Live data from Hacker News

CNET Injecting Malware into Downloads

insecure.org

51–60 of 80 posts

Re: CNET Injecting Malware into Downloads

#51
post #14

"This is probably why CNET switch to installing the Babylon Toolbar yesterday. This is a good and welcome move by Microsoft, but the whole process of paying “distribution partners“ to changer user's home page to MSN and search engine to Bing is rather sketchy" I am puzzled by the reaction of some journalists and people here. Have you actually thought why the toolbar is marked as malware? Usually, that's because one g…

It's malware because it's installing something that you didn't agree to install.

Re: CNET Injecting Malware into Downloads

#52
post #31
post #20

There's three things here. First, adding a toolbar and screwing with user settings is freaking lame, but everyone does it and it's something that's been an accepted way to monitize software development. However, injecting that into other people's software is low, especially if the developers aren't aware of it. CNET should be ashame. Lastly, the way they present it to users should be plainly criminal. There's a way t…

"but everyone does it and it's something that's been an accepted way to monitize software development" No piece of software that I have installed during the past two years has done so, and I sure wouldn't accept it as a way of funding development. I'd rather pay for a product in that case. Can you give a few examples from your list of "everyone"?

Trillian & Daemon Tools

Re: CNET Injecting Malware into Downloads

#53
post #31
post #20

There's three things here. First, adding a toolbar and screwing with user settings is freaking lame, but everyone does it and it's something that's been an accepted way to monitize software development. However, injecting that into other people's software is low, especially if the developers aren't aware of it. CNET should be ashame. Lastly, the way they present it to users should be plainly criminal. There's a way t…

"but everyone does it and it's something that's been an accepted way to monitize software development" No piece of software that I have installed during the past two years has done so, and I sure wouldn't accept it as a way of funding development. I'd rather pay for a product in that case. Can you give a few examples from your list of "everyone"?

Adobe tries to sneak Mcafee on your system with either flash or acrobat reader, which is worse and should also be criminal.

Re: CNET Injecting Malware into Downloads

#54
post #20

There's three things here. First, adding a toolbar and screwing with user settings is freaking lame, but everyone does it and it's something that's been an accepted way to monitize software development. However, injecting that into other people's software is low, especially if the developers aren't aware of it. CNET should be ashame. Lastly, the way they present it to users should be plainly criminal. There's a way t…

I strongly disagree with the following part: "but everyone does it and it's something that's been an accepted way to monitize software development". Here's why: - bundling such software with any product kills trust in one single fire; why would I allow such a software to make it into my environment? What if there are additional hidden things inside the code which steal data from my system and send it to a third party…

Piriform uses this to great effect. Not sure what they're taking in from their enterprise level offerings, but everyone and their brother uses their free products.

Re: CNET Injecting Malware into Downloads

#55
post #8
post #6

When my mother forwards me the latest malware scare chain letter she got frm her friends, I tell her to picture her computer as a plane flying at Mach 4, high above in the stratosphere, confident almost nothing launched from the ground can harm her. That's because she doesn't use Windows.

But this is ignorant and not true.

It's true for very broad values of true.

Techies know that there are OSX/Linux viruses, rootkits, etc. But there just aren't enough of them to have to expect the grief we get from Windows.

Re: CNET Injecting Malware into Downloads

#56
post #29

Earlier quoted context omitted.

They do not injecting it, it's just a small downloader that helps to download applications even with bad connection. And potentially may use a p2p distribution, as for example some game developers upload their game clients(>1gb). Well-known companies pay per download for their software suits, and they don't really like to pay for the interrupted downloads. Im not sure about the deceptive tactics, they just trying to…

Most trojan & trojan downloaders are also "just a small downloader that helps to download applications". The only problem is that you will have to reinstall the OS, erase everything and need a new bank account or even a new job. Also, HELLO, CNET, NICE TRY.

Pff i just know the kitchen as i worked there for some time :) It's not a trojan or malware for sure. 3/43, http://www.virustotal.com/file-scan/report.html?id=cb2428c76...

Some crappy adware? probably :)

Re: CNET Injecting Malware into Downloads

#57
post #14

"This is probably why CNET switch to installing the Babylon Toolbar yesterday. This is a good and welcome move by Microsoft, but the whole process of paying “distribution partners“ to changer user's home page to MSN and search engine to Bing is rather sketchy" I am puzzled by the reaction of some journalists and people here. Have you actually thought why the toolbar is marked as malware? Usually, that's because one g…

> the quote above that its actually a good thing to replace StartNow with Babylon

He meant it was good for Microsoft to stop paying them to screw people; not good for CNET to keep screwing people in the service of a different client.

Re: CNET Injecting Malware into Downloads

#58
post #27

Earlier quoted context omitted.

Everything on CNET is being tested manually with VirusTotal. If it gets at least 4 positives/false positives from 43 antivirus engines they don't publish it or work with it, until developers get things settled down with anti-virus/anti-malware companies. They get not that much profit from paid accounts cause of small percentage of subscribers, and give away tons of traffic + man hours even for free products. That inc…

Welcome to HN Georgiy. Here's the deal: That still doesn't mean it's not crapware. You mention the difficulty of funding your download site (built almost exclusively on supplying other people's free content). I can't imagine what the bandwidth costs must be on a site like that. I'm sure there are plenty of other visitors on HN that are familiar with this issue and are daily encountering similar ethical decisions abou…

It's just my humble opinion as an internet marketer :) i'm not related to CNET atm, worked there as tech for some time. And i think it's really an ingenious idea with wrapper, maybe not so good with all that toolbars. Maybe it's crapware and they lose like all geeks, 20% publishers and 30-40% users maximum - they still will be like x10 profitable than before. Don't get me wrong but Google wasted like hundreds of millions on unprofitable YouTube, and now they airing this shitty advertisements that are so fucking annoying %) luckily there are all theese adblock extensions out there.

Re: CNET Injecting Malware into Downloads

#59
post #27
post #14

"This is probably why CNET switch to installing the Babylon Toolbar yesterday. This is a good and welcome move by Microsoft, but the whole process of paying “distribution partners“ to changer user's home page to MSN and search engine to Bing is rather sketchy" I am puzzled by the reaction of some journalists and people here. Have you actually thought why the toolbar is marked as malware? Usually, that's because one g…

Everything on CNET is being tested manually with VirusTotal. If it gets at least 4 positives/false positives from 43 antivirus engines they don't publish it or work with it, until developers get things settled down with anti-virus/anti-malware companies. They get not that much profit from paid accounts cause of small percentage of subscribers, and give away tons of traffic + man hours even for free products. That inc…

Which CNET office do you work at: NY, Kentucky, or SF? ;)

Re: CNET Injecting Malware into Downloads

#60
post #27

Earlier quoted context omitted.

Everything on CNET is being tested manually with VirusTotal. If it gets at least 4 positives/false positives from 43 antivirus engines they don't publish it or work with it, until developers get things settled down with anti-virus/anti-malware companies. They get not that much profit from paid accounts cause of small percentage of subscribers, and give away tons of traffic + man hours even for free products. That inc…

Which CNET office do you work at: NY, Kentucky, or SF? ;)

I've worked in Moscow ^.^ all tech staff has been outsourced to different countries - Germany, Russia, India and etc.
Post reply on HN