bootsy@ avast have stated many times before that it will not add this option so you’re wasting your time in asking, if you don’t like it then please feel free to move to another product.
At what point is it going to get through your thick scull, this is a request that will not fly.
If you can’t wait for the short amount of time it takes avast! to rectify a false positive then
please, continue to turn of your protection. It is your computer and your option to make a foolish move any time you so desire.
It is also your option if you aren’t happy the way this program works to keep you safe, to find an alternative.
We will miss you.
if you don't like it then please feel free to move to another product.
I do feel free to do so. I am also free to post here unless the mods want to ban me… for …making a valid argument and asking for a response?
If this is out of line, that’s pretty ridiculous.
Lisandro said there are security concerns regarding an IGNORE option but did not say what they were, though I understand he feels this has been covered in the past. But regardless of what the policies were before, policies are always changing, often (if not most of the time) in response to user feedback.
If AVAST really doesn’t want to know what its users think, then a team member can say so.
I wasn’t asking Lisandro to change policy. I was asking how an IGNORE function is a “security concern” (his words) given the logical way users – common and advanced – use an AV. I was responding to his post. I assume this is allowed.
Of course, you can ask. But you may not get the answer you want to hear. An AV is supposed to seamlessly protect you. Turning it off will remove all protection.
I know you are not asking me about the IGNORE function, but IMHO, choosing to ignore an alert is unwise without any further investigation on the internet, and offering such a function to avast! users without requiring some effort on the part of users to submit the file to avast! engineers to look at and fix a possible false positive would be more than foolish. Kind of defeats the necessary reason to have an real-time antivirus program running on your system in the first place.
As a significant number of users likely would automatically bypass that safety feature and just choose IGNORE and be done with it. And then who would blame avast! for something they did, if indeed, they got infected?
With millions upon millions of virii, and more discovered every day, it is not possible to [stay] ahead of the latest threats, at least for most folks. Can you choose wisely?
Russian roulette, is what it is, to turn off your AV protection. Sooner or later, you’ll have shot your computer system dead. [But] I hope that never happens to you.
As already explained many times and by many people, your “workaround” is unsafe.
If you want to do that to your own computer, be my guest. It’s your computer It is not recommended and not a safe practice.
I would also suggest that you lose your attitude. It has no business on this support forum.
Actually it wasn’t. Please point to where Lisandro or any AVAST team answered post #20 in this thread? Lisandro only dismissed the question early on, ignoring the argument that challenged him.
I appreciate your reply, mchain, but it doesn’t appear you are familiar with hash values. Hashes are published for purposes of file verification, to ensure the downloaded file is not an imposter or has been tinkered with in any way. A kind of digital fingerprint. A small program incorporated into the Windows shell allows you to check the hash values of any file from the Properties window. You generate the hash, then paste the value from the author. If the hashes match, the file is an exact, unchanged copy of the original.
So when downloading reputable software, recommended by reputable sites, from the author’s own site or a reputable mirror, and you check the hash value, you know the file is clean.
The problem is, people here think they know better than others, when they clearly don’t (even those well-intended). And the logic AVAST uses to justify not including an IGNORE option is clearly flawed, as I laid out. But apparently AVAST is happy using flawed logic, which would explain why they updated machines against user settings without warning, and would also explain why AVAST has fallen so far from the top in it’s AV standing.
It appears it is time to find a new AV, when the company behind the AV you are using, can’t be trusted (by their own actions) to make sound decisions or to use common sense… even on this forum. Drake127 excepted. But I am getting the feeling Drake is the exception and not the rule, sadly.
I’m afraid there is one thing you are missing here (with the hashes).
If an “imposter” managed the hack the site where you download the file from (to replace the file in question with a different content), it’s quite likely that he/she would also be able to change the hash shown there. So a hash published on the download site is giving you only a false sense of security, nothing else (i.e. from a security point of view, it’s worse than if it wasn’t there, because now “you know the file is clean”, as you write. The purpose of the hashes is to detect corruptions during download, not forged files).
A digital signature - linking the content of the file to a particular subject - is something else, but even here we’ve seen certificates stolen, signing machines compromised… so you can never be sure.
