Live data from Hacker News

UTorrent.com compromised, malware added to installer

blog.bittorrent.com

31–40 of 40 posts

Re: UTorrent.com compromised, malware added to installer

#31
post #9

Earlier quoted context omitted.

May I suggest Deluge ( http://deluge-torrent.org/ )? It's open-source, cross-platform and very similar to µTorrent in both functionality and looks.

Can I choose which files to download before it puts empties on the file system?

Yes. It might create some folder structure, but if you choose at the time of adding the torrent to not download particular files, it won't create files. Tested just now on 1.3.1/Linux. I haven't tested recently, but I know I've gone in after adding the torrent, told it not to download some files, deleted what it had on the fs, and it did not regenerate them.

Re: UTorrent.com compromised, malware added to installer

#32

Earlier quoted context omitted.

Transmission ( http://www.transmissionbt.com/ ) is an open source torrent client with a nice web interface (as well as native interface) just like Deluge. I think it is somewhat lighter resource-wise (I'm running it on my NAS), but apart from that I don't know the exact differences between Deluge and Transmission, but I thought I'd mention it for completeness' sake.

I love Transmission on OS X and wish they had a real Windows port!

Their website demonstrates a Qt GUI, as well as a web interface. What would, in your opinion, constitute a "real" Windows port?

Re: UTorrent.com compromised, malware added to installer

#33
post #5

I stopped using it since it wasn't open source. Worse when it became infested with "optional" ~~adware~~ search bar.

Optional adware I can deal with in an otherwise open source application, but I've never understood why anyone would use a closed source bittorrent client if they ever plan on committing copyright infringement.

Re: UTorrent.com compromised, malware added to installer

#34
post #24

Earlier quoted context omitted.

> $400/yr That's VeriSign for you. Thawed sells the very same certificates for $200, and Comodo runs a coupon deal for Tucows members that gets you the cert for $99 (though the actual process is a bit too contrived compared to Thawte's).

startssl.com has code signing certificates for 60$, valid for 2 years.

yeah, I didn't go out of my way to find the cheapest price there. I just searched for "authenticode certificate" and that was the first result.

Re: UTorrent.com compromised, malware added to installer

#35
post #30
post #10

Earlier quoted context omitted.

courgette is just a binary diff algorithm -- there's nothing fancy to it (they use some really neat tricks, though), and apparently (I haven't verified) the source is in the chromium tree. validating your updates via asymmetric crypto can be mildly expensive ( http://www.verisign.com/code-signing/content-signing-certifi... lists Windows Authenticode certificates at $400/yr) but is within the realm of a small company.…

I was talking about downloading their update code from their repositories and setting it up. That's not easy and you can see the discussions about this on their forum.

you can either use Courgette or bsdiff or some other binary diff algorithm for compressing code updates, or punt and choose to fully replace all of your code every time you rev.

update verification is a for Chrome-style background updating, the solution is as simple as:

1) running a thread in the background to ping an API to check when updates are available, 2) downloading them via HTTP when they arrive, and 3) having a program which gets run at update-required-exit, which verifies and applies the patch to your main executable.

yes, writing update machinery for your software is some work. no, it's not insurmountable, and will certainly get easier as the Mac App Store and Windows Store gain traction because they allow you to piggyback on the update machinery of the platform.

Re: UTorrent.com compromised, malware added to installer

#36
post #5

I stopped using it since it wasn't open source. Worse when it became infested with "optional" ~~adware~~ search bar.

I installed it recently and even though I tried being careful not to install anything unnecessary, it tricked me into it! There was a checkbox saying something like "accept terms and conditions and install Bing toolbar", and I only readbthe beginning and left it checked as Eulas have conditioned me (of course I had accepted terms and conditions of utorrent before that).

Re: UTorrent.com compromised, malware added to installer

#37

Earlier quoted context omitted.

pacman cough cough sorry I just lost it for a second...

Some explanation to counter those terrible downvotes: Pacman, the package manager of Archlinux, is not implementing the verification of package signatures. It's a recurrent issue in the Arch community.

It seems things are changing http://allanmcrae.com/2011/08/pacman-package-signing-3-pacma...

Re: UTorrent.com compromised, malware added to installer

#38
post #32

Earlier quoted context omitted.

I love Transmission on OS X and wish they had a real Windows port!

Their website demonstrates a Qt GUI, as well as a web interface. What would, in your opinion, constitute a "real" Windows port?

Something better than those options? What about a web interface or a Qt GUI screams "great Windows UI" to you?

Re: UTorrent.com compromised, malware added to installer

#39
post #32

Earlier quoted context omitted.

Their website demonstrates a Qt GUI, as well as a web interface. What would, in your opinion, constitute a "real" Windows port?

Something better than those options? What about a web interface or a Qt GUI screams "great Windows UI" to you?

I suppose I did not place the same emphasis on "great" as you did. Alternatively, I couldn't name a "great" Windows UI offhand, anyway.

However, my experience is that some Qt apps on Windows behave normally, and depending on the application (but in this case, especially just the need to manage torrents) a web UI works just fine and avoids the waste of developer hours fighting against the local platform's quirks.

For my enlightenment, what do you consider as an example of a great Windows UI?

Re: UTorrent.com compromised, malware added to installer

#40
post #7

Earlier quoted context omitted.

still using the last-open source version with the auto-updater disabled!

I'm pretty sure uTorrent was never open source. The mainline client was, though.

my mistake it wasn't oss, it was the last version before BitTorrent began bundling it into installers.
Post reply on HN