App Review Can't believe in signature test Kaspersky get outperformed by ClamAV

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
Eski Ejder
And when you manually update today, what happens tomorrow, by which time Bitdefender has released already more than 15 updates?

The statement that products like Avast and Sophos with 250 mb databases or products like BD with 2x 500 mb can be used offline is misleading.

It’s like saying that WhatsApp for desktop is useful without connection.
Yes, you’ll see some messages. But you cannot use it to its full potential.
Some of air-gaped PC users even use scripts to remove MSD and use PC with no AV at all, depending on scanning the intended to be used software on the PC used to download before install to the air-gaped ones.
They consider saving PC resources for resource-intensive programs is an advantage, especially they are not connected to internet.
 
Some of air-gaped PC users even use scripts to remove MSD and use PC with no AV at all, depending on scanning the intended to be used software on the PC used to download before install to the air-gaped ones.
They consider saving PC resources for resource-intensive programs is an advantage, especially they are not connected to internet.
An AV with no connection is useless either way.

People think that behavioural blocking is magical. From user point of view, it’s easy, you monitor the behaviour, you record, the file started modifying files and dropping “your_files_are_encrypted.txt”, so you start remediating.

But when you look at it programmatically, all that the AV sees is an ocean of calls and memory operations. From these calls, the AV needs to filter what’s not related to any known threats (which changes by the minute), it needs to correlate, take a decision and it needs to do it quickly.
There are hundreds of ways to achieve the same behavioir and they all result in different calls. When you group these in sequences, there are probably millions of combinations possible.

It’s possible to create short behavioural profiles, but these lead to more false positives.

This necessitates either a connecion to the cloud for quick processing of huge volumes of information quickly and accurately, or constant pushing of behavioural sequences/profiles, whatever you wanna call them.

All pre-execution detections need frequent updating too.
 
Trying to prove some products can be manually updated and used on air-gaped PCs used for gaming or productivity (rednering, multimedia editing) and some other products cannot as they rely on internet connectivity to provide the promised protection.

For such purposes, it is simpler to use a good AV with a strong cloud backend + allowlisting security layer.
I use such a computer as a media center. Every few months, I connect the computer to the Internet to make auto-updates.
 
The utility of both approaches is questionable, and their rationale is unclear. 🤪

People have the right to both sometimes. :)
I am usually helpful in explaining my point of view.(y)
 
Last edited:
Indeed you are smart, but some of those criticizing Leo are smart too; which smart should I follow?
None of us. Think for yourself.

He doesn’t…
And he is not unbiased, he is on the principle “I like the one that pays”.
Of course he is biased. He dislikes Microsoft in particular. He receives revenue from some of the software that he reviews or makes commentary about.

I am not sure what is more strange, me when defending Comodo (which I do not use) or you when defending those tests. :)
Leo's most controversial videos are not tests or at least not tests that most people can figure out what he is really saying.

Leo, as a matter of deliberate choice or habit, does not provide adequate or sufficient context to make viewers understand his "arguments" or "positions." I've advised him that how he explains himself works against him.

His perspectives are based a lot upon Microsoft Security marketing, but he never explains what his grips about Malware Defender are truly about. Saying "I have a problem with the way Microsoft does this..." - I get it - but not providing sufficient detail so that everybody can get it works against Leo. He's aware of this and just doesn't much care. He has got his own gigs and is not interested in addressing or rectifying criticisms.

When he says "A security product [Microsoft Defender] fails," well then, that is such a generic, accurate statement that he is not wrong. He does not seem interested in providing any more clarity - despite what he is getting at is correct.