Site icon Panda Security Mediacenter

Deconstructing the urban myths in the IT security sector

The IT security industry is no stranger to urban myths: stories that spread and, over time, become accepted as general truths. With the collaboration of our communities on Facebook, Twitter and this blog, we have compiled the most popular urban myths about the security industry, and in particular about antivirus companies. Below we give you our take on each of these:

1. Antivirus security companies make the viruses. This is a claim we have often heard at Panda Security throughout our 20 years in the business, and no doubt the same goes for other companies in the sector. The claim is absurd, particularly if you think that we receive around 63,000 new viruses every day. What’s more if it were true, such a scandal would surely have been uncovered in the 20 or more years that the sector has been protecting users. One of the main problems that the industry has had to resolve has been how to cope with the workload of processing such an enormous number of threats to keep our users protected.

2. Security companies hire hackers. Of course we can’t speak on behalf of the entire industry, but at Panda Security this issue has been a concern for us and we have never knowingly contracted ‘black hat’ hackers. We have however hired (and we are always looking to) ‘white hat’ hackers. Another variation of this myth is that you have to be an IT engineer to work in security, which is also false. The profile of those who work at Panda is highly varied: engineers, mathematicians, physicists, self-taught, etc. What all of them have in common is a genuine interest -sometimes a real passion- in IT security.

3. There are no viruses for Mac, Linux or cell phone platforms. We would all like this to be true! It is commonly held that none of these present any risks to users, as viruses are only designed for Windows platforms. The truth is that there are viruses for all these platforms. The difference lies in the amount of threats circulating in comparison with those designed for Windows. The explanation is simple: Hackers are looking for profit. If the aim is to reach as many people as possible and consequently more potential victims to steal from, what is the best target? A platform with 10 million users or one with 500 million? The answer is obvious.

4. It requires a lot of knowledge to be a hacker, create viruses, infiltrate systems… in some cases yes, in others no. Some years ago it was difficult to develop viruses, worms, Trojans, etc., and it required technical know-how. In fact many of the hackers started out “playing around” while they learnt, and acquired significant knowledge of programming languages, communication protocols, etc. Today this is no longer necessary. In the case we witnessed recently with Operation Mariposa, those responsible had quite limited knowledge.

This is because kits are sold across the Internet which allow the uninitiated to generate and configure malware. We wouldn’t quite say that anyone can do it, but with a little bit of knowledge and dedication, it’s possible to construct, for example, a botnet capable of infecting millions of computers around the world.

5. Women don’t work in security companies. This assumption is as frequent as it is untrue. At Panda at least this is clearly untrue: more than 30% of the workforce are women, many in technical or management areas. This figure is growing, as an increasing amount of women are training for sectors such as IT security.

6. 100% security and privacy. There is no such thing as 100% security. Simply installing an antivirus does not guarantee 100% protection. In fact, nothing does. Every day, thousands of new threats are created, and these have to reach security laboratories before they can be analyzed and the corresponding vaccine created. Some of these new threats are located thanks to proactive technologies designed to detect unknown malware, but not all of them are.

From the moment a threat appears until the corresponding vaccine is provided, users are exposed to the risk of infection. On the other hand, not all security companies have absolutely all the new samples. Therefore, even if you have security software, there is still no such thing as 100% security. It continues to be a race in which the security companies are still, unfortunately, trailing the bad guys. For this reason it is advisable, in addition to having a good security suite, to pay heed to basic security recommendations.

The issue of privacy, however, is different. When we talk about privacy, we often refer to the information that we voluntarily share on social networks, either on Web communities or similar sites. In this case, no antivirus solution can prevent you from sharing such information. Good training and awareness about what you’re doing on these types of communities will help you to be prudent.

7. Viruses, viruses, viruses… there are many urban myths about viruses themselves. Let’s take a look at a few of them:

8. Conspiracy theories… In the 20 years our company has been in business, we have heard many conspiracy theories of all types. Obviously there are many which we can neither confirm or deny, because they are not in our hands… let’s take a look:

If you’re interested in these or other similar issues, we would be delighted to keep talking on Facebook, Twitter or through this blog.

We would also like to thank all of you for your help 😉

Exit mobile version