Live data from Hacker News

Cyber Scarecrow

cyberscarecrow.com

241–250 of 253 posts

Re: Cyber Scarecrow

#241
It asks for our names and emails, provides an opaque exe and no source code, asks to be run as admin, pings home, doesn’t say who you are or how many of you there are, and justifies it all with “trust me bro”.

People, this is malware. Please don’t fall for it.

I don’t think it’s wise to leave this on the front page. I hope dang agrees and takes it down.

Re: Cyber Scarecrow

#242

Earlier quoted context omitted.

Look into Windows NT source code that was leaked. The if-else/switch statements in there is just another level of string matching hell. Seems like software development just become "let's jerry rig it to just make it work and forget about it." Pretty sure management (without tech clue) have something to do behaviours like this.

> Pretty sure management (without tech clue) have something to do behaviours like this. Always the same bullshit with you people here. Could never possibly someone built a sub-optimal system -- it HAD to be management fucking with our good intentions!

Well yeah. Left to their own devices, people want to build good stuff. It's when some dumb turd with his metrics and clueless plan shows up that things get screwy.

Re: Cyber Scarecrow

#243

Earlier quoted context omitted.

It is a cat and mouse game. And security by obscurity practice. Not saying it won't work, but if it is open sourced, how long before the malware will catch on? Here is one on github: https://github.com/NavyTitanium/Fake-Sandbox-Artifacts

It's not a cat an mouse game; it's a diver and shark game. In SCUBA training we joked that you had the "buddy system" where you always dive in pairs, because that way if you encounter a shark you don't have to outswim the shark, you only have to outswim your buddy. A low-effort activity that makes you not be the low-hanging fruit can often be worth it. For example, back in the '90s I moved my SSH port from 22 to ...…

What I've heard is: If you're running from a bear, you only have to be faster than the other guy.

Re: Cyber Scarecrow

#244

Earlier quoted context omitted.

Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive for windows. Smartscreen also triggers when you install it. Id be weary of installing it myself as well, especially considering it runs as admin, to be able to create the fake indicators. I have just added a bit of info about us on the website. I'm not sure w…

Where is that additional info? It just says you're a group of security researchers, but there are no names, no verifiable credentials, nothing. You haven't really added any info that would contribute to any real trust.

Exactly. This continues to tell us absolutely nothing.

"Who are you?

We are cyber security researchers, living in the UK. We built cyber scarecrow to run on our own computers and decided to share it for others to use it too."

Re: Cyber Scarecrow

#245

Earlier quoted context omitted.

I have no idea of the costs but I am confused where that percentage came from. It doesn’t match anything not the parent comment.

What percentage of 195 is 70?

$70 isn't correct though. The cost was originally described upthread as ($10 per month) + ($5 per month), not ($10 per year) + ($5 per month).

That said, EV certs jumped in price over the past couple years. The total cost ends up being higher than the list price -- vendors tack on a non-trivial extra fee for the USB hardware token and shipping. All-inclusive I paid like $450 a year ago, and that was after getting a small repeat-customer discount.

So yes, Azure's service is substantially cheaper than an EV cert. And it also has the flexibility of being a monthly plan, rather than an annual commitment.

Re: Cyber Scarecrow

#246

Earlier quoted context omitted.

What percentage of 195 is 70?

$70 isn't correct though. The cost was originally described upthread as ($10 per month) + ($5 per month), not ($10 per year ) + ($5 per month). That said, EV certs jumped in price over the past couple years. The total cost ends up being higher than the list price -- vendors tack on a non-trivial extra fee for the USB hardware token and shipping. All-inclusive I paid like $450 a year ago, and that was after getting a…

[deleted]

Re: Cyber Scarecrow

#247

Earlier quoted context omitted.

What percentage of 195 is 70?

$70 isn't correct though. The cost was originally described upthread as ($10 per month) + ($5 per month), not ($10 per year ) + ($5 per month). That said, EV certs jumped in price over the past couple years. The total cost ends up being higher than the list price -- vendors tack on a non-trivial extra fee for the USB hardware token and shipping. All-inclusive I paid like $450 a year ago, and that was after getting a…

[deleted]

Re: Cyber Scarecrow

#248

Earlier quoted context omitted.

> MS does not follow "last used" switching order Furthermore: 1. The Shift+Alt chord is obnoxiously unreliable, sensitive to which key comes down first, or something. 2. Japanese is always comeing up in A mode even though you last had it in あ mode. 3. Bad performance: sllllow language switching at times: you hit some keyboard sequence for changing languages or modes within a language, and nothing happens. This intera…

I have to use a 3rd party Japanese IME precisely because of 2. No idea why they haven't add an option for it to be default to あ mode. Also, in ANY modern Chinese IME (Microsoft or 3rd party), switching between English/中文 mode is simply pressing shift once. You still have to use alt+` for that in JP IME, which I find unbearable.

> You still have to use alt+` for that in JP IME

I have no idea whether it is any better for you, but another way is Ctrl+CapsLock.

Re: Cyber Scarecrow

#249

This software pings home. Also uses .NET which is complete overkill for such a simple app. Would not recommend installing. It's someone's hobby project that runs as administrator.

What would you use instead?

I don't know, just not this. Wouldn't be hard to make it yourself though.

Re: Cyber Scarecrow

#250
post #4

Fun concept. If the creators read this, I suggest some ways of building trust. There’s no “about us”, no GitHub link, etc. It’s a random webpage that wants my personal details, and sends me a “exe”. The overlap of people who understand what this tool does, and people who would run that “exe” is pretty small.

Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive for windows. Smartscreen also triggers when you install it. Id be weary of installing it myself as well, especially considering it runs as admin, to be able to create the fake indicators. I have just added a bit of info about us on the website. I'm not sure w…

I'd suggest putting down the actual authors. If you're UK based there should really be no issue in putting down each of the people involved and what their background in the industry is. Otherwise this just looks like a v1 to get people interested and v2 could include malware. Tbh it'd be quite a clever ploy if it is malware. Trust isn't built blindly, most smaller software creators always have their details known. I'd suggest if you want it to pick up traction, you have a full "about us" page.
Post reply on HN