9 ms·
Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive
by CyberScarecrow 2y ago
Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive for windows. Smartscreen also triggers when you install it. Id be weary of installing it myself as well, especially considering it runs as admin, to be able to create the fake indicators.
I have just added a bit of info about us on the website. I'm not sure what else we can do really. Its a trust thing, same with any software and AV vendors.
- Z7YCx5ieof4Std 2y agoIs it possible to fake being from Russia. I heard some malware won't install on computers from Russia or with the Russian language as primary language
- CyberScarecrow 2y agoGreat idea. Looking at installing an additional keyboard or language with out it being anoying to the user is next on the feature list.
- llama_drama 2y agoThis might be not a good idea. There are some reports of malware (npm packages, iirc) specifically targeting russian computers since the invasion
- n2d4 2y agoThis can have the opposite effect too: https://arstechnica.com/information-technology/2022/03/sabotage-code-added-to-popular-npm-package-wiped-files-in-russia-and-belarus/ https://arstechnica.com/information-technology/2022/03/sabot...
- kozak 2y agoAnd be targeted by cyberwarfare from the first-world side.
- DougN7 2y agoOr has the Russian keyboard installed, even if not used IIRC.
- whaleofatw2022 2y agoRussia has serious penalties for hacking their citizens. Not for hacking non citizens
- kiney 2y agoNot very convincing tbh. Theres's no source code and no real name or company on the website...
- efilife 2y agoIt ceases to be a trust thing once you open source the code
- wongarsu 2y agoIn a world where everybody builds from source or downloads from a trusted build service
- shadowgovt 2y ago... and trusts their entire toolchain hasn't been compromised.
- deleted 2y ago[deleted]
- beeboobaa3 2y agogithub link? if it's not open source it's dead on arrival
- wasteduniverse 2y ago[dead]
- AnthonyMouse 2y ago> We also dont have a code signing certificate yet either, they are expensive for windows. When someone is offering you a certificate and the only thing you have to do in order to get it is pay them a significant amount of money, that's a major red flag that it's either a scam or you're being extorted. Or both. In any case you should not pay them and neither should anyone else.
- hluska 2y agoThere’s an audit to go through where you (sort of) prove who you are. The system isn’t great, but if you can come up with something better there’s a lot of space to make software more secure for people.
- DougN7 2y agoBesides paying money you also go through a (pretty simplistic) audit. It’s about the only way we have to know who published some code, which is important. If you can come up with a better way you should implement it and we’ll all follow. As a side note, I’ve been trying to figure out how to get an EV code signing cert that isn’t tied to me (want to make a tool Microsoft won’t like and don’t want retaliation to hurt my business) but I haven’t come up with a way to do it - which is a good thing I suppose.
- hunter2_ 2y agoCan you have someone else go through the process of getting it, like a Craigslist rando to whom you pay cash?
- wongarsu 2y agoIf said Craigslist rando likes getting police visits and potentially being criminally liable for helping you commit a felony ... All code signing promises to give you the name of a real person or company that signed the binary. From there it's the end user's responsibility to decide if they trust that entity. In practice the threat of the justice system makes any signed executable unlikely to be malicious. But that doesn't mean you have to uncritically trust a binary signed by Joe Hobo
- yamakadi 2y agoI’m sure it’s closed source for the eventual plans to monetize it, but what’s the real difference to something like https://github.com/NavyTitanium/Fake-Sandbox-Artifacts https://github.com/NavyTitanium/Fake-Sandbox-Artifacts and why can’t you at least name yourselves? Not many software promises to fend off attackers, asks for an email address before download, and creates a bunch of processes using a closed source dll the existence of which can easily be checked. Then again, not many malware targeting consumers at random check for security software. You are more likely to see a malware stop working if you fake the amount of ram and cpu and your network driver vendor than if you have CrowdStrike, etc. running.
- mistercheph 2y agoI am pretty sure this is just malware being upvoted with sockpuppet accounts, I'm surprised it hasn't been flagged.
- twixfel 2y agoThere are things that you can do that make you seem trustworthy, and you've done none of them.
- hyperific 2y agoSomething that would have built trust with me that I didn't find on the site was any mention of success rate. Surely CyberScarecrow has been tested against known malware to see if the process successfully thwarts an attack.
- px43 2y agoObviously this should be an open source tool that people can build for themselves. If you want to sell premium services or upgrades for it later, you need to have an open/free tier as well. Also are you aware of the (very awesome) EDR evasion toolkit called scarecrow? Naming stuff is hard, I get that, but this collision is a bit much IMO. https://github.com/Tylous/ScareCrow https://github.com/Tylous/ScareCrow
- bryant 2y agoIt's a neat concept, although I imagine this'll be a cat and mouse endeavor that escalates very quickly. So, a suggestion - apply to the Open Technology Fund's Rapid Response Fund. I'd probably request the following in your position: * code signing certificate funding * consulting/assessment to harden the application or concept itself as well as to make it more robust (they'll probably route through Cure53) * consulting/engineering to solve for the "malware detects this executable and decides that the other indicators can be ignored" problem, or consulting more generally on how to do this in a way that's more resilient. If you wanted to fund this in some way without necessarily doing the typical founder slog, might make sense to 501c3 in the US and then get funded by or license this to security tooling manufacturers so that it can be embedded into security tools, or to research the model with funding from across the security industry so that the allergic reaction by malware groups to security tooling can be exploited more systemically. I imagine the final state of this effort might be that security companies could be willing to license decoy versions of their toolkits to everyone that are bitwise identical to actual running versions but then activate production functionality with the right key.
- sangnoir 2y ago> consulting/engineering to solve for the "malware detects this executable and decides that the other indicators can be ignored" problem, or consulting more generally on how to do this in a way that's more resilient. This would be a boon for security folk who analyze/reverse malware: they can add/simulate this tool in their VMs to ensure the malware being analyzed doesn't deactivate itself!
- CodeWriter23 2y ago> decoy versions of their toolkits to everyone that are bitwise identical to actual running versions but then activate production functionality with the right key I kinda think this functionality could be subverted into a kill switch for legit-licensed installs simply by altering the key.
- eganist 2y agoI mean, the existing licensing mechanisms can be similarly abused.
- rft 2y agoConcerning code signing: Azure has a somewhat new offering that allows you to sign code for Windows (SmartScreen compatible) without having an EV cert. It is called "Trusted Signing" [1], non-marketing docs [2]. The major gotcha is that currently you need to have a company or similar entity 3 years or older to get public trust. I tried it with a company younger than 3 years and was denied. You might have a company that fits that criteria or you might get lucky. The major upside is the pricing: currently "free" [3] during testing, later about 10 USD/month. As there doesn't seem to be a revocation mechanism based on some docs I read, signed binaries might be valid even after a canceled subscription. [1] https://azure.microsoft.com/en-us/products/trusted-signing https://azure.microsoft.com/en-us/products/trusted-signing [2] https://learn.microsoft.com/en-us/azure/trusted-signing/quickstart?tabs=registerrp-portal%2Caccount-portal%2Ccertificateprofile-portal%2Cdeleteresources-portal https://learn.microsoft.com/en-us/azure/trusted-signing/quic... [3] You need a CC and they will likely charge you at some point. Also I had to use some kind of business Azure/MS 365 account which costs about 5 USD/month. Not sure about the exact lingo, not an Azure/MS expert. The docs in [2] was enough for me to get through the process.
- Tepix 2y agoSo $10+$5 per month versus $195 per year? That's not a big discount.
- jagged-chisel 2y ago64% is indeed a hefty discount
- jonplackett 2y agoI have no idea of the costs but I am confused where that percentage came from. It doesn’t match anything not the parent comment.
- jrflowers 2y agoWhat percentage of 195 is 70?
- housebear 2y agoWhere is that additional info? It just says you're a group of security researchers, but there are no names, no verifiable credentials, nothing. You haven't really added any info that would contribute to any real trust.
- archon810 2y agoExactly. This continues to tell us absolutely nothing. "Who are you? We are cyber security researchers, living in the UK. We built cyber scarecrow to run on our own computers and decided to share it for others to use it too."
- notreallyauser 2y agoYou're collecting personal info and claiming to be in the UK: identifying the data controller would be a start, both for building trust and complying with GDPR.
- peter_l_downs 2y agoOne more thing you could do is put the real name of any human being with any track record of professionalism, anywhere on the website. Currently you're: - commenting under a pseudonymous profile - asking for emails by saying "please email me. contact at cyberscarecrow.com" - describing yourself in your FAQ entry for "Who are you?" by writing "We are cyber security researchers, living in the UK. We built cyber scarecrow to run on our own computers and decided to share it for others to use it too." I frequently use pseudonymous profiles for various things but they are NOT a good way to establish trust.
- bzmrgonz 2y agoHow are you planning on preventing bad actors to identify scarecrow itself? You gonna randomize the name/processes etc?? Like anti-malware software do to install in stealth-mode??
- deleted 2y ago[deleted]
- IncognitoEntity 2y agoI'd suggest putting down the actual authors. If you're UK based there should really be no issue in putting down each of the people involved and what their background in the industry is. Otherwise this just looks like a v1 to get people interested and v2 could include malware. Tbh it'd be quite a clever ploy if it is malware. Trust isn't built blindly, most smaller software creators always have their details known. I'd suggest if you want it to pick up traction, you have a full "about us" page.