Security software can put computers at risk: study

Image
Press Trust of India Toronto
Last Updated : May 05 2016 | 2:42 PM IST
Is the antivirus programme running on your computer really making your computers safer to use, say for online banking? New research shows security software might actually make online computing less safe.
Researchers examined 14 commonly used software programmes that claim to make computers safer by protecting data, blocking out viruses or shielding users from questionable content on the internet.
They found that these programmes were doing more harm than good.
"Out of the products we analysed, we found that all of them lower the level of security normally provided by current browsers, and often bring serious security vulnerabilities," said Xavier de Carne de Carnavalet from Concordia University in Canada.
"While a couple of fishy ad-related products were known to behave badly in the same set-up, it was stunning to observe that products intended to bring security and safety to users can fail as badly," said de Carnavalet.
At the root of the problem is how security applications act as gatekeepers, filtering dangerous or unwanted elements by inspecting secure web pages before they reach the browser, researchers said.
Normally, browsers themselves have to check the certificate delivered by a website, and verify that it has been issued by a proper entity, called a Certification Authority (CA).
But security products make the computer "think" that they are themselves a fully entitled CA, thus allowing them to fool browsers into trusting any certificate issued by the products, researchers said.
The findings have important implications not only for everyday computer users, but also for the companies producing the software programmes themselves, they said.
"We reported our findings to the respective vendors so they can fix their products. Not all of them have responded yet, but we hope to bring their attention to these issues," said Mohammad Mannan from Concordia University.
"We also hope that our work will bring more awareness among users when choosing a security suite or software to protect their children's online activities," added de Carnavalet.
He cautioned that internet users should not view these security products as a panacea.
"We encourage consumers to keep their browser, operating system and other applications up-to-date, so that they benefit from the latest security patches," said de Carnavalet.
"Parental control apps exist that do not interfere with secure content, but merely block websites by their domain name, which is probably effective enough," he added.
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: May 05 2016 | 2:42 PM IST

Next Story