Live data from Hacker News

7zip.com Is Serving Malware

malwarebytes.com

91–100 of 104 posts

Re: 7zip.com Is Serving Malware

#91
post #82

Earlier quoted context omitted.

You can corroborate multiple trusted sources, especially those with histories. You can check the edit history of the Wikipedia article. Also, if you search "7zip" on HN, the second result with loads of votes and comments is 7-zip.org. Another is searching the Archlinux package repos; you can check the git history of the package build files to see where it's gotten the source from.

And we're really going to do all the brouhaha for a single dl of an alternative compressor ? And then multiple that work as a best practice for every single interaction on the Internet? No we're not.

My point was more along the lines of "there's no need to complain about Wikipedia being hijackable, there are other options", and now you're complaining about having too many options...

You don't need to do everything or anything. They're options. Use your own judgment.

Re: 7zip.com Is Serving Malware

#93
post #41
post #15

Earlier quoted context omitted.

How can the average 7zip user know which one it is? Search results can be gamed by SEO, there were also cases of malware developers buying ads so links to the malware download show up above legitimate ones. Wikipedia works only for projects prominent enough to have a Wikipedia page. What are the other mechanisms for finding out the official website of a software?

Open source software will have a code repo with active development happening on it. That repo will usually link to official Web page and download places.

The fork with malware embedded could fairly easily apply most commits to the main repo in its public repo.

They could even have support pages that look real, by copying them from the legitimate site.

And the process of creating a repo that stays in sync with another fork can be automated, so, if needed, malware writers likely will do that.

Re: 7zip.com Is Serving Malware

#97
post #15
post #6

7zip.com has never been the official website of the project. It's been 7-zip.org

How can the average 7zip user know which one it is? Search results can be gamed by SEO, there were also cases of malware developers buying ads so links to the malware download show up above legitimate ones. Wikipedia works only for projects prominent enough to have a Wikipedia page. What are the other mechanisms for finding out the official website of a software?

Fails to load for me with: "The page was blocked because of a matching filter in uBlock filters – Badware risks."

Which is enabled by default in uBlock. And installing it is pretty much a standard suggestion for any web user.

Re: 7zip.com Is Serving Malware

#98
The only solutions for the malicious domain would be lawsuits or hactivism. As others have said it is blocked in uBlock by default which everyone should be using at a bare minimum.

Re: 7zip.com Is Serving Malware

#99

Earlier quoted context omitted.

How would you ensure that the "average user" actually gets to the page he expects to get to? There are risks in everything you do. If the average user doesn't know where the application he wants to download _actually_ comes from then maybe the average user shouldn't use the internet at all?

> How would you ensure that the "average user" actually gets to the page he expects to get to? I think you practically can't and that's the problem. TLS doesn't help with figuring out which page is the real one, EV certs never really caught on and most financial incentives make such mechanisms unviable. Same for additional sources of information like Wikipedia, since that just shifts the burden of combatting misinfor…

> People die in car crashes. We can't eliminate those altogether, but at least we can take steps towards making things better, instead of telling them that maybe they should just not drive. Tough problems regardless.

I agree with the sentiment but there are limits to what we can and should do. To stay with your analogy: We don't let people drive around without taking a test. In that test they have to prove that they know the basics of how to drive a car. At least where I come from that means learning quite a bit of rules and regulations.

In other words: Don't let people off the hook. They need to do some form of learning by themselves. It's no different with what you do on the internet. If you're not willing to do some kind of work to familiarize yourself with how the bloody thing work then it's not the job of everyone else to make sure you'll be okay. It's _your_ job to understand the basics.

I'm getting tired of just another thing we must take off peoples minds so that they can "just" use whatever they want to use. Don't try to blame (or god forbid sue) someone else because you didn't do your homework.

Re: 7zip.com Is Serving Malware

#100

Earlier quoted context omitted.

> How would you ensure that the "average user" actually gets to the page he expects to get to? I think you practically can't and that's the problem. TLS doesn't help with figuring out which page is the real one, EV certs never really caught on and most financial incentives make such mechanisms unviable. Same for additional sources of information like Wikipedia, since that just shifts the burden of combatting misinfor…

> People die in car crashes. We can't eliminate those altogether, but at least we can take steps towards making things better, instead of telling them that maybe they should just not drive. Tough problems regardless. I agree with the sentiment but there are limits to what we can and should do. To stay with your analogy: We don't let people drive around without taking a test. In that test they have to prove that they…

> It's _your_ job to understand the basics

I feel like this line of thinking is dangerous: people hit the wall hard when they don’t have sex ed, or financial education classes, or even basic classes on how to cook or do crafts (we had those in school, girls mostly cooked and the guys got to learn woodworking but also swapped sometimes; and later in university there were classes about work safety in general), or computer literacy classes.

I think a lot of people don’t even have basic mental models of how OSes or the Internet works, what a web browser is (“the Google”) and so on.

Saying that they should know that stuff won’t change the fact that they don’t unless you teach them as a part of their overall education.

Post reply on HN