I did not miss this, I mentioned it earlier. It amounts to a near-virtual zero risk, especially since hash values are uploaded to many sites making the one ‘wrong’ hash stand out and be easily and quickly identified. Which is why no one ever bothers doing that. When is the last time some widely used file was hacked and then a fake hash was uploaded to an author’s site, or any other reputable site? And if you can name even one event when this happened, how long was it before the fake hash was discovered?
So a hash published on the download site is giving you only a false sense of security, nothing else (i.e. from a security point of view, it's worse than if it wasn't there, because now "you know the file is clean", as you write.
What I wrote was that the hash tells you the file was unchanged from the original. You can then assume it is clean since the context of this statement was downloading reputable sftw from a reputable site.
The purpose of the hashes is to detect corruptions during download, not forged files).
It is used for BOTH purposes, as you well know (or should, being an AVAST team member).
A digital signature - linking the content of the file to a particular subject - is something else, but even here we've seen certificates stolen, signing machines compromised... so you can never be sure.
Yes, you can. Downloading a hash from a reputable author/website guarantees the file is unchanged from the original… and reputable means it is not an infected file or malware to begin with, so if it is unchanged, that’s that.
The default action of DELETE should satisfy all concerns about protecting uninformed, “common users” (as Lisandro put them). The rest of us would like an IGNORE feature and there is no argument against it that AVAST can make, that makes any logical sense. If you read this entire thread you saw my arguments. And no one has yet directly addressed them. A “common user” won’t dig into the UI to make AVAST ask advice when it finds a potential threat… and if they did for some reason, they certainly would not choose the option to IGNORE that threat, unless they were very, very stupid. Only advanced users change the action to ASK and only an advanced user who knows what s/he is doing would use the handy IGNORE option, when they know the file is safe.
It is not AVAST’s job to make all my decisions for me when I have the capability to choose for myself and my choice is more convenient. You either want the software to be useful and easy to use or you don’t. Considering AVAST is plummeting in the lab tests, you’d think it would be jumping to listen to its user base instead of insisting it stay dumbed-down and continue on its slide… not just losing AV standing but users and user-loyalty too.
I’m not commenting on the actions in any way as I don’t feel anything I could say would change anyone’s mind, so I won’t bother.
I’m just saying your previous comment is wrong (and dangerous, actually). You wrote “Hashes are published for purposes of file verification, to ensure the downloaded file is not an imposter or has been tinkered with in any way”, and even went to great lengths to describe how to do that. However, if you consider the possibility of someone compromising the file, then using the hash published there doesn’t make sense. Saying that different hashes would get recognized across the Internet doesn’t change anything about that statement - you could as well say that different files would get recognized (if different download sites served different content). Sure, maybe they would be, after a while (probably more likely than the hashes themselves as I don’t really believe many people checks those) - but then you are basically disregarding the possibility of someone compromising the site/file (or at least someone visiting the site while it’s compromised) that you assumed in the very beginning and because of which you are checking the hashes. The logic is wrong here. If you believe any modification would immediately be found and fixed, then why check the hashes at all?
A text hash on a web page is an unverified/unsigned piece of information that has zero impact on security; it certainly doesn’t tell you that a file downloaded from that page is unchanged. Sure, you can browse multiple sites to check that all show the same hash (hoping those different sites aren’t actually served from a single server and that it isn’t your network connection / router / ISP that got compromised, redirecting all your network traffic somewhere else), maybe ask other users across the world what their file hash is (hoping the downloaded the file before the potential attack)… well, I think there are better ways to spend time. Digital signatures, binding the [file] content to a particular subject via a trusted authority, have been created for a reason…
Anyway, enough time spent on this particular detail for me… so good luck with the hashes
Bootsy I am with you 100%. There needs to be an ignore button. I only have 3 more customers of mine that I have not switched away from Avast yet. But I will. As for this forum. Just go into your settings and choose to ignore Bob and Eddy’s posts. I did so over a year ago and this forum is much more pleasant to read.
Right. Because there is no logical argument in which it makes sense that users who don’t know anything about viruses would dig deep into the UI to make configuration changes so that the AV would ask them for advice and then hit IGNORE. Only imbeciles would do this.
I'm just saying your previous comment is wrong (and dangerous, actually).
No, hashes are used to avoid the very danger you are proposing.
