Live data from Hacker News

CNET Injecting Malware into Downloads

insecure.org

71–80 of 80 posts

Re: CNET Injecting Malware into Downloads

#71
post #31

Earlier quoted context omitted.

"but everyone does it and it's something that's been an accepted way to monitize software development" No piece of software that I have installed during the past two years has done so, and I sure wouldn't accept it as a way of funding development. I'd rather pay for a product in that case. Can you give a few examples from your list of "everyone"?

Adobe tries to sneak Mcafee on your system with either flash or acrobat reader, which is worse and should also be criminal.

Adobe does not pretent to give you an open source project like VLC player and bundle malware/adware into the installer as if VLC team did it. They even make the .exe signature identical to that of the original to fool people. Its wrong. and puts blame on the original makers. Its like if google wrapped every app submitted with ads that give only google money. The ads are annoying, and apps get bad reviews, but the app makers had no say in it.

Re: CNET Injecting Malware into Downloads

#72
post #56

Earlier quoted context omitted.

Most trojan & trojan downloaders are also "just a small downloader that helps to download applications". The only problem is that you will have to reinstall the OS, erase everything and need a new bank account or even a new job. Also, HELLO, CNET, NICE TRY.

Pff i just know the kitchen as i worked there for some time :) It's not a trojan or malware for sure. 3/43, http://www.virustotal.com/file-scan/report.html?id=cb2428c76... Some crappy adware? probably :)

What an antivirus says about some adware / adware downloader / toolbar doesn't matter - if it's adware, I don't want it; if it's shoved down my throat by some installer, I don't want it.

I had to deal with cleaning up a lot of machines in a corporate environment where the previous admin didn't care about security policies and security.

I found a gem, I think I might still have the photo somewhere, it was a PC which had so many toolbars in IE that they took more than half the height of the screen to display them all. Obviously, the "faces for yahoo messenger" and "good looking email" (incredimail) were among the installed "goodies" on that machine.

Just to make it clear, I see the adware installed by apps as exploits all kinds of assholes use on people who have no clue what security is about. Telling them they might find their bank account empty or that their email account might send emails with porn to their entire list of contacts usually gives them a hint about what they expose themselves to.

P.S.: If you really "worked" there and you stopped doing that, I can hardly see the point in defending them. Perhaps you're the guy they paid to write that adware injector ("the small downloader")? You come off as the guy who defends the company he's working for because he wants to keep his job.

Please stop trying to explain or excuse what CNET is doing. It's not ok.

Re: CNET Injecting Malware into Downloads

#73
post #25
post #21

Earlier quoted context omitted.

http://www.clamav.net/ if you were actually wondering. There's also a sweet osx port: http://www.clamxav.com/

Did you ever catch something with it?

Not in the practical "you've got a virus" sense, but if I have a suspicious file I want to scan, it gets good detection there.

I think it's mainly used on mail servers.

For scanning tiny individual files, http://www.virustotal.com/ is the site to use.

Re: CNET Injecting Malware into Downloads

#74
post #8

Earlier quoted context omitted.

But this is ignorant and not true.

For laymen's purposes it pretty much is, though. When was the last time anyone on Linux/OSX got some adware / popups? I've also never heard of antivirus for Linux. Which doesn't mean there aren't viruses, it means it's not a concern on the most part.

The vectors are different.

They are also, for the most part, add-on (and readily removable) parts of the system. Usually some network service or web app vulnerability.

There have been a few kernel-level exploits, most of which are DoS vulnerabilities, though a few are privilege escalations (meaning: paths to root or full system ownership).

Still, as a whole, the modular architecture and high system transparency of Linux means that it's far easier to avoid, detect, and recover from attacks than Windows. Mac OS X is slightly less protected, but only somewhat.

Contrast this to the gaping security whole that remains the Windows shell, the tightly integrated default Web browser, the "document as application" model, various unsecured default services, very low system transparency (/proc, /sys, strace/ltrace/dtrace, netstat, etc., are wonderful), and, oh, say, the fucking impossibility of deleting open files, and you've got a massive security migraine.

Still.

And, yes, Virginia, there's antivirus for Linux. We run clamav on our servers to keep all those damned Windows viruses from proliferating by way of our services. But viruses as an attack vector for Linux itself? No.

Re: CNET Injecting Malware into Downloads

#75
post #51
post #14

"This is probably why CNET switch to installing the Babylon Toolbar yesterday. This is a good and welcome move by Microsoft, but the whole process of paying “distribution partners“ to changer user's home page to MSN and search engine to Bing is rather sketchy" I am puzzled by the reaction of some journalists and people here. Have you actually thought why the toolbar is marked as malware? Usually, that's because one g…

It's malware because it's installing something that you didn't agree to install.

