> Why would everyone be hosed just because a binary got committed to version control?
We’re hosed if someone submits malware to source control and other people run it?
> Either way, surely you can set up some policies or monitoring for that sort of thing.
Like a tool that comes with windows that checks that nobody has done that, called windows defender? The tool I have a problem with?
> I've been developing on Windows for decades without an antivirus and I've never had these issues
This is a 100 person company with maybe 30 programmers, 30 artists and 30 designers. I don’t know which of those people are “capable” - and the people who say they are are the people I probably trust least. In a perfect world we’d tell everyone to be careful, and not click on random phishing links, and they’d listen. But they don’t, and we have to take some basic precautions. Using the OS provided, historically good, tools is a good starting point.
> Are your people downloading and installing random software all the time?
Dunno, we don’t monitor what people do. We just get an email if defender quarantines something. But we’re dealing with people working from home, and being given gaming spec machines. I would put money in the fact that people are using these for personal use.