When is there too much security?

Adding layer after layer of security sometimes actually gets in the way of securing your computer.

By sjvn  4 comments

I was recently surprised when someone asked me what anti-virus programs they should be running. Note, he said 'programs,' not program, and that's what he meant. He thought that if one A/V (anti-viral) program would do him good then two or three would be even better.

Ah.... no, that's not how it works.

While it's certainly true that one A/V program will catching something that another program might miss, if you add layers of A/V software to one PC, you're asking for the two of them to clash with each other. The end result is a PC that will certainly run slower, and might very well stop working from time to time because of conflicts between them.

You're much better off if you just get one good A/V program and keep it updated.

The same is also true with firewall and other security programs. Multiple layers of the same kind of protection on a single PC just means that there are more ways for things to go wrong, not better, added protection.

It's a different story if you're running a network. Even on a small network you should have firewalls both on your PCs and on your server or device that stands between you and the Internet, like a SONICWall TZ or NSA Series appliance. You'll still need to make sure that everything works smoothly together. I can't count the number of times I've found that an Internet program was 'broken' because while one firewall let the software access its required port, another blocked it.

Finding and fixing that kind of problem comes with a network administrator's job. With so much malware and automated network attacks on the Internet, you have no choice but to block potentially dangerous connections from both your network as a whole and on each individual PC.

I also run a different A/V program on my servers, especially my mail server, than I do on my PCs. Since I'm not running the programs on the same box, I avoid the problems of conflicting programs, while making sure that I don't miss any problems on the servers.

Here again though I'm not going to run multiple programs to do the same job on the same box. If you try that, workstation or server, you're just asking for trouble. And, after all, the entire point of using security software in the first place is to avoid trouble.

4 comments

    Anonymous 2 years ago
    Sure having two firewalls ans several anti-virus running in the background is ridiculous.First, it's much better to have a proper firewall in an external box and not a kind of, running on the computer itself. Even at home (and I think a lot of people don't realize that there might well have one ready to be configured in their ADSL box)...As for AVs, it's good to have one (up-to-date) running in the background, however I must say that it helped me not to rely on a single tool when scanning my disks.Different tools have different scanning methods and different targets (virii, spyware, etc), and none is good at everything.I usually do three passes with three different scanners and it occurs that one detects something that the other ones didn't see.People should also think about disabling unneeded networking services such as network client and sharing (for Windows) on isolated home PC. They should also ensure not to install lots of arguably useful freebies that could open potential security holes.Those two last points is security by removing useless stuff instead of by loading the computer with extra stuff.
    Anonymous 2 years ago
    Right now I am helping somebody that had Shaw put Shaw Secure on their Laptop. After the install failed they tried to get it uninstalled. This didn't work and now they could not access the internet though IE. When I look at it I found they had 2 firewalls + plus what Shaw Secure left behind and 3 AntiVirus. I am having a very tough time reverting the changes as even a system restore won't work and have verified that the hardware is good by Ubuntu Live CD. I have only got the mail programs and the Windows updates working.
    Anonymous 2 years ago
    Avira Antivir + ThreatFire + Firefox NoScript + Sandbox + VM = Not too muchEach has caught many baddies.Also-Take disk image backup of the OS regularly-Run browser and email sandboxed or in a virtual machine-Keep your most valuable data off the netTF is one the least customizable HIPS out there, but recommendable just because of this: install it and it just works.
    Anonymous 2 years ago
    Too much security is when there's no single place to go and get a picture of where everything stands that doesn't require a geek to get it. A proper and effective security posture is one where a CEO can pull up a screen and decide for themselves if everything is AOK. Security is a process not a product.

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      SecurityWhite Papers & Webcasts

      White Paper

      Overcome Top 7 Admin Challenges of Active Directory

      As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

      White Paper

      Insiders Can Ruin Your Company. Take Action.

      Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

      White Paper

      Top Solutions and Tools to Prevent Devastating Malware

      Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

      White Paper

      Streamline Compliance and Increase ROI

      Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

      White Paper

      X-Ray of the PCI Process-4 Proactive Steps

      This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

      See more White Papers | Webcasts

      Ask a question

      Ask a Question