Live data from Hacker News

Cyber Scarecrow

cyberscarecrow.com

1–10 of 253 posts

Re: Cyber Scarecrow

#3

If you're going to go through the effort of faking honeypot/analysis tools, why not just run them?

Costs a lot of cycles to run those for real, and it’s not super common to get infected with anything, so you’re wasting cycles for a small chance at avoiding it. This could be better since, I assume, it doesn’t do a lot of stuff.

Re: Cyber Scarecrow

#4
Fun concept.

If the creators read this, I suggest some ways of building trust. There’s no “about us”, no GitHub link, etc. It’s a random webpage that wants my personal details, and sends me a “exe”. The overlap of people who understand what this tool does, and people who would run that “exe” is pretty small.

Re: Cyber Scarecrow

#5
Isn't the risk then that they'll first start scanning for "Scarecrow", or is that hidden somehow?

Also somewhat surprised the source isn't available. That makes trusting it harder, especially to the people it's aimed at.

Re: Cyber Scarecrow

#6
When is Scarecrow Advanced++ with NextGen Anti-Detection and Cloaking will be released?

Jokes aside, this is a temporary fix at best, a waste of resources and impression of safety at worst.

Re: Cyber Scarecrow

#7
I would assume there would be a small intersection of people that would download and install a windows program from an unknown web page and those that are worried about malware.

But perhaps I'm wrong

Re: Cyber Scarecrow

#9
Narrator: and so the arms race continues.

I guess if this gets enough attention, malware will just add more sophisticated checks and not just look at the exe name.

But on that note, I wondered the same thing at my last workplace where we'd only run windows in virtual machines. Sometimes these were quite outdated regarding system and browser updates, and some non-tech staff used them to browse random websites. They were never hit by any crypto malware and whatnot, which surprised me a lot at first, but at some point I realized the first thing you do as even a halfway decent malware author is checking whether you run in a virtualized environment.

Re: Cyber Scarecrow

#10
post #5

Isn't the risk then that they'll first start scanning for "Scarecrow", or is that hidden somehow? Also somewhat surprised the source isn't available. That makes trusting it harder, especially to the people it's aimed at.

Well then you just need to put scarecrow on your honeypot boxes.
Post reply on HN