After months of problems with NIS10 (some still unresolved), yesterday I reinstalled NIS09 and am now on 16.8.0.41. Previously, I was on 17.1.0.19 and had been blocking 17.5.0.127 by running with Automatic Live Update off and just manually updating my virus defs. However, that started out only as a short-term work around and had already gone on for six weeks ... looked like it could easily go on indefinitely.
Things that drove me to this, in no particular order:
* Overly aggressive deletion of files by new SONAR2/cloud component in NIS10.
* Inadequate UI options to tweak SONAR2 and lack of proper integration with AP and SCAN exclusions.
* Extended fiasco of NIS10 UI not loading on my XP SP3 systems. Contrary to what Symantec has asserted that this was only a UI issue and that no security was compromised, I beg to differ. This is like saying to a driver while doing 60mph, "The road ahead is straight. I am now going to place this blind fold on you. I will remove it in maybe 30 minutes. There is nothing to worry about. Just drive straight.".
* Inability to run various applications due NIS10's problem with full screen resolution changing applications.
* Correction of critical problems extremely slow. In the order of weeks to months.
* No immediate work arounds provided to impacted customers.
The above is complicated by the forced streaming of both definition/rules and patches with no option to suspend patches without also halting streaming of definitions/rules. Symantec makes it difficult to avoid ending up on the latest patch even when you are fully aware that it has critical unresolved issues that directly impact you. Additionally, it is not easy or obvious how to get back to older patch versions and stay there.
After all of this, it seemed safest for my situation to go back to and remain on NIS09. I may well in the future decided to lag NIS upgrades by a year until NIS+2 has been released.
You may say that the above is compromising my security profile. Perhaps, but I just could not take being on the bleeding edge anymore.
Just curious if anyone has reached this conclusion as well? Or simply deferred upgrading to NIS10? Or switched to another product, but is still participating in these forums?
BTW, although this post is critical of NIS10 and Symantec's process model for doing things, it is not meant as an individual criticism of particular individuals who work for Symantec. Of course, NIS10 and the process model is ultimately the result of individuals, but there is no way looking in from the outside to know what happens within a large business.