Live data from Hacker News

Using fake reviews to find dangerous extensions

krebsonsecurity.com

101–105 of 105 posts

Re: Using fake reviews to find dangerous extensions

#101

I'm surprised anyone ever installs browser extensions, given how many malicious extensions exist, and how intrusive they are whether malicious or not.

Yeah. The only extensions people should install are uBlock Origin and EFF extensions like Privacy Badger. All others are potential malware. I get downvoted a lot every time I post this here.

The downvotes are probably from talking about downvotes, as per site rules?

Re: Using fake reviews to find dangerous extensions

#102

Earlier quoted context omitted.

I moved from old HoverZoom to Imagus, wasn't aware a reboot of HoverZoom around, thanks for sharing. I'm curious how the sieves and also writing custom sieves compare, if anyone has experience with both.

Imagus has been abandoned by the developer. Its no longer work on many sites

Makes sense, recently had it break with a couple sites, and I noticed the seive is a big json file it downloads from its own server. Will try Hoverzoom+ and see how it goes.

Re: Using fake reviews to find dangerous extensions

#103

Earlier quoted context omitted.

The trust industry is awful and somehow Google and Apple came up with worse versions. Simple domain validated publishing similar to Let's Encrypt would be way better for devs and users, but that would require Google and Apple to give up control and that doesn't happen in monopoly markets. Edit: And Microsoft. Between them those 3 companies are the gatekeepers of almost all (signed) app distribution.

> The trust industry is awful and somehow Google and Apple came up with worse versions. You're putting them in the same bucket, but TFA calls out Google (and not Apple) for good reason. > Between them those 3 companies are the gatekeepers of almost all (signed) app distribution. And? I'm assuming you're not saying "software should not be signed", in which case I'm missing your point.

> And? I'm assuming you're not saying "software should not be signed", in which case I'm missing your point.

You're right. I'm not saying "software should not be signed". What I'm saying is the current trust industry is providing almost no value.

When I run an application on Windows that passes SmartScreen, all I know is that some company somewhere paid for an EV code signing certificate. In most cases, I don't know who the company is and don't have a way of finding out. That doesn't benefit me at all and most normal users misunderstand it to mean the company is trustworthy when that's not the case.

I've seen enough malware and adware signed with EV certificates that I personally place their value at zero. That's also influenced by my own experience in getting code signing certificates where the process used by CAs for identity verification are not anything official, but seem to be a rigid checklist of items that needs to be followed by someone with no cultural or local knowledge of my jurisdiction. IE: Easy to game once you know the process.

So, for me, the way code is currently signed tells me that someone had $2k USD to start a company and buy an EV certificate. That's it.

When I say that simple, domain validated code signing would be more useful for devs and users, I mean that I'd prefer to have the (ex:) UAC prompt tell me "This application is distributed by example.com" rather than "This application is distributed by Example XYZ LLC". I have a much better chance of determining the trustworthiness of the signer by knowing their domain than I do by knowing their registered business name.

And when I say Google and Apple are worse, I mean they've created systems that are completely opaque. It's "trust us" and they've both demonstrated repeatedly that they aren't worthy of being trusted.

As a specific example for Apple, there was a fake Fall Guys app on their store when it was at peak popularity. The fake app used the IP of the real one to trick users. Starting with the assumption that Apple's capable of ensuring that doesn't happen, you assume it's a legit app. If you expect to see what "website" (aka domain) is distributing the app it gets much easier.

Distributed by fallguys.com vs distributed by fallguysapp.com is the worst IP squatting you'd see and I could visit both sites if I wasn't satisfied enough assuming the more valuable domain is the real app creator.

In addition to that, IP squatting via a domain has a well established set of rules for trademark disputes, so a publisher can take action immediately to protect their trademarks rather than begging Apple or Google to take down a fake app.

The problem with a "good" system is that Apple, Google, and Microsoft have to give up control in order to let publishers self police their IP / trademarks and none of them will do that.

IMHO, anyone doing curation should be liable for IP theft and trademark violations. I have that opinion about _all_ online providers. As soon as they start curating or moderating they should be liable as if they're a publisher / distributor.

Re: Using fake reviews to find dangerous extensions

#104

Earlier quoted context omitted.

Yeah. The only extensions people should install are uBlock Origin and EFF extensions like Privacy Badger. All others are potential malware. I get downvoted a lot every time I post this here.

The downvotes are probably from talking about downvotes, as per site rules?

I never mentioned downvotes before though.

Re: Using fake reviews to find dangerous extensions

#105
post #68

Earlier quoted context omitted.

Do you think reporting these requests to the store(s) in question might result in investigation, or at the least, a list of suspicious investors to use to vet extensions/apps?

I don't think that would be useful, for two reasons: 1. What rules are being violated by these offers? It is what happens after the sale might break the rules but I can't report someone for having bad intentions. 2. I do not believe Google would be interested in spending even a minute of their precious human time to do any real investigation. If they can't automate the solution then they ignore the problem.

> 1. What rules are being violated by these offers? It is what happens after the sale might break the rules but I can't report someone for having bad intentions.

They might be people who were already banned for modifying other extensions into malware, back at it again on a new account. The hint that they're trying the same tactic might be enough to link their previous and new accounts, and then ban them again.

Post reply on HN