Live data from Hacker News

Cyber Scarecrow

cyberscarecrow.com

71–80 of 253 posts

Re: Cyber Scarecrow

#71
post #43

Earlier quoted context omitted.

“Sophisticated” detection can be as simple as checking rss and pcpu, the bullshit decoy processes probably aren’t wasting a lot of CPU and RAM, otherwise might as well run the real things; if they are, well, just avoid, who cares. So no, it’s not going to meaningfully complicate anything.

Wouldn't that be more fragile though? CPU usage is not constant in time, so if - again - you're not sophisticated enough, you get more false negatives / positives, depending on which side of the heuristic you err.

This is only useful for dragnet malware targeting the masses, where false positives/negatives have low impact to begin with. High value targets can run the real programs if this is proven to have any effect — the average corporate IT can approve some more bloat for security, no problem. Also, you take a sample.

Re: Cyber Scarecrow

#72
post #15

not surprised if this is the trojan horse

Next you'll be suggesting that some AV vendors have been known to sponsor development of new viruses and malware.

I also wouldn't download this in 1000 years with no additional information and sourcecode / github etc...

Re: Cyber Scarecrow

#73

Earlier quoted context omitted.

Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive for windows. Smartscreen also triggers when you install it. Id be weary of installing it myself as well, especially considering it runs as admin, to be able to create the fake indicators. I have just added a bit of info about us on the website. I'm not sure w…

Is it possible to fake being from Russia. I heard some malware won't install on computers from Russia or with the Russian language as primary language

This can have the opposite effect too: https://arstechnica.com/information-technology/2022/03/sabot...

Re: Cyber Scarecrow

#74

Earlier quoted context omitted.

Is it possible to fake being from Russia. I heard some malware won't install on computers from Russia or with the Russian language as primary language

Great idea. Looking at installing an additional keyboard or language with out it being anoying to the user is next on the feature list.

This might be not a good idea. There are some reports of malware (npm packages, iirc) specifically targeting russian computers since the invasion

Re: Cyber Scarecrow

#75
I get the idea but the "science" is based on reports it doesn't look like this has been tested with actual malware. Would be interesting to know how well it works

Also make it OSS and ask for donations. Not sure what your feature earning model is but is seems easy to replicate and as point out several times right now it asked to blindly thrust you

Re: Cyber Scarecrow

#76

One of the reference in "How does it work" [1] mentioned that some hackers will not mess with computers with Russian keyboard, so you can add one to reduce your chance of getting hacked. Hilarious aside, it would only work if you don't actually use multiple keyboard -- otherwise an additional one would make switching between multiple keyboards very annoying [*]. It also mentions some other changes like adding RU keyw…

> A little rant: as someone who use three virtual keyboards (English, Chinese, Japanese), it is already a pain in ass to switch them since MS does not follow "last used" switching order (like alt+tab). Instead, it just switches in one direction.

Actually, I much prefer this order. Depending on what keyboard I currently use, I know exactly how often to switch instead of having to remember what I used previously. In fact, I don't even like this order when Alt+Tab'ing, it makes switching between more than two windows pretty inconsistent (yes, I know Windows+Number works, too).

Re: Cyber Scarecrow

#77

One of the reference in "How does it work" [1] mentioned that some hackers will not mess with computers with Russian keyboard, so you can add one to reduce your chance of getting hacked. Hilarious aside, it would only work if you don't actually use multiple keyboard -- otherwise an additional one would make switching between multiple keyboards very annoying [*]. It also mentions some other changes like adding RU keyw…

> MS does not follow "last used" switching order

Furthermore:

1. The Shift+Alt chord is obnoxiously unreliable, sensitive to which key comes down first, or something.

2. Japanese is always comeing up in A mode even though you last had it in あ mode.

3. Bad performance: sllllow language switching at times: you hit some keyboard sequence for changing languages or modes within a language, and nothing happens. This interacts with (2): did we hit an unreliable chord? Or is it just slow to respond?

Re: Cyber Scarecrow

#79
post #67
post #47

Earlier quoted context omitted.

That's the WHOIS privacy service enabled by default on .com domains registered through Namecheap.

Hmm my Namecheap domains keep the location details even with WHOIS privacy enabled. To be fair they are 7+ years old so maybe something has changed in that time?

You can still apologize by editing your parent comment. Humility is a gift.

Re: Cyber Scarecrow

#80

Earlier quoted context omitted.

Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive for windows. Smartscreen also triggers when you install it. Id be weary of installing it myself as well, especially considering it runs as admin, to be able to create the fake indicators. I have just added a bit of info about us on the website. I'm not sure w…

Is it possible to fake being from Russia. I heard some malware won't install on computers from Russia or with the Russian language as primary language

And be targeted by cyberwarfare from the first-world side.
Post reply on HN