3 ms·
To our new generation of human shields willing to use software releases less than a month old, we salute your sacrifice.
by jl6 6mo ago
To our new generation of human shields willing to use software releases less than a month old, we salute your sacrifice.
- deleted 6mo ago[deleted]
- mikestorrent 6mo agoIs there a tool out there that you can put software releases into and it will tell you how safe it is? I don't seem to be able to buy anything to do this. Crowdstrike and other modern antivirus may react to it once it's on a device, SAST / SCA tooling will help with CVEs, but there's nothing I can give my users where they can put in some piece of random software and get a reputation metric out the other side, is there?
- Foobar8568 6mo agoBeside Virus Total, I am unsure https://www.virustotal.com/ https://www.virustotal.com/
- mikestorrent 6mo agoThanks, that's helpful
- __natty__ 6mo agoNot exactly for software (although there is such section) but I use end of life [0] website. Besides time when certain software will be outdated it also tells you their release time. [0] https://endoflife.date/ https://endoflife.date/
- seanw444 6mo agoYou could put it into an LLM, since that's what we do for everything else nowadays.
- vladvasiliu 6mo ago> put in some piece of random software and get a reputation metric out the other side Well, the enterprise version of ms defender will not only react to it if it does something "weird", but will specifically look at its "reputation" before it runs at all. However, as another commenter pointed out, this generates a ton of false positives. Basically everything that's "brand new" is liable to trigger it. Think your freshly compiled hellow_world.exe. So, all in all, people may no longer pay attention to it and just click through all warnings.
- tranceylc 6mo agoWorked on a minecraft clone on steam that would falsely get flagged by defender as a “bitcoin miner” for YEARS.
- DarkUranium 6mo agoWell, they got one half of that label right...
- JohnTHaller 6mo agoI run software downloads through VirusTotal before installing or using. And I scan all releases I make on PortableApps.com through it as well. (Except those that are bigger than the max size in which case those get scanned with Defender, ClamAV, and at least one commercial Windows antivirus.)
- sourcegrift 6mo agoThanks the web that produced css programmers who have been taught latest is greatest and shiny gets money.
- leptons 6mo ago"new, shiny" has never been a problem with CSS. Either browsers support some CSS attribute or they don't. You're probably thinking about Javascript programmers.
- layer8 6mo agoI’m not one to chase the new and shiny, but how do you know a nominally months-old software package isn’t a newly compromised version at the time you download it?
- jeremie_strand 6mo ago[dead]
- herecomesthepre 6mo agoWindows has this thing called digital signing with certificates that Linux users like to pretend doesn't exist or in the case of yesterday's Wireguard / VeraCrypt discussion, think it's an evil capitalist scheme to control the world. Digital signing on Windows predates Mac developer certificates by years but arguably wasn't widely used outside of security-paranoid organizations. Before someone says Linux offers GPG signing it's mostly useless without a central PKI. Developers offer the public key for download on the same server as the software. If someone uploaded compromised software, surely they would replace the key with their own.
- badsectoracula 6mo ago> Windows has this thing called digital signing with certificates that Linux users like to pretend doesn't exist ...or, much more likely, any potential benefits are not worth the negatives.
- BenjiWiebe 6mo agoLinux package managers (the normal way to install software) use signed packages. I don't know how easy/hard it would be to compromise that.
- steve1977 6mo ago> Before someone says Linux offers GPG signing it's mostly useless without a central PKI One could also argue that GPG signing is useful exactly because it doesn't rely on a central PKI.
- leptons 6mo agoI hope you don't think that waiting a month will protect you. Malicious software can wait to be triggered months or years before anything malicious happens.
- BenjiWiebe 6mo agoIt helps. If I were a malware/backdoor author, I have the choice to make it lie idle for a couple months; this would help me get more victims, BUT it gives more time for someone to notice it BEFORE I get any victims at all. Whereas if it is active immediately, I'm likely to get at least a few victims.
- xandrius 6mo agoNot fair take, cpuz and hwmonitor are often used on new installations of PCs (or at least for me) to verify hw specs and stuff. Or when I need to do some upgrade work for a desktop computer. I just go to the trusted site, download what's there and get going. This is not an npm package that a dev is updating on day 0 of its release for being a "human shield", it's literally the first version which comes up when DLing the new software.
- saltcured 6mo agoSeems like the kind of thing to just have on a bootable thumb drive, to inspect any machine without requiring installation on the fly. In fact, I think I used to use memtest86+ this way as it is a baked in boot option on Fedora bootable ISO images. (Or at least was in the past, I haven't checked this recently.)
- avazhi 6mo agoCPU-Z gets updated to recognise new CPUs and memory configs and thus must be downloaded new to recognise the new hardware in a new machine (otherwise it can’t recognise it properly). With Memtest sure but CPU-Z is something you actually need the latest version of when you first fire up a new PC.
- saltcured 6mo agoOK, so a bootable thumb drive rather than a read-only ISO image? I mean, it should be possible to give it an update function which you can run from any utility host, rather than requiring a live install at the moment you want to test a new machine. That update function could do normal package management and repository things with digital signature checks, etc. And it could be done ahead of time to support sneaker-net scenarios, i.e. where you won't have networking on the new machine that is being burned-in/validated.