Why I HATE Windows Defender

Поділитися
Вставка
  • Опубліковано 9 чер 2024
  • Windows Defender is often seen as a good antivirus, but I want to inform you of a cost noone sees but developers because of Defender.
    Website Article: christitus.com/bad-windows-de... .
    ►► Digital Downloads ➜ www.cttstore.com
    ►► Reddit ➜ / christitustech
    ►► Titus Tech Talk ➜ / titustechtalk
    ►► Twitch ➜ / christitustech
  • Наука та технологія

КОМЕНТАРІ • 341

  • @ChrisTitusTech
    @ChrisTitusTech  Рік тому +43

    Website Article: christitus.com/bad-windows-defender/
    It should also be noted that I bought my code signing certificate from comodo and it was fulfilled by Sectigo. Which is strange because comodo's pricing is considerably cheaper.

    • @adityaharekrishna
      @adityaharekrishna Рік тому +3

      Hey Chris , what's your opinion on virustotal? Multiple anti-virus together?

    • @eputty123
      @eputty123 Рік тому +2

      after watching this it made me even happier that i don't have an anti-virus, i disabled windows defender and i highly doubt someone will be able to get me to install malware without me knowing beforehand that it is malware.

    • @ChrisTitusTech
      @ChrisTitusTech  Рік тому +7

      @@adityaharekrishna VirusTotal is amazing site and use it often.

    • @psd993
      @psd993 Рік тому +4

      I probably hate microsoft more than the average person, but after watching this video, I still have no idea what exactly is "corrupt", what the so called "monopoly" is, and how Microsoft is benefitting from it. You are using these terms in such a broad and vague sense, that by the same standard, the whole drug approval process in most developed countries is "like the mafia" -- you are required to go through these steps, it costs a lot no matter who you contract, and at the end of the day the process isnt even all that foolproof!
      It's like the entire time, you know your actual point does not make much sense, so you state a bunch of tertiary facts that are true... But the part where you put it all together is missing. This video is basically just pandering material from tech bros who talk about privacy and security without ever having heard of a threat model.

    • @ce1cecl
      @ce1cecl Рік тому +1

      why don’t you recommend some open source av? and one that might be cross compatible?

  • @slembcke
    @slembcke Рік тому +123

    As a dev, my least favorite part of Defender is the "real time protection" crap. It hooks every time a program closes a file to scan it for anything suspicious. The Defender process seems to be single threaded. When compiling code, it saturates a single core and prevents the rest from actually doing work. Turning it off on my old 4 core 7700K machine speeds up compile times by ~20%, and even more on my newer 8 core AMD machine. Annoyingly it helpfully turns it back on the next day. You're supposed to be able to exclude folders, but it simply doesn't work. Oh, and this is on top of the 2-3x slowdown in compile times compared to Linux running the same tools on the same machine. Augh! Pretty happy that I can usually just get away with cross-compiling from Linux. >_>

    • @peterjansen4826
      @peterjansen4826 Рік тому +3

      That is bad! So here the dilemma, should reviewers like Hardware Unboxed and Gamer Nexus benchmark with this bloatware on or off? Most people have it on but anyone can easily turn it off. Kind of easily.

    • @peterjansen4826
      @peterjansen4826 Рік тому +2

      What kind of software do you develop?

    • @artur-rdc
      @artur-rdc Рік тому +2

      I'm always surprised that people don't mention this when talking about defender.

    • @NavJack27gaming
      @NavJack27gaming Рік тому

      excluded drives 100% work. all my windows PCs it just works. it'll do a scheduled scan of just basically nothing and never touch the drives. i went from turning off real time protection to just setting full drive exclusions and everything works perfectly.

    • @wrockd
      @wrockd Рік тому +2

      That is more of an "Antivirus" problem rather than a "Defender" problem. Any antivirus with proper RT eats away at the resources, And defender is relatively quite non resource intensive compared to it's RT performance and other AV solutions. And one could always disable RT which works perfectly fine.
      Also, excluding folders works but only when what you're doing is confined in that folder itself, it would still scan and check Temp folders which most of the processes use for operations and store a copy of the process exec there.
      And the slowdown seems to be a Windows problem, Linux is generally much faster in compiling stuff and most of the other stuff than windows. You could remove Defender pre-install and still get nowhere near Linux in compile times.

  • @LeonisYT
    @LeonisYT Рік тому +95

    LMAO the thumbnail

    • @thejohnbeck
      @thejohnbeck Рік тому +6

      That is the number one clip of family guy

    • @jater10
      @jater10 Рік тому

      It is a classic

  • @karu8291
    @karu8291 Рік тому +56

    Since moving to Linux, this hasn't really been a thing I've thought about. I figured people using my FLOSS apps on Windows could just audit the code if they were concerned. But I suppose my ignorance is allowing MS to grow their AV monopoly.

  • @do0nv
    @do0nv Рік тому +22

    I just zip up my executables, it bypasses the smartscreen because the unzipped executable technically originated from the computer, not the internet.

    • @SmilerRyanYT
      @SmilerRyanYT Рік тому

      I often unzip and run executables forgetting smartscreen is even a thing, nice to know it's helpful for "security" too.

  • @AJ-wf1vh
    @AJ-wf1vh Рік тому +17

    Apple does worse with gatekeeper, where they require you to send them your executables each release to sign them. Granted, it's cheaper
    At least with Microsoft you can choose your key provider and don't have to upload your code to their site.
    Yes it costs money, but it's an easy and cheap solution to a complex problem: developers pay 300$ per year and in exchange windows gets rid of most spammy viruses
    If you mess with your key or distribute malware with it it will be blacklisted and you'll have to pay again. It makes gaming the system unaffordable for hackers (generic malware etc). Also, that 300$ goes into somebody validating the company is legit before issuing the cert, so even if a hacker had the economic power to print certs they wouldn't be able to order them en mass
    Perhaps Microsoft may get to keep a cut. But it's peanuts compared to having all computer users having to pay 50$ per year to keep their computer secure.

