Live data from Hacker News

Show HN: I got hacked, felt paranoid, made an app – GlassWire

glasswire.com

301–310 of 341 posts

Re: Show HN: I got hacked, felt paranoid, made an app – GlassWire

#301

Another request from me for a Linux version! --- maybe related... I remember when switched to linux some years ago, the software I really missed was ZoneAlarm and still haven't find a nice alternative (for fast and easy control of the outbount(!)/inbound net trafic). I liked that I could block and unblock the internet access of each application from the systray icon. Any suggestions?

try ufw https://help.ubuntu.com/community/UFW pretty straight forward

What I would like to have: 1. a notification in real time: "Application FooApp tries to access internet (ip, port, etc)" and options like "Allow Now | Allow Today | Allow Always | Never Allow" (in the gui...) So I will get informed that an application is starting to send data.. and I could block it.

I think it's much easier to set the filters and k control list for the applications while you are using the pc rather than setting them up all at once.

2. "Internet & Bandwidth Usage Monitoring" similar to the Glasswire screenshots. (Stats, Application List that access the internet, hosts, etc) and feature to block with a click some of these (apps,ports,hosts) or all

do I ask a lot? :)

Re: Show HN: I got hacked, felt paranoid, made an app – GlassWire

#302
post #295

Hello all, The company that made this is: SecureMix LLC (est. 04/15/2014); aka Free Firewall Antivirus LLC (est. 10/17/2013); aka Blue Quail Capital, LLC (est. 06/21/2010). Here is the corporate registration: https://mycpa.cpa.state.tx.us/coa/servlet/cpa.app.coa.CoaGet... . The person opted to use a CPA (EDWARD H. GOWETT) to register their LLC (looks like a nice guy: https://www.linkedin.com/profile/view?id=34375436…

What's up with the doxxing? Has GlassWire done anything wrong?

How is searching Google while I sleepily sip my morning coffee "doxxing?" I don't even own a Guy Fawkes mask.

Re: Show HN: I got hacked, felt paranoid, made an app – GlassWire

#303
post #67
post #23

Earlier quoted context omitted.

GitHub for Windows is another beautifully designed Windows app. They even published a blog post about it: https://github.com/blog/1151-designing-github-for-windows

that app has less features than a rock.

Agreed. At least with a rock I can print off my source code, wrap it around the rock, and rapidly transfer it to my coworker.

Re: Show HN: I got hacked, felt paranoid, made an app – GlassWire

#305

Earlier quoted context omitted.

It's not just about screwing intentionally. Open source also helps with getting more eyes on the code. You need to be able to catch vulnerabilities before the bad guys or no amount of good reputation would survive. That is the primary reason for security software to be open source - reducing security by obfuscation and easy vulnerability check. That said, all software is written and audited by a group of individuals.…

That argument is often repeated and also that often falsified, that Open Source is better because there are more people who have an eye on it. I just want to mention: — The famous Debian-Bug, which lead to easily guessable "random" numbers. Nobody reviewed that code change for years. — SSL Heartbleed. Nobody reviewed the code change by that guy. Not even the maintainer reviewed it. So the problem with Open Source is,…

It's a problem with the people who make that assumption. Not everyone does.

Just because you have examples of code that wasn't reviewed properly doesn't mean it applies to all open source software. I personally have my eyes on open source quite often, and I know many others who do. I also know we wouldn't have our eyes on it if it weren't for the source.

Really, software being open source doesn't make it secure. It's just a precondition that allows us to find out if it is secure (and fix it when it isn't). If it isn't open source, then we should assume the worst, as we likely have no other way of knowing whether it's reasonably secure.

Re: Show HN: I got hacked, felt paranoid, made an app – GlassWire

#306

I wish there was something like this for my wifi router (or in the Tomato Firmware) because that way if there is a malware in the phone, or my laptop I can immediately know about it without installing this on each device. Also I hope it has list of known malware hosts for which it should give a huge red alert dialog if a connection is made to it.

I agree. I wonder what the best way would be for GlassWire to tap into the majority of routers? If you have some ideas please let me know. We're still investigating.

I use Networx( http://www.softperfect.com/products/networx/manual/?lang=Eng...) , they have SNMP & UPnP for monitoring routers. No idea how they actually do it, I'm afraid.

Re: Show HN: I got hacked, felt paranoid, made an app – GlassWire

#307

Earlier quoted context omitted.

It's not just about screwing intentionally. Open source also helps with getting more eyes on the code. You need to be able to catch vulnerabilities before the bad guys or no amount of good reputation would survive. That is the primary reason for security software to be open source - reducing security by obfuscation and easy vulnerability check. That said, all software is written and audited by a group of individuals.…

That argument is often repeated and also that often falsified, that Open Source is better because there are more people who have an eye on it. I just want to mention: — The famous Debian-Bug, which lead to easily guessable "random" numbers. Nobody reviewed that code change for years. — SSL Heartbleed. Nobody reviewed the code change by that guy. Not even the maintainer reviewed it. So the problem with Open Source is,…

> SSL Heartbleed. Nobody reviewed the code change by that guy. Not even the maintainer reviewed it.

I think this is a blatant counterexample actually.

The code _was_ reviewed. It passed the review. This just shows that security is hard and that reviews don't always catch everything.

But the only reason that heartbleed ever came to light was that OpenSSL is open source. Had it not been, such a bug would have been much much more difficult to find. Yes, this is not instant, yes, it takes time and leaves people vulnerable in that time, but it did work out in the end.

If a similar bug were to exist in proprietary software, there's a good chance it would never come to light at all. Save for the extremely dedicated intelligence agencies who may have the people and desire to exert the effort to find it. That's who proprietary security software helps.

The Debian bug isn't a terrible example, but it simply shows that distro-specific patches aren't well reviewed, not projects in general. Most people who want to see OpenSSL code go to OpenSSL, not Debian.

Bugs happen, reviewers miss things or may not look in the right places. Open source does not mean secure by any means, it simply removes some requirements of trust of a sole entity and eases reviews.

Re: Show HN: I got hacked, felt paranoid, made an app – GlassWire

#308
post #295

Earlier quoted context omitted.

What's up with the doxxing? Has GlassWire done anything wrong?

It is a made up title from a big $$$ company to promote their new app, that's what's wrong in the first place. How can you trust a company that uses a title like this to ultimately get you sign their licence and fetch your private data to make money out of it? This leads to being hacked with your own consent and that's why it is wrong and misleading. Try install the app and read the license to see what they want from…

There is no big company here and we don't even have an office. I currently have no ownership in any other businesses or products. Your graph data is never sent to our servers. We plan to make money via a paid software version with more features, for example the ability to monitor multiple remote servers. I agree that it wouldn't make sense to have a product like ours that collects user data.
Post reply on HN