Live data from Hacker News

CNET Injecting Malware into Downloads

insecure.org

41–50 of 80 posts

Re: CNET Injecting Malware into Downloads

#41
post #27
post #14

"This is probably why CNET switch to installing the Babylon Toolbar yesterday. This is a good and welcome move by Microsoft, but the whole process of paying “distribution partners“ to changer user's home page to MSN and search engine to Bing is rather sketchy" I am puzzled by the reaction of some journalists and people here. Have you actually thought why the toolbar is marked as malware? Usually, that's because one g…

Everything on CNET is being tested manually with VirusTotal. If it gets at least 4 positives/false positives from 43 antivirus engines they don't publish it or work with it, until developers get things settled down with anti-virus/anti-malware companies. They get not that much profit from paid accounts cause of small percentage of subscribers, and give away tons of traffic + man hours even for free products. That inc…

The problem with this statement is that what you say is true... but only for the software the developers are actually distributing on CNET.

Whether CNET passes their own wrapped installer through VirusTotal is a good question, and I for one highly doubt that's the case. Who knows, maybe they tried, got a hit for malware and decided that they would ignore it because it would be counter productive...

Re: CNET Injecting Malware into Downloads

#42
post #29
post #20

There's three things here. First, adding a toolbar and screwing with user settings is freaking lame, but everyone does it and it's something that's been an accepted way to monitize software development. However, injecting that into other people's software is low, especially if the developers aren't aware of it. CNET should be ashame. Lastly, the way they present it to users should be plainly criminal. There's a way t…

They do not injecting it, it's just a small downloader that helps to download applications even with bad connection. And potentially may use a p2p distribution, as for example some game developers upload their game clients(>1gb). Well-known companies pay per download for their software suits, and they don't really like to pay for the interrupted downloads. Im not sure about the deceptive tactics, they just trying to…

They do not injecting it, it's just a small downloader

Oh I am so going to tweet that.

Re: CNET Injecting Malware into Downloads

#43
post #18

What good alternatives would people suggest? What should be the "goto" site we could suggest to a novice for finding a clean copy of almost any software...any suggestions? (Assuming that an expert user would straight to the source website)

The software producer's website is the only safe place.

Regular users have no way to reliably identify the software producer's website. Advising them to "just google it" is likely to end up with them clicking a scammy AdWords link where paying $40 to download some freeware counts as getting off lightly.

Re: CNET Injecting Malware into Downloads

#45
post #8

Earlier quoted context omitted.

But this is ignorant and not true.

It's "relatively true." The fact is that there is malware including viruses for Linux. The fact is though that they are pretty rare, and the types involved are unlikely ever to become serious threats on the desktop. It's not perfectly safe, but it's safe enough that safe enough that basic precautions for the desktop are currently good enough. Of course mobile systems are something different.

Scam emails will likely exploit your email client, your browser or your technical/it sec inability - neither of which is solved by windows alone. Education is the definite answer, not switching platforms.

Re: CNET Injecting Malware into Downloads

#46
post #27
post #14

"This is probably why CNET switch to installing the Babylon Toolbar yesterday. This is a good and welcome move by Microsoft, but the whole process of paying “distribution partners“ to changer user's home page to MSN and search engine to Bing is rather sketchy" I am puzzled by the reaction of some journalists and people here. Have you actually thought why the toolbar is marked as malware? Usually, that's because one g…

Everything on CNET is being tested manually with VirusTotal. If it gets at least 4 positives/false positives from 43 antivirus engines they don't publish it or work with it, until developers get things settled down with anti-virus/anti-malware companies. They get not that much profit from paid accounts cause of small percentage of subscribers, and give away tons of traffic + man hours even for free products. That inc…

Welcome to HN Georgiy.

Here's the deal: That still doesn't mean it's not crapware.

You mention the difficulty of funding your download site (built almost exclusively on supplying other people's free content). I can't imagine what the bandwidth costs must be on a site like that. I'm sure there are plenty of other visitors on HN that are familiar with this issue and are daily encountering similar ethical decisions about how best to fund their business.

There are many ways of resolving difficult ethical decisions. http://en.wikipedia.org/wiki/Normative_ethics One useful technique is to ask yourself: If everyone behaved in this manner, what kind of world would result?

So let's imagine such a world:

* Want to view a .pdf on the web? ... receive and run an executable downloader from an unrelated party.