I am not sure I follow you. By that you mean that CNET installer is a malware because its installing toolbar without disclosing it to the user? Surely StartNow toolbar should not be marked because somebody decides to bundle it. If I take your software and bundle it does it make it malware? I am arguing that all those toolbars do same things, and they should be marked as PUP not as malware as they are not in the same category as viruses.

Re: CNET Injecting Malware into Downloads

#76
Press release from the CNET few minutes ago:

A note from Sean Download.com Developer Community,

My last communication to you was shortly after we launched the Download.com Installer in late summer. At that time I asked for patience as we began work to deliver a mutually beneficial model to market.

We are on the verge of fulfilling our vision of coming to market with an installer model that delivers files faster and more efficiently to users, while enabling developers to a) opt-in to the Installer, b) influence the offers tied to their files, c) gain reporting insight into the download funnel, and d) share in the revenue generated by the installer. However, due to some press that surfaced yesterday and the potential for subsequent misinformation, I am reaching out now to address that press and to provide a progress report on the upcoming launch:

First, on the press that surfaced yesterday: a developer expressed anger and frustration about our current model and how his file was being bundled. This was a mistake on our part and we apologize to the developer and user communities for the unrest it caused. As a rule, we do not bundle open source software and in addition to taking this developers file out of the installer flow, we have gone in and re-checked all open source files in our catalog. We take feedback from our developer & user communities very seriously and take pains to both act on it and respond in a timely manner.

With that, I want to share progress made thus far: This week we will launch the alpha phase of our new installer. This alpha phase is intended to test the tech and do QA, and will roll through the next few weeks to ensure that our installer is bug free. Between this week and the end of January we will be completing the necessary engineering and administrative work to roll out our beta, which will include a small group of developers who've agreed to participate in the beta launch. Our goal is to exit beta by end of February and have the necessary systems in place to enable opt-in, influence over advertising offers (for those offers that impact your product), download funnel reporting and revenue share back to you, the developers. In the weeks/months following the full release, we will continue to iterate on the model, adding more features to the Installer and bringing greater efficiency to our own download funnel (read: increased install conversion). The initial feedback from developers on our new model has been very positive and we are excited to bring this to the broader community as soon as possible. More communication will follow as we move into Q1, and until then, thank you for continuing to work with Download.com.

Sincerely,

-- Sean

Re: CNET Injecting Malware into Downloads

#77
post #57
post #14

"This is probably why CNET switch to installing the Babylon Toolbar yesterday. This is a good and welcome move by Microsoft, but the whole process of paying “distribution partners“ to changer user's home page to MSN and search engine to Bing is rather sketchy" I am puzzled by the reaction of some journalists and people here. Have you actually thought why the toolbar is marked as malware? Usually, that's because one g…

> the quote above that its actually a good thing to replace StartNow with Babylon He meant it was good for Microsoft to stop paying them to screw people; not good for CNET to keep screwing people in the service of a different client.

OK. So the payment goes to Google instead of Microsoft, what's good about it?

Re: CNET Injecting Malware into Downloads

#78

Earlier quoted context omitted.

It's "relatively true." The fact is that there is malware including viruses for Linux. The fact is though that they are pretty rare, and the types involved are unlikely ever to become serious threats on the desktop. It's not perfectly safe, but it's safe enough that safe enough that basic precautions for the desktop are currently good enough. Of course mobile systems are something different.

Scam emails will likely exploit your email client, your browser or your technical/it sec inability - neither of which is solved by windows alone. Education is the definite answer, not switching platforms.

Scam emails are unlikely to affect your platform in their current form for most users. They affect, instead, in most cases, your bank account.

Yes, education is the key, but certain classes of problems are largely solved by switching platforms.

In fact the PCI-DSS standard requires all desktops in the processing environment to be running antivirus software unless they are on a UNIX-like operating system.

Re: CNET Injecting Malware into Downloads

#79
post #76

Press release from the CNET few minutes ago: A note from Sean Download.com Developer Community, My last communication to you was shortly after we launched the Download.com Installer in late summer. At that time I asked for patience as we began work to deliver a mutually beneficial model to market. We are on the verge of fulfilling our vision of coming to market with an installer model that delivers files faster and m…

Dear CNET,

I hope your servers get fried, along with all your backups.

Sincerely,

kermitthehermit

Re: CNET Injecting Malware into Downloads

#80
post #75
post #51

Earlier quoted context omitted.

It's malware because it's installing something that you didn't agree to install.

I am not sure I follow you. By that you mean that CNET installer is a malware because its installing toolbar without disclosing it to the user? Surely StartNow toolbar should not be marked because somebody decides to bundle it. If I take your software and bundle it does it make it malware? I am arguing that all those toolbars do same things, and they should be marked as PUP not as malware as they are not in the same…

You want to download, say, Winzip. CNet gives you something else other than just plain Winzip.
Post reply on HN