4 ms·
Didn't this also happen somewhat recently? How can this be prevented? The window could be reduced by actively monitoring mirrors? Could BitTorrent help mitig
by nnutter 9y ago
Didn't this also happen somewhat recently? How can this be prevented? The window could be reduced by actively monitoring mirrors? Could BitTorrent help mitigate this because the torrent file validates data and isn't under the control of the parties?
- zalmoxes 9y agoThis could have been prevented by hosting downloads on a reputable site(Github), instead of developer's own PHP backend. Software like https://github.com/google/santa https://github.com/google/santa can help, especially if you're doing IT in a large enterprise. The feed used by the software's autoupdate framework(sparkle) was signed, so that would've prevented bad downloads through autoupdate.
- 21 9y agoHosting on GitHub solves one problem, but creates another. Chrome for example has a sort of a bloom filter which is used to check all downloaded executables. This will raise a nasty warning if the thing you downloaded is not a "popular" download. For obvious reason, this check is disabled for a bunch of sites, like github, sf, ... I know for a fact that some malware authors host their stuff on GitHub exactly to bypass this Chrome check.
- gaadd33 9y agoDo you have any more info about this? I've downloaded random executables from a lot of unpopular (and in some cases, newly created by me) sites and never seen anything pop up in chrome warning me not to download it.
- 21 9y agoInformation is scarce on this (a little bit of security through obscurity). Here is theirs blog post introducing the feature in 2012: https://chrome.googleblog.com/2012/02/faster-browsing-safer-downloading.html https://chrome.googleblog.com/2012/02/faster-browsing-safer-... > Chrome also does checks on executable files (like ".exe" and ".msi" files). If the executable doesn't match a whitelist, Chrome checks with Google for more information, such as whether the website you're accessing hosts a high number of malicious downloads. At the time I looked at the implementation in the Chrome source code, but I remember that it took me a while to locate it.
- Girlang 9y agoHow is github a reputable site?
- h1d 9y agoIt should be a non centralized solution. Blindly trusting GitHub is a problem when , say, a Chrome extension rewrites the links on GitHub.
- soraminazuki 9y agoUnfortunately not, because even if you trust the distribution platform, you still have to trust the build environment.