Technology in terms you understand. Sign up for the Confident Computing newsletter for weekly solutions to make your life easier. Click here and get The Ask Leo! Guide to Staying Safe on the Internet — FREE Edition as my thank you for subscribing!

Resist Those Dancing Bunnies

There are those who believe anti-malware applications aren’t needed. While I disagree with that as an absolute statement, if you really know what you’re doing — deeply — then it may be possible to be relatively safe on your own.

It’s not something I advise at all, since it relies on being 100% right 100% of the time when it comes to identifying and avoiding potential threats. Things have become much too complex to rely on that kind of accuracy.

Not only do I advise running anti-malware tools, I run them myself.

The real problem is something else entirely.

Become a Patron of Ask Leo! and go ad-free!

All the security software in the world can’t protect you from yourself. It’s important to remain skeptical, and pay attention to the warnings that your security tools  give you. Don’t bypass them based on the fake promises of malware authors.

Dancing Bunnies

The real problem is, even with those tools in place, there’s no way to avoid what’s been called the Dancing Bunnies Problem1.

It works like this: if users receive an email saying, “Click here to see dancing bunnies”, a significant number of them are going to circumvent any and every protection the system might have in place.

They want to see dancing bunnies, dammit, and nothing’s going to get in their way.

That’s one form of what’s called “social engineering”: promise something you know will cause people to bypass security measures so as to get you whatever you really had in mind.

Dancing Bunny! At that point, it doesn’t matter what the ideal operating system is or even what the best anti-malware tool is. We’ve all seen or heard of users who very carefully and determinedly dismiss, ignore, or otherwise bypass every warning and every roadblock put in place to keep them safe, simply to see those dancing bunnies.

Don’t be that person.

Pay attention to your tools

Pay attention to what security tools and measures tell you. If your anti-malware tools throw up a warning, STOP. Yes, it could be a false positive, though most often it’s not. It could be an annoyance, but it’s an annoyance meant to keep you safe.


Do some research before you proceed. Read the messages your anti-malware tool is giving you, as well as any additional information it offers. Search the internet to see what others’ experiences have been in your situation. Ask a trusted adviser. Get more information before proceeding.

Your security tools are warning you for a reason.

Remember, once your machine has been compromised by malware, it’s not your machine any more. Once your account has been hacked into, it’s not your account any more.

The cost of failure in scenarios like this can be very, very high.

And it’s extremely likely that there are no dancing bunnies at all, no matter what you’ve been promised.

If you found this article helpful, I'm sure you'll also love Confident Computing! My weekly email newsletter is full of articles that help you solve problems, stay safe, and give you more confidence with technology. Subscribe now and I'll see you there soon,


Podcast audio


Footnotes & references

1: Larry Osterman, a Long time Microsoft developer who started there a year after I did, posted some years ago discussing dancing bunnies.

19 comments on “Resist Those Dancing Bunnies”

  1. Excellent article! I couldn’t agree more, and I like the title – it fits so well. Of the many friend’s computers that I get to put back on track, the “Dancing Bunnies” likely caused 90% of the problems.

  2. This is so true. There is no software in the world that can protect people from their own stubborn stupidity. I have a customer whose computer keeps getting infected. He knows where it’s happening. Certain adult websites he visits. However, he won’t stop visiting those websites, even though he knows what is going to happen to his computer when he goes there. He just won’t. His argument is that there should be software that will allow him to visit bad websites safely. Last time I checked, no one had yet perfected a condom for a computer. He keeps getting stung by these websites, but persists in going back. Makes no sense to me. I collect a check, though, every time he brings one of his laptops in to be cleaned up agaon.

  3. Those large share buttons that pop up on top of the text of this and other articles are annoying. Why not a bar at the top of the page?

      • Yes, but it’s annoying to have to do it on every article. If I haven’t read the article, how do I know if I want to share it? In another article, Leo says that if the advertising annoys us, we should tell the advertiser by not visiting their site. Does that mean Leo wants me to leave/unsubscribe?

        Actually, I notice that today there is a wider margin on the left side and the buttons fit in the margin, so the text is not hidden. That is a satisfactory compromise for me. So keep the margin and I’m happy.

  4. Hi Leo,
    Nowadays I find some websites (I mean the decent ones, and not the…!) displaying adds ‘You’ve won… Not a Joke..’ As I’m afraid clicking those ads, I want to know about them safely from you!

    • If it sounds too good to be true, it’s probably not true. Most sites – including Ask Leo! – have only limited control over the ads that are displayed.

  5. On my company email address I get a notable amount of unsolicited emails selling stuff that is totally unrelated to what we do. Examples from today’s batch include, separately, travel socks, a travel bag and knee braces. They’re quite well put together and appear to be genuine – they may well be. Except I’m pretty sure I’ve had exactly the same promo email but from different email addresses. That’s fishy! Why would a legit firm use different emails?

    The one thing they have in common is that right by the unsubscribe link (which I have not and will not click) is the identical full postal address in Florida. It wouldn’t surprise me if many of those reading this also get these emails from that source, too.

    I’m using Windows Live Mail and have set that whole address (and elements of it) as “delete Rules”. And yet I still get multiple emails from them every day. Any idea what gives here? Is my WLM Rule failing for some reason or have they got a way to bypass it? I’m partly technically curious about how come they make it through but also getting a bit hacked off that they do.

    OK, it’s not a dancing bunny, but the emails are attractive enough to make some folk open them up. I won’t but I’d like to know what’s up!


Leave a reply:

Before commenting please:

  • Read the article.
  • Comment on the article.
  • No personal information.
  • No spam.

Comments violating those rules will be removed. Comments that don't add value will be removed, including off-topic or content-free comments, or comments that look even a little bit like spam. All comments containing links and certain keywords will be moderated before publication.

I want comments to be valuable for everyone, including those who come later and take the time to read.