University is Forcing Anti-Virus: Which one is lesser of the poisons?

So the university is forcing an an anti-virus installation if we want to establish a connection to their wifi. I'm a longtime mac user and think that anti-virus softwares do nothing but take up resources and steal data. But I have to choose one from the list below. SentinelOne seems to be their main choice and then Sophos. I've tried Sophos before but find it way too resource demanding as it's constantly updating its malware database.


Ultimately, does anybody know which one uses the least computer resources?


  • Avast
    • Business Antivirus
    • Mac Security
    • One
  • Avira
    • Free Antivirus
    • Mac Security
  • AVG 
    • AntiVirus
  • Bitdefender
    • Endpoint Security for Mac
    • Antivirus for Mac
    • Virus Scanner Plus
  • CrowdStrike
    • Falcon
  • Dr.Web
    • Dr.Web for MacOS
  • ESET
    • Endpoint Antivirus
    • Cyber Security
    • Cyber Security Pro
    • Endpoint Security
    • NOD32 Antivirus
  • Malwarebytes
    • Endpoint Protection
  • McAfee
    • All Access - Internet Security
    • AntiVirus Plus
    • Endpoint Protection for Mac
    • Endpoint Security for Mac
    • Internet Security
    • LiveSafe
    • Multi Access - Internet Security
    • Security
    • Total Protection
  • Norton
    • 360
    • AntiVirus
    • Internet Security
    • Security
  • SentinelOne
    • Sentinel Agent
  • Sophos
    • Home
    • Endpoint
    • Anti-Virus
  • Symantec
    • AntiVirus
    • Endpoint Protection
    • Endpoint Protection Cloud
  • Trend Micro 
    • Antivirus
    • Internet Security
    • Security
    • VirusBuster
    • Apex One (Mac) Security Agent


MacBook Pro 16″, macOS 14.3

Posted on Feb 5, 2024 12:12 AM

Reply
Question marked as Top-ranking reply

Posted on Feb 5, 2024 7:58 PM

I agree that MalwareBytes is probably the best option if they allow it.


However, if they insist on Sentinel One, then go with that one. My organization is currently using it and I have not seen it cause any major problems although it will falsely alert sometimes. I haven't really seen Sentinel One cause any Kernel Panics on my organization's Mac. My organization has so much other stuff installed on these Macs that I cannot say how much of a performance impact Sentinel One has on the Mac.


I can tell you that my organization has used Norton/Symantec & Sophos which were very problematic. I can tell you that most of the others on your list are just as bad. This forum is full of posts where those AV products caused Kernel Panic system crashes and/or severe performance impacts where the Mac was nearly unusable. Avast was caught selling users' personal information (IIRC they did it twice). AVG is owned by Avast (or Avast's parent company...I forget exactly).


My organization requires the use of Sentinel One to comply with their cyber insurance coverage.


Hope this helps.

18 replies
Question marked as Top-ranking reply

Feb 5, 2024 7:58 PM in response to alisheikhpour

I agree that MalwareBytes is probably the best option if they allow it.


However, if they insist on Sentinel One, then go with that one. My organization is currently using it and I have not seen it cause any major problems although it will falsely alert sometimes. I haven't really seen Sentinel One cause any Kernel Panics on my organization's Mac. My organization has so much other stuff installed on these Macs that I cannot say how much of a performance impact Sentinel One has on the Mac.


I can tell you that my organization has used Norton/Symantec & Sophos which were very problematic. I can tell you that most of the others on your list are just as bad. This forum is full of posts where those AV products caused Kernel Panic system crashes and/or severe performance impacts where the Mac was nearly unusable. Avast was caught selling users' personal information (IIRC they did it twice). AVG is owned by Avast (or Avast's parent company...I forget exactly).


My organization requires the use of Sentinel One to comply with their cyber insurance coverage.


Hope this helps.

Feb 5, 2024 6:24 AM in response to alisheikhpour

I don't have time to do this search myself, but you can do it.


Search for each of these in the forum along with "etrecheck". Use Google, not the site search tool. Google something like:


"bitdefender" "etrecheck" site:discussions.apple.com


This will tell you how many pieces each one installs. For example, Intego isn't on your list, but I know it is one of the more extreme, with maybe 15 different tasks it installs.


There are two things to look for. One is the number of launchd tasks that each installs. The other, more important issue to look for is the presence of modern "System Extensions". These are different than the old kernel extensions. System Extensions are very difficult to uninstall - impossible in some cases.


The irony here is that if your IT is this clues, they are probably clueless on multiple levels. You could locate an antivirus tool that has the least impact and install it. If it has system extensions, those have to be approved by you, the end user. You could choose not to approve them. You could also use the new "background items" user interface in Venura or Sonoma to prevent the other AV launchd tasks from running. This way, it would be installed, but not running.


Just so you know, blocked or not, the system extension will still be difficult or impossible to remove.

