Live data from Hacker News

CNet's Download.com now bundling Nmap with malware

seclists.org

41–50 of 71 posts

Re: CNet's Download.com now bundling Nmap with malware

#41
post #33

This should be sufficient cause for all web filters and security software to block access to CNET due to the malware. But will it actually happen, or are they treated with a special standard?

As the "malware" is only downloaded after you installed a download manager, I doubt the Cnet website will get marked as the distributor. I believe it goes like this: - User clicks on link to download software - User is being asked to install Cnet download manager - Download manager downloads more software, including the crapware Because the actual download does not happen on the Cnet site, it does not gets marked as…

[deleted]

Re: CNet's Download.com now bundling Nmap with malware

#42
post #12

This is one upside to using trusted repositories with signed applications in the Linux Distribution model. It's not perfect but at least this kind of sadness doesn't happen. There's no good reason this couldn't be done for Windows as well; it's just that users are conditioned to download from assorted random sites to collect the apps they want. Would be a good community project which would likely attract the kinds of…

More to the point: if you pick the right distribution, there's at least a stated policy of not doing crap like this.

Debian has a social contract (http://www.debian.org/social_contract ), a constitution (http://www.debian.org/devel/constitution ), and a policy (http://www.debian.org/doc/debian-policy/). Each of these serves to describe what the Debian Project does, and more importantly, doesn't do. The social contract clearly states "Our priorities are our users and free software". Software which violates this principle will, at the very least, generate rancorous debate, if not be pulled outright. Odds are very good that behavior such as that CBSi / CNET / Download.com has exhibited would NOT be tolerated.

This is among the key benefits of using Free Software (in the FSF sense). You aren't the enemy or product of your software vendor. You are the goal.

I've got very strong reasons for believing that the Microsoft Windows applications model is fundamentally and philosophically incompatible with this mode of operation.

The Mac world seems slightly better, but it's likewise got some serious conflicts of interest, though there's far less a record of useless OEM bundling (forbidden by Apple) and force / drive-by installs. Mostly due to Apple's very focused attention on the end-user experience, if not freedom.

Re: CNet's Download.com now bundling Nmap with malware

#43
This seems to a phenomenon unique to Windows and growing.

No wonder everybody complains about Windows being slow and full of popups and spam, almost everything you try and install on it seems to want to also install some free trial/browser toolbar/sign up for some online service etc.

Re: CNet's Download.com now bundling Nmap with malware

#44

Earlier quoted context omitted.

Yes. Download.com is the 173rd highest traffic site in the world. They're probably pushing over 100-200k downloads a month at least. Nothing compared to the Apple or Android app stores, but still a significant number.

I'm guestimating that you're off by an order of magnitude. According to Alexa, somewhere between 0.6% and 0.8% of the entire web goes there every day.

Download.com users are probably over-represented on Alexa simply because of all the tracking crapware they have installed.

Re: CNet's Download.com now bundling Nmap with malware

#45
post #4

Off the topic here, are there still many people download software programs from download sites, like download.com, brothersoft.com or softpedia?

I pulled my apps from download.com years ago because the traffic was neglibile. It's probably alright if you are in the top ten for a category, otherwise there are much better ways to promote your software.

Re: CNet's Download.com now bundling Nmap with malware

#46
post #37

Shit. I just found that my application which was updated last week and is the 10th most popular system utility app on Download.com is also being similarly bundled [1]. This was not the case last week. I think Softpedia and FileHippo are the only big sites left not doing this ridiculous practice. I'm debating whether or not to pull the application listing. What do you guys think? [1]: http://download.cnet.com/EasyBCD/…

While you're here: The gallery link appears to 404: ( http://neosmart.net/EasyBCD/gallery/album/view/neosmart/Easy... )

Thanks. It was a absolute link missing the leading / so it went elsewhere. Should point to http://neosmart.net/gallery/album/view/neosmart/EasyBCD/Easy... now!

Re: CNet's Download.com now bundling Nmap with malware

#48
post #39
post #16

Earlier quoted context omitted.

Until this story hits mainstream, there's no hope of that happening. Even if it does hit mainstream, you need a bunch of talking heads that are able to explain to luddites what the implications are.

One can hope it destroys the brand for power-users. It's been a while since I've been using windows, but in the past I've trusted download.com when I needed some piece of freeware. I'll be more careful now. What about all the the open source projects hosted there? A quick search shows that they offer VLC and Firefox - are they clean?

The guy in the Nmap mailing list says

    I've just discovered that C|Net's Download.Com site has started
    wrapping their Nmap downloads (as well as other free software
    like VLC)

Re: CNet's Download.com now bundling Nmap with malware

#49
post #47

Surely this is a case for a DMCA take down notice? If they are distributing the copyrighted software outside the terms of the licence, then they are violating copyright and the DMCA can come into play?

Yes, of course, that's exactly what the takedown notice is for. But only a copyright holder can send it (or someone legally allowed to act on their behalf).

Re: CNet's Download.com now bundling Nmap with malware

#50
There's something gone very wrong with download sites in the last few years. Aside from this nonsense I've noticed a predominance of very misleading advertisements on download sites (attempting to misdirect you into thinking an ad is your download link). The site owners have to know about this but it seems they don't care enough to do anything about it.

Given the cheapness of s3 storage and such-like I'd say it's smart to avoid hosting on download sites in general.

Post reply on HN