Live data from Hacker News

Cyber Scarecrow

cyberscarecrow.com

231–240 of 253 posts

Re: Cyber Scarecrow

#233

Earlier quoted context omitted.

I’m sure it’s closed source for the eventual plans to monetize it, but what’s the real difference to something like https://github.com/NavyTitanium/Fake-Sandbox-Artifacts and why can’t you at least name yourselves? Not many software promises to fend off attackers, asks for an email address before download, and creates a bunch of processes using a closed source dll the existence of which can easily be checked. Then ag…

I am pretty sure this is just malware being upvoted with sockpuppet accounts, I'm surprised it hasn't been flagged.

agreed

Re: Cyber Scarecrow

#234

Earlier quoted context omitted.

I’m sure it’s closed source for the eventual plans to monetize it, but what’s the real difference to something like https://github.com/NavyTitanium/Fake-Sandbox-Artifacts and why can’t you at least name yourselves? Not many software promises to fend off attackers, asks for an email address before download, and creates a bunch of processes using a closed source dll the existence of which can easily be checked. Then ag…

I am pretty sure this is just malware being upvoted with sockpuppet accounts, I'm surprised it hasn't been flagged.

Are you talking about this GitHub script or the Scarecrow app?

Re: Cyber Scarecrow

#235
post #4

Fun concept. If the creators read this, I suggest some ways of building trust. There’s no “about us”, no GitHub link, etc. It’s a random webpage that wants my personal details, and sends me a “exe”. The overlap of people who understand what this tool does, and people who would run that “exe” is pretty small.

That's a problem with a lot of software and developers these days. An "About Me" section with a real face and presence is important and I don't mean anime characters and aliases either. Tell me who you are, put yourself out there.

Re: Cyber Scarecrow

#236
post #4

Fun concept. If the creators read this, I suggest some ways of building trust. There’s no “about us”, no GitHub link, etc. It’s a random webpage that wants my personal details, and sends me a “exe”. The overlap of people who understand what this tool does, and people who would run that “exe” is pretty small.

Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive for windows. Smartscreen also triggers when you install it. Id be weary of installing it myself as well, especially considering it runs as admin, to be able to create the fake indicators. I have just added a bit of info about us on the website. I'm not sure w…

How are you planning on preventing bad actors to identify scarecrow itself? You gonna randomize the name/processes etc?? Like anti-malware software do to install in stealth-mode??

Re: Cyber Scarecrow

#238
post #213
post #179

Earlier quoted context omitted.

Concerning code signing: Azure has a somewhat new offering that allows you to sign code for Windows (SmartScreen compatible) without having an EV cert. It is called "Trusted Signing" [1], non-marketing docs [2]. The major gotcha is that currently you need to have a company or similar entity 3 years or older to get public trust. I tried it with a company younger than 3 years and was denied. You might have a company th…

So $10+$5 per month versus $195 per year? That's not a big discount.

Don't you know.. microsoft doesn't believe in discounts. The evil-empire runs a taxing system envied by the IRS itself. Entire industries have gone up in arms complaining that M$ cloud price structure doesn't allow for third party margins and still they hold strong to their price structure.

Re: Cyber Scarecrow

#239

Earlier quoted context omitted.

Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive for windows. Smartscreen also triggers when you install it. Id be weary of installing it myself as well, especially considering it runs as admin, to be able to create the fake indicators. I have just added a bit of info about us on the website. I'm not sure w…

How are you planning on preventing bad actors to identify scarecrow itself? You gonna randomize the name/processes etc?? Like anti-malware software do to install in stealth-mode??

[deleted]

Re: Cyber Scarecrow

#240

Earlier quoted context omitted.

I am pretty sure this is just malware being upvoted with sockpuppet accounts, I'm surprised it hasn't been flagged.

Are you talking about this GitHub script or the Scarecrow app?

The closed source one that asks for your email and has very little information about its developers.
Post reply on HN