Educause Security Discussion mailing list archives

Re: AV client for Macs


From: Russell Fulton <r.fulton () AUCKLAND AC NZ>
Date: Sat, 7 Nov 2009 21:49:08 +1300

On 6/11/2009, at 9:50 AM, Chris Green wrote:

We deployed Sophos for Mac AV.   It really was a PITA with FileVault
but seems to be well support these days.  It's a tad bit annoying
for an end user to install since they have install and then enter a
user/password for the installer but that's how they make everyone
pay up.



I echo Chris's comments about sophos.  I have not tired the latest
release with filevault on snow leopard but file vault and sophos have
not played well together in the past.

Currently I'm running F-secure AV for the Mac (Beta)  Free down load
-- seems to work (in the sense that it does not impact performance or
interfere with filevault) but who knows what protection it gives with
so little Mac malware actually in the wild (long may it stay that
way!).  It does not detect Windows malware -- that suits me as I often
deliberately have samples of windows malware on my mac book.  THis
used to be problematic with Sophos from  point of view of a security
professional.

I also know that some early betas failed to detect some generic unix
perl malware...

For the record we maintain two AV products, Nod32 for windows and
Sophos for Macs.  We currently do not mandate AV for Macs but want to
be in a position where we can deploy it quickly if we have to (we have
a fairly small number of licenses but maintain the servers and
updating infrastructure).

Russell



Current thread: