Earlier quoted context omitted.
> It's caught things that the others have missed. What other things? Did you run FSecure, Panda, ESET, Emsisoft, Avira, Avast, Herdprotect? It might be useful, but it is dangerous. It should be an absolute last ditch effort, not standard procedure. >AdwCleaner requires a restart to finish up, as I understand it. Try running it twice in a row without a restart. Try running it before and after a malwarebytes scan, with…
Don't forget TDSSKiller and Norton Power Eraser. Super useful tools for checking MBRs.
What Happens When You Install the Top Download.com Apps
321–330 of 395 posts
Re: What Happens When You Install the Top Download.com Apps
#322Earlier quoted context omitted.
I don't have a fully baked design in mind, but I could probably come up with one if I had a long time to focus on it. I do have a general framework in mind for how one might approach the question. First and foremost, security should be a primary OS design objective and it should go into the design deep . It should be something you think about before secondary concerns like a process model, binary format, driver frame…
Thanks for taking the time to reply. -- I don't understand how only allowing signed execution would help avoid this problem. Like you said, anyone could pay to get their company listed as a 'trusted' entity. The problem is you cant push this task to the user, because the non-technical layman user is not in a position to determine this. If we only allow signed binaries to be loaded in memory, then we won't need IPC to…
The purpose of signing isn't to guarantee that an entity is anything, but to allow the user to absolutely and decisively rule what code is allowed to execute. If the Russian Mob sneaks some code from "G0ogle, Ink." onto my machine by tricking me into authorizing that cert, I can just de-authorize it and then it all DIAF.
When I say signing, I don't necessarily mean the app store feudal model. I mean an inverted version of that -- where the user decides what runs by approving certs by signing them with some kind of master key.
"Poof, no more program debuggers, profilers, no more device drivers, no more third party file systems, no more"
You can debug Java pretty effectively. There are great toolchains for that. I agree that direct ASM may be required for a few things like drivers, but those are going to be the exceptions not the rule.
"How does that help my mom? She's just going to call me when the computer asks her "weird questions about keys and permissions"."
"Again, why would the user WANT to be in the drivers seat? They have no clue how to drive the car!"
Freedom and control are things you should have, but should not be forced to exercise. It should be possible to leave them alone and just trust one or more vendors. This is a UI/UX issue.
With things like iOS I don't have the option.
"That only tackles the problem of cleanup, which is a separate problem. By that time, the malware is already on the system and it's sent your credit card and documents to the bad guys."
Absolute security perfection isn't possible, but I think huge improvements can be made. Don't let the perfect be the enemy of the good.
Data leakage and social engineering are particularly thorny because they're really only half technical problems. The meat sack using the machine is always going to be a weak point in any security model. But if the machine were secure, it would help.
Re: What Happens When You Install the Top Download.com Apps
#323Earlier quoted context omitted.
At least the actual, genuine result is visible without scrolling. A few years Google were paying computer manufacturers to set a special version of Google with more prominent ads as their default search engine. The net result was that if you got a new computer and searched for Firefox using their default, Google-supplied search the genuine result was actually below the fold in some cases.
Can you back that up with a citation?
[1] See http://blog.opendns.com/2007/05/22/google-turns-the-page/
Re: What Happens When You Install the Top Download.com Apps
#324Earlier quoted context omitted.
Can I get an example? I am considering moving some family to Linux and I couldn't find anything they would be missing upon a cursory glance.
I used to re-install windows to my family like once a year, but then I refused to doing it anymore but I offered to install ubuntu on their machines. It's being like 4 years so far and they hardly need any maintenance from me. IMOE the main issue are software-suites Cad and 3D : my dad is really used to windows, and learning the linux environment was an easy step for him. He could never do the switch to open source c…
Re: What Happens When You Install the Top Download.com Apps
#325Earlier quoted context omitted.
> and that it's our own fault Whose fault exactly is it? Has anybody in HN worked with a company which does this crapware bundling, let alone creating? Or does anybody know anyone who's "in the business"? Because I, quite honestly, can't understand how or why people would be doing this. Is it really that "Well, I know this shit is going to infect thousands of machines with software which nobody would like to have, bu…
> Has anybody in HN worked with a company which does this crapware bundling, let alone creating? If anyone here has worked for Adobe (Flash included crapware for a long time), Oracle (Java updates used to or still do include crapware), Google (browser toolbar was crapware), or Apple (Quicktime for Windows attempted to install iTunes and Safari), then yes.
The truth is, if you look far enough, you can always find something to be guilty about. I'm not going to blame programmers working for any of those companies, but I will squarely place the blame on companies with hypocritical culture.
