Live data from Hacker News

CNET Injecting Malware into Downloads

insecure.org

21–30 of 80 posts

Re: CNET Injecting Malware into Downloads

#21
post #8

Earlier quoted context omitted.

But this is ignorant and not true.

For laymen's purposes it pretty much is, though. When was the last time anyone on Linux/OSX got some adware / popups? I've also never heard of antivirus for Linux. Which doesn't mean there aren't viruses, it means it's not a concern on the most part.

http://www.clamav.net/ if you were actually wondering. There's also a sweet osx port: http://www.clamxav.com/

Re: CNET Injecting Malware into Downloads

#22

What good alternatives would people suggest? What should be the "goto" site we could suggest to a novice for finding a clean copy of almost any software...any suggestions? (Assuming that an expert user would straight to the source website)

filehippo is excellent, and they have a pretty good update checker (although that is obviously not as comprehensive as, say, sumo.)

Re: CNET Injecting Malware into Downloads

#23

What good alternatives would people suggest? What should be the "goto" site we could suggest to a novice for finding a clean copy of almost any software...any suggestions? (Assuming that an expert user would straight to the source website)

This is one reason app stores will continue to gain traction. It's a single place you can go and know you are getting the developer approved version, all with the addition of easy updates.

Re: CNET Injecting Malware into Downloads

#24
post #8
post #6

When my mother forwards me the latest malware scare chain letter she got frm her friends, I tell her to picture her computer as a plane flying at Mach 4, high above in the stratosphere, confident almost nothing launched from the ground can harm her. That's because she doesn't use Windows.

But this is ignorant and not true.

I can tell you that since she moved away from Windows, I never had to clean up her computer. Under Windows, it was a monthly chore.

I am aware there are attack vectors than can be employed against her setup, but the odds of something that could affect her friends also affecting her are vanishingly small - and I have never observed one of those on the wild. Education plays a role too and I took the steps to show her what looks fishy. Her box is also behind a very paranoid router that will page me if anything fishy starts to happen on her side of the network. It was so silent I programmed a weekly "lamp test" so I know it's still watching.

Re: CNET Injecting Malware into Downloads

#25
post #21

Earlier quoted context omitted.

For laymen's purposes it pretty much is, though. When was the last time anyone on Linux/OSX got some adware / popups? I've also never heard of antivirus for Linux. Which doesn't mean there aren't viruses, it means it's not a concern on the most part.

http://www.clamav.net/ if you were actually wondering. There's also a sweet osx port: http://www.clamxav.com/

Did you ever catch something with it?

Re: CNET Injecting Malware into Downloads

#26
post #18

What good alternatives would people suggest? What should be the "goto" site we could suggest to a novice for finding a clean copy of almost any software...any suggestions? (Assuming that an expert user would straight to the source website)

The software producer's website is the only safe place.

If you download something from the programmer page it is impossible to be sure that it has no spyware/crazy-toolbars/whatever. Some time ago, if you download it from download.com you know that it was safe.

Re: CNET Injecting Malware into Downloads

#27
post #14

"This is probably why CNET switch to installing the Babylon Toolbar yesterday. This is a good and welcome move by Microsoft, but the whole process of paying “distribution partners“ to changer user's home page to MSN and search engine to Bing is rather sketchy" I am puzzled by the reaction of some journalists and people here. Have you actually thought why the toolbar is marked as malware? Usually, that's because one g…

Everything on CNET is being tested manually with VirusTotal. If it gets at least 4 positives/false positives from 43 antivirus engines they don't publish it or work with it, until developers get things settled down with anti-virus/anti-malware companies. They get not that much profit from paid accounts cause of small percentage of subscribers, and give away tons of traffic + man hours even for free products. That includes manual testing, checking and writing descriptions, reviewing, and that repeats for each update. And lots of companies update their products like 10 times a week, just to get bumped in search, or create like 20 versions of 1 program under different names, especially Chinese developers. So they just monetizing traffic and stimulating developers to get subscriptions to remove ad for their products. I personally hate all kind of that toolbar stuff, but hey, there are not so many ways to promote an alternative search engines that work for free.

Re: CNET Injecting Malware into Downloads

#28
post #8

Earlier quoted context omitted.

But this is ignorant and not true.

For laymen's purposes it pretty much is, though. When was the last time anyone on Linux/OSX got some adware / popups? I've also never heard of antivirus for Linux. Which doesn't mean there aren't viruses, it means it's not a concern on the most part.

[deleted]

Re: CNET Injecting Malware into Downloads

#29
post #20

There's three things here. First, adding a toolbar and screwing with user settings is freaking lame, but everyone does it and it's something that's been an accepted way to monitize software development. However, injecting that into other people's software is low, especially if the developers aren't aware of it. CNET should be ashame. Lastly, the way they present it to users should be plainly criminal. There's a way t…

They do not injecting it, it's just a small downloader that helps to download applications even with bad connection. And potentially may use a p2p distribution, as for example some game developers upload their game clients(>1gb). Well-known companies pay per download for their software suits, and they don't really like to pay for the interrupted downloads.

Im not sure about the deceptive tactics, they just trying to get people attention, not just unmarking checkboxes without reading.

Re: CNET Injecting Malware into Downloads

#30
post #18

What good alternatives would people suggest? What should be the "goto" site we could suggest to a novice for finding a clean copy of almost any software...any suggestions? (Assuming that an expert user would straight to the source website)

The software producer's website is the only safe place.

True but when you want to suggest to a novice "Why don't you use "X" " It is unrealistic to expect them to search for X in Google, go to the appropriate link of X's creator, figure out the right page to download it from.

Instead - Go to filehippo search for X in the big search bar at top - download first result - is a much easier workflow. (Trust me on this one - I tech support about 6 relatives)

Post reply on HN