  • @Nomad-qm3zf
    @Nomad-qm3zf Рік тому +107

    Awesome video man. I gotta stop giving microsoft credit when they don't deserve it. I legit believed MS just wanted windows to be a secure platform and offered free AV protection for people. Silly me.

    • @thejohnbeck
      @thejohnbeck Рік тому +6

      Me too. I figured they were providing it for free to enhance the reputation of windows, not to gouge others

    • @devnull1013
      @devnull1013 Рік тому +3

      So instead you buy into this dudes cult of bs "tech reporting"

    • @wrockd
      @wrockd Рік тому +9

      This is making it more secure, the video is blatantly twisted to look like as if MS is doing it to gain money.
      You could run software not signed with EV with ease, it's just a single prompt which says that the executable could be malicious. And that is only if your executable hasn't been downloaded by a few thousand people, after which it doesn't show that prompt.
      This is important because Cheap certificate could be purchased by anyone and they don't even verify your identity properly before giving you the Certificate nor do they revoke it easily. This allows any person to just modify a executable, sign it with their certificate and most people won't even suspect that anything is wrong.
      EV certificates tackle this by having a pretty elaborate and extensive check to verify if you're really a legitimate person or not by verifying your documents and cross checking them through official portals. On top of that, as soon as you're found distributing stuff that is malicious your certificate gets revoked.
      This reduces the chance of anyone spending that high amount of their chances of getting their certificate revoked are high.
      And the price is not something that MS is just putting up without reason, manual verification of documents requires manpower and that requires money to pay salaries.
      You could either verify your legitimacy by having a few thousand people running your executable or proving that you're a legitimate person by going through the vetting process of EV and paying high amount of money.

  • @katbryce
    @katbryce Рік тому +44

    That makes the $99 Gatekeeper certificate from Apple look really cheap in comparison.
    Where Microsoft makes their money is that the certification authorities have to pay Microsoft (and Google, and Apple, and Mozilla) to be approved as certification authorities.

    • @encycl07pedia-
      @encycl07pedia- Рік тому +13

      This is a tangent, but Apple has done far more harm to computing than help. Their anti-consumer practices are not only hurting Apple customers but the general public as other companies are emboldened by Apple's commercial success to copy Apple's policies like overpricing, impractical independent repair, and removal of features (among others).
      Growing up in the 1990s with Macs that hardly worked with anything (by design) and switching to Windows XP was like moving from an authoritarian country to a free one, so I have strong reactions whenever Apple is mentioned in a remotely positive light... That company has been evil and oppressive for a long time and it has only gotten worse.

    • @psd993
      @psd993 Рік тому

      so how much do these licenses cost for certification authorities? There's like 4 of them. Who's making the millions/billions here?

    • @wrockd
      @wrockd Рік тому

      That is how anyone could verify that the said CAs are trustable, what do you want them to do? Add every other CA applicant to their trusted CA list?

    • @NyneT9
      @NyneT9 Рік тому

      @@psd993 Microsoft Stakeholders? Gotta buy Microsoft shares when I have the money- They hit the new oil reserve!

  • @alanelston2330
    @alanelston2330 Рік тому +11

    This is an interesting heads up and update on a couple of things: ...
    _ If I recall correctly, your first self-written Debloat/ Utility script back in July 2020, disabled Windows defender, and the next version enabled it. Your first GUI version in December 2020 gave the option to disable or enable it., I think.
    Since then it was not discussed much on the script so good to get an update on your thoughts on it
    _ I heard a few rumours or background comments on what Microsoft were doing with some Validation stuff more recently. It sounded a bit suspicious, but as a Layman I don't really understand these things. So it’s helpful when you catch these things and pass on some actual info on them for us.
    Alan

  • @jacksoncremean1664
    @jacksoncremean1664 Рік тому +5

    Extended Validation Certificates is a way of proving that you really are a certain company
    in order to obtain an EV cert you have to prove you are who you say you are, not just that you own a domain like with DV certificates.

  • @xpyr
    @xpyr Рік тому +5

    I've looked at the price of the certificates in general and it's all about how much insurance they are insured for if they are ever breached at the provider's end. That's why some cost more. Some may only insure them for $10,000, while others it is $250,000, and that is what you're paying more for.

  • @Z_o_r_r_o1267
    @Z_o_r_r_o1267 Рік тому +11

    If the fee contributes to making sure the code a developer distributes is malicious free, I'm all for it. If, on the other hand, nobody makes sure the code is malicious free, then yes, it is like the mafia.

    • @wayland7150
      @wayland7150 Рік тому +1

      No it is the Mafia either way. Why should someone be gatekeeping Windows and collecting a fee?

    • @luxemier
      @luxemier Рік тому +1

      @@wayland7150 well why wouldnt they? Everyone is forced to do it and microsoft makes rhe big bucks on the side

  • @javabeanz8549
    @javabeanz8549 Рік тому +12

    EV requires a lot of eyes on the subject, at least when doing a certificate for a website. So I suspect that carries over to signing of code as well. The EV usually comes with better assurances as well.