Apple upper management: Hey, let's bundle all this crap with something that people actually want!
Years later
Apple upper management: Wow! People are bundling crap with things that people actually want! We should put a stop to that by fucking over our customers' right to choose in a free market!
Re: What Happens When You Install the Top Download.com Apps
#326Earlier quoted context omitted.
Ironic, considering that Apple did exactly the same, when you installed QuickTime on Windows. They tried to trick you into installing iTunes and Safari and set them as default apps. Also, it stinks that Apple has nailed iOS that shut that even as a knowledgeable user you are not able to bypass it. They did not yet dare to do the same on Mac OS, but who knows when that comes.
iTunes for Windows is a monster that drains the life out of the PC. Microsoft Office for Mac OSX was coded with the same evil spirit. This behavior is unethical but pervasive, and should be outlawed somehow, it hurts everyone. Specially when it comes from the two biggest players in the market.
I'm sure they get no support from corporate IT, their company's marketing constantly makes fun of their chosen field of expertise, and they probably even have their own table in the cafeteria. :(
Re: What Happens When You Install the Top Download.com Apps
#327And this is why Apple created Gatekeeper and made the Mac OS X App Store so ridiculously onerous for developers[1]. The software world is, for all intents and purposes, a thin sheen of gold flecks and diamonds atop a veritable cesspool of shit. You can just imagine the conversation at 1 Infinite Loop: Marketer: The Panic guys are considering pulling out of the App Store. Maybe we should reconsider our App Store strat…
> and that it's our own fault Whose fault exactly is it? Has anybody in HN worked with a company which does this crapware bundling, let alone creating? Or does anybody know anyone who's "in the business"? Because I, quite honestly, can't understand how or why people would be doing this. Is it really that "Well, I know this shit is going to infect thousands of machines with software which nobody would like to have, bu…
If 'we' wanted to, we would at least work on getting rid of this kind of behaviour. In an alternative world, the equivalent of GreenPeace would parade the C|NET offices, newspapers would write angry editorials about them, harmed users would write them millions of complaint letters, and class action lawsuits would be filed.
Problem is that 'normal' users have been slowly subdued into "it's my fault" mode.
Re: What Happens When You Install the Top Download.com Apps
#328Instead of dowloading from Sourceforge (loaded with ads and its own devious 'installer'), CNET, Download, etc, there are no-crapware alternatives that offer more management tools as well (remembering your list of apps across machines, automated updates, discoverability): Ninite: nice, simple, installer: just select apps and let the installer do it all for you. AllMyApps: all the apps, no crapware (at least for now).…
We have much the same functionality at http://PortableApps.com/ You get an app store, an automatic app updater, an app manager, and hundreds of freeware and open source apps. All free of malware and bundleware. As a bonus, all the apps run from a single directory each, making it easy as pie to uninstall and remove all the apps settings at the same time (as opposed to bits left behind in AppData, Local AppData, the Re…
Re: What Happens When You Install the Top Download.com Apps
#329Microsoft dropped the ball with lack of App Store. With all app store's drawbacks, that's the place where regular user can pay easily without thinking will someone steal his/her credit car number, the place where applications should be harmless, and the place where (and this is important) the user can compare prices between similar applications. Windows doesn't have the app store. And nobody (read: very, very small p…
The one who dropped the ball is CNet. They could have used their good name to establish a curated software marketplace and done subscription, app sales, freemium... anything at all other than giving their reputation a giant flush for a few bucks and earning themselves a 127.0.0.1 in the hosts file of computers I work on.
Re: What Happens When You Install the Top Download.com Apps
#330Earlier quoted context omitted.
Thanks for taking the time to reply. -- I don't understand how only allowing signed execution would help avoid this problem. Like you said, anyone could pay to get their company listed as a 'trusted' entity. The problem is you cant push this task to the user, because the non-technical layman user is not in a position to determine this. If we only allow signed binaries to be loaded in memory, then we won't need IPC to…
"I don't understand how only allowing signed execution would help avoid this problem. Like you said, anyone could pay to get their company listed as a 'trusted' entity." The purpose of signing isn't to guarantee that an entity is anything, but to allow the user to absolutely and decisively rule what code is allowed to execute. If the Russian Mob sneaks some code from "G0ogle, Ink." onto my machine by tricking me into…
The entire problem is that the users have no idea prior to installing the software, whether its legit or malware. I don't see anything in what you've proposed that solves the root problem. Yes, we can look at peripheral problems like cleanup and revoking certificates but those only affect users AFTER they've already made the choice of installing a particular piece of software.