9 ms·
CNET Injecting Malware into Downloads
- risource 15y agoCNET was a very tested brand in its day.
- deleted 15y ago[deleted]
- iamandrus 15y agoI remember back in 2006 when the Download.com logo had "Safe, Trusted, and Spyware-Free" under it. EDIT: Picture. http://www.crunchbase.com/assets/images/original/0000/5821/5821v1.png http://www.crunchbase.com/assets/images/original/0000/5821/5...
- DanBC 15y agoPrevious post was mentioned on HN (http://news.ycombinator.com/item?id=3317121 http://news.ycombinator.com/item?id=3317121)
- chalst 15y agoThere was also a report in late August, when I think CNET started the practice: http://news.ycombinator.com/item?id=2910554 http://news.ycombinator.com/item?id=2910554 The list of news reports on seclist.org's page justifies the new story. I guess that this will get mainstream coverage soon.
- skitzzo 15y agoYeah, I guess I wasn't paying enough attention but this was the first I'd heard of it.
- rbanffy 15y agoWhen my mother forwards me the latest malware scare chain letter she got frm her friends, I tell her to picture her computer as a plane flying at Mach 4, high above in the stratosphere, confident almost nothing launched from the ground can harm her. That's because she doesn't use Windows.
- karolist 15y agoBut this is ignorant and not true.
- kajecounterhack 15y agoFor laymen's purposes it pretty much is, though. When was the last time anyone on Linux/OSX got some adware / popups? I've also never heard of antivirus for Linux. Which doesn't mean there aren't viruses, it means it's not a concern on the most part.
- blub 15y ago"For laymen's purposes it pretty much is, though. When was the last time anyone on Linux/OSX got some adware / popups?" For OS X, one or two months ago. Do a web search, the times are changing for Mac security. "I've also never heard of antivirus for Linux. Which doesn't mean there aren't viruses, it means it's not a concern on the most part." No, it just means it's not your concern. When online crime has become a business, it makes sense to try to protect yourself. Major AV companies have a product for Linux.
- maqr 15y agohttp://www.clamav.net/ http://www.clamav.net/ if you were actually wondering. There's also a sweet osx port: http://www.clamxav.com/ http://www.clamxav.com/
- rbanffy 15y agoDid you ever catch something with it?
- easy_rider 15y agoCNET was the top choice for me back 10-12 years ago whenever i wanted to download a utility / piece of freeware/shareware. Of course when their market share went down... they had to change their business-model...This is just the next step after bloating their pages with ads. I'm guessing that not the same people are in charge as those who were in their glory days:_)
- Georgiy 15y agoI'm surprised software catalogs are still alive :D Especially when you can get literally everything you need from torrents with keygens/cracks.
- suprgeek 15y agoWhat good alternatives would people suggest? What should be the "goto" site we could suggest to a novice for finding a clean copy of almost any software...any suggestions? (Assuming that an expert user would straight to the source website)
- nik61 15y agoFilehippo may be clean, if with less coverage?
- Deestan 15y agoAny good "goto" site won't stay that way for long, because it will automatically have strong incentives to try tons of stupid crap like this. But you can use these sites for software lookup. Then you check the listed developer name, Bing your way onto their website, and look for a download link.
- monochromatic 15y agoBing? What happened, did some malware install a Bing toolbar on your computer or something? :)
- blub 15y agoThe software producer's website is the only safe place.
- suprgeek 15y agoTrue but when you want to suggest to a novice "Why don't you use "X" " It is unrealistic to expect them to search for X in Google, go to the appropriate link of X's creator, figure out the right page to download it from. Instead - Go to filehippo search for X in the big search bar at top - download first result - is a much easier workflow. (Trust me on this one - I tech support about 6 relatives)
- gus_massa 15y agoIf you download something from the programmer page it is impossible to be sure that it has no spyware/crazy-toolbars/whatever. Some time ago, if you download it from download.com you know that it was safe.
- forcer 15y ago"This is probably why CNET switch to installing the Babylon Toolbar yesterday. This is a good and welcome move by Microsoft, but the whole process of paying “distribution partners“ to changer user's home page to MSN and search engine to Bing is rather sketchy" I am puzzled by the reaction of some journalists and people here. Have you actually thought why the toolbar is marked as malware? Usually, that's because one guy in one of the AV companies installed the toolbar, didn't like it and so put a flag on. Malware as a definition is something that does harm to your computer. We could argue whether this is actually the case as most of the toolbars, including StartNow just provide search functionality and homepage reset - this is how they make money - there is no reason to do anything sketchy on top of that. I am not trying to defend toolbar companies here but the quote above that its actually a good thing to replace StartNow with Babylon is misinforming the public. These toolbars all do the same thing and they should either be marked all by AV companies or not. Of course its never gonna happen because there are some AV companies that won't flag toolbars because hey - they distribute toolbars too!