  • @FireStormOOO_
    @FireStormOOO_ Рік тому +6

    For extended validation they're *supposed* to make sure you are who you say you are, verify the information provided is accurate, check business records for the company specified, etc before providing the cert. Whereas for the normal one they'll mostly just revoke it if you give BS info and they later notice.

  • @timfd.w.4163
    @timfd.w.4163 Рік тому +6

    For noobs and ordinary users (99 % of windows desktop), some antivírus is necessary, unfortunately. Anyone with a bit more knoledge wont need any, as If Vírus total is there to check when we download stuff ... What is indeed nice is a firewall running with inbound and outbound blocked except for the services and processes that we manually set. Try Malware Bytes Firewall Control freeware

  • @oM477o
    @oM477o Рік тому +6

    So what happens if you don't sign your software? Isn't it just a one time popup warning the user that the software is unsigned?

  • @ClassyOnionUK
    @ClassyOnionUK Рік тому +17

    Thank you for this video, Chris. I was unaware of this but as you say it’s definitely mafia-esque territory!

  • @patrick71994
    @patrick71994 Рік тому +3

    The certificate is for proving that the software is indeed from the vendor it is telling. So, if the software tells me it is from Chris Titus Tech and it is not signed by a trusted authority, then what is the prove that it is coming from this vendor?
    It is all build on trust and the certificate authorities cannot make mistakes, because they are out of business when they do as they cannot be trusted anymore. So yeah… there are some checks involved to see if they are doing it correctly.
    You can still ship your software without a certificate. Smart Screen will only yell at you for the first x downloads because that is what the warning is for: hey, this file is not very much downloaded. When you thing this should be the case, pay attention.
    This has nothing to do with the maffia or more money for microsoft. You can try to set up a trustworthy free service for this kind of certificates, like Let’s Encrypt.

  • @Loader7272
    @Loader7272 Рік тому +4

    "This industry has always been a little corrupt". Every industry is corrupt.

  • @GYTCommnts
    @GYTCommnts Рік тому +2

    This is a VERY interesting subject, and not to be seen discussed very much. Thank you for the enlightenment. I didn't knew the rabbit hole was more deep that I thought about this.

  • @SpeedRacer24X
    @SpeedRacer24X Рік тому

    What a great and informative video! Thanks so much for your candor and honest opinions on this topic. Keep up the great work!

  • @bobwong8268
    @bobwong8268 Рік тому

    👍👍👍Thanks for sharing. Learnt something new today.
    Hmmm.... hv upgraded from Xp to Linux and away from the "yearly headache" of jumping from 1 AV to another. Yes, every year I sat down and re-evaluate AV before buying a 1yr subscription for myself - that is living with winboxes.
    Now I simply use ClamAV for my Nixboxes.
    Software houses shifted this cost to consumers...
    Wonder how win freeware & open source s/w developers handle this issue.

  • @pyrokamileon
    @pyrokamileon Рік тому

    I used to use AVG many many years ago but ever since one of my family members had a really hard time with it and I had to come to the rescue and reset everything I had a hard time recommending it after that. ever since then I used Avast but since I actually haven't been using Windows for at least 10 years and anytime I get on my wife's computer i see that Avast is always trying to sell her things I started getting tired of them as well. when Windows defender came prepackaged with Windows 10, I figured taking the easy route was not the worst option, but I am glad that you are getting the word out. I've always heard really good things about Kaspersky, but since you have had a hit or miss time with it, I will try out bitdefender. I should have known better than to go with the Microsoft default.. bitdefender is not one that I've used myself in the past, but I will give it a try..

  • @smarfbag8714
    @smarfbag8714 Рік тому +38

    Never knew how Microsoft could be this dirty with there windows defender. It’s built into windows and they are doing this type of stuff behind the users back this is straight up shady af.

    • @dgourley8922
      @dgourley8922 Рік тому

      I solved this by installing Windows 10 LTSC. Windows Defender is included.

    • @_zetrax
      @_zetrax Рік тому +2

      This is messed up, but the linux community could have beaten them if they worked together to build a usable Desktop Environment instead of spreading thin into many buggy DEs. I haven't switched to linux because I'm having lag and artifact issues on KDE and Gnome, sad... I really love linux, and unix tools too..

    • @sanjayKumar-sx5bv
      @sanjayKumar-sx5bv Рік тому +1

      @@_zetrax it's a different story now the de had become very stable now as far as my experience
      If you want a solid experience with fluid touchpad gesture's use pop os
      It's very solid Ubuntu based distro

    • @peterjansen4826
      @peterjansen4826 Рік тому +1

      @Smarfbag It is nothing new, MS has been doing this for over 2 decades. We just caught on way too late with Defender.

    • @_zetrax
      @_zetrax Рік тому +1

      @@sanjayKumar-sx5bv I get there is PopOS or something, but I topically use Manjaro because of the AUR... It would be sweet if the Desktop Environment was solid enough instead of relying on a vendor. That just seems like square 1 all over again

  • @alanelston2330
    @alanelston2330 Рік тому +9

    As a Layman, I had just a gut feel that Microsoft were like a Protection Racket, especially since windows 10, - they protect you from the other bad people, as long as you pay up and do what they want.
    It’s great that you, as a professional, share your ideas on these things.

  • @Sich97
    @Sich97 Рік тому +1

    Hi Chris. Thank you for the video.
    Question: Why do you not recommend Webroot anymore? I remember reading that was your preferred AV.

    • @wabajack9929
      @wabajack9929 Рік тому

      If I had to guess it’d be the fact that it scores horribly low, missing many viruses. I haven’t checked in the past year though.

    • @Sich97
      @Sich97 Рік тому

      @@wabajack9929 I just remember Chris vouching for it just 2 years ago.

