Live data from Hacker News

What we discovered about InstallMonetizer

news.ycombinator.com

41–50 of 188 posts

Re: What we discovered about InstallMonetizer

#42
post #23

I dunno, 1. and 2. seem like a cop out to me. When crappy freeware Windows installers provide a checkbox (checked by default, of course) to opt out of Bonzai Buddy or a million Ask.com toolbars or some bullshit malware scanner, they are still shitty and sketchy, and it's disappointing to me to know that YC is now behind a company that makes such software. And saying this crapware is popular does little to assuage my…

Definitely. I find it hard to find any reason why something like Babylon (one of the things I remember that IM might install) should not be called "crapware" or malware. Babylon hijacks your browser and then becomes practically unremovable (it can be removed but the people savvy enough to remove it are the ones savvy enough to never install it).

If users like this software so much then why do the creators of this software have to work so hard to make it next to impossible to remove? Who would want to get rid of software they love?

Re: What we discovered about InstallMonetizer

#43
Some of you guys are being ignorant, and too much time on your hands. What IM is doing seems legit from all the information here. It's giving devs some opportunity to make a living. If you don't like the wares don't install it. Simple.

If you were seriously concerned about internet privacy you'd be discussing in depth Google, Microsoft, etc.. policies which affect virtually all inet users and not some small operation like IM.

Re: What we discovered about InstallMonetizer

#45

Paul, I'm one of the two people you're indirectly addressing with this HN post. (The second is Long Zheng.) I wrote here: http://www.withinwindows.com/2013/01/16/installmonetizer-qui... Long zheng wrote here: http://www.istartedsomething.com/20130115/y-combinator-is-fu... I'll respond to each of your items individually. 1. OK. 2. Maybe. Or more likely users are mistakenly installing these applications because the off…

Also, transmitting MAC addresses and IP addresses in the clear really isn't anything to write home about -- that's how all TCP/IP packets are transmitted over ethernet, after all. The real question is what they do with that data on the server side. If they so desire, they could change that behavior far more easily, and retroactively apply that transform to all the data they've retained.

Re: What we discovered about InstallMonetizer

#46
Despite the defense of InstallMonetizer, their payment model and practices do not appear to be what you would find with a legitimate software business.

InstallMonetizer has been used by malware as a method to make money as early as April 2011. It was being silently installed by a large botnet, and I assume that the botnet affiliate was making money off the installs.

Their installers are also labeled as a malware by AV vendors, and treated as such by network monitoring infrastructure.

Re: What we discovered about InstallMonetizer

#48
post #33

Earlier quoted context omitted.

Perhaps worth noting that mac addresses do not have 48 bits of entropy . You can prioritize the OUIs actually being used in consumer NICs and chop that down substantially. IP addresses don't have 32 bits of entropy either for that matter.

That's true. However, with adequate salting it really shouldn't matter.

I think the idea of the hash for IM is to prove uniqueness in a dispute. Salting the hash would make it useless in that case.

Re: What we discovered about InstallMonetizer

#49
Confusing inept users into installing random toolbars[1] that break their browsers and force them to call IT pros to 'clean up' their computers is pretty scummy. Sorry, but it is.

You can make a lot of money doing all kinds of popular things -- pimping women, selling drugs, selling 'likes' on facebook, selling botnets that create fake clicks on advertisers, ponzi schemes, etc. Some are illegal, some are just barely legal, but they are all damaging to someone. This line of business is known as 'scummy' and InstallMonetizer is plain 'scummy'.

Simple fact, trying to rationalize it doesn't help.

[1] http://installmonetizer-review.blogspot.com/ " 3. Which type of bundled software does Install Monetizer include in your installation package? Most of the bundled software are toolbars, though the company is always changing which software are available. When I first started Install Monetizer they offered just two softwares. A toolbar called White Smoke and good old Real Player. Today they have about seven install packages available. However, only USA Search and Facebook Profile turned profitable."

Re: What we discovered about InstallMonetizer

#50
post #45

Paul, I'm one of the two people you're indirectly addressing with this HN post. (The second is Long Zheng.) I wrote here: http://www.withinwindows.com/2013/01/16/installmonetizer-qui... Long zheng wrote here: http://www.istartedsomething.com/20130115/y-combinator-is-fu... I'll respond to each of your items individually. 1. OK. 2. Maybe. Or more likely users are mistakenly installing these applications because the off…

Also, transmitting MAC addresses and IP addresses in the clear really isn't anything to write home about -- that's how all TCP/IP packets are transmitted over ethernet, after all. The real question is what they do with that data on the server side. If they so desire, they could change that behavior far more easily, and retroactively apply that transform to all the data they've retained.

Not exactly, the MAC address (which is a far stronger unique identifier than an IP address) will usually only survive the first hop in an IP transmission.
Post reply on HN