Live data from Hacker News

CNet's Download.com now bundling Nmap with malware

seclists.org

61–70 of 71 posts

Re: CNet's Download.com now bundling Nmap with malware

#63
post #55

Earlier quoted context omitted.

It's not (most likely) the case of Microsoft going to them. Microsoft (as well as google) just pays for customers that you bring to their search. Many products make living out of it. Now, CNet just wanted to make more money. It's a shady practice to do it this way, but Microsoft shouldn't be the one to blame.

I'm not buying this idea that Microsoft doesn't know what's going on. For CNet to make money on the deal, Microsoft would need a way to attribute the increased traffic to CNet. If Microsoft is paying them significant sums and yet remaining willfully ignorant of the means, then Microsoft is no better than your bottom feeding pay-per-install malware services. The fact that we're even discussing Microsoft's reputation i…

The toolbar installation is optional. It might not be nice but I don't see why it should be forbidden from Microsoft's side as that's the point behind these partnership after all (same with Google). Every other product asks you to install their toolbar. The product in this case is downloader and most importantly CNet's traffic.

Re: CNet's Download.com now bundling Nmap with malware

#64
post #12

This is one upside to using trusted repositories with signed applications in the Linux Distribution model. It's not perfect but at least this kind of sadness doesn't happen. There's no good reason this couldn't be done for Windows as well; it's just that users are conditioned to download from assorted random sites to collect the apps they want. Would be a good community project which would likely attract the kinds of…

Yes, I do have one word of caution though:

I downloaded VLC to my netbook through apt-get and ran it from the terminal. When run from the terminal it was outputting errors like the below (not actual domains): cannot reach 442g.com => skipping... cannot reach muzak.com => skipping... cannot reach 3g3.com => skipping... cannot reach gewedw.com => skipping... cannot reach ewfr.com => skipping... I've always wondered why but never really looked into it.

Re: CNet's Download.com now bundling Nmap with malware

#66
post #63

Earlier quoted context omitted.

I'm not buying this idea that Microsoft doesn't know what's going on. For CNet to make money on the deal, Microsoft would need a way to attribute the increased traffic to CNet. If Microsoft is paying them significant sums and yet remaining willfully ignorant of the means, then Microsoft is no better than your bottom feeding pay-per-install malware services. The fact that we're even discussing Microsoft's reputation i…

The toolbar installation is optional. It might not be nice but I don't see why it should be forbidden from Microsoft's side as that's the point behind these partnership after all (same with Google). Every other product asks you to install their toolbar. The product in this case is downloader and most importantly CNet's traffic.

Hmm. I wonder if we'd find any of Microsoft's installers being wrapped in such a manner.

Re: CNet's Download.com now bundling Nmap with malware

#67
post #31

This is disgusting behavior from what could be considered the first "app store". What a shame.

First "app store"? Hello, Simtel? Tucows? and before them countless BBSes?

How about Stroud's? It's even still sort of up: http://cws.internet.com/

Re: CNet's Download.com now bundling Nmap with malware

#68
post #7

What an egregiousness abuse of user trust. I hope this destroys their brand forever.

It has in my mind. I feel sorry for all the users who would still trust them.

I feel sorry for anyone who's ever had to use download.com.

Re: CNet's Download.com now bundling Nmap with malware

#69
I work for CBSi just got this response from the dowload.com team:

"We remove the installer from pretty much all publishers who request it removed, and the wrapping of nmap was an error. Fyodor has been contacted and had the issue explained. The Download.com Installer has been removed from the product, and we shouldn't be wrapping open-source software. It was a mistake and when Fyodor contacted us, we fixed it."

Re: CNet's Download.com now bundling Nmap with malware

#70
post #12

This is one upside to using trusted repositories with signed applications in the Linux Distribution model. It's not perfect but at least this kind of sadness doesn't happen. There's no good reason this couldn't be done for Windows as well; it's just that users are conditioned to download from assorted random sites to collect the apps they want. Would be a good community project which would likely attract the kinds of…

Yes, I do have one word of caution though: I downloaded VLC to my netbook through apt-get and ran it from the terminal. When run from the terminal it was outputting errors like the below (not actual domains): cannot reach 442g.com => skipping... cannot reach muzak.com => skipping... cannot reach 3g3.com => skipping... cannot reach gewedw.com => skipping... cannot reach ewfr.com => skipping... I've always wondered why…

Perhaps it is looking for details of your music/CD/DVD. There is an option for it automatically fetch such details as a list of tracks, artist, etc, to display.
Post reply on HN