  • @flaminbutt
    @flaminbutt Рік тому +5

    Please, please, look more in depth into EV certification and you’ll see that your main point here is invalid. It’s NOT the same thing as a regular certificate.
    Not to say that MS defender doesn’t have its fair share of flaws, but between it and any other AV, even paid ones, I’d rather use Defender.

  • @wilfredotorres6628
    @wilfredotorres6628 Рік тому +2

    hi Chris, you may be right there used to be over three hundred breweries in the U.S. Now you see only a few national brands but that has changed. Now you see a new mix of microbreweries all over the country in every state and this could be a new beginning for small software developers in creating new antivirus software or software content that you and many other developers aren't trying to break the mold of software creation independent thinking and ideas to revitalize a revolution.

  • @brhestervids
    @brhestervids Рік тому

    Thank you for bringing this issue to light. I'm not a dev but appreciate this information. As far as Windows Defender I disabled it years ago.
    I use Comodo's fire wall only, not their antivirus as you can only get the firewall as part of their Internet Security Suite now, and then disable the whitelist entries, the firewall, for any program that I have installed, including any Microsoft entries, so the firewall catches any outgoing internet requests.
    This works very well for putting a check on any app that wants to randomly call home. The firewall asks if its ok for the app to access the internet. Not running an anti-virus at this time. Was using AVG but Avast has been slowly disabling features on AVG in an attempt to move AVG users to Avasts anti-virus. One valuable feature AVG had that is now gone is their free emegency boot CD to run AVG off the CD oe USB to check for virus's. It's now an Avast feature.

  • @crapphone7744
    @crapphone7744 Рік тому +3

    Unless there's barriers to entry as a code signing certificate provider, which I suspect there are, overtime the market should drive this down to a price equals marginal cost level.

  • @trailblazercombi
    @trailblazercombi Рік тому

    Is this applicable to end-user apps (say, office suites or note-taking apps) as well, or is it required simply for apps that dwindle in Windows' guts (say, anti-viruses, PowerShell scripts, Anti-Cheat software)?
    And if the former is true, can it be avoided by publishing the app on Microsoft Store?

  • @kmemz
    @kmemz Рік тому +3

    Every Windows 10 installation I have, I've used all the workarounds I can to disable Defender and all components related to it. I understand tge internet well enough that I don't normally have any issues with not having antivirus.

  • @rarminqorset3628
    @rarminqorset3628 Рік тому +25

    I think it's a fresh and strong step from Microsoft towards Linux evolution

    • @inthego
      @inthego Рік тому +2

      and what pc will linux run on when all but windows will run on the CPU

    • @luhgarlicbread
      @luhgarlicbread Рік тому

      @@inthego
      I think Microsoft would be in some deep stuff if they did that

    • @inthego
      @inthego Рік тому +3

      @@luhgarlicbread it is edging that way NOW.. Pun intend.

    • @rarminqorset3628
      @rarminqorset3628 Рік тому +2

      @@inthego that's impossible. By the nature of close sourced software all the powerfull tech companies have to keep each other in check. Microsoft and Intel are friends with knife in their hands. They can betray each other anyday. If all computer actually start using windows all other companies will double down on creating an alternative,i.e, Linux or some other. Microsoft is what it is because of developers whether you like it or not and most developers do not prefer windows anymore. It's just a matter of time till it keels over

    • @inthego
      @inthego Рік тому

      @@rarminqorset3628 we can hope

  • @fluffycloud331
    @fluffycloud331 Рік тому +1

    hey Christitustech hope you are doing well I just dual boot pop is with Windows and it has been great with pop os. All my games work with Linux and am doing everything on pop os
    thank you for teaching Linux and have a great day.

  • @Ernur05
    @Ernur05 Рік тому

    hello, so basically i had a virus on Windows 11 called Trojan or something like that, and i removed it but after that my Windows Updates arent working and i cant downloand anything from the Microsoft Store, is there any way to fix it without to Factory reset my pc?

  • @animegamer3336
    @animegamer3336 Рік тому

    Hey Chris will you do a Video on Umbrel , it's a self host everything dashboard and one click installer for self host alternatives for most of the free Cloud services

  • @AliensInc.
    @AliensInc. Рік тому +1

    Have you seen that Britec09 have shown your 'Ultimate Tool for Windows' in his latest vid?

  • @nikczemnydev
    @nikczemnydev Рік тому +3

    I have been using ESET for a few years now as I also found it the lightest, but if you want to recommend something free, I'd go Panda Dome over BitDefender. On my PCs it was lighter, it had 0 popups or ads (you untick those 2 from within settings), there are more false positives especially after you enable PUA option, but not by that much in everyday use - other than that it's the lightest you can get for free* IMO. ; )
    *-the only 2 that were lighter on my machines were K7 and eset, both paid. BTW, K7 is hella cheap these days, like 8 dollars for a year and around 15 for 3 years if I remember well, really good deal, if they keep that price I'll think about switching to it when my current eset licence expires. : )

  • @NavJack27gaming
    @NavJack27gaming Рік тому +2

    what do you mean "required"? i run unsigned stuff on my PC and my mac all the time. just do the "run anyway" thing. its literally not an issue unless i guess you have a locked down work PC that is trying to run the program. i "run" defender. i set exclusions for all my mounted drives. smart screen pops up when it should. nothing is limited... i'm confused.

    • @NavJack27gaming
      @NavJack27gaming Рік тому +1

      could you please explain in another video in what situations not having a cert for your program actually is a blocker? i'm completely unaware of a situation where windows would completely block you from running a program without a code sign. i've not used a computer where this is a thing.

