Live data from Hacker News

Until further notice, think twice before using Google to download software

arstechnica.com

161–170 of 242 posts

Re: Until further notice, think twice before using Google to download software

#161

Google was once considered trustworthy. It never was, but we thought it trustworthy. Where can you find a trustworthy source for software? Depends on your platform. Linux: Your package manager. In my case, apt. Mac: Apple has an app store of its own. Use that, or one of the BSD package management systems ported over. Ios: Apple app store is decently curated. Android: Google's app store is terribly curated. Give up no…

Linux package managers are not trustworthy. That is another case where everyone pretends that it is. Usually packages are created and updated by random people and can be pseudonymous.

Yes, but these are the same people who are managing every single program on your system. At some point you either have to compile every single item from source yourself, or accept the fact that you will need to place a certain level of trust into the vetting system your distribution has established.

Re: Until further notice, think twice before using Google to download software

#162

Back in the early 2000s I helped create policy and procedures at Google to stop this kind of thing. Google's early anti-malware policies, extended to ads, and internal procedures to make sure we effectively stopped malware ads. That was a long time ago though and it's sad and frustrating to read it's not working so well now. In particular the article points out several big red flags about how malware scanners are aut…

those results and the wikipedia page seem to be for an unrelated tool also called downloadstudio

Re: Until further notice, think twice before using Google to download software

#163
post #125

Earlier quoted context omitted.

> but what sort of things are y'all searching for where reddit's opinion is relevant If you want real, unvarnished reviews and opinions of products, you need to get it from real people that have owned the product for more than 1 day before leaving the review. I recently needed to purchase a new winter coat. Surfing many reddit threads across a dozen or so subs actually convinced me to not purchase the coat I had in m…

Why do you assume the posts on reddit are at all organic? Big brands 100% astroturf on reddit.

If you read the conversation threads, you can pretty easily pick out astroturfing.

Plus, do your own research of course. I don't exclusively use reddit for this sort of research... if I'm looking for outdoor gear I will browse outdoor gear forums for people's thoughts. Cycling, same thing... etc. You look for a consensus to be formed before making your own opinion.

My point was default google search results are now unreliable because they are almost always affiliate links.

Re: Until further notice, think twice before using Google to download software

#164
post #131

Earlier quoted context omitted.

What’s the difference between the App Store and a package manager? Mostly it comes down to trust: I can give you Mac .pkg files all sorts of ways but what you really want is a way to know that I am who I claim to be. Package management has a boot-strapping problem for mainstream platforms: the same people telling the public that you should install Firefox using their ad bundle installer would instantly pivot to sayin…

> real solution is probably something regulatory requiring Microsoft and Apple to run a basic store at cost "At cost" for digital stores run well* appears to be between 12% and 18% depending how readily end users can unsubscribe or how easily they can end up interacting with a human for a support, since it costs more to be user friendly. Stores charging less, e.g. 8%, have processing billed separately, generally adds…

Yes, getting that balance right is tricky since there isn't a precise way to say how much additional features are worth to everyone. It could be low-cost if the service was just publisher ID verification and PKI, but then you'd see a lot of bottom feeders trying to stay just below the threshold where they'd get their signing key revoked.

That might still be worthwhile if the idea was something like allowing your computer to have a policy saying it'll only run signed binaries but the default assumption is that most people should stick to the higher-margin more curated App Store since that would still make it more expensive to run malware / adware campaigns if you had to burn a business identity as each one was discovered.

Re: Until further notice, think twice before using Google to download software

#165

Earlier quoted context omitted.

For music, also adding -extended feels necessary. Along with -60fps for anything anime related.

Oh my GOD. The 60 FPS 4K memescaling shouldn't drive me as insane as it does, but jesus christ, the amount of times I have wanted to show someone some opening, gone on YouTube, and literally everything is some tweened upscale. I usually give up and end up having to go and StackOverflow the ffmpeg filters I'll never remember for burning in subs just to clip it myself -- `ffmpeg -i episode.mkv -vf "subtitles='episode.m…

Another nice video on the topic: https://youtu.be/_KRb_qV9P4g

Re: Until further notice, think twice before using Google to download software

#166
post #95
post #77

Earlier quoted context omitted.

That'll work just fine until they trash their reputation with carp like this. Then, no one will use them, and they will have a hard time getting it back; they may still exist, but only as a husk of their former stature.

You’re not wrong but the manager making that call will have retired rich by then.

Yup, highly likely.

But this is why someone in the executive or CxO suite must be on top of flagging potentially existential issues like this and getting on top of it — instantly.

If it were my company, I'd be temporarily pulling down all ads not from a known previously-vetted source (e.g., the major agencies of publicly listed US companies), setting up an emergency team to develop some recognition technology, then opening it back up again with very strong surveillance.

But yeah, likely the execs there will just say 'it won't collapse that fast, and I'll be off on sunnier beaches then...

Re: Until further notice, think twice before using Google to download software

#167

Earlier quoted context omitted.

Linux package managers are not trustworthy. That is another case where everyone pretends that it is. Usually packages are created and updated by random people and can be pseudonymous.

Oh crud, you are right. Any idea how to fix this? Perhaps a more curated (and more manageable) list? That would seem to be in conflict with our bazaar model.

AUR is one of those "at your own risk" repos where I always check the pkgbuild and comments of a package first before installing something new. I don't know why I should hesitate to trust the default repos though since they're curated by the same people making the distro I use. Either I trust them or I use another distro.

Re: Until further notice, think twice before using Google to download software

#168
post #5

Took me a while to understand what "using Google to download software" means. Was there a hidden functionality I wasn't aware of? Turns out, what they mean is "don't use Google to search for software you wish to download".

It describes perfectly what users use Google for. Look at your non-IT colleagues over the shoulder while asking them "hey, can you log in to Netflix?"... 60% chance, 90% for older folks, they'll type "Netflix" into the browser bar and click on the first link because they don't realize "Netflix" is not a domain name. Or ask them to "download VLC" - they'll type "download vlc" into the bar and click on the first link,…

I started running a pretty popular forum back in the late 90s and I was shocked when I noticed this behavior. The name of the forum itself was shorter than typing "google" yet most sessions started with someone typing the name of the forum into google and following the first link.

Re: Until further notice, think twice before using Google to download software

#169

Google's search product has become a shadow of its former self. Every year it seems harder to find what I'm looking for. The top half of the first search result page is now (potentially malicious) ads, and what follows is likely SEO spam. I need to add "reddit" or "stackoverflow" to half my searches these days so I'm not served nearly useless results. It's a sad decline from 10+ years ago when I'd type a half-formed…

at this point Google is more of a brochure than a search engine

"here are some ads that match your search query"

Re: Until further notice, think twice before using Google to download software

#170
I once saw a google search ad result for a malware version of GNU Cash. It was extremely easy to miss. The website was identical except the Windows download was replaced with malware instead of linking to Sourceforge. The malware installer was signed with a key from a random Taiwanese electronics company (likely stolen). I emailed DigiCert and got the cert revoked. None of the scanners on VirusTotal flagged the installer. A GNU Cash malware wouldn't need to do any typical malware behavior (crypto mining, ransomware) because they could just send off your bank account credentials. Within half an hour of uploading to VirusTotal the website was replaced with a placeholder blog.
Post reply on HN