Earlier quoted context omitted.
64% is indeed a hefty discount
I have no idea of the costs but I am confused where that percentage came from. It doesn’t match anything not the parent comment.
Cyber Scarecrow
231–240 of 253 posts
Re: Cyber Scarecrow
#232Re: Cyber Scarecrow
#233Earlier quoted context omitted.
I’m sure it’s closed source for the eventual plans to monetize it, but what’s the real difference to something like https://github.com/NavyTitanium/Fake-Sandbox-Artifacts and why can’t you at least name yourselves? Not many software promises to fend off attackers, asks for an email address before download, and creates a bunch of processes using a closed source dll the existence of which can easily be checked. Then ag…
I am pretty sure this is just malware being upvoted with sockpuppet accounts, I'm surprised it hasn't been flagged.
Re: Cyber Scarecrow
#234Earlier quoted context omitted.
I’m sure it’s closed source for the eventual plans to monetize it, but what’s the real difference to something like https://github.com/NavyTitanium/Fake-Sandbox-Artifacts and why can’t you at least name yourselves? Not many software promises to fend off attackers, asks for an email address before download, and creates a bunch of processes using a closed source dll the existence of which can easily be checked. Then ag…
I am pretty sure this is just malware being upvoted with sockpuppet accounts, I'm surprised it hasn't been flagged.
Re: Cyber Scarecrow
#235Fun concept. If the creators read this, I suggest some ways of building trust. There’s no “about us”, no GitHub link, etc. It’s a random webpage that wants my personal details, and sends me a “exe”. The overlap of people who understand what this tool does, and people who would run that “exe” is pretty small.
Re: Cyber Scarecrow
#236Fun concept. If the creators read this, I suggest some ways of building trust. There’s no “about us”, no GitHub link, etc. It’s a random webpage that wants my personal details, and sends me a “exe”. The overlap of people who understand what this tool does, and people who would run that “exe” is pretty small.
Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive for windows. Smartscreen also triggers when you install it. Id be weary of installing it myself as well, especially considering it runs as admin, to be able to create the fake indicators. I have just added a bit of info about us on the website. I'm not sure w…
Re: Cyber Scarecrow
#237Lots of people on HN could easily spin up their own fake processes if they knew the names?
Re: Cyber Scarecrow
#238Earlier quoted context omitted.
Concerning code signing: Azure has a somewhat new offering that allows you to sign code for Windows (SmartScreen compatible) without having an EV cert. It is called "Trusted Signing" [1], non-marketing docs [2]. The major gotcha is that currently you need to have a company or similar entity 3 years or older to get public trust. I tried it with a company younger than 3 years and was denied. You might have a company th…
So $10+$5 per month versus $195 per year? That's not a big discount.
Re: Cyber Scarecrow
#239Earlier quoted context omitted.
Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive for windows. Smartscreen also triggers when you install it. Id be weary of installing it myself as well, especially considering it runs as admin, to be able to create the fake indicators. I have just added a bit of info about us on the website. I'm not sure w…
How are you planning on preventing bad actors to identify scarecrow itself? You gonna randomize the name/processes etc?? Like anti-malware software do to install in stealth-mode??
Re: Cyber Scarecrow
#240Earlier quoted context omitted.
I am pretty sure this is just malware being upvoted with sockpuppet accounts, I'm surprised it hasn't been flagged.
Are you talking about this GitHub script or the Scarecrow app?