MRG Effitas Online Banking Browser Security Assessment Project Q3 2013 – Q1 2014

Discussion in 'other anti-malware software' started by malexous, Jun 18, 2014.

Thread Status:
Not open for further replies.
  1. malexous

    malexous Registered Member

    Joined:
    Jun 18, 2010
    Posts:
    830
    Location:
    Ireland
    Norton Internet Security 21 has been out for nearly a year and they list Norton Internet Security 20.5.0.28 (released around May 2014) in their Q2 -2014 test.
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Well, the thing that bothers me about the MRG style of testing, is that they don´t explain how the malware is stopped. Are they stopped by signature or by HIPS? That would be interesting to know. For example, Wontok doesn´t use signatures AFAIK, so it´s relying completely on pro active defense methods. To me it ´s more impressive if these banking trojans are stopped by HIPS or so called "safe browsers". :)
     
  3. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    Strangely enough, in both tests, the same version of WSA is used. When WSA previously failed banking tests, they improved the Identity Shield and released a new version. This leaves me curious to know if they really block the information-stealing behavior from the SpyEye in question, or only updated the cloud heuristics to block these SpyEye variations.
     
  4. tgell

    tgell Registered Member

    Joined:
    Nov 12, 2004
    Posts:
    1,097
    The free version is MyPOQ. I have used it and there is no lag. IE needs an Active X plugin and Firefox needs Java I believe. When logging in, you can decide which version to use. I have not used it in awhile but if I remember correctly, there are 3 levels of protection available. When launched you get a new browser with a border around the window.

    https://www.quarri.com/products/mypoq/
     
  5. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    So you can keep using your own browser like IE and Firefox? But even though their protection methods seem to be superior, I just don´t like this approach.

    This is what annoys me also, I think MRG should clearly indicate how these attacks are stopped. I don´t care about signatures, I only care about the pro active defense part. :)
     
  6. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    Well not in all situations the future is already here. :thumb:

    2014-06-26_13-24-28.png

    TH
     
    Last edited: Jul 28, 2014
  7. tgell

    tgell Registered Member

    Joined:
    Nov 12, 2004
    Posts:
    1,097
    Yes, you use your own browser.
     
  8. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Can you give some more info about Webroot´s Identity Shield? Perhaps you can shed some light on post #53? :)

    https://www.wilderssecurity.com/thre...ct-q3-2013-q1-2014.365079/page-3#post-2394812

    Well, if that´s the case, I really wonder what kind of technique it´s using to protect the browser? For example, Wontok and Bitdefender use their own "safe browser".
     
  9. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
  10. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    @Rasheed187 this is the info I got:

    Thanks,

    Daniel :thumb:
     
    Last edited: Aug 1, 2014
  11. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    @ Triple Helix

    Thanks, but it´s still not really clear to me. From what I understand, the Identity Shield didn´t really block the SpyEye trojan, which is a bad thing. Apparently it´s caught by signature only. But I must say that the Identity Shield feature looks kinda cool, perhaps an idea to release it as a standalone product, like Prevx SafeOnline? :)
     
  12. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    I can't see that happen as all the modules are part of the whole and Prevx SafeOnline was still the whole product so nothing new there IMO.
     
  13. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    @ Triple Helix

    The reason why I asked, is because I´m not into security suites. I´m also not into dedicated "safe browsers". I´ve also read bad stuff about Trusteer Rapport, and Zemana and SpyShelter are horrible when it comes to the GUI. So I´m still looking for a good solution. :)
     
  14. Triple Helix

    Triple Helix Specialist

    Joined:
    Nov 20, 2004
    Posts:
    13,275
    Location:
    Ontario, Canada
    Last edited: Aug 4, 2014
  15. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    @ Triple Helix

    Thanks, but no thanks. Like I said I´m not into security suites, and I did read about Webroot, trust me. ;)

    By the way, I´ve found another app dedicated to online banking security, it also seems to be using the "safe browser" method of protection, perhaps some of you can check it out. :)

    http://www.k7computing.com/en/Product/k7-secureweb.php
     
    Last edited: Aug 2, 2014
  16. SweX

    SweX Registered Member

    Joined:
    Apr 21, 2007
    Posts:
    6,429
    I don't need some fancy feature or app for that, I just keep my PC malware free and connect to the bank via a secure connection that's all I need. :D
     
  17. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    Chris from MRG has given an explanation on the Webroot forum:

    https://community.webroot.com/t5/Community-Announcements/Nice-Report-Webroot/td-p/131554
     
  18. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    @ BoerenkoolMetWorst

    Thanks for the info, nice to know that Webroot fixed the problem. :)

    But it would have been nice if MRG could have posted that over here, since the question was raised in this thread. Although I appreciate the MRG tests, it´s disappointing that they haven´t responded to my questions in this thread. :thumbd:
     
  19. 1000db

    1000db Registered Member

    Joined:
    Jan 9, 2009
    Posts:
    718
    Location:
    Missouri
    Quarri's armored browser is designed to be used on a potentially infected machine.
     
  20. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    @ 1000db, I don´t get it, same goes for all other tools mentioned? :)
     
  21. 1000db

    1000db Registered Member

    Joined:
    Jan 9, 2009
    Posts:
    718
    Location:
    Missouri
    Not necessarily. Quarri's My Protect service is not a replacement for a locally installed security program. It's a service you could use on a public or shared use computer, to make a secure transaction without leaving traces. It has no ability to "detect" malicious files (or a simulator), it just blocks methods used by malware. I use it when I travel.
     
  22. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    @ 1000db,

    OK I see what you mean, however all other apps also claim that they can protect an already infected machine, that is what´s so cool about this type of technology. :)
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.