Live data from Hacker News

CNET Injecting Malware into Downloads

insecure.org

31–40 of 80 posts

Re: CNET Injecting Malware into Downloads

#31
post #20

There's three things here. First, adding a toolbar and screwing with user settings is freaking lame, but everyone does it and it's something that's been an accepted way to monitize software development. However, injecting that into other people's software is low, especially if the developers aren't aware of it. CNET should be ashame. Lastly, the way they present it to users should be plainly criminal. There's a way t…

"but everyone does it and it's something that's been an accepted way to monitize software development"

No piece of software that I have installed during the past two years has done so, and I sure wouldn't accept it as a way of funding development. I'd rather pay for a product in that case.

Can you give a few examples from your list of "everyone"?

Re: CNET Injecting Malware into Downloads

#32
post #29
post #20

There's three things here. First, adding a toolbar and screwing with user settings is freaking lame, but everyone does it and it's something that's been an accepted way to monitize software development. However, injecting that into other people's software is low, especially if the developers aren't aware of it. CNET should be ashame. Lastly, the way they present it to users should be plainly criminal. There's a way t…

They do not injecting it, it's just a small downloader that helps to download applications even with bad connection. And potentially may use a p2p distribution, as for example some game developers upload their game clients(>1gb). Well-known companies pay per download for their software suits, and they don't really like to pay for the interrupted downloads. Im not sure about the deceptive tactics, they just trying to…

Hello CNET

Re: CNET Injecting Malware into Downloads

#33

What good alternatives would people suggest? What should be the "goto" site we could suggest to a novice for finding a clean copy of almost any software...any suggestions? (Assuming that an expert user would straight to the source website)

Not a site for grabbing any software, but for most of the software I (or, for example, my mother in law) would use (outside of dev tools), I go to ninite.com, tick the boxes of what I want and get what is essentially a single installer for everything.

That's my current 'goto' site, at least.

Re: CNET Injecting Malware into Downloads

#34
post #25
post #21

Earlier quoted context omitted.

http://www.clamav.net/ if you were actually wondering. There's also a sweet osx port: http://www.clamxav.com/

Did you ever catch something with it?

It's great as an additional protection in your mail setup. My personal domains are few and email accounts not widely exposed. ClamAV caught 7 viruses in 2010, though I get about 20 spam emails per day. Since I never check the imap folders for spam, it might be that some of them were not caught by ClamAV, but by spam filters instead.

Anyway, for 7 virus emails per year I couldn't justify 100+Mb memory requirement on my 512 linode, so ClamAV no more.

Re: CNET Injecting Malware into Downloads

#35
post #31
post #20

There's three things here. First, adding a toolbar and screwing with user settings is freaking lame, but everyone does it and it's something that's been an accepted way to monitize software development. However, injecting that into other people's software is low, especially if the developers aren't aware of it. CNET should be ashame. Lastly, the way they present it to users should be plainly criminal. There's a way t…

"but everyone does it and it's something that's been an accepted way to monitize software development" No piece of software that I have installed during the past two years has done so, and I sure wouldn't accept it as a way of funding development. I'd rather pay for a product in that case. Can you give a few examples from your list of "everyone"?

I think the Java runtime installer asks to install a toolbar. There is something else that I can't recall (flash runtime?) that asks to install the Ask.com toolbar all the time as well. Some popular open source projects too (PDFCreator).

Re: CNET Injecting Malware into Downloads

#36
post #8

Earlier quoted context omitted.

But this is ignorant and not true.

For laymen's purposes it pretty much is, though. When was the last time anyone on Linux/OSX got some adware / popups? I've also never heard of antivirus for Linux. Which doesn't mean there aren't viruses, it means it's not a concern on the most part.

rkhunter and chrootkit are two free malware scanners (also in ubuntu repos). There's also Avast for Linux. Avira have a free scanner (no GUI though) etc. If you actually look there are plenty of antivirus and antimalware tools.

Re: CNET Injecting Malware into Downloads

#37
post #8
post #6

When my mother forwards me the latest malware scare chain letter she got frm her friends, I tell her to picture her computer as a plane flying at Mach 4, high above in the stratosphere, confident almost nothing launched from the ground can harm her. That's because she doesn't use Windows.

But this is ignorant and not true.

It's "relatively true."

The fact is that there is malware including viruses for Linux. The fact is though that they are pretty rare, and the types involved are unlikely ever to become serious threats on the desktop.

It's not perfectly safe, but it's safe enough that safe enough that basic precautions for the desktop are currently good enough. Of course mobile systems are something different.

Re: CNET Injecting Malware into Downloads

#38
post #8
post #6

When my mother forwards me the latest malware scare chain letter she got frm her friends, I tell her to picture her computer as a plane flying at Mach 4, high above in the stratosphere, confident almost nothing launched from the ground can harm her. That's because she doesn't use Windows.

But this is ignorant and not true.

Don't forget smug as fuck.

Re: CNET Injecting Malware into Downloads

#39
post #25
post #21

Earlier quoted context omitted.

http://www.clamav.net/ if you were actually wondering. There's also a sweet osx port: http://www.clamxav.com/

Did you ever catch something with it?

If ever, it catches Windows viruses usually. Prevent them from spraying and is also very useful on Linux server setups.

Re: CNET Injecting Malware into Downloads

#40
post #31

Earlier quoted context omitted.

"but everyone does it and it's something that's been an accepted way to monitize software development" No piece of software that I have installed during the past two years has done so, and I sure wouldn't accept it as a way of funding development. I'd rather pay for a product in that case. Can you give a few examples from your list of "everyone"?

I think the Java runtime installer asks to install a toolbar. There is something else that I can't recall (flash runtime?) that asks to install the Ask.com toolbar all the time as well. Some popular open source projects too (PDFCreator).

Hahaha, Sun/Oracle does it, therefore it's OK.

Ask me why I quit Java long ago.

Post reply on HN