in particular go into details as to why Antivirus Fight Club is probably not something worth paying much attention to.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: NONE</title>
		<link>http://www.asktheadmin.com/2007/08/antivirus-fight-club.html/comment-page-1#comment-3516</link>
		<dc:creator>NONE</dc:creator>
		<pubDate>Wed, 15 Aug 2007 16:31:00 +0000</pubDate>
		<guid isPermaLink="false">http://ata.inspiritnetworks.com/2007/08/antivirus-fight-club-2.html#comment-3516</guid>
		<description>im not surprised i hate them nai peopel</description>
		<content:encoded><![CDATA[<p>im not surprised i hate them nai peopel</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Karl L. Gechlik</title>
		<link>http://www.asktheadmin.com/2007/08/antivirus-fight-club.html/comment-page-1#comment-3515</link>
		<dc:creator>Karl L. Gechlik</dc:creator>
		<pubDate>Wed, 15 Aug 2007 15:01:00 +0000</pubDate>
		<guid isPermaLink="false">http://ata.inspiritnetworks.com/2007/08/antivirus-fight-club-2.html#comment-3515</guid>
		<description>Wow I&#039;m Shocked. We might just need to rethink our AV strategy! Good looking out.</description>
		<content:encoded><![CDATA[<p>Wow I&#8217;m Shocked. We might just need to rethink our AV strategy! Good looking out.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced)

Served from: www.asktheadmin.com @ 2012-02-09 11:50:43 -->