* Want to watch a video on YouTube? ... receive and run an executable downloader from an unrelated party.

* Want to install an application? ... receive and run an executable downloader from an unrelated party.

Do you see the problem here?

(Maybe you don't, but most everyone else on HN will and I'm doubtful that you're even reading the responses. But if you are still interested I'm sure we can politely explain it further for you.)

Re: CNET Injecting Malware into Downloads

#47
post #20

There's three things here. First, adding a toolbar and screwing with user settings is freaking lame, but everyone does it and it's something that's been an accepted way to monitize software development. However, injecting that into other people's software is low, especially if the developers aren't aware of it. CNET should be ashame. Lastly, the way they present it to users should be plainly criminal. There's a way t…

I strongly disagree with the following part: "but everyone does it and it's something that's been an accepted way to monitize software development".

Here's why:

- bundling such software with any product kills trust in one single fire; why would I allow such a software to make it into my environment? What if there are additional hidden things inside the code which steal data from my system and send it to a third party or to the maker of the app? What if it steals my credit card info or if it uploads confidential data somewhere?

- it's a "no go" for people in corporate environments - if it has anything bundled with it (optional or not), it's not installed on any system inside the company, no further questions asked

- it doesn't matter if you offer a "paid" version without these things in it, how can I know you haven't added some other "extras" which steal data?

- if you choose to bundle software with your apps, you have some kind of issues with your business model

- bundling such software always exposes the user to all kinds of exploits, hacks and trojans

As for "optimizing" the experience of the persons on the receiving end of this crappy wrapper which shoves adware / malware / trojans down the people's throats, it's like saying we screw you over, but we intend to make it look GOOD and actually make you like it.

CNET and download.com should really be blocked at company level, along with all the security policies. They live in 2005-2006, not at the end of 2011. I doubt the guys running CNET are capable of coming up with any business model which doesn't involve making money off the software of other individuals.

Re: CNET Injecting Malware into Downloads

#48
post #31

Earlier quoted context omitted.

"but everyone does it and it's something that's been an accepted way to monitize software development" No piece of software that I have installed during the past two years has done so, and I sure wouldn't accept it as a way of funding development. I'd rather pay for a product in that case. Can you give a few examples from your list of "everyone"?

I think the Java runtime installer asks to install a toolbar. There is something else that I can't recall (flash runtime?) that asks to install the Ask.com toolbar all the time as well. Some popular open source projects too (PDFCreator).

The flash download page asks you if you want to install an antivirus, I believe it's mcafee.

It's funny, though, that I encountered a "not so bright" person who simply told me "oh, I didn't know you could opt out, I was always uninstalling it afterwards".

You can also block the ask toolbar from downloading by killing toolbar.ask.com or the entire ask.com domain. It most certainly will not be missed.

Re: CNET Injecting Malware into Downloads

#49
post #29
post #20

There's three things here. First, adding a toolbar and screwing with user settings is freaking lame, but everyone does it and it's something that's been an accepted way to monitize software development. However, injecting that into other people's software is low, especially if the developers aren't aware of it. CNET should be ashame. Lastly, the way they present it to users should be plainly criminal. There's a way t…

They do not injecting it, it's just a small downloader that helps to download applications even with bad connection. And potentially may use a p2p distribution, as for example some game developers upload their game clients(>1gb). Well-known companies pay per download for their software suits, and they don't really like to pay for the interrupted downloads. Im not sure about the deceptive tactics, they just trying to…

Most trojan & trojan downloaders are also "just a small downloader that helps to download applications".

The only problem is that you will have to reinstall the OS, erase everything and need a new bank account or even a new job.

Also, HELLO, CNET, NICE TRY.

Re: CNET Injecting Malware into Downloads

#50
post #31

Earlier quoted context omitted.

"but everyone does it and it's something that's been an accepted way to monitize software development" No piece of software that I have installed during the past two years has done so, and I sure wouldn't accept it as a way of funding development. I'd rather pay for a product in that case. Can you give a few examples from your list of "everyone"?

I think the Java runtime installer asks to install a toolbar. There is something else that I can't recall (flash runtime?) that asks to install the Ask.com toolbar all the time as well. Some popular open source projects too (PDFCreator).

The difference is that Sun adds the toolbar installer itself (and earns the revenue from it).
Post reply on HN