Live data from Hacker News

Cyber Scarecrow

cyberscarecrow.com

141–150 of 253 posts

Re: Cyber Scarecrow

#141

Earlier quoted context omitted.

It is a cat and mouse game. And security by obscurity practice. Not saying it won't work, but if it is open sourced, how long before the malware will catch on? Here is one on github: https://github.com/NavyTitanium/Fake-Sandbox-Artifacts

Author of scarecrow here. Our thinking is that if malware starts to adapt and check if scarecrow is installed, we are doing something right. We can then look to update the app to make it more difficult to spot - but its then a cat and mouse game.

You had an answer canned for one part of the query. Why are you trying to release security software completely anonymously? This is insane - you want an incredible amount of trust from users but can’t even identify a company.

Simply, if users are as intelligent as you think, they’re too intelligent to use your product.

Re: Cyber Scarecrow

#142
post #4

Fun concept. If the creators read this, I suggest some ways of building trust. There’s no “about us”, no GitHub link, etc. It’s a random webpage that wants my personal details, and sends me a “exe”. The overlap of people who understand what this tool does, and people who would run that “exe” is pretty small.

> It’s a random webpage that wants my personal details, and sends me a “exe”. No different from MacAffee, Trend Micro, Symantec. Oh, but those are brand names you can trust, like Coca-Cola and Kellog's Corn Flakes.

You can't spot the super subtle difference between a name with a rep to protect and a no-name?

Re: Cyber Scarecrow

#143

Earlier quoted context omitted.

Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive for windows. Smartscreen also triggers when you install it. Id be weary of installing it myself as well, especially considering it runs as admin, to be able to create the fake indicators. I have just added a bit of info about us on the website. I'm not sure w…

> We also dont have a code signing certificate yet either, they are expensive for windows. When someone is offering you a certificate and the only thing you have to do in order to get it is pay them a significant amount of money, that's a major red flag that it's either a scam or you're being extorted. Or both. In any case you should not pay them and neither should anyone else.

There’s an audit to go through where you (sort of) prove who you are. The system isn’t great, but if you can come up with something better there’s a lot of space to make software more secure for people.

Re: Cyber Scarecrow

#144
post #135

I decided to use Bitdefender a few months ago becouse i suspected my Mac had malware. I was right, there was a adware in the firefox files so it did it’s job. But, my experience with the antivirus was horrible. When i first opened the app there were popus everywhere advertising for their other products, and the overall ui didn’t look trustworthy. I am no security expert, so I’m asking: is this the best way to deal wi…

Not get it in the first place.

Not an expert myself, but I think cleaning up and reinstalling your whole OS once in a while probably deals with malware.

Re: Cyber Scarecrow

#145

Earlier quoted context omitted.

Author of cyber scarecrow here. You are right, its a trust thing. Completly understand if people wouldnt want to install it and thats fine. It's the same for any software really. We just havent built up any confidence or trust like a big established company will have.

But why not make it open source? Why not identify who you are as humans? There are ways to establish trust, you aren’t doing any of them.

At this point, the simplest explanation is that it actually is malware. A more credible explanation than security researchers making something that looks this much like malware, but actually isn't.

Re: Cyber Scarecrow

#146

Earlier quoted context omitted.

The really fun part is when malware authors add detections for "fake sandbox" and then real sandbox authors get to add those indicators.

Look into Windows NT source code that was leaked. The if-else/switch statements in there is just another level of string matching hell. Seems like software development just become "let's jerry rig it to just make it work and forget about it." Pretty sure management (without tech clue) have something to do behaviours like this.

> Pretty sure management (without tech clue) have something to do behaviours like this.

Always the same bullshit with you people here. Could never possibly someone built a sub-optimal system -- it HAD to be management fucking with our good intentions!

Re: Cyber Scarecrow

#147
post #92

Earlier quoted context omitted.

I'd be willing to bet good money that 99% of malware authors won't adapt, since 99% (more like 99.999%) of the billions of worldwide windows users will not have this installed. For the cat to care about the mouse it needs to at least be a good appetizer.

I think this is a same thing as betting on your own failure: "not enough people will use this for it to be an important consideration for hackers".

I've worked in companies with horrendous security, where someone with just a bit of SQL injection experience could have easily carried out the data. Yet, since this was a custom in-house application and your off-the-shelve-scanners did not work, this never happened; the only times the servers were hacked was when the company decided to host an (obviously never updated) grandfathered Joomla instance for a customer.

But even more simply, just setting your SSH port to something >10000 is enough to get away with a very mediocre password. It's mostly really not about being a hard target, not being the easiest one is likely quite sufficient :)

Re: Cyber Scarecrow

#148
Neat.

But this literally comes off as probably being malware itself.

If your going to ship something like this, it needs to be open source preferably with a GitHub pipeline so I can see the full build process.

You also run into the elephant repellent problem. The best defense to malware will always be regular backups and a willingness to wipe your computer if things go wrong.

Re: Cyber Scarecrow

#149
post #92

Earlier quoted context omitted.

It is a cat and mouse game. And security by obscurity practice. Not saying it won't work, but if it is open sourced, how long before the malware will catch on? Here is one on github: https://github.com/NavyTitanium/Fake-Sandbox-Artifacts

I'd be willing to bet good money that 99% of malware authors won't adapt, since 99% (more like 99.999%) of the billions of worldwide windows users will not have this installed. For the cat to care about the mouse it needs to at least be a good appetizer.

If I were to run a Windows computer, I wouldn't care what 99.999% of other people didn't do to make their computer safe. If it were something that I could do, then that's good enough for me. However, the best thing one can do to protect themselves from Windows malware is to not use Windows. This is the path I've chosen for myself

Re: Cyber Scarecrow

#150

Earlier quoted context omitted.

It is a cat and mouse game. And security by obscurity practice. Not saying it won't work, but if it is open sourced, how long before the malware will catch on? Here is one on github: https://github.com/NavyTitanium/Fake-Sandbox-Artifacts

Author of scarecrow here. Our thinking is that if malware starts to adapt and check if scarecrow is installed, we are doing something right. We can then look to update the app to make it more difficult to spot - but its then a cat and mouse game.

If you think that is what will make it a cat and mouse game instead of understanding it has been a cat and mouse game since the beginning of time, then you're not compelling me into thinking you're very experienced in this space.
Post reply on HN