Lesson 4.4

4.4: Do You Need Antivirus?

9 minutes

Do You Need Antivirus?

The short answer, for almost everyone reading this: you already have it, it’s already running, and adding more rarely helps.

Windows ships with Microsoft Defender, a capable product that scores at or near the top of independent testing, updates itself, and costs nothing. macOS runs XProtect and Gatekeeper quietly underneath everything you do. Phones are locked down harder still: iOS doesn’t allow traditional antivirus to exist at all (apps can’t inspect each other), and Android’s Play Protect screens what you install. The built-in protection on every mainstream device in 2026 is what the paid products of 2010 wished they could be.

What third-party antivirus suites mostly add: a subscription fee, nag screens, browser toolbars of their own, and one more program granted deep access to everything on your machine. For a typical person practicing what this course teaches, that’s cost without benefit. (One fair carve-out: if you routinely handle risky downloads for work, or you’re the family member who fixes everyone else’s already-infected machines, a second-opinion scanner has its uses. That’s not most people.)

Where infections come from in 2026

The reason “install antivirus” feels safe but does little is that modern infections mostly don’t arrive as viruses in the old sense. They arrive as things you were talked into installing.

Fake installers. You search “download VLC” or “Zoom install,” click an ad sitting above the real result, and get a lookalike site serving the real program bundled with malware. The counter isn’t software; it’s habit. Download from the maker’s own site, and treat ads in search results as what they are: paid placements anyone can buy. This is Spot the Scam thinking, applied to downloads.

Cracked software and “free” premium apps. The pirated game, the licensed tool with the license removed, the “mod” from a Discord link. Running an untrusted stranger’s executable is the compromise. No scanner reliably un-decides that decision, and the machines from Module 1 don’t need to break in when you carry the payload inside yourself.

Browser extensions. This one deserves the most attention, because it’s where the real action is now. An extension runs inside your browser with whatever permissions it holds, and “read and change all your data on all websites” is a common ask. That’s every page you view and every field you type into, visible to a piece of software antivirus barely examines. Worse, extensions rot: a legitimate free extension gets sold, and its next silent auto-update delivers the new owner’s business model to every existing user. You audited app permissions in 4.1. Extensions are the same audit with higher stakes.

The hands-on: audit your extensions

Open your extension list — chrome://extensions in Chrome, Edge, or Brave; Safari → Settings → Extensions — and ask three questions of each one:

  1. Do I remember installing this, and do I still use it? If not, remove it. Remove, not disable.
  2. What can it read? Click Details and read the permissions. A coupon-finder that can read all data on all sites is a decision worth re-making deliberately, not a default worth keeping out of inertia.
  3. Do I have two doing one job? Redundant ad-blockers and shopping helpers multiply exposure for no benefit. Keep the one you trust.

A typical first audit removes half the list, and every removal shrinks an attack surface your antivirus never covered. It takes three minutes; do it before moving on.

The summary

Defender or XProtect on, which they already are. Downloads from real sources. Nothing cracked. Extensions few and audited. That combination beats any boxed security suite on the market, and most of it is judgment, which nobody can sell you. Next: the one device in your house nobody ever logs into.