Feb 5, 2024 2:01 AM in response to alisheikhpour

If I may


University is a place for the Student to learn


There are times where it is appropriate to " Up-Teach " the IT Department and or Powers that Be at the University of how macOS is designed to protect from Non Existent Viruses that they fear are lurking around


Of course, this would need to be done with great tactic and diplomacy


The Operating System resides in a Sealed and Read Only Volume that can not be opened by the User nor by Third Party Applications.


The only Entity that can open and modify or alter this Volume is Apple.


Security. Built right in


Mac app security enhancements


 The Built in Security  is all that is required to protect the computer.

Feb 5, 2024 2:50 AM in response to alisheikhpour

It would appear, one of my more Learned Colleagues has presented the idea of war with the IT Department


That is not what was put forth " Of course, this would need to be done with great tactic and diplomacy "


The intent was to offer the IT Department with Facts suppled by Apple on how the OS is designed rather than how the Uneducated IT Depart may think it works

Feb 5, 2024 5:32 PM in response to alisheikhpour

alisheikhpour wrote:

I could be off here, but my initial thought was the school was doing this because our exams are administered on our own computers using “Examplify”.

I'm so glad I'm done with that. I would hate to be in higher education today.


Just so you know, you're playing with fire there. Early in the term, try to ensure that the officially blessed version of Examplify works with your Mac. Then, do not update your computer in any way or for any reason. Otherwise, you will get burned.


Apparently Exemplify has an iPad version. See if you can use that. The same rules apply, but the iPad version may be more stable - especially if you are being forced to use AV on your Mac. In any case, can't hurt to have a backup.

So if someone attempts to modify the software internally or whatnot, most of these AVs might flag the software as PUA?

These AVs will regularly flag system files as malicious. The better ones will detect about half of actual malware. Unfortunately, they rarely tell users what the actual files were. Instead, they only report their scary-sounding code names.

Alternatively, they’re trying to protect their own systems?

I'm sure that their own system has very poor security. No target is softer than higher ed IT. It's just a way to control people, that's all. They really don't like Mac users. They will push you to install AV and to install every latest update from Apple, but then they will require out-of-date versions of software like Examplify. When you can't do the exam or complete your coursework, it will be your problem. They'll blame you. They'll blame Apple. They are not your friends.

I don’t know but I sort of doubt the IT department is so selflessly trying to protect me from myself. The AV they’re pushing hardest is SentinelOne, but I’ve seen the logs IT admins can get from users using SentinelOne and it’s literally Big Brother on steroids.

While they definitely want to control you, they will not able to surveil all students' log files. I assume that if they require this software, they should have some way of ensuring compliance. You probably don't have to worry about personal data.


Here are the most popular AV products from EtreCheck reports:


SentinelOne, and any of the others, were all under 1%. Because SentinelOne has so few data points, I can't reliably judge its performance in detecting malware like I can the more popular products. Let's hope that with more SentinelOne data, it would show significantly better performance 😄.


However, I did find a few EtreCheck reports with SentinelOne installed:

FCPX 10.6.5 constantly crashes on MacOS 1… - Apple Community

late 2015 27" iMac keeps slowing down; sp… - Apple Community

https://discussions.apple.com/thread/254619275

https://discussions.apple.com/thread/254785658


So it looks like it has one network System Extension that is typically not running. As far as launchs tasks go, it's relatively high with 8 separate tasks. Because SentinelOne has so few installations, it's hard to judge how problematic it might be.


Generally speaking, if someone has power over you, it's best to keep them happy. If SentinelOne will make them happy, it should be fine.

Feb 5, 2024 4:41 AM in response to alisheikhpour

alisheikhpour wrote:

"Student expelled for attempting to be a smart-***..."


This is not being a "smart-***". It's fact.


Anyone or any thing claiming some specialized, proprietary knowledge superior to the company that develops and maintains macOS ought to be treated with extreme skepticism, if not outright ridicule. Whoever is advocating that policy belongs in the latter category.

Feb 5, 2024 11:44 AM in response to Yer_Man

I could be off here, but my initial thought was the school was doing this because our exams are administered on our own computers using “Examplify”. So if someone attempts to modify the software internally or whatnot, most of these AVs might flag the software as PUA? Alternatively, they’re trying to protect their own systems?


I don’t know but I sort of doubt the IT department is so selflessly trying to protect me from myself. The AV they’re pushing hardest is SentinelOne, but I’ve seen the logs IT admins can get from users using SentinelOne and it’s literally Big Brother on steroids.

Feb 5, 2024 3:59 PM in response to alisheikhpour

No, they are not trying to protect you from yourself. You don't really feature in their thinking. They are trying to protect their network - and indeed their jobs - from cr*p and malware on computers attached to the network. And even if they know it's pointless. they also know that - in the event of the network being compromised - someone further up the food chain is going to want to know if there was virus protection. And they are going to be able to say "Why Yes, we have X and Y installed and demand that all the students do too". And that will be their rear end covered.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

University is Forcing Anti-Virus: Which one is lesser of the poisons?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.