    • @skillyhizoh
      @skillyhizoh Рік тому +2

      Exactly. Anyone doing dev work would bake in the signing requirement if they intended to distribute software on a decent scale, too. This whole video is silly. Nothing is hindered except a warning to a end-user to consider the risk ...these end-users which vastly outnumber folks authoring software which defender is there to literally protect for zero cost to them.

  • @peterschmidt9942
    @peterschmidt9942 Рік тому +2

    I recently gave Avira the flick on my windows machines and just starting using Defender again, as I was fed up with all of Avira's add on crap and slowing my system down. I think you're on the money here if that's what's happening behind the scenes. Think I might put Bitdefender on instead

  • @ABsazerNer
    @ABsazerNer Рік тому +1

    so how to completely uninstall it? please

  • @ArniesTech
    @ArniesTech Рік тому +5

    Unfortunately this is the level of in depth look that 99,9999% of Windows users will never do 🙏

    • @astroid-ws4py
      @astroid-ws4py Рік тому

      If they’re so dumb to use Windowz they can fk on their "system", Developers should start targeting immediately Linux and BDSs and maybe other creatures like HaikuOS and just leave the Windowz platform completely, Lets make those who would like to use some software installing/switching to Linux, If they can’t they just can stay inside their little Windowz bubble dystopian world and fk off...

  • @ScottMosier12345
    @ScottMosier12345 Рік тому +1

    One clarification, this is the personal, home user version. The enterprise version (MDE) is actually quite good.

  • @smileynetsmileynet7922
    @smileynetsmileynet7922 Рік тому +1

    Im making a new set of programming tools, mostly languages. Im making it for both windows and linux, with linux prefferred now. Granted, i do install from zip file so far, but why have i never had to worry about this, or being flagged as virus falsely? Is my language too similar to java? I know it shares some concepts, but it has a lot of differences too. Its not designed for it, but im sure its capable of being used for a virus so far, even though im doing everything i can to prevent that.

  • @ahmet05ac
    @ahmet05ac Рік тому

    do we really need an antivirus or defender if we are using strong adblockers, maybe a pi hole server, and avoid pirated stuff? where do you guys think the point that we should start worrying about viruses? i mean what is the minimum use case that requires us to use defender and kind of av?

  • @henryfleischer404
    @henryfleischer404 Рік тому

    I knew there was something wrong when it declared an exe I downloaded was ransomware, but when I ran it anyway, nothing happened. I'll remember to do that every time!

  • @computeremail9063
    @computeremail9063 Рік тому

    Ya, it is like secure boot signatures. And btw I just use Kaspersky Internet Security. Really really good AV.

  • @herpmcderp5707
    @herpmcderp5707 Рік тому

    I dont like how i cant really control Defender. Theres no obvious way to shut it off until i want to turn it on again, it always turns on itself after a period of time. I switched to the free Comodo versionrecently and I dont have any problems so far.

  • @MiguelDeMarchena
    @MiguelDeMarchena Рік тому +3

    first thing i do with windows 10 (was not necessary in other versions) is deactivate windows antimalware software, if you don't know how to deactivate it permanently then there is a small program that can do it for you (dcontrol)

  • @thedduck
    @thedduck Рік тому +2

    Wait, so any unsigned executable can't run on Windows box anymore? I'm confused!? AFAIK Code Signing is a pretty universal thing, no? It works on any platform as a way of validating the authenticity of a code. Your argument seems to point to a disadvantage for the app developer side rather than the consumer side. Also I'm not clear on why recommending another AV accomplish? Is it just to disable smartscreen and or to avoid supporting their "bad practice" to validate a piece of software? 🙃
    PS. MS Defender Smartscreen have a review system where you can submit your file for analysis if you believe a warning or block was incorrectly shown for a file or application, or if you believe an undetected file is malware.

    • @leeuniverse
      @leeuniverse Рік тому

      LOL no... it can run still. It's just your AV will generally interpret the EXE as a "virus" which just looks bad to your customers.

    • @skillyhizoh
      @skillyhizoh Рік тому +1

      Exactly! Well said. Blaming Defender for protecting users from potentially malicious code is short sighted. There are way more consumers than software devs, which is what this system is designed to safeguard.

  • @TheExileFox
    @TheExileFox Рік тому +2

    You forgot the garbage called McAfee which is practically unavoidable if you try to buy a new laptop or pre-built system

  • @Dragemesteren
    @Dragemesteren Рік тому +16

    I can not help wondering why developers keep taking that crap. We need a developer revolution. More and more people are making the Jump to Linux based operating systems. And since Flatpack has come into the world, distributing to all linux users has become a lot simpler. I am sure that many people use Windows purely out of habit. They feel secure that all programs will have a Windows version. Maybe if developers bypassed windows. The users would migrate to Mac or Linux, and see the advantages.

    • @astroid-ws4py
      @astroid-ws4py Рік тому +2

      Many developers on Windowz are in love in developing software with Micro$oft’s $hit languages like TypeScript and C#, They like being their slaves so let them be....

    • @ejazahmed4609
      @ejazahmed4609 Рік тому +5

      @@astroid-ws4py Both typescript and C# are open source and cross platform though .

  • @nickademuss42
    @nickademuss42 Рік тому +1

    I always though that Windows was so insanely vulnerable that they had to create somthing to keep it from getting infected, to save them from all the bad press. Also when you get a cert, doenst that mean that the program wont harm windows or let in the bad guys?

