Author Topic: What anti-malware products cannot be longer trusted through media manipulation?  (Read 2427 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Quote
Browser companies (Mozilla, Google, Microsoft) limit the usage of Toolbars and browser extension. Soon users will only be able to install extensions approved by Google on Chrome. This has led to media companies to adapt with an almost certain loss of revenues, at an attempt to comply with new challenging regulations. Happily Komodia can help with these challenges via the ad injection SDK. Additionally supporting Safari and Opera, two browsers that are not monetize by current plugins solutions.
quote from article by https://blog.malwarebytes.org/author/jeromesegura/

My question what anti-malware vendors have been abusing such schemes in their cloud technology.
I know now some Bitdefender programns fell through, as did Lenovo, Ad-aware. What companies are also into intercepting content via https, the certificate stays behind  as the app is being removed.

Simple who can still be trusted online, as Google browser already was stripped of certificate revocation checking in 2012.
Did they know what was coming: http://arstechnica.com/business/2012/02/google-strips-chrome-of-ssl-revocation-checking/
 
I think this is undermining end-user trust. Anyone?

polonus
« Last Edit: March 01, 2015, 06:42:11 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
There is a utility program for downloading and dumping the current Chrome CRLSet: https://github.com/agl/crlset-tools
This in the light of what we may read here, (article author = Adrian Dimcev) ->
http://www.carbonwind.net/blog/post/Inside-Google%E2%80%99s-pushing-revocation-list-approach.aspx

Also read: https://www.eff.org/deeplinks/2015/02/dear-software-vendors-please-stop-trying-intercept-your-customers-encrypted

This is what firefox plans: https://wiki.mozilla.org/CA:RevocationPlan

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Myself I would never use Chrome as it is becoming very easy to subvert.  Note the number of instances where I have asked for Chrome to be uninstalled whilst I fix the problems... The main one is developer mode

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Im using Chrome and its pretty much borked with one of the last updates.

But never had big issues like these before.

I might go back to IE/Spartan later down the road.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Hi essexboy and Steven Winderlich,

That is why I switched to Sleipnir6,  because I can have my favorite Chrome extensions there as well without this apparent  chrome developer manipulation. Google Chrome bended the browser curves quite a bit, because of their main revenue stream interests, while IE, because of incompatibilty of their earlier browser versions, sticked with old(er) technology and did not adopt new more secure technology in an attempt to please all global users' experience. So we find ourselves in between Scylla and Charybdis, and how to steer clear of Gibraltar then (read your classics, it is very actual sometimes) ;D

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Here I stumbled upon that google chrome bork- the proof of the pudding is always in the eating":
https://groups.google.com/a/chromium.org/forum/#!topic/chromium-os-dev/hT1ZTMPac-M
and the solution: https://codereview.chromium.org/239553004/

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!