Do these injectors work with https (ssl) sites? Where in the web page fetch/render process does this occur?
5% is a lot. If HTTPS reduces this number to 1%, it might be worth the change.
31–40 of 156 posts
Do these injectors work with https (ssl) sites? Where in the web page fetch/render process does this occur?
5% is a lot. If HTTPS reduces this number to 1%, it might be worth the change.
Earlier quoted context omitted.
You can't trust anybody except for open source repositories. Like Sourceforge? http://blog.gluster.org/2013/08/how-far-the-once-mighty-sour...
Ah yes sourceforge. How far the mighty have fallen.
Well maybe they should stop allowing download sites that offer ad infected downloads to buy the top spots on the google search results page? https://i.imgur.com/Ote9c2k.png Adwords is probably one of the main infection vectors for malware these days. Previous rant: https://news.ycombinator.com/item?id=8879229
Absolutely. Though they're apparently changing their policy sometime this month to require ads advertising downloads be that apps' "primary download source".
Do you have a source for that information?
Earlier quoted context omitted.
Ah yes sourceforge. How far the mighty have fallen.
Sourceforge was doing this on like day 3, so i'm not sure they fell that far?
Then times got tough and sourceforge sold to new owners and that's when the trouble started.
Do these injectors work with https (ssl) sites? Where in the web page fetch/render process does this occur?
Well maybe they should stop allowing download sites that offer ad infected downloads to buy the top spots on the google search results page? https://i.imgur.com/Ote9c2k.png Adwords is probably one of the main infection vectors for malware these days. Previous rant: https://news.ycombinator.com/item?id=8879229
Your rant is outdated. This is what "download firefox" looks like now: http://i.imgur.com/dG7wONC.png
Earlier quoted context omitted.
You can't trust open source repos either; you can only verify them. And is anyone really reading all of the code they run before they run it? With all of its third-party dependencies? I don't think open source repositories are safer because they're open source, but precisely because there is no commercial benefit to shoveling BS into them. In fact, with the bigger commercial open source software, you often do see cra…
You also need to verify that the binary you run is the same source code and be able to identify malware in source code that may be very well hidden. This isn't remotely practical and for even simple software. The only practical solution I can see is proper sandboxing of applications so you don't need to trust them in the first place.
Well maybe they should stop allowing download sites that offer ad infected downloads to buy the top spots on the google search results page? https://i.imgur.com/Ote9c2k.png Adwords is probably one of the main infection vectors for malware these days. Previous rant: https://news.ycombinator.com/item?id=8879229
This, right here, is why I have no qualms installing Adblock Edge and insisting that my parents (and anyone else who isn't very tech-savvy) do the same. It's not about not wanting to support independent bloggers. It's about making sure that unsuspecting users don't accidentally download malware when they're doing something mundane like downloading their web browser . In the age of the web, Adblock is the new anti-vir…
Also the javascript late load "oops click" tricks they're pulling to scam advertisers now (google search, youtube, bing search - all use late load javascript to get misclicks).