    • @markh.6687
      @markh.6687 Рік тому

      Microsoft was never serious about security, until they started getting really awful press coverage, and likely some lawsuits over security issues, and finding out people would pay for a 3rd party solution to their dreckware. As Chris said, early in its lifespan Defender was a joke.

  • @xzaratulx
    @xzaratulx Рік тому +16

    I have never seen it that way and hearing about it shocks me.
    What freaks me out the most is even if we switch to linux, these businesses will find a way to creep in there as well and ruin it ...

    • @LyricsVillage
      @LyricsVillage Рік тому +5

      The businesses already ruin ubuntu...

    • @encycl07pedia-
      @encycl07pedia- Рік тому +1

      You act like there's one Linux. That's just not the case. People will keep forking and giving the middle finger to any corporations trying to ruin their freedom. Some shady company bought Audacity and added spyware to it, so the community just forked it.

    • @LyricsVillage
      @LyricsVillage Рік тому +2

      @@encycl07pedia- I know but it is quite sad that we have to play this cat and mouse game. 😛

    • @sanjayKumar-sx5bv
      @sanjayKumar-sx5bv Рік тому

      Linux is secure because user know what's happening because we learn Linux and every aspect of it
      Window is insecure because we see what it want to show us and hide what it doesn't want to show us
      Windows was designed to be as a guider
      And we trust it because we can't understand what's going under it
      It shows us what facinates us and and we never know what the hell is going on behind the scenes
      And that's where Linux shines
      It's Fully transparent so you knows what's happening such as what permission is using, environment for application can be sandboxed for example flatpak with very good payment method beneficial for developer , Linux decision is bring taken by community so there is no monopoly

    • @encycl07pedia-
      @encycl07pedia- Рік тому +1

      ​@@LyricsVillage Doesn't Ubuntu ship with GNOME and Unity before that? I mean you're kind of asking for it if you trust the decision-makers there... They've been trying and succeeding in making their default GUI the ugliest around... At least it makes sense considering their primary color is orange.

  • @muddyexport5639
    @muddyexport5639 Рік тому +1

    Again, thank you for another excellent content vid!

  • @darklucifer2853
    @darklucifer2853 Рік тому

    What's your thoughts on tronscript would want to know your insight on it, if possible

  • @nikolatesla169
    @nikolatesla169 11 місяців тому

    Thanks for the information it helped me to keep choosing Windows Defender over the rest of AV

  • @vladislavkaras491
    @vladislavkaras491 2 місяці тому

    Well, I did not expect that high prices for nothing...
    Thanks for the video!

  • @sanjayKumar-sx5bv
    @sanjayKumar-sx5bv Рік тому +3

    If you use windows you don't have privacy
    That is so accurate

  • @TroySchulz
    @TroySchulz Рік тому

    Totally unrelated, but I'm diggin' the Gil Grissom look rather than Mr Babyface. Makes you look more "seasoned" and knowledgeable. 😉👍

  • @briianhebert
    @briianhebert Рік тому

    Thanks for the video!

  • @wilfridtaylor
    @wilfridtaylor Рік тому

    Sounds like we need a lets encrypt like service in this space. We used to see the same bullshit for SSL certs on sites too.

  • @davidpetersonharvey
    @davidpetersonharvey Рік тому +3

    Unfortunately, you sound spot on. Fortunately, I ditched Windows as my daily driver some time ago.

  • @mypeeps1965
    @mypeeps1965 Рік тому +5

    I use Bitdefender paid version. I buy it every 2 years when it goes on sale. 2 year key, 7 devices for $14 on ebay.

    • @IanIanIII
      @IanIanIII Рік тому +1

      💀

    • @sudo11
      @sudo11 Рік тому +1

      Is the company directly selling it on ebay?

    • @ClifffSVK
      @ClifffSVK Рік тому +5

      So you're probably paying for a virus instead of an antivirus lol

    • @mypeeps1965
      @mypeeps1965 Рік тому

      @@ClifffSVK it's NOT a virus. Your just trolling..lol. every year at the end of December thru the 1st part of January Bitdefender goes on sale for less than half the normal price.

    • @mypeeps1965
      @mypeeps1965 Рік тому

      @@sudo11 yes, see below.

  • @twistfire74
    @twistfire74 Рік тому

    Hey Chris, love your work. I just got a new budget gaming laptop. Ryzen 7 5800H, RTX 3060, 16bg ram, 1 TB NVMe But it came with Win 11. I really want to use Win 10 still yet. Would I be best served by creating a bootable USB drive with win 10? I have a Win 10 Pro key. I don't even want to waste my time for a sec on win 11. This won't effect the machine? To just install 10 even though it never ran win 10 on it?

  • @TheCocoaDaddy
    @TheCocoaDaddy Рік тому

    The only time I've seen Windows Defender detect anything is during tests of it in videos I see here. PC Security channel videos, mostly. "In the real world", the ONLY time I've seen Windows Defender 'detect' anything was in a scam web page designed to trick the user into thinking Defender found child pr0n on the user's computer. In all of the computers I've worked on where Windows Defender was running, I've noticed two things: 1) Defender hasn't detected or blocked anything and the system was free of viruses or malware; 2) Defender didn't detect or block anything and the system had malware running which I had to deal with. How is it that I NEVER see anything Defender has blocked or put in quarantine across a handful of Windows systems (handful = 10-15) I've dealt with over the past decade? Is it a personal thing with me? lol Great video! Interesting points about "Smartscreen". Recently, I've been dealing with frustrations using "Controlled Folder Access". Anyway, thanks for posting!

