4 ms·
How does anyone trust software uploaded to the Internet Archive?
by moremetadata 4y ago
How does anyone trust software uploaded to the Internet Archive?
- Incipient 4y agoAny evidence to suggest we shouldn't?
- Joel_Mckay 4y agoI also encountered some nastiness looking for 30 year old x86 drivers for a project. If you can't find the CD hash signature, than all bets are off. Not Archive.org fault either, as most issues were on the original CDs too. =)
- moremetadata 4y ago> CD hash signature How do you know the CD Hash Sig is genuine though? I see this with hash values on websites next to ISO and other files. Its like a really blatant confidence trick when you can pull one of those off!
- TeMPOraL 4y ago> How do you know the CD Hash Sig is genuine though? You don't, unless you trust the source of it, or supply your own. > I see this with hash values on websites next to ISO and other files. This doesn't solve the problem you have in mind - verifying the file is genuine; it solves the problem of verifying that what you got is what you expected, i.e. what the site promised. The hash is there so you can detect download errors (used to be a much more frequent thing than it is now). Secondarily, because the files usually sit on a different server than the site itself, the hash lets you detect some cases of your download being tampered with in-flight, or the file itself altered on the server. Not all of such cases, just those where the attacker could affect the download, but couldn't modify the website itself.
- moremetadata 4y ago> This doesn't solve the problem you have in mind - verifying the file is genuine; it solves the problem of verifying that what you got is what you expected Exactly. > Secondarily, because the files usually sit on a different server than the site itself, the hash lets you detect some cases of your download being tampered with in-flight, or the file itself altered on the server. That assumes the download file is on a different webserver, but if they can gain access to one server, its not beyond the realms of possibility they can alter the hash values on another webserver. I just find all this crypto stuff to be misleading whilst it overstates its effectiveness.
- throwawaylinux 4y agoThose cryptographic hashes that sit on the same sever or are under control of the same group that publish the file itself really came about so you could verify untrusted copies like mirrors and CDs, not data integrity or hacks on the trusted source or a connection to the trusted source.
- Joel_Mckay 4y agoActually, the signed hashes tend to only provide a out-of-band chain of accountability. The old Microsoft signed drivers and Application publishers certs were not perfect. This was because the chain of trust eventually breaks down in time (insufficient strength, leaked signing key re-pack, and most people didn't check installer signatures). FOSS projects can also suffer integrity rot on rare occasion, but it tends to be individuals feigning ignorance as their BS is reverted. Archive.org allows one to often search for the CD hash and files of interest in the Wayback Machines snapshot copy of the publishers website. This method does still require the publishers cert or known hash to verify contents are valid. =)
- Joel_Mckay 4y ago1. well known signature hashes documenting what an non-tampered CD iso should have. 2. you are absolutely correct in that old software sometime comes infested with known malware/virus... however one also needs to acknowledge it was often in the original files too (Sony root kit etc.) 3. 86box is slow, but can contain most nastiness that came with old PC games =)
- irjustin 4y agoI don't understand this statement. Are you trying to use banking-software-2002.exe file to transfer a balance? The IA is a best effort (and a damned good one too) and so if I want to get Commander Keen running again I can! I still run it in VM/Emulation/whatever isolation. Do YOU have Commander Keen available, fully vetted on your trusted archive platform?
- haunter 4y ago> Do YOU have Commander Keen available, fully vetted on your trusted archive platform? You can still buy it. DRM free, runs on modern PCs. And hey no malware included! https://www.gog.com/en/game/commander_keen_complete_pack https://www.gog.com/en/game/commander_keen_complete_pack Edit: I have it on Steam and just tried that version is DRM free too https://store.steampowered.com/app/9180/Commander_Keen/ https://store.steampowered.com/app/9180/Commander_Keen/
- exitb 4y agoThe comments indicate that it's incomplete, which isn't surprising, as GOG is not an archive platform and shouldn't be treated as one.
- notafraudster 4y agoIt is incomplete. There are 7 Commander Keen core games: a trilogy (Invasion of the Vorticons, Keen 1-3), a duology (Goodbye, Galaxy, Keen 4-5), and two standalone games (Aliens Ate My Babysitter, Keen 6 and Keen Dreams, Keen 3.5). The complete pack includes Invasion of the Vorticons and Goodbye, Galaxy, which gives you five of the seven. Aliens Ate My Babysitter has never been commercially rereleased and is owned by Softdisk, not iD Software Keen Dreams was -- believe it or not -- bought at auction by a kid named Javier Chavez who didn't know anything about programming or games and subsequently got himself permanently banned from Steam after posting a bunch of alt-right political stuff (!) and eventually changing his developer username to contain homophobic insults against the guy who owns Steam. He also released a reskin of the open source Hovertank 3D that changed the plot to be about killing refugees. You can see some documentation of the above (note: obviously this has insults, slurs, homophobia, insulting people by calling them Jews, etc.) https://twitter.com/dosnostalgic/status/1100869421336268813 https://twitter.com/dosnostalgic/status/1141540162679316481 https://twitter.com/dosnostalgic/status/1145771721162723328 https://twitter.com/dosnostalgic/status/1344739372105654273 https://twitter.com/dosnostalgic/status/1437721497221713923 https://twitter.com/dosnostalgic/status/1437723155704029185 Anyway, after he was banned from Steam, the company Nightdive Studios initially reached an agreement with him to transfer ownership to them. They released a more technically polished version on Steam. At some point he began to contest their licensing arrangement and he had the game pulled again. There is a Switch release licensed by him. If you want to buy Keen Dreams from him, you can do so at https://www.keendreams.com/ https://www.keendreams.com/, knowing you are giving money to the person I described above. You might notice that the "About us" page reads "We’re a small team of independent devs with a huge liking for older and unappreciated games, who took it upon us to re-release them to new players to enjoy! Look out for our releasr of Keen Dreams soon to be succeeded by more!" or that the main page features an incredibly JPEG artifacted low resolution image of the title screen and other gems like "Commander Keen keen dreams was considered the “lost episode” of Commander Keen, a franchise of 2d side scrolling games developed by id software decades ago." [sic] or "Smooth as butter 60fps gameplay, after all 30fps that’s so next gen consoles…" [sic] So, that's the sad fate of Keen Dreams.
- boomboomsubban 4y agoAt least they clearly label their malware https://archive.org/details/malwaremuseum https://archive.org/details/malwaremuseum
- slackdog 4y agoA lot of the old software they host can be run in an emulator in your browser. I don't think there's much cause for concern in these cases. Doom via in-browser DOSBox: https://archive.org/details/doom-play https://archive.org/details/doom-play
- guipsp 4y agohttps://datomatic.no-intro.org/index.php?page=search&s=64 https://datomatic.no-intro.org/index.php?page=search&s=64
- causi 4y agoI'd put five bucks on the average piece of software uploaded to the IA being less harmful to my computer than the average Windows update.