arsenaloyal said:
I think they leave it at automatic for compatibility reasons, i have to agree with ESET on this one atleast for the AV,hips in automatic mode is better,but perhaps in ESS they can change the default setting.
Automatic mode: Follow rules, if not, Allow.
Only 1 rule is defined: load drivers.
If that is the case, then have it disabled or on Learning mode as default.
I much rather pair it up with a BB. NOD32 paired with CFW and D+ nets way better results (HIPS) or even Emsisoft's BB.
Short answer: ESET HIPS for a beginner = no HIPS simply because the beginner will not drill in to find out whats automatic mode's rules nor configure them. If he/she has the brilliant idea of setting straight to Interactive mode, after a few programs being opened, chances of HIPS being disabled by the user are 99% due to the rain of alerts and questions.
If the user sets as Policy based and then starts running programs, no program will run since Policy based = Follow rules, if not, Block. This is 100% chance of user disabling or setting back to automatic, loosing the zero day protection.
Been like this since they incorporated HIPS. on RC still same rule.
Oh and initially until i believe the last build or last 2 builds, settings were Automatic Mode but no rules were present.