recommendation: use anti-virus

2026-09-11

A common recommendation to mitigate cyberattacks is to use anti-virus software and keep its signature database up to date.

This is a good idea on the surface, but there are a few problems with this:

  • not all anti-virus are created equally. some work well, some don’t. it is hard for the average person to pick appropriate solutions here. This is one of the most common questions i get when people find out that i have anything to do with cybersecurity: Which antivirus should i use?

  • this relies on the anti-virus software having a signature for the malware you’ve been targeted with. If someone WANTS to hack you, it is often trivial to tweak or re-write pieces of malware so they run undetected. So while anti-virus can be awesome for catching run of the mill commodity malware, the topic of antivirus evasion is well-studied by attackers and often trivial to implement.

  • most of the good/reputable antivirus software that doesnt subject you to a bunch of ads and stupid bullshit isn’t free. I don’t think this basic level of security should be a luxury item, effectively pricing out those who need it the most.

  • just running antivirus gives a lot of people a sense of false hope. this is largely due to them not understanding what anti-virus does or how malware works on a deep technical level. I’d have a shitload of dollars if i got a dollar each time i heard someone say something along the lines of “i ran a scan and found nothing. should be good to go now!”

  • antivirus is another system to maintain and understand. running it adds complexity to an organization.


Links to this note