You wrote "Hashes are published for purposes of file verification, to ensure the downloaded file is not an imposter or has been tinkered with in any way",
[shadow=red,left] If the hashes match, the file is an exact, unchanged copy of the original.[/shadow]
So when downloading reputable software, recommended by reputable sites, from the author’s own site or a reputable mirror, and you check the hash value, you know the file is clean.
When software is highly recommended from reputable sites, and you get it from the author’s site or a reputable mirror and compare hash values, the chance of getting an infected file is small (they’d have to hack the site to replace the hash too) and I’m happy to take that chance on those occasions, b/c the chance of it coming back to bite me is a near-virtual zero, while the hassle of dealing with AVAST’s lack of an IGNORE option is a certainty.
However, if you consider the possibility of someone compromising the file, then using the hash published there doesn't make sense. Saying that different hashes would get recognized across the Internet doesn't change anything about that statement - you could as well say that different files would get recognized (if different download sites served different content). Sure, maybe they would be, after a while (probably more likely than the hashes themselves as I don't really believe many people checks those) - but then you are basically disregarding the possibility of someone compromising the site/file (or at least someone visiting the site while it's compromised) that you assumed in the very beginning and because of which you are checking the hashes. The logic is wrong here. If you believe any modification would immediately be found and fixed, then why check the hashes at all?
The reason igor, is because THIS DOESN’T ACTUALLY HAPPEN to any significant (if any) degree. Again I ask, when is the last time a widely used, reputable software program was uploaded to its author’s site, and subsequently hacked ALONG with its hash, which were both uploaded, bamboozling an entire slew of users who unknowingly got infected? While it could happen in principle, it doesn’t happen in reality enough to even name ONE TIME, so as to make all your dread about it even less reasonable than if I tell you not to drive home because there are car accidents every day. At least there really ARE car accidents every day. But the context of what we are talking about here just doesn’t happen as a matter of course. Why doesn’t it happen more often? Because it would be a very short-term run for the hacker before discovery, which makes it a useless endeavor from their viewpoint.
A text hash on a web page is an unverified/unsigned piece of information that has zero impact on security; it certainly doesn't tell you that a file downloaded from that page is unchanged.
Let’s not play word games. The context is that reputable authors (and companies) generate hashes from the original file then publish them so downloaders can be assured the file they get is unchanged from the original. Everyone from Microsoft to Mac to Linux uses hash codes for this reason.
Sure, you can browse multiple sites to check that all show the same hash (hoping those different sites aren't actually served from a single server and that it isn't your network connection / router / ISP that got compromised, redirecting all your network traffic somewhere else), maybe ask other users across the world what their file hash is (hoping the downloaded the file before the potential attack)...
Actually that isn’t necessary, and you know this. With the billions of people online 24/7 downloading files and exchanging information at the speed of light, any single user has an infinitesimal chance of coming upon a widely recommended file & hash that has been replaced with a bogus file/hash before it’s been found out by the community at large. And that’s on those if-pigs-could-fly-days that someone would bother to replace such a program and hash… since they know this isn’t an effective way to spread a virus. Infecting torrents or binaries or sending infections through HTML-enabled email is much easier and less likely to be traced back to the offender.
[...] Digital signatures, binding the [file] content to a particular subject via a trusted authority, have been created for a reason...
Hash files work very well for their intended purpose… or maybe the whole world is wrong and AVAST is right?
Anyway, enough time spent on this particular detail for me... so good luck with the hashes ;)
No luck required. OTOH it seems like AVAST will need all the luck it can get to stay afloat with sinking AV labs and no sense the company wants to improve the product for those users who are bothering to make their needs known. Makes me wonder if anyone on the board of directors ever reads this forum… maybe someone should email them and warn them they should.
Actually that wasn’t too helpful, bob, as it’s mostly for technical phone support. Perhaps you have a public email address for Vincent Steckler, Ondrej Vicek or Bill Salisbury? Anyone? (If they have public email addresses.)
If anyone on the AVAST team has public contact info for any board member who makes him/herself available for public comments, (and maybe none of them do) please don’t hesitate to follow in bob’s footsteps.
Sorry for butting into your business but why don’t just stop posting as it seems like You’re fighting a losing battle. Not trying to be rude, just expressing my opinion.