Wed, Dec 2 2009 19:45
bradley
I'm going naked
.... on my server when it comes to Antivirus. Yes you read that right. Why? Because at this point in time I really feel that my antivirus vendors are putting me more at risk with the software on than off.
Why do I say this? Because I don't trust antivirus anymore. At least not on my Servers these days. Sure the fix for the tdi.sys is now included in SP2, but I am really questioning why we knee jerk install antivirus on the servers these days. For sure not on hyperV boxes that should only be HyperV and nothing else in that role.
But even for SBS boxes... I'm going naked.
If we have mail hygiene in the front...
If we have antivirus on the workstations....
If we have a firewall that is a business class that is used to block sites appropriately....
If we use Opendns to additionally filter....
If we move our workstations to not have local administrator rights (I mean you have to go out of your way in SBS 2008 to get local admin)
I know you'll say ... but Susan it's belts and suspenders.
But I don't TRUST that belt and I sure don't TRUST that suspender. I don't want a firewall driver on my server that ALREADY has a firewall that works. I don't want software that doesn't stop the rogue antivirus. I'm using other defensive means
So when you build your SBS 2008 boxes, make sure SP2 is on there first and foremost. It will only MU/WU down when all other "Important" patches are hidden or installed. Manually download it if you must. Get it on the box... THEN... sit back and decide if the risk of that antivirus software is really and truly worth it. Don't knee jerk install it just because...because it quite frankly doesn't make as much sense anymore.
Filed under: Security