In
this thread, one of many on the DonationCoder forum where we are all screaming about the harm that lazy antivirus companies are doing with their false positives, I suggested that maybe we need to do something productive to encourage these companies to be more responsible about the alerts they show.
So today I want to begin that process by asking for your help in coming up with a short and clear list of requirements that would be worthy of our recognition for a new antivirus/anti-malware
standard that is focused not on the number of virus detections, but on how users are told about alerts which may be false positives, and how well they deal with false positives.
Once we've got something I'd like to make an official web page about this, and then try to contact the antivirus companies and maybe get some other websites that want to join us in this movement. And hopefully one day in the near future we will be able to give this award out to a company and lavish them with praise, recommendations, reviews, etc.
Let me start out with my first draft of requirements for what i'll call the DonationCoder "Superior Antivirus" Award/Certification:
When a suspected malware is found, the user must be presented with a dialog that clearly describes:
- The complete file path of the suspected file.
- A description of the suspected malware (not just some cryptic name), with an easy link to search the web for more info about this virus and the file found.
- A clear indication of the date that the antivirus signature matching the file was added, with a clear statement about the possibility that this may be a false positive, and telling the user some information about the confidence that the file is indeed a real malware vs a false positive. this should be a statement like "this is a generic rule of thumb pattern that was recently added, so the chance that this is in fact a false alarm and not a virus is quite high."
- In the alert there should be a url to take the person to the antivirus company's forum where they can talk to others about whether the problem is real or not.
- The user must be given an opportunity to not delete the file.
- The user must be given an alternative to go to a page where they can report a suspected false positive
- The user must be given the alternative to upload the file to an online site like virustotal for a second opinion.
Thoughts? What am i missing? Anything here that is asking too much?