Live data from Hacker News

Cyber Scarecrow

cyberscarecrow.com

191–200 of 253 posts

Re: Cyber Scarecrow

#191
post #175

Earlier quoted context omitted.

Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive for windows. Smartscreen also triggers when you install it. Id be weary of installing it myself as well, especially considering it runs as admin, to be able to create the fake indicators. I have just added a bit of info about us on the website. I'm not sure w…

It's a neat concept, although I imagine this'll be a cat and mouse endeavor that escalates very quickly. So, a suggestion - apply to the Open Technology Fund's Rapid Response Fund. I'd probably request the following in your position: * code signing certificate funding * consulting/assessment to harden the application or concept itself as well as to make it more robust (they'll probably route through Cure53) * consult…

> decoy versions of their toolkits to everyone that are bitwise identical to actual running versions but then activate production functionality with the right key

I kinda think this functionality could be subverted into a kill switch for legit-licensed installs simply by altering the key.

Re: Cyber Scarecrow

#192
post #4

Fun concept. If the creators read this, I suggest some ways of building trust. There’s no “about us”, no GitHub link, etc. It’s a random webpage that wants my personal details, and sends me a “exe”. The overlap of people who understand what this tool does, and people who would run that “exe” is pretty small.

Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive for windows. Smartscreen also triggers when you install it. Id be weary of installing it myself as well, especially considering it runs as admin, to be able to create the fake indicators. I have just added a bit of info about us on the website. I'm not sure w…

Where is that additional info? It just says you're a group of security researchers, but there are no names, no verifiable credentials, nothing. You haven't really added any info that would contribute to any real trust.

Re: Cyber Scarecrow

#194
post #4

Fun concept. If the creators read this, I suggest some ways of building trust. There’s no “about us”, no GitHub link, etc. It’s a random webpage that wants my personal details, and sends me a “exe”. The overlap of people who understand what this tool does, and people who would run that “exe” is pretty small.

Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive for windows. Smartscreen also triggers when you install it. Id be weary of installing it myself as well, especially considering it runs as admin, to be able to create the fake indicators. I have just added a bit of info about us on the website. I'm not sure w…

You're collecting personal info and claiming to be in the UK: identifying the data controller would be a start, both for building trust and complying with GDPR.

Re: Cyber Scarecrow

#195
post #4

Fun concept. If the creators read this, I suggest some ways of building trust. There’s no “about us”, no GitHub link, etc. It’s a random webpage that wants my personal details, and sends me a “exe”. The overlap of people who understand what this tool does, and people who would run that “exe” is pretty small.

Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive for windows. Smartscreen also triggers when you install it. Id be weary of installing it myself as well, especially considering it runs as admin, to be able to create the fake indicators. I have just added a bit of info about us on the website. I'm not sure w…

One more thing you could do is put the real name of any human being with any track record of professionalism, anywhere on the website. Currently you're:

- commenting under a pseudonymous profile

- asking for emails by saying "please email me. contact at cyberscarecrow.com"

- describing yourself in your FAQ entry for "Who are you?" by writing "We are cyber security researchers, living in the UK. We built cyber scarecrow to run on our own computers and decided to share it for others to use it too."

I frequently use pseudonymous profiles for various things but they are NOT a good way to establish trust.

Re: Cyber Scarecrow

#196

Earlier quoted context omitted.

I think this is a same thing as betting on your own failure: "not enough people will use this for it to be an important consideration for hackers".

I've worked in companies with horrendous security, where someone with just a bit of SQL injection experience could have easily carried out the data. Yet, since this was a custom in-house application and your off-the-shelve-scanners did not work, this never happened; the only times the servers were hacked was when the company decided to host an (obviously never updated) grandfathered Joomla instance for a customer. Bu…

> But even more simply, just setting your SSH port to something >10000 is enough to get away with a very mediocre password.

Given how easy and free tools like Wireguard are to setup now (thanks Tailscale!), I really don't understand why folks feel the need to map SSH access to a publicly exposed port at all anymore for the most part, even for throw away side projects.

Re: Cyber Scarecrow

#197
post #167
post #23

Earlier quoted context omitted.

I know people /plural/ that will happily download cracked antivirus software from a torrent site.

Many torrent sites have stronger reputation vetting than Microsoft code signing certs.

I mean you can look at the comments and check the vibe.

Re: Cyber Scarecrow

#198

Earlier quoted context omitted.

elephant repellent problem? What is that? This is literally the first occurrence of that string on the internet.

Better known as the Elephant Repellant Fallacy — a claim that a preventative is working when, in fact, the thing it prevents rarely or never happens anyway. "Hey you better buy my elephant repellant so you don't get attacked!" 'Okay.' ... "So were you attacked?" 'No, I live in San Francisco and there are no wild elephants." "Well, I guess the repellant is working!"

I know this as 'Moms cooking drove the vampires away'

Re: Cyber Scarecrow

#199
post #175

Earlier quoted context omitted.

It's a neat concept, although I imagine this'll be a cat and mouse endeavor that escalates very quickly. So, a suggestion - apply to the Open Technology Fund's Rapid Response Fund. I'd probably request the following in your position: * code signing certificate funding * consulting/assessment to harden the application or concept itself as well as to make it more robust (they'll probably route through Cure53) * consult…

> decoy versions of their toolkits to everyone that are bitwise identical to actual running versions but then activate production functionality with the right key I kinda think this functionality could be subverted into a kill switch for legit-licensed installs simply by altering the key.

I mean, the existing licensing mechanisms can be similarly abused.

Re: Cyber Scarecrow

#200
I really don't get why this would be a 71mb installer that takes up 113mb when installed. If they are literally just fake processes running that have the right names, why couldn't this be a 100kb installer?
Post reply on HN