  • @RASELMX
    @RASELMX Рік тому

    I would never use windows if my fingerprint works as a touch/tap to unlock fingerprint instead of swipe to unlock fingerprint in Linux. Please help me sir Chris

    • @RASELMX
      @RASELMX Рік тому

      It's a Asus vivobook laptop with Elan drivers.

  • @gregbirger5810
    @gregbirger5810 Рік тому +8

    In Microsoft's "perfect world", we - the end users - would not be able to install any software on our computers that didn't come from the Microsoft store. Of course MS knows that's not going to fly, so you're right - they will put up obstacles as much as they can, like smartscreen. Personally I'm shocked how much privacy invasion MS has been able to get away with, but Win11 adoption seems to show people in general don't care about it enough to switch OS usage at scale.
    I'll continue to stick with Linux and a highly customized, ameliorated++ version of Win10 for gaming & the rare program that just won't work on anything else. Have been dual booting for ~15 years now, really just part of SOP.
    Started using Windows with v.3.1. On top of DOS. Moved on to 95, 98, NT, XP, 7 (still the best overall windows experience in my opinion), then 10. Entirely skipped Vista, 8, & 8.1. End of the windows line for me, not going to use 11 or what follows based on Microsoft's business practices & trajectory, even with new hardware.

    • @zilog1
      @zilog1 Рік тому +3

      They are just Apple with a different logo :)

    • @TimeoutMegagameplays
      @TimeoutMegagameplays Рік тому +1

      @@zilog1 And worse products LOL. At least Apple gives you something in exchange for the walled garden and people seem to like it...

    • @zilog1
      @zilog1 Рік тому +1

      @@TimeoutMegagameplays HAH you are funny. apple giving you something out of their "goodness of their heart" People like it because the marketing material is good and its a status/pop symbol. people like them because the average person doenst know or give a shit about tech to know any better. Its all a scam dude :/
      Dont defend that trash company smh. they dont give you crap

    • @TimeoutMegagameplays
      @TimeoutMegagameplays Рік тому +2

      @@zilog1 I don't defend them, I don't own Apple products (I'm a Linux enjoyer myself), but honestly if someone asks me if they should buy a Surface Laptop or a Macbook and price isn't a problem for them I will 100% of the time recommend the Macbook. Apple is not a good company, it's predatory, but their business model is still healthier than the one Microsoft employs on their products and consumers (which arguably are the products themselves).

    • @zilog1
      @zilog1 Рік тому +1

      @@TimeoutMegagameplays Framework laptop + PopOS

  • @mr.f3134
    @mr.f3134 Рік тому

    Thanks for sharing!

  • @yehonatan2020
    @yehonatan2020 Рік тому +1

    Chris, how do we remove Windows Defender completely from windows 11?

    • @pfeerick
      @pfeerick Рік тому

      You uninstall windows and install Linux :P but more seriously, installing another av product such as bitdefender should turn defender off automatically.

    • @yehonatan2020
      @yehonatan2020 Рік тому +1

      @@pfeerick I already run Arch Linux. And I wouldn't want to install something else. I just want to know how to get rid of it completely. Im sure if you delete the program from the programs folder it just comes back

    • @pfeerick
      @pfeerick Рік тому

      @@yehonatan2020 well, naturally, by design it would... Would you not expect your antivirus program to have protections from it being removed? But I'm sure someone has figured out how to strip it out from the install ISO, and patch any gaps. I'm a ubuntu/Windows user myself, as I found the arch curve a bit too steep. This is yet another thing making me want to totally dump MS though. But like the mafia... Their machinations run deep. :/

  • @gorilladev
    @gorilladev Рік тому

    What about ClamAV for windows ?

  • @randomgaminginfullhd7347
    @randomgaminginfullhd7347 Рік тому +1

    I have been using Kaspersky TS for years and have never got a single malware even tho I have downloaded a f ton of stuff.

  • @princemjmc
    @princemjmc Рік тому +2

    The thumbnail is perfect!

  • @weekendtech
    @weekendtech Рік тому

    Don't you need EV for Kernel Mode Driver Signing?

  • @gnulinuxoffline
    @gnulinuxoffline Рік тому +5

    That was one of the reasons I've been using Fedora Linux for a long time. Actually, if you don't need it, for work or something else, apps that only work in Win# moving to Linux is the healthiest thing to do. Greetings Chris!

  • @Fullmetal.Alchemist
    @Fullmetal.Alchemist Рік тому +7

    Malwarebytes Antimalware for me

    • @tonyrums
      @tonyrums Рік тому +1

      Agreed. That's been my go to for over a decade now

  • @syrefaen
    @syrefaen Рік тому

    Thanks for info

  • @ZeroB4NG
    @ZeroB4NG Рік тому +1

    I don't use AV software, i disabled Defender and i disabled UAC...

  • @markconger8049
    @markconger8049 Рік тому +18

    I haven’t used Windows for years. Thought I’d watch this video to see what’s going on in Windows world. Good grief! I’m all Linux now. Glad I switched.

  • @rallisf1
    @rallisf1 Рік тому

    Yup, the whole code signing scheme is totally a mafia system. The cheapest issuer I could find was certum, who has special open source certificates but still not 100% smartscreen-proof like the EV ones. Another solution would be to ditribute your self-signed key along with the software but that makes more sense for an enterprise internal tool of some kind. There's sigstore for containers and linux apps but doesn't help with smartscreen (you can pracically sign anything with sigstore, it just ain't trusted by MS or Apple). Apple only trusts its own certificates btw and they sign your app themselves upon auditing (on every update/version), which can take months if you have the slightest mistake in your app manifest...

  • @simpeers
    @simpeers Рік тому

    Sounds like the same sort of experience as when making iOS apps. You pay Apple 99 dólares a year for the privilege of being able to upload your apps to the app store, which they can revoke at any time if breaching the agreement (but Sir, of course, you might think), and then having to maintain signing certificates for signing the apps and so on.
    That's for being able to distribute to end consumers. There's a different one price and certificate type for if you want to distribute your app as an in-house app etc.

  • @rubikzombie
    @rubikzombie Рік тому +40

    Thanks again Dude for telling it like it is. Another reason why I switched to Linux for sure.

  • @logicalfundy
    @logicalfundy Рік тому +1

    Also, it's curious that you're claiming that even removing telemetry is not any better for your privacy in Windows, and it's still invading privacy? How so?

    • @ChrisTitusTech
      @ChrisTitusTech  Рік тому +1

      There is still about 10-15 processes that are part of Windows phoning home. You can use the app TCPview (provided by Microsoft) to see it yourself.

  • @christ6968
    @christ6968 Рік тому

    Doesn't the other OS Apple do something similar (if you don't pay your not getting in)

  • @tomspencer1364
    @tomspencer1364 Рік тому +4

    I am already laughing at 2 minutes. MS shady weirdness? Who would have thunk?
    Edit: Well, it sucks, but most people seem happy to be ripped off for billions of dollars by what amounts to a monopoly of a product that needs to be fixed to work well -- or at all.

  • @v.vangent.2904
    @v.vangent.2904 Рік тому

    Believe it Chris, remember back in the day nobody could prove a thing with the internet explorer thing. And what did we find out eventualy.....!!?

  • @cackoocacho1629
    @cackoocacho1629 Рік тому +1

    0:52 MS has never once been 'good guy', or 'awesome', in its entire history. Not once. These people would charge you for every breath of air you breathe, if they could.
    First thing to die in a Windows installation of mine, is "Windows Defender", and "SmartScreen". I rip them both out of my install ISO entirely.

  • @mikeoxlong4043
    @mikeoxlong4043 Рік тому

    looks like even ur average dev needs to pay for mafia protection

  • @zilog1
    @zilog1 Рік тому +2

    you know there are people in here like "tHiS iS wHy i uSe a mAc"
    *snrk

  • @jimwiltshire6824
    @jimwiltshire6824 Рік тому +2

    Your payment for getting "Validation' or 'Extended Validation' was a waste of money Chris. I've had to manually turn off Windows Defender. And I do have your '.exe' file version of your program. Windows "Smart Screen" is just too stupidly intrusive. Incidentally, having a signed version of your program ALSO DOES NOT MATTER with either Malwarebytes AntiMalware or Trend Micro. They BOTH declare it a virus. Malwarebytes is particularly aggressive & persistent in doing so, even after following their instructions to Allow it, and Never show it as a virus. This includes, most recently, declaring the UNPACKED file a virus. Incidentally, I have several computers, before anyone accuses me of using multiple anti virus programs on one computer & getting conflicts as a result. Several days later, Trend Micro has been removed permanently, from one machine, and Malwarebytes removed & reloaded on another. No further problem. Sorry Chris.

  •  Рік тому +1

    Imagine having to pay to publish software so that it isn't considered malicious instead of having an AV that actually detects real malicious software

  • @AmrHazem_EG
    @AmrHazem_EG Рік тому +1

    you came in a good time, yesterday I decided to kill anti malware executable service! cause it uses a lot of ram.

  • @mccrh7737
    @mccrh7737 Рік тому +3

    Good video and yes sad but true. As a developer I have seen the same kind of fuckery and as a tech I recommend Avira AV 100%.

    • @TheCocoaDaddy
      @TheCocoaDaddy Рік тому +1

      So, you're the other Avira fan out there. :) I'm a fan of Avira as well but I must admit, BitDefender (free version) does interest me.

    • @mccrh7737
      @mccrh7737 Рік тому +2

      @@TheCocoaDaddy Been using Avira since the early 2000s and compared to other AV programs, it's 100% effective. As well for my clients, I have had no complaints in almost 20+ years :)

  • @mtech1961
    @mtech1961 Рік тому +1

    Bit defender sucks for sys admins as you have to boot up in safe mode to uninstall certain programs. PITA. My Wholesalers sell Bitdefender 3 Licence for equivalent of $8 and $12 for 5 User. Most of my work is remote and booting up in safe mode is a PITA with BD.

  • @PS_Tube
    @PS_Tube Рік тому +2

    Choosing an antivirus besides Defender then my go choice is Sophos.

  • @xodus02
    @xodus02 Рік тому +1

    Let's not forget that Windows Defender is a resource hog, making your PC really slow. I have it disabled from gpedit and regedit on every install.

  • @quantumbits1952
    @quantumbits1952 Рік тому +1

    I have duel booted Linux and win 11
    No third party antivirus installed
    Whenever I boot into windows the fan just ramps up just after startup on idle
    Why??
    I opened the task manager and it's antimalware service executable (AKA Windows Defender) consuming 30% of my CPU and 50% of ram ( 4 core and 8 gigs )
    😡😤
    Then i boot into Linux
    It's a breath of fresh air
    and my laptop stays quite and cool
    😇😌

  • @wilet.3088
    @wilet.3088 Рік тому

    "You have to pay us for protection". Doesn't sound like a mafia at all lol

  • @MichaelMantion
    @MichaelMantion Рік тому

    Update on Lenovo Chromebook please

  • @likebot.
    @likebot. Рік тому

    the irony.
    So many programs you'd download that have paid the extortion can be backdoors to your system. And don't get me started on Cortana...