- deleted 15y ago[deleted]
- Georgiy 15y agoEverything on CNET is being tested manually with VirusTotal. If it gets at least 4 positives/false positives from 43 antivirus engines they don't publish it or work with it, until developers get things settled down with anti-virus/anti-malware companies. They get not that much profit from paid accounts cause of small percentage of subscribers, and give away tons of traffic + man hours even for free products. That includes manual testing, checking and writing descriptions, reviewing, and that repeats for each update. And lots of companies update their products like 10 times a week, just to get bumped in search, or create like 20 versions of 1 program under different names, especially Chinese developers. So they just monetizing traffic and stimulating developers to get subscriptions to remove ad for their products. I personally hate all kind of that toolbar stuff, but hey, there are not so many ways to promote an alternative search engines that work for free.
- eslachance 15y ago
- dendory 15y agoThere's three things here. First, adding a toolbar and screwing with user settings is freaking lame, but everyone does it and it's something that's been an accepted way to monitize software development. However, injecting that into other people's software is low, especially if the developers aren't aware of it. CNET should be ashame. Lastly, the way they present it to users should be plainly criminal. There's a way to offer additional programs, and that's with a checkbox. The screenshot they show is CLEARLY meant to confuse users, whereas even I would have clicked next hadn't I seen the circled text. On this point CNET should be sued for deceptive tactics, because they put NMAP (or the name of whatever you downloaded) as the title, and present buttons that are meant to deceive, making it seem like it's NMAP's own EULA.
- Zirro 15y ago"but everyone does it and it's something that's been an accepted way to monitize software development" No piece of software that I have installed during the past two years has done so, and I sure wouldn't accept it as a way of funding development. I'd rather pay for a product in that case. Can you give a few examples from your list of "everyone"?
- colkassad 15y agoI think the Java runtime installer asks to install a toolbar. There is something else that I can't recall (flash runtime?) that asks to install the Ask.com toolbar all the time as well. Some popular open source projects too (PDFCreator).
- marshray 15y agoHahaha, Sun/Oracle does it, therefore it's OK. Ask me why I quit Java long ago.
- kermitthehermit 15y agoThe flash download page asks you if you want to install an antivirus, I believe it's mcafee. It's funny, though, that I encountered a "not so bright" person who simply told me "oh, I didn't know you could opt out, I was always uninstalling it afterwards". You can also block the ask toolbar from downloading by killing toolbar.ask.com or the entire ask.com domain. It most certainly will not be missed.
- jiggy2011 15y agoWhen it comes for Windows software I only use 2 types, Open source software downloaded from the projects website directly or fully paid up commercial software. I never install anything from ad banners
- AlekseyKorzun 15y agoClass action by software developers in 3..2..1
- potatolicious 15y agoIt's funny seeing this posted so soon after "Don't be a Free User"...
- forcer 15y agoPress release from the CNET few minutes ago: A note from Sean Download.com Developer Community, My last communication to you was shortly after we launched the Download.com Installer in late summer. At that time I asked for patience as we began work to deliver a mutually beneficial model to market. We are on the verge of fulfilling our vision of coming to market with an installer model that delivers files faster and more efficiently to users, while enabling developers to a) opt-in to the Installer, b) influence the offers tied to their files, c) gain reporting insight into the download funnel, and d) share in the revenue generated by the installer. However, due to some press that surfaced yesterday and the potential for subsequent misinformation, I am reaching out now to address that press and to provide a progress report on the upcoming launch: First, on the press that surfaced yesterday: a developer expressed anger and frustration about our current model and how his file was being bundled. This was a mistake on our part and we apologize to the developer and user communities for the unrest it caused. As a rule, we do not bundle open source software and in addition to taking this developers file out of the installer flow, we have gone in and re-checked all open source files in our catalog. We take feedback from our developer & user communities very seriously and take pains to both act on it and respond in a timely manner. With that, I want to share progress made thus far: This week we will launch the alpha phase of our new installer. This alpha phase is intended to test the tech and do QA, and will roll through the next few weeks to ensure that our installer is bug free. Between this week and the end of January we will be completing the necessary engineering and administrative work to roll out our beta, which will include a small group of developers who've agreed to participate in the beta launch. Our goal is to exit beta by end of February and have the necessary systems in place to enable opt-in, influence over advertising offers (for those offers that impact your product), download funnel reporting and revenue share back to you, the developers. In the weeks/months following the full release, we will continue to iterate on the model, adding more features to the Installer and bringing greater efficiency to our own download funnel (read: increased install conversion). The initial feedback from developers on our new model has been very positive and we are excited to bring this to the broader community as soon as possible. More communication will follow as we move into Q1, and until then, thank you for continuing to work with Download.com. Sincerely, -- Sean
- kermitthehermit 15y ago