This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

Security researcher trashes Sophos Antivirus in scathing report

by Shaun Nichols

06 Aug 2011

View Comments

  • Tweet this

Sophos is on the defensive after a report claimed that its anti-virus tools use flawed and ineffective techniques to protect against malware attacks.

Researcher Tavis Ormandy said in a paper and presentation titled 'Sophail' that Sophos Antivirus uses weak cryptographic techniques and poor malware signature detection, and is unable to prevent exploits on many systems.

Ultimately, Ormandy claimed that Sophos offers a "substandard product far exceeded by existing published solutions".

"The promise of anti-virus is that users will be less dependent on making good trust decisions," he said. "While certainly desirable, Sophos appears ill equipped to keep this promise with its current technology."

Sophos, meanwhile, issued a statement defending its Antivirus platform. Senior technology consultant Graham Cluley said in a blog post that the encryption tool mentioned in the report is being phased out and that, while it is working to address other vulnerabilities pointed out in the report, customers are not believed to be at risk.

"Having assessed the findings in Tavis's report, Sophos can assure customers that their protection is not compromised," Cluley wrote.

"We appreciate the help from Tavis Ormandy, and others like him in the research community, in working with us to make our products stronger and more secure."

Do you agree

blog comments powered by Disqus

Poll

Business security poll

How concerned are you by the rising tide of cyber threats?

15%

58%

10%

9%

8%

Popular Threads

Powered by Disqus
BlackBerry Q5

BlackBerry Q5 video demo

BlackBerry's latest smartphone is a mid-tier handset that will cost less than the Q10 and Z10

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

.Net Software Developer - C# / ASP.Net / SQL Server

.Net Software Developer - C# / ASP.Net / SQL Server...

Database Developer - SQL Server / T-SQL - Free iPad-mini

Database Developer - SQL Server / T-SQL / Stored Procedures...

Windows Developer - C# / WP8 / Mobile / Free iPad mini

Windows Developer - C# / WP8 / Metro / Mobile / Desktop...

C++ Low Latency Developer

C++ Low Latency Developer (C++, Multi-threading, sockets...

Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.

To send to more than one email address, simply separate each address with a comma.