Live data from Hacker News

Y Combinator is funding the future of spam in Windows

istartedsomething.com

451–460 of 468 posts

Re: Y Combinator is funding the future of spam in Windows

#451
post #143
post #119

Earlier quoted context omitted.

A lot of people these days are bashing Apple and Google for creating walled gardens with their app stores, but this is really the primary reason such walled gardens have taken off. They offer a mostly crapware-free experience. If Linux on the desktop were to get popular, I'd hate to imagine what might happen to the open source Fedora and Debian/Ubuntu repositories.

I'm not sure that's a legit fear... Linux on the desktop in 2013 is fairly 'popular' and if it were that simple to infiltrate popular repos with spyware it would have been done years ago. There are a ton of good people who work to keep those repos clean. Lets not trivialize their contribution by acting like anyone and their mother can make changes to the repo for a popular distro. Sure, a black[/grey] hat can make th…

>Linux on the desktop in 2013 is fairly 'popular' and if it were that simple to infiltrate popular repos with spyware it would have been done years ago.

What on earth are you talking about? Linux on the desktop is just above line noise. If hackers don't bother targeting Mac's ~10% desktop share, why would they bother targeting Linux' ~1%?

Re: Y Combinator is funding the future of spam in Windows

#452

Earlier quoted context omitted.

May be the case on iOS but with Android I've had apps that stick extra shortcuts on my homescreen and spam notifications every few hours. This makes battery life and usability a lot worse throughout the phone until you can find and kill the offending app.

I want to switch to Android, but I fear needing to have constant vigilance over what I install. Like running a Windows install but forced to use Java as well. However, it's still preferrable to Apple's draconian policies.

I've been running Android since 2.3, I've not installed a malicious app yet (to my knowledge of course).

If you want, you can install security tools which scan apps prior to being installed, like Lookout, which will alert you to various issues.

Yes there's a lot of spammy apps, but if you're even halfway aware of what you're doing, you'll have to be very unlucky to be caught out by one.

Re: Y Combinator is funding the future of spam in Windows

#453

Earlier quoted context omitted.

Exactly this. I'm often advising people to install VLC when they are having problems with Windows Media Player, but whenever I tell them to google for it on their own they end up with some toolbar infested crap. So now I specifically instruct them to go to videolan.org.

Googling for "vlc", "vlc download", or "vlc player", the top 3-4 results are all to videolan.org. Ads may distort this for some users, though...

On your Google, with your results, with your search history and thus in your specific filter bubble.

Fuck, people, don't you get this already? There is no n-th result on Google. Don't act like there is.

Re: Y Combinator is funding the future of spam in Windows

#454
post #395
post #326

We're investigating. It will take at least a couple days, because we'll need to meet with the founders in person. FWIW, the install window Patrick overlaid on top of InstallMonetizer's site in that screenshot is not actually InstallMonetizer.

But the Babylon installer is from one of IM's advertizers, so it is possibly indicative of the types of pages that IM inserts in other installers. If nothing else, the poor reputation of Babylon is indicative of the types of software that IM wants to co-install. In the end, we don't have much information about what IM adds to installers--I suppose they don't want it too well known. We'd need to find an app that uses…

It is back up as of now: http://installmonetizer.com/

Re: Y Combinator is funding the future of spam in Windows

#455

Earlier quoted context omitted.

You may be right about the industry as a whole, but I'm betting you're wrong about this particular instance based on what I know about PG and YC. When I was reading the original TC article, I was thinking that there is actually an incredible opportunity here to create a legitimate ad network that would allow desktop developers to monetize similarly to how it's done on the web - to basically become the DoubleClick of…

"Can someone explain why creating a legitimate, privacy-respecting ad platform which allows desktop developers to monetize their applications in a manner that's almost exactly the same as ad supported web and mobile apps is that awful?" Tracking IP and even MAC addresses? Hello? Spyware is spyware. Also: ads are ads. If your product does nothing respectable (as opposed to selling eyeballs to advertisers under false p…

The same level of tracking is done on the web, constantly. And you don't need to give any sort of permission for it. What is different is gaining root/Administrator access on the machine in order to ensure the tracking is done vs a client side browser script asking if it can run. And then using that access to install a rootkit or mess with the registry to ensure tracking software starts on reboot, etc. That is what is annoying.

Re: Y Combinator is funding the future of spam in Windows

#456

Earlier quoted context omitted.

No, I use countless file formats with countless different programs. This is especially important if you want to work in a Unix style. Friends who do graphics or audio work do the same thing. This sounds like a complex solution that would require every program to know which other programs might want to interact with it's particular files. You also have programs like text editors and hex editors which don't necessarily…

This sounds like a complex solution that would require every program to know which other programs might want to interact with it's particular files. I don't see why. Any application can register its own file types, and gets full access to files of those types by default. Allow for common file types to be registered as well (the OS provider could start with a list) and some basic grouping ("all text files", "all files…

What you are doing is adding an extra dimension to your permissions vector, instead of just worrying about which users can access what you have to think about individual programs. There are already implementations of this, for example SELinux.

It difficulties in that how do I know which files a particular program might need and how is this implemented at a UI level? For example, what if a program asks for permissions on PNG files? Is this because it wants to manipulate them or is it simply that some of it's internal assets are stored as PNGs? What happens if I add a plugin or update to a program that allows it to work with different file types? How do you prevent "dick moves" like a new program locking other programs out of a file type it decides to claim?

How do you implement the UI? Is it some central permissions manager or do you have endless popups (which people are likely to just unthinkingly click accept on)?

Re: Y Combinator is funding the future of spam in Windows

#457

Earlier quoted context omitted.

If Linux on the desktop were to get popular, I'd hate to imagine what might happen to the open source Fedora and Debian/Ubuntu repositories. Nothing. In case you haven't been paying attention, Debian repositories were "app stores" before there were app stores. The software goes through extensive vetting and rigorous testing; no, I'm not saying every line of code is inspected, but to claim that a Debian maintainer wou…

...through extensive vetting and rigorous testing... I wanted to upvote your comment, but then I almost died laughing when I read that. Most Linux distributions are better about it now than they were many years ago, but I still remember being absolutely floored when RedHat had packaged a Perl module with a syntax error some years ago. Same goes for Debian; some of the more "fringe packages" (those of upstream project…

Maybe I should have clarified, as some people obviously have forgotten that testing does not indicate the absence of bugs, and vetting is for many things.

I had hoped the addition of "not every line of code" would have made clear that I make no claim that every package in Debian is bug free. But I still insist, Debian extensively tests packages, mostly for compatibility and dependencies, not to mention bug squashing parties. They are also very careful about what's allowed in (due to being license sticklers).

Of course, all of this strays from my main point: the Debian maintainers are highly unlikely to let in crapware, as opposed to some stores that have had viruses. And that's just the stuff they (eventually) got rid of; don't start me on all the officially approved software that tracks users.

As for your opinion of the ease of use, well, you're entitled to it but it doesn't make it true. What's so hard about using apt-get or, if you can't use a keyboard, one of the graphical managers? So it asks you if you really want to install dependencies instead of just filling up your hard drive, and that's a bad thing? Does the Apple or Google way of "managing" packages even track dependencies, or are they still forcing every vender to include their own (possibly filled with security holes) copy of a library with their apps? I haven't had to answer a configuration question for years, and I've never had a dependency issue with Debian. I say this as a daily user of, developer on, and administrator of machines running Debian for the past twelve years.

Re: Y Combinator is funding the future of spam in Windows

#458

Likely they got funded because they have a real way to make money! Unlike whoever offers the next airbnb for dogs. From an ethical standpoint, better the devil you know? Windows freeware developers deserve some compensation for their work, and this seems less scuzzy than other drive-by downloaders. If it became widespread it might break out of the user-exploitation ghetto and pick up real, actually synergistic softwa…

Unlike whoever offers the next airbnb for dogs. Hmm. I've actually heard of dumber ideas than that. Dog owners would prefer not to board their pets with commercial kennels, because you always get your dog back with some bug or another. A service that hooks up vacationing dog owners with local families who agree to take care of small numbers of other peoples' dogs might make some sense.

It would be interesting, I think the problem is that people are very attached to their pets. I have no idea how you can vet potential dog sitters, to give a good level of certainty that they won't lose/have sex with/eat your pet. It's like finding a babysitter on Craigslist.

Re: Y Combinator is funding the future of spam in Windows

#459
post #135
post #87

Earlier quoted context omitted.

The cool thing about Mac applications is they are self contained. Very rarely do you see an actual installer. Uninstallation is usually just deleting the application from the Applications folder. I wish other operating systems did it that way. It's very convenient.

The problem is it leads apps to include their own copies of libraries - which then get out of date and have bugs. I remember when a vulnerability was found in zlib and just to update all of apple's first-party programs with the fix required something like 2.6gb of updates. I wouldn't be at all surprised if there were still some more obscure third party mac programs shipping the old, vulnerable version.

Well the alternative (dynamic loaded libraries) have their issues as well. After "DLL hell" and various issues on Linux in the past, I'm not convinced one side is fundamentally better than the other. 3 gig is nothing these days.

Re: Y Combinator is funding the future of spam in Windows

#460
post #418

Earlier quoted context omitted.

Jeez, I'm surprised that the people who created this filth aren't in prison. It's one TINY step away from botnet territory, which actually lands people in prison.

Botnets don't usually include a low-prominence opt-out link / checkbox / something that might not look quite like a button. Maybe they'd walk free if they did...

That is really interesting. What are the legal implications of using a computer in a botnet if the owner of that computer agrees to a EULA, I wonder?

Edit: I should say, "agrees" to it (unknowingly